Loading ...

Play interactive tourEdit tour

Analysis Report 61b2f50b_by_Libranalysis

Overview

General Information

Sample Name:61b2f50b_by_Libranalysis (renamed file extension from none to exe)
Analysis ID:399791
MD5:61b2f50b1b79f50e074a8d5e05926a4c
SHA1:d4bf226519262da7ea1746dac3d8de7dc0ad7675
SHA256:6bc21092f49a473b0fd4d1e1a77ce5d7e97e961334764b606b7014710fb75466
Infos:

Most interesting Screenshot:

Detection

CryLock
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Found ransom note / readme
Multi AV Scanner detection for submitted file
Sigma detected: Delete shadow copy via WMIC
Yara detected CryLock ransomware
Creates autostart registry keys with suspicious names
Creates files in the recycle bin to hide itself
Deletes shadow drive data (may be related to ransomware)
Drops executable to a common third party application directory
Infects executable files (exe, dll, sys, html)
Machine Learning detection for sample
Spreads via windows shares (copies files to share folders)
Uses bcdedit to modify the Windows boot settings
Uses ping.exe to check the status of other devices and networks
Writes many files with high entropy
Antivirus or Machine Learning detection for unpacked file
Contains capabilities to detect virtual machines
Creates a process in suspended mode (likely to inject code)
Drops PE files
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • 61b2f50b_by_Libranalysis.exe (PID: 6628 cmdline: 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe' MD5: 61B2F50B1B79F50E074A8D5E05926A4C)
    • svcuwq.exe (PID: 6804 cmdline: 'C:\Users\user\appdata\local\temp\svcuwq.exe' MD5: 61B2F50B1B79F50E074A8D5E05926A4C)
      • cmd.exe (PID: 7064 cmdline: 'C:\Windows\System32\cmd.exe' /c 'vssadmin delete shadows /all /quiet' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 7076 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
        • vssadmin.exe (PID: 7148 cmdline: vssadmin delete shadows /all /quiet MD5: 7E30B94672107D3381A1D175CF18C147)
      • cmd.exe (PID: 7084 cmdline: 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 7104 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • cmd.exe (PID: 7112 cmdline: 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE BACKUP -keepVersions:0' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 7160 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • cmd.exe (PID: 4388 cmdline: 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 4400 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
        • WMIC.exe (PID: 5096 cmdline: wmic SHADOWCOPY DELETE MD5: 79A01FCD1C8166C5642F37D1E0FB7BA8)
      • cmd.exe (PID: 5692 cmdline: 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 992 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • cmd.exe (PID: 6220 cmdline: 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures' MD5: F3BDBE3BB6F734E357235F4D5898582D)
        • conhost.exe (PID: 5780 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 6820 cmdline: 'C:\Windows\System32\cmd.exe' /c 'ping 0.0.0.0&del 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe'' MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • conhost.exe (PID: 6836 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • PING.EXE (PID: 6868 cmdline: ping 0.0.0.0 MD5: 70C24A306F768936563ABDADB9CA9108)
  • svcuwq.exe (PID: 7404 cmdline: 'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222' MD5: 61B2F50B1B79F50E074A8D5E05926A4C)
  • svcuwq.exe (PID: 8640 cmdline: 'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222' MD5: 61B2F50B1B79F50E074A8D5E05926A4C)
  • cleanup

Malware Configuration

Threatname: CryLock

{"Extensions": "ods,xar,xlr,xls,xlsb,xlsm,xlsx,xlt,xltm,xltx,asp,accdb,b2,crypt,crypt5,crypt6,crypt7,crypt8,crypt12,dat,db,dbf,dbx,kdc,log,mdb,mdf,sdf,sis,sql,awb,bin,cdi,cdr,css,csv,eap,efx,gam,gbr,ged,gtp,mpp,msc,mts,one,otf,nbk,nbp,ndb,prf,prj,rtp,sav,scppy,sgml,tax2010,tbl,tmp,ts,vcd,xml,xsl,xslt,1cd,epf,erf,^^^,$er,4dd,4dl,accdc,accde,accdr,accdt,accft,adb,ade,adf,adp,alf,ask,btr,cat,cdb,ckp,cma,cpd,crypt9,dacpac,dad,dadiagrams,daschema,db-shm,db-wal,db3,dbc,dbs,dbt,dbv,dcb,dct,dcx,ddl,dlis,dp1,dqy,dsk,dsn,dtsx,dxl,eco,ecx,edb,epim,exb,fcd,fdb,fic,fmp,fmp12,fmpsl,fol,fp3,fp4,fp5,fp7,fpt,frm,gdb,grdb,gwi,hdb,his,ib,idb,ihx,itdb,itw,jet,jtx,kdb,kexi,kexic,kexis,lgc,lwx,maf,maq,mar,marshal,mas,mav,mpd,mrg,mud,mwb,myd,ndf,nnt,nrmlib,ns2,ns3,ns4,nsf,nv,nv2,nwdb,nyf,odb,oqy,ora,orx,owc,p96,p97,pan,pdb,pdm,pnz,qry,qvd,rbf,rctd,rod,rodx,rpd,rsd,sas7bdat,sbf,scx,sdb,sdc,spq,sqlite,sqlite3,sqlitedb,te,teacher,temx,tmd,tps,trc,trm,udb,udl,usr,v12,vis,vpd,vvv,wdb,wmdb,wrk,xdb,xld,xmlff,{pb,~hm,17t,1pe,1ph,3dmdef,3dp,3dr,3dt,3dw,3me,3pe,4dv,4fs,5vw,73c,73l,8xg,8xk,8xs,8xv,a5l,a5w,a65,aam,aao,ab,ab1,ab3,abcd,abi,abkprj,abp,aby,aca,acc,acf,acg,acq,acr,acz,adcp,addism,adi,adif,adt,adu,adv,advs,adx,aes,afe,aff,aft,agd,aggr,aifb,alc,ald,aldf,ali,amb,amc,aml,amm,amsorm,an1,an8,anime,anme,ans,ansym,anx,apalbum,aph,aplibrary,arc,arff,arn,art,as,ashprj,asm,asnd,asr,ast,atf,atomsvc,ats,avc,avhdx,avj,avl,avp,aw,awbr,awdb,awg,azz,azzx,bafl,bar,baserproj,bc,bcc,bci,bcl,bcm,bct,bdc,bdf,bdic,bed,bfx,bgl,bgt,bho,bim,binary,bionix,bjo,bk,blb,bld,blg,bln,blockplt,blogthis,bluebutton,bm2,bms,bnk,bok,book,box,bpd,bpdx,bphys,bpj,bplx,bpm,brain,brd,brf,brl,brn,brs,brw,bsd,bsdl,btf,btif,btinstall,btm,bul,bvp,c3d,c4p,caf,camm,cap,capt,capx,car,cav,cawr,cbg,cbmap,cbz,cca,cch,ccld,ccp,cct,cdf,cdm,cdp,cdpz,cdx,cdxml,cef,cel,celtx,cfa,cfb,cfs,cfx,cgd,chg,chk,chr,cif,circ,ckt,cl2,classlist,clb,cld,clg,clix,clk,clkm,clks,clktk,clkv,clm,clp,clx,cm10,cm5,cmap,cmbl,cml,cmr,cms,cna,col,collab,contact,cpaa,cpf,cpk,cpmz,cptx,cram,crev,crtx,cry,cs,csa,ctb,ctf,ctl,ctm,ctp,ctproject,ctt,ctv,ctv3,cub,cube,cursorfx,curxptheme,cva,cvd,cvn,cwk,cww,cxa,cxd,cxf,cxr,cxt,cyo,cys,czi,czp,da2,daf,dal,dam,dap,das,dbd,dbgsym,dcf,dcl,dcm,dcmd,dcmf,dcpf,dcpr,ddb,ddc,ddcx,ddt,def,deproj,des,det,develve,deviceinfo,dex,dfm,dfproj,dgs,dhcd,dia,dict,dif,dig,dii,dip,dita,ditamap,ditaval,dkt,dl,dlc,dlt,dltemp,dm2,dmc,dmm,dmmx,dmo,dmpr,dmr,dmsp,dna,dng,dockzip,dot,dpb,dpn,dps,dpt,dpx,dr,drf,drl,drscan,dsb,dsc,dsd,dsl,dsx,dsy,dsz,dt,dtd,dtp,dtr,dupeguru,dvb,dvc,dvdproj,dvds,dvo,dwi,dws,e2p,eas,ebm,ebuild,ec0,ec3,ec4,ecc,ecl,ect,edat,edat2,edf,edfx,edg,edi,eep,ef,efp,eglib,egp,ekb,els,em,emb,embl,emd,emlxpart,emrg,emrg2,enc,enex,enl,enlx,enq,env,enw,epp,epw,er1,erd,erg,erp,ersx,es,es2,esb,ese,esp,esq,est,esx,et,ete,etng,ett,ev,ev3,ev3p,ev3s,evx,evy,ews,exif,exl,exm,exp,exx,f04,f06,fa,familyfile,far,fas,fasta,fbk,fbq,fcpbundle,fcpevent,fcpproject,fcpxdest,fcpxml,fcs,fct,fdf,fdm,fdt,fdx,fes,ffd,fff,ffindex,ffo,ffwp,fg3,fhc,fid,fig,fil,fingnet,flam3,flame,flg,flipchart,flk,fll,flm,flo,flow,flp,flt,flwa,fmat,fmc,fmt,fnbk,fnm,fnrecipes,fo,fob,fodp,folx,fop,fox,fpa,fpp,fpr,fpsl,fqc,frameset,frd,frl,fro,fsa,fsc,fsif,fss,fstab,ftl,ftm,ftw,fwdict,fxf,fxg,fxp,g1m,g3m,ga3,gadgeprj,gal,gallery,gan,gb,gbk,gbl,gbo,gbp,gbs,gc,gcg,gcproj,gcw,gcx,gdbtable,gdf,gdt,gdtb,gedata,gedcom,gen,genbank,gexf,gfi,gform,gfs,ggb,gis,gla,gld,glo,gls,gmap,gmbl,gml,gmp,gms,gno,gnp,gnutar,gp3,gpf,gpi,gpj,gpp,gpr,gpscan,gra,grade,graphml,graphmlz,grd,grf,grib,grib2,grind,grindx,grk,grp,grr,grt,grv,gs,gtable,gtar,gtl,gtm,gto,gts,gui,guides,gwk,gwp,gxl,gxt,h10,h11,h12,h13,h14,h15,h16,h17,h2o,h2w,h4,h5,h6x,h77t,haas,hal,hcc,hce,hci,hcl,hcr,hcu,hcx,hcxs,hda,hdf,hdi,hdl,hdpmx,hds,hdumx,helpindex,hif,hin,hjt,hkdb,hl,hm3,hml,hmt,hmxp,hmxz,hol,hpp,hs2,hsdt,hsk,hst,htb,htg,huh,hvc,hyv,i5z,ias,iba,ibcd,ibg,icalevent,icaltodo,icg,ichat,icr,id2,id3tag,idx,ies,ifaith,ifiction,ifm,ifs,igc,igg,igma,ign,igq,ii,iif,ilg,ilogicvb,ima,image,imp,imr,imt,in,incp,ini,ink,inp,ins,inx,ip,ipalias,iphoto,iplb,ipmeta,ipr,iproject,iq4,iqmol,irock,irp,irr,irx,is1,is2,isf,ish1,ish2,ish3,ispc,ist,ite,itl,itlp,itm,itmsp,itn,itx,iup,ivc,ivd,ivs,ivt,iw,iwxdata,ix2,ixb,jasper,jbi,jbr,jclic,jdat,jdb,jef,jgcscs,jmp,jnt,joboptions,joined,jph,jrprint,jrxml,jsd,jsda,jtbackup,jude,kal,kap,kbits,kbs,kdbx,kdz,keb,kelgfile,key,key-tef,keychain,keytab,kgtemp,kid,kismac,kma,kms,kmy,kno,kpf,kpp,kpr,kpx,kpz,krc,ksm,kth,kvtml,l,l3dw,l6t,la,label,laccdb,las,lav,lay,lbl,lbx,lcd,lcm,ld2,ldf,ldif,lef,lev,lex,lfp,lgf,lgh,lgi,lgl,lhr,lib,lib4d,lif,life,lin,list,livereg,liveupdate,lix,llb,lmf,lms,lmx,lng,lnt,loc,lp7,lpdb,lpk,lpkg,lpmd,lpp,lqm,lrcat,lrdata,lrlib,lrlibrary,lrm,lrtoolkit,ls3,lsa,lsd,lsf,lsl,lsp,lsr,lst,lsu,lud,lut,lutx,lvm,lvw,lw4,lwd,lxf,lxk,ly,lyt,m,mai,map,mat,mba,mbd,mbg,mbp,mbx,mc1,mcat,mcd,mcdx,mcmac,mcp,md,md8,mdc,mdd,mdj,mdl,mdm,mdsx,mdx,meg,mega,mem,menc,merlin2,met,mex,mf4,mfa,mfe,mfl,mfo,mfp,mft,mfu,mfv,mgourmet,mgourmet4,mindnode,mjk,mlb,mlm,mls,mm,mmap,mmc,mmf,mml,mmm,mmp,mmw,mnc,mng,mnk,mno,mny,mod,moho,mol,money,mosaic,mox,mph,mpj,mpkt,mppz,mpr,mps,mpx,mpz,ms10,msb,msct,msf,msp,mss,mtf,mtff,mth,mtm,mtw,mtxt,mum,mup,mvm,mw,mwf,mws,mwx,mx,mxad,mxc2,mxi,myi,myo,nam,nap,nas,nbe,nc,ncorx,nct,ndif,ndk,nds,ndx,nessus,net,neta,netspd,netspm,nfi,nfl,nfo,nfs,nitf,nl,nlogo,nlogo3d,nma,nmea,nmind,nmm,nmp,nni,nnp,not,notebook,np,npl,npr,npt,npy,nrb,nrc,nrd,nrf,nrl,nrm,nrt,nru,nrx,nsq,nsr,nst,nt,ntf,ntx,nupkg,nvdl,nvl,nvm,nvram,nwcab,nwcp,nwelicense,nwo,nwp,nws,oab,obb,obd,obj,occ,ocimf,od,odc,odf,odp,odt,odx,oeaccount,oem,ofc,ofm,oft,ofx,ogg,oggu,ogm,ogmu,ogs,olk,olk14event,olk14group,olk14note,olk14task,oll,olm,olt,omcs,omp,ond,ont,ontx,oo3,op,op2,op4,opal,opax,opd,opf,opj,opju,opx,or2,or3,or4,or5,or6,org,osz,ot,otl,otln,otp,otx,out,ova,ovf,ovolog,ovx,owx,p3,p7x,pab,paf,pat,paw,pbd,pbix,pbk,pc,pcap,pcapng,pcb,pcc,pcd,pch,pck,pcr,pct,pd4,pd5,pdas,pdd,pdfig,pdo,pds,pdw,pdx,pep,pes,pex,pez,pf,pfc,pfl,phb,phd,phm,pj2,pjm,pjt,pka,pkb,pkh,pks,pkt,planner,pln,pls,plt,plw,pmatrix,pml,pmm,pmo,pmr,pnproj,pns,pod,poi,popshape,por,pot,potm,potx,pp,pp2,ppf,ppp,ppr,pps,ppsm,ppsx,ppt,pptm,pptx,prc,prdx,printcd2,prn,prnx,pro4,pro4pl,pro4plx,pro4x,pro5,pro5pl,pro5plx,pro5x,prs,prt,prv,prx,psa,psf,psm,pspd,pss,pst,psv,psw,pswx,ptb,ptf,ptn,ptz,pvd,pvw,pxf,pxj,pxl,q07,q08,q09,q3d,qb,qb2005,qb2006,qb2007,qb2009,qb2010,qb2011,qb2012,qb2013,qb2014,qb2015,qb2016,qb2017,qba,qbj,qbr,qbw,qbxml,qby,qdat,qdb,qdf,qdf-backup,qdfm,qdfx,qdp,qdt,qel,qf,qfilter,qfx,qif,qm,qmbl,qmtf,qpb,qpf,qph,qrc,qrmx,qrp,qs,qsd,quiz,quox,qvf,qvp,qvw,qxf,ral,ray,rbt,rcd,rcg,rcx,rda,rdata,rdb,rdf,rdg,rdlx,rdx,reb,rec,redif,ref,reference,rel,rep,ret,rez,rf1,rfa,rfo,rge,rgmc,rgo,rhistory,rl,rmd,rmuf,rmx,rng,rnq,roadtrip,roca,rodz,rog,roi,rou,rox,roxio,roz,rp,rpa,rpp,rpprj,rpres,rpt,rptr,rpyb,rrt,rsc,rsf,rsm,rso,rsp,rsv,rsw,rta,rte,rtstn,rtttl,rtwsh,ruel,rupaf,rvl,rvt,rwd,rwg,rws,s85,saf,sah,sar,sbc,sbd,sbw,sbx,sc4,sc45,sca,scd,scf,scg,scgc,scgp,scgs,sch,scm,scn,scz,sdl,sdlxliff,sdp,sds,sdz,se1,seed,sen,seo,seq,ses,sfd,sff,show,shw,shx,sidx,sim,skv,skx,sldtm,sle,slk,slp,slx,sm,smc,smp,smpkg,smx,snag,snapshot,sp,spb,speccy,spj,spk,sps,spt,spub,spv,sq,sqd,sqf,sqr,srf,ssc,ssd,ssp,ssv,sta,stc,stdl,stk,stl,stm,stp,stproj,str,stt,stu,sty,styk,stykz,sub,sum,svd,svf,swk,sx,sxi,syn,t01,t02,t03,t04,t05,t06,t07,t08,t09,t10,t11,t12,t13,t14,t15,t16,t17,t18,t2,t2k,t2ks,t2kt,ta4,ta5,ta6,ta7,ta8,tab,tac,tag,tar,tardist,tax,tax08,tax09,tax10,tax11,tax12,tax13,tax15,tax16,tax17,tax2008,tax2009,tax2011,tax2012,tax2013,tax2014,tax2015,tax2016,tax2017,tax2018,tax2019,tb,tbd,tbk,tbx,tc,tcc,tclogs,tcnet,tcx,tda,tdb,tde,tdl,tdm,tdms,tdt,te3,ted,tef,ter,terrn,terrn2,tet,tfa,tfd,tgc,tgd,tgf,tie,time,timeline,tjp,tkfl,tl5,tlp,tlx,tmr,tmw,tmx,tmzip,top,topc,totalsdb,tpb,tpd,tpf,tqs,tra,trd,trf,trk,trs,trx,tsk,tsl,tsr,tst,tsv,tt10,tt11,tt12,tt13,tt14,tt15,tt16,tt17,tt18,ttd,ttk,ttmd,ttskey,tvc,tvdownload,twb,twbx,twh,twm,twz,twzip,txa,txd,txf,txn,txtrpt,tyimport,tyset,u10,u11,u12,ubj,ubox,uccapilog,ud,udc,udeb,uds,ulf,ulp,ulz,umf,uop,update,upoi,upr,useq,ustar,uvf,uvw,uwl,uwrf,val,vault,vbpf1,vbw,vce,vcf,vcrd,vcs,vct,vdb,vdf,vdx,vec,vff,vfs,vi,vibe,vip,vle,vlg,vmsd,vmsn,vmss,vmt,voi,vok,voxb,vpol,vpp,vpx,vrd,vs,vsch,vscontent,vssm,vssx,vsv,vsx,vtx,vud,vvf,vxml,vym,vzm,w02,wab,wac,wallet,wb1,wb2,wb3,wcat,wcd,wcf,wd3,wdf,wdq,wea,webapp,wfm,wgt,whf,wid,wjr,wk1,wk2,wk3,wk4,wk5,wke,wlx,wnk,wpc,wpf,wpk,wpo,wpost,ws,wsi,wsm,wtb,wtml,wtr,wvp,xaf,xaiml,xappl,xas,xbc,xbd,xbk,xbrl,xbt,xcsl,xdf,xdna,xdp,xds,xef,xem,xer,xfd,xfdf,xflow,xfo,xfr,xft,xgml,xgmml,xgp,xlc,xle,xlf,xlgc,xliff,xlw,xmap,xmcd,xmct,xmd,xmi,xmind,xmlper,xmp,xmpz,xmwx,xmzx,xpdl,xpg,xpj,xpll,xpm,xpr,xpt,xrb,xrdml,xrff,xrp,xry,xsc,xsf,xsvf,xtg,xtm,xtp,xum,xvct,xxd,xyz,xyzv,yam,ychat,ygf,yka,yrcbkm,yrcdat,yumtx,zap,zdb,zdc,zdct,zim,zix,zma,zmc,zpl,_xls,_xlsx,123,12m,aws,bks,cell,dfg,dis,edx,edxz,ess,fm,fods,fp,gnm,gnumeric,gsheet,hcdt,nb,ncss,numbers,ogw,ogwu,ots,pmd,qpw,sxc,tmv,tmvt,uos,wki,wkq,wks,wku,wq1,wq2,wr1,xl,xlshtml,xlsmhtml,xlthtml,|||sqml,7z,ace,arj,cab,cbr,deb,exe,gz,gzip,jar,pak,pkg,rar,rpm,sh,sib,sisx,sit,sitx,spl,tar-gz,tgz,zip,zipx,0,000,001,a00,a01,a02,ain,alz,apz,ar,archiver,arduboy,ari,b1,b64,b6z,ba,bdoc,bh,bndl,boo,bundle,bz,bz2,bza,bzip,bzip2,c00,c01,c02,c10,cb7,cba,cbt,cp9,cpgz,cpt,ctx,cxarchive,czip,dar,dd,dgc,dist,dl_,dz,ecs,ecsbx,edz,efw,egg,epi,f,f3z,fdp,fp8,fzbz,fzpz,gca,gmz,gz2,gza,gzi,ha,hbc,hbc2,hbe,hki,hki1,hki2,hki3,hpk,hpkg,hyp,iadproj,ice,ipg,ipk,ish,isx,ita,ize,j,jgz,jic,jsonlz4,kgb,kz,layout,lbr,lemon,lha,lhzd,libzip,lnx,lqr,lz,lzh,lzm,lzma,lzo,lzx,mint,mpkg,mzp,nex,npk,nz,oar,opk,oz,p01,pa,package,pae,paq6,paq7,par,par2,pbi,pea,pet,pim,piz,psz,pup,puz,pwa,qda,r0,r00,r01,r02,r03,r04,r1,r2,r21,r30,rev,rk,rnc,rp9,rss,rz,s00,s01,s02,s7z,sea,sfs,sfx,shr,smpf,spd,sqx,sqz,taz,tbz,tbz2,tg,tlz,tlzma,tx_,txz,tz,tzst,uc2,uha,uzip,vem,vmcz,voca,vpk,vsi,wa,waff,war,warc,wastickers,wdz,whl,wlb,wot,wux,xapk,xez,xip,xmcdz,xx,xz,xzm,y,yz,yz1,z,z01,z02,z03,z04,zi,zi_,zl,zoo,zpi,zsplit,zst,zw,zz,|||spi,v2i,sv2i,mobackup,tib,hqx,kwm,mim,mime,pub,uue,bak,dmp,gho,ghs,json,adame,adobe,aep,afp,asc,aurora,axx,b2a,bc5b,bfa,bhx,bip,bit,blower,bpk,bpw,bsk,btoa,bvd,ccf,cdoc,cerber,cerber2,cgp,chml,cng,cpio,cryptra,dc4,dcd,dco,ddoc,dim,dime,dm,e4a,ecd,edoc,efl,efr,efu,emc,enx,esf,eslock,exc,extr,filebolt,film,fpenc,fsm,gdcb,gfe,gxk,gzquar,hbx,hex,hid,hid2,htpasswd,idea,iwa,jac,jceks,jcrypt,jks,jmc,jmce,jmck,jmcp,jmcr,jmcx,kde,keystore,kkk,klq,kode,krab,ks,ksd,kxx,lastlogin,lcn,lilocked,litar,locked,locky,lvivt,meo,mjd,mme,mse,null,nxl,odin,pdc,pfile,pfo,plp,psw6,pwv,rap,rdi,rsdf,rzk,rzx,safe,scb,sef,shy,sme,snk,spdf,suf,switch,uea,ufr,uu,uud,vdata,viivo,vlt,vp,wcry,werd,wls,wlu,wncry,wnry,wolf,wpe,wrypt,xmdx,xtbl,xxe,xxx,yenc,ykcol,ync,zepto,zps,zzzzz,__a,__b,~cw,$$$,$db,002,003,113,73b,aba,abbu,abf,abk,acp,aea,afi,asd,ashbak,asv,asvx,ba6,ba7,ba8,bac,backup,backupdb,bak~,bak2,bak3,bakx,bbb,bbz,bck,bckp,bdb,bff,bif,bifx,bk1,bkc,bkf,bkp,bkup,bkz,blend1,blend2,bm3,bmk,bookexport,bpa,bpb,bpn,bps,bup,cbs,cbu,cenon~,ck9,cmf,crds,csd,csm,da0,dash,dba,dbk,dss,fbc,fbf,fbu,fbw,fh,fhf,flka,flkb,fpsx,ftmb,ful,fwbackup,fza,fzb,gb1,gb2,gs-bck,ibk,icbu,icf,inprogress,ipd,iv2i,j01,jbk,jdc,jpa,jps,kb2,lbf,lcb,ldabak,llx,mbf,mdbackup,mddata,mdinfo,msim,nb7,nba,nbak,nbd,nbf,nbi,nbs,nbu,nco,nda,nfb,nfc,noy,npf,nps,nrbak,nrs,nwbak,obk,oeb,old,onepkg,ori,orig,oyx,paq,pbf,pbj,pbx5script,pvhd,qbb,qbk,qbm,qbmb,qbmd,qbx,qic,qsf,qv~,rbc,rbk,rbs,rgmb,rmbak,rrr,sbs,sbu,skb,sn1,sn2,sna,sns,spf,spg,sqb,srr,stg,sv$,tibkp,tig,tis,tlg,trn,ttbk,uci,vbk,vbm,vbox-prev,vpcbackup,vrb,w01,walletx,wbb,wbcat,wbk,win,wjf,wpb,wspak,wx,xlk,yrcbck,zbfx,|||apt,err,pwi,ttf,tex,text,txt,cdd,cpp,doc,docx,docm,dotm,dotx,epub,fb2,gpx,ibooks,indd,kml,mobi,mso,oxps,pages,pdf,pl,ps,rtf,sldm,snb,wpd,wps,xps,cfg,4ui,anh,ao,ap,article,av,avery,bcf,bcp,biz,blk,bmml,bpf,bro,btw,caj,cal,cbf,cd2,cdml,cl2arc,cl2doc,cl2lyt,cl2tpl,clkb,clkc,clkd,clt,cndx,comicdoc,comiclife,consis,cov,cpe,cph,cpy,crtr,cst,cvw,cw,cwt,de,dpd,dra,drmx,drmz,dtx,dwdoc,eddx,edrwx,el4,fadein,fax,fcdt,fd2,fdd,fey,fgc,flb,flowchart,flw,folio,form,fpe,fr3,frdoc,frf,fsd,fxm,gde,gdoc,gdocx,gem,gofin,gslides,gsp,gwb,hfd,hft,hmk,hpd,hpt,hwdt,icap,icml,icmt,idap,idml,idms,idpk,ifd,ildoc,imm,imtx,imx,incd,inct,incx,ind,indb,indl,indp,inds,indt,inlx,isale,isallic,isd,jtp,jwc,lab,lld,lma,lpdf,lsc,ltf,max,mcsp,mdi,mga,mif,mtc,mvd,mvdx,mwl,npp,nud,ola,p65,pcl,pde,pdp,pdr,pgs,pmx,pnh,ppx,psg,psproj,psr,ptx,pwt,pzf,pzfx,q3c,qpt,qxb,qxd,qxp,qxt,rb4,rels,rfd,rlf,rmr,rpc,rpx,rwt,sbk,sbv,sdt,simp,sjd,sma,snp,t2d,tds,tp3,uxf,vfc,webtheme,wlp,wmga,wpt,wwf,xdw,xif,xmt,xsn,xzfx,zdl,zdp,zds,zfx,zno,_doc,_docx,1st,602,abw,act,adoc,aim,ase,awp,aww,bad,bbs,bdp,bdr,bean,bib,bibtex,bml,bna,boc,brx,btd,bzabw,calca,charset,chord,cnm,cod,crwl,cws,cyi,diz,dne,dox,dvi,dwd,dxb,dxp,eio,eit,emf,eml,emlx,etf,etx,euc,fbl,fcf,fdr,fds,fdxt,fft,fgs,flr,fodt,fountain,frt,fwdn,gmd,gpd,gpn,gsd,gthr,gv,hbk,hht,hs,hwp,hz,iil,ipf,ipspot,jarvis,jis,jnp,joe,jp1,jrtf,jtd,kes,klg,knt,kon,kwd,latex,lbt,lis,lp2,ltr,ltx,lue,luf,lwp,lxfml,lyx,mbox,mcw,mell,mellel,mnt,msg,mwd,mwp,ndoc,ngloss,njx,note,notes,now,nwctxt,nwm,ocr,odif,odm,odo,ofl,opeico,openbsd,ort,ott,p7s,pages-tef,pfx,plantuml,pu,pvm,pwd,qdl,rad,readme,rft,ris,rst,rtd,rtfd,rtx,run,rvf,rzn,safetext,scc,scriv,scrivx,sct,scw,sdw,session,sgm,sig,sla,smf,sms,ssa,story,strings,sxw,tdf,template,thp,tlb,tm,tmdx,tmvx,tpc,trelby,tvj,u3i,unauth,unx,uof,uot,upd,utf8,utxt,vnt,vw,webdoc,wn,wp,wp4,wp5,wp6,wp7,wpa,wpl,wpw,wri,wsd,wtt,wtx,xbdoc,xbplate,xdl,xwp,xy,xy3,xyp,xyw,zabw,zrtf,tsc,tsf,uld,unt,upf,vet,vnd,vtf,vwx,wdp,x_b,x_t,xise,xnc,xv3,acsm,apnx,azw,azw1,azw3,azw4,bkk,bpnueb,cebx,dnl,ea,eal,ebk,edn,etd,fkb,han,html0,htmlz,htxt,htz4,htz5,jwpub,kfx,koob,lit,lrf,lrs,lrx,mart,ncx,nva,oebzip,orb,pef,phl,qmk,rzb,rzs,tcr,tk3,tpz,tr,tr3,webz,ybk,|||3g2,3gp,3gp2,3gpp,3gpp2,asf,asx,avi,drv,f4v,flv,h264,m4v,mkv,moov,mov,mp4,mpeg,mpg,rm,rmvb,srt,swf,vid,vob,webm,wm,wmv,yuv,264,3mm,3p2,60d,787,890,aaf,aec,aepx,aet,aetx,ajp,ale,am,amv,amx,anim,arcut,arf,avb,avchd,ave,avs,avv,axm,bdm,bdmv,bdt2,bdt3,bik,bik2,bix,bk2,blz,bmc,bnp,bs4,bsf,bu,bvr,byu,camproj,camrec,camv,ced,cine,cip,clpi,cme,cmmp,cmmtpl,cmproj,cmrec,cpi,cpvc,cx3,d2v,d3v,dav,dce,dck,dcr,dir,divx,dlx,dmb,dmsd,dmsd3d,dmsm,dmsm3d,dmss,dmx,dpa,dpg,dream,dv,dv-avi,dv4,dvdmedia,dvr,dvr-ms,dvx,dxr,dzm,dzp,dzt,edl,evo,exo,eye,eyetv,ezt,f4f,f4m,f4p,fbr,fbz,fcarch,fcp,fcproject,ffm,flc,flh,fli,flic,flx,fpdx,ftc,fvt,g2m,g64,g64x,gcs,gfp,gifv,gl,gom,grasp,gvi,gvp,gxf,hdmov,hdv,hevc,hkm,ifo,imovieproj,insv,int,ircp,irf,ism,ismc,ismclip,ismv,iva,ivf,ivr,izz,izzy,jdr,jmv,jnr,jss,jts,jtv,k3g,kdenlive,kmv,ktn,lrec,lrv,lsx,lvix,m1pg,m21,m2p,m2t,m2ts,m2v,mani,mgv,mj2,mjp,mk3d,mnv,moi,mp21,mpf,mpgindex,mpl,mpls,mproj,mpsub,mpv,mqv,msdvd,mswmm,mtv,mvc,mve,mvp,mvy,mxf,mxv,n3r,ncor,nfv,nsv,ntp,nut,nuv,nvc,ogv,ogx,orv,osp,otrkey,pac,pgi,photoshow,piv,pjs,plproj,pmf,ppj,prel,pro,prproj,prtl,psb,psh,pvr,pxv,qsv,qt,qtch,qtindex,qtl,qtm,qtz,r3d,ravi,rcproject,rcrec,rcut,rmp,rms,rmv,roq,rsx,rts,rum,rv,rvid,sbz,screenflow,sdv,sec,sfvidcap,siv,smi,smil,smk,snagproj,ssf,stx,svi,swi,swt,tda3mt,theater,tid,tivo,tix,tod,tp,tp0,tpr,trec,trp,tsp,ttxt,tvlayer,tvs,tvshow,usf,usm,v264,vbc,vc1,vcpf,vcr,vcv,vdo,vdr,veg,vep,vf,vft,vfw,vfz,vgz,video,viewlet,viv,vivo,vix,vlab,vmlf,vmlt,vp3,vp6,vp7,vpj,vr,vro,vs4,vse,vsh,vsp,vtt,w32,wcp,wfsp,wgi,wlmp,wmd,wmmp,wmx,wp3,wsve,wtv,wvm,wvx,wxp,xej,xel,xesc,xfl,xlmv,xmv,xvid,y4m,yog,zeg,zm1,zm2,zm3,zmv,|||dem,kmz,mid,ov2,geo,3d,3dc,3dd,3dl,477,apl,apr,aqm,at5,atx,aux,axe,axt,bil,bt,cor,csf,cvi,div,dix,dlg,dmf,dmt,dt0,dt1,dt2,e00,embr,ers,eta,ffs,fit,fls,fme,fmi,fmv,fmw,geojson,gfw,glb,gmf,gprx,gps,grb,gsb,gsi,gsm,gsr,gsr2,gst,gvsp,gws,hdr,hgt,imd,img,imi,jgw,jnx,jpgw,jpr,jpw,lan,len,mpk,msd,mxd,mxt,ngt,nm2,nm3,nmap,nmc,nmf,obf,ocd,osb,osc,osm,pix,prm,ptm,ptt,qct,rdc,rgn,rrd,sbn,shp,sld,style,svx,sxd,sym,tfrd,tfw,th,timestamp,tpx,ttkgp,vdc,wfd,wld,wor,xol,|||3dm,3ds,a2c,ccd,cdw,cr2,dgn,dwg,dxf,ics,igs,iso,ma,mb,part,rnd,sldasm,sldprt,wm2d,ai,eps,svg,vsd,vst,wmf,aac,ac3,aif,aiff,amr,aob,ape,aud,bwg,flac,iff,m3u,m3u8,m4a,m4b,m4p,m4r,midi,mp3,mpa,msv,nkc,ra,ram,sln,temp,vb,wav,wave,wma,xsb,xwb,cur,icns,ico,mds,pict,png,bmp,dds,djvu,gif,hta,jpeg,jpg,php,psd,pspimage,scr,tga,thm,tif,tiff,xcf,0cc,2sf,2sflib,3ga,3gpa,4mp,5xb,5xe,5xs,669,6cm,8cm,8med,8svx,a2b,a2i,a2m,a2w,a52,aa,aa3,aax,abc,abm,acb,acd,acd-bak,acd-zip,acm,adg,adts,afc,agm,agr,ahx,aifc,aimppl,akp,alaw,all,als,amf,ams,amxd,amz,ang,apf,aria,ariax,3d2,3d4,3da,3df,3dmf,3dmk,3don,3dv,3dx,3dxml,3mf,a3d,a8s,album,animset,anm,aof,aoi,atl,atm,b3d,bio,blend,br3,br4,br5,br6,br7,brg,bto,bvh,c3z,c4d,cas,ccb,cg,cg3,cga,cgfx,chrparams,cm2,cmod,cmz,crf,crz,cso,d3d,dae,daz,dbl,dbm,ddd,dff,dfs,ds,dsa,dse,dsf,dsi,dso,dsv,duf,dwf,e57,f3d,facefx,fbm,fbx,fc2,fcz,fg,fnc,fpf,fpj,fry,fsh,fsq,fun,fuse,fx,fxa,fxl,fxs,fxt,glf,glm,gltf,gmmod,gmt,grn,hd2,hdz,hip,hipnc,hlsl,hr2,hrz,hxn,ifc,iges,igi,igm,ik,irrmesh,iv,ive,j3o,jas,kfm,kmc,kmcobj,ktz,ldm,llm,lnd,lp,lps,lt2,ltz,lwo,lws,lxo,m3,makerbot,maxc,mc5,mc6,mcz,md5anim,md5camera,md5mesh,meb,mesh,mix,mot,mp,mqo,mrml,ms3d,mtl,mtx,mtz,mxm,mxs,n2,n3d,nff,nif,nm,nsbta,obp,obz,oct,off,ogf,ol,p21,p2z,p3d,p3l,p5d,phy,pigm,pigs,pl0,pl1,pl2,ply,ppz,prefab,psk,pz2,pz3,pzz,qc,rcs,rds,rig,s,sc4model,sh3d,sh3f,skl,skp,smd,step,sto,t3d,tcn,tgo,thing,thl,tme,tmo,tri,truck,ts1,tvm,u3d,ums,v3d,v3o,v3v,vac,vert,visual,vmd,vmo,vox,vrl,vso,vue,vvd,w3d,wft,wow,wrl,wrp,wrz,x,x3d,x3g,xmf,xmm,xof,xrf,xsi,xv0,yaodl,ydl,z3d,zt,123c,123d,123dx,2d,3w,a2l,afd,any,ard,asy,att,bbcd,bcd,bdl,bimx,bmf,bpmc,bpz,bsw,bswx,bxl,cad,cam,catdrawing,catpart,catproduct,cddx,cdl,cgr,ckd,cmp,cnc,cnd,cpa,crv,cyp,czd,db1,dbq,dc,dc1,dc2,dc3,dft,dfx,dgb,dgk,dlv,drg,drw,drwdot,dsg,dst,dwfx,dwt,dxe,dxx,easm,edrw,eld,eprt,eqn,ewb,ewd,ezc,ezp,fan,fcstd,fcstd1,fcw,fmz,fpd,fz,fzm,fzp,fzz,g,g3d,gbx,gcd,gcode,gds,gxc,gxd,gxh,gxm,hcp,hsc,hsf,hus,iam,ic3d,icd,ide,idv,idw,if,ifcxml,ifczip,ipj,ipn,ipt,ise,isoz,jam,jbc,job,jt,jvsg,jvsgz,kit,l3b,lcf,ldr,ldt,li3d,lia,lizd,logicly,ltl,lyc,lyr,mc9,mcx,mhs,mmg,model,modfem,mp11,mp13,mp14,mp7,ms11,ms13,ms14,msm,nc1,neu,ngc,ngd,nwc,nwd,nwf,olb,opt,pc6,pc7,phj,pho,pipd,pipe,pla,prg,qpm,rcv,red,rml,rra,rs,rsg,sab,sat,sbp,scad,scdoc,sdg,skf,slddrw,t3001,tak,tbp,tc2,tc3,tcd,tcm,tcp,tct,tcw,topprj,topviw,at3,au,aup,ay,b4s,band,bap,bcs,bcstm,bdd,bfstm,bfwav,bidule,bonk,brr,brstm,bun,bwf,bww,caff,cda,cdda,cdlx,cdo,cgrp,cidb,ckb,conform,copy,cpr,csh,cts,cwb,cwp,d00,d01,dewf,df2,dfc,djr,dls,dmsa,dmse,ds2,dsm,dsp,dtm,dts,dtshd,dvf,ear,efa,efe,efk,efq,efs,efv,emp,emx,emy,eop,erb,esps,evr,evrc,exs,f2r,f32,f3r,f4a,f64,fda,fev,frg,fsb,fti,ftmx,fuz,fzf,fzv,g721,g723,g726,gbproj,gig,gio,gm,gmc,gp5,gpbank,gpk,gro,groove,gsf,gsflib,guit,gym,h0,h3b,h3e,h4b,h4e,h5b,h5e,h5s,hbb,hbs,hca,hdp,hma,hmi,hps,hsb,iaa,igp,igr,imf,isma,it,iti,itls,its,jo,jo-7z,jspf,k25,k26,kar,kfn,kin,kmp,koz,kpl,krz,ksc,ksf,kt2,kt3,ktp,lof,logic,logicx,lqt,lso,lvp,lwv,m2,m5p,ma1,mbr,mdr,med,minigsf,miniusf,mka,mmlp,mmpz,mo3,mp2,mpc,mpdp,mpga,mscz,msmpl_bank,mte,mti,mtp,mui,mus,musx,mux,mx5,mxl,mxmf,myr,naac,narrative,ncw,nfa,nkb,nki,nkm,nks,nkx,nml,nmsv,nra,nsa,ntn,nus3bank,nvf,obw,ofr,oga,oggstr,okt,oma,omf,omg,omx,opus,orc,ota,ove,ovw,pandora,pca,pcast,pcg,pd,peak,pek,pk,pkf,pna,ppc,pts,ptxt,q1,q2,qcp,r,r1m,raw,rax,rcy,record,rex,rfl,rgrp,rip,rmf,rmi,rmj,rmm,rmt,rns,rol,rsn,rti,rtm,rvx,rx2,s3i,s3m,sap,sb,sbi,sc2,scs11,sd,sd2,sdat,sdx,sesx,sf2,sfk,sfl,sfpack,sfz,sgp,shn,sid,smpx,snd,sng,sou,sph,sppack,sseq,stap,sth,strm,swa,sxt,syh,syw,syx,td0,tfmx,thx,tm2,tm8,tmc,toc,trak,tta,txw,u,u8,uax,ub,ulaw,ult,ulw,uni,usflib,ust,uw,uwf,v2m,vag,vap,vc3,vdj,vgm,vlc,vmf,voc,voxal,vpl,vpm,vpr,vpw,vqf,vrf,vsq,vsqx,vyf,w64,wand,wax,wem,wfb,wfp,wpp,wproj,wtpl,wtpt,wus,wut,wv,wvc,wve,wwu,wyz,xa,xbmml,xfs,xi,xm,xma,xms,xmu,xmz,xopus,xp,xpf,xrns,xsp,xspf,xt,ym,yookoo,zab,zgr,zpa,zvd,zvr,af3,afdesign,artb,ccx,cddz,cdmm,cdmt,cdmtz,cdmz,cds,cdt,cgm,cil,clarify,cmx,cnv,csy,cv5,cvg,cvs,cvx,dcs,ddrw,design,dhs,dpp,drawing,drawit,egc,emz,ep,epsf,esc,ezdraw,fh10,fh11,fh3,fh4,fh5,fh6,fh7,fh8,fh9,fhd,fif,fs,ft10,ft11,ft7,ft8,ft9,ftn,gdraw,gks,glox,graffle,gstencil,gtemplate,gvdesign,hgl,hpg,hpgl,hpl,hvif,igt,igx,jsl,lmk,mgcb,mgmf,mgmx,mgs,mvg,odg,otg,ovp,ovr,pen,pmg,qcc,rdl,scv,sk2,sketch,slddrt,snagstyles,std,svgz,tlc,tne,tpl,vbr,vml,vsdm,vsdx,vstm,vstx,wmz,wpg,wpi,xmmap,yal,ydr,zgm,2bp,360,411,73i,8ca,8ci,8pbs,8xi,acorn,afphoto,afx,agif,agp,aic,apd,apm,apng,aps,apx,arr,arw,aseprite,avatar,awd,blkrt,bmq,bmx,bmz,bpg,brk,brt,bss,bti,bw,can,cd5,cdg,cid,cin,cit,clip,colz,cpc,cpg,cps,cpx,ct,dgt,dib,dic,dicom,dm3,dmi,dtw,dvl,ecw,exr,face,fal,fits,flif,fpg,fpos,fppx,fpx,g3,gcdp,gfb,gfie,ggr,gih,gim,gmbck,gmspr,gp4,grob,gry,hdrp,heic,heif,hf,hpi,hr,hrf,i3d,ic1,ic2,ic3,ica,icb,icn,icon,icpr,ilbm,imj,info,insp,ipick,ipx,itc2,ithmb,ivue,iwi,j2c,j2k,jb2,jbf,jbg,jbig,jbig2,jbmp,jfi,jfif,jia,jif,jiff,jng,jp2,jpc,jpd,jpe,jpf,jpg-large,jpg2,jpx,jtf,jwl,jxr,kdi,kdk,kic,kodak,kpg,kra,lb,lbm,lip,ljp,lrpreview,lzp,mbm,mdp,miff,mipmaps,mnr,mpo,mrxs,myl,ncd,ncr,neo,nlm,nol,oc3,oc4,oc5,oci,odi,oplc,otb,oti,ozb,ozj,ozt,pano,pbm,pc3,pcx,pdn,pe4,pfr,pgf,pgm,pi2,pic,picnc,piskel,pixadex,pm,pnm,pov,ppm,prw,psdx,pse,psp,pspbrush,ptex,ptg,px,pxd,pxm,pxr,pyxel,pza,pzp,pzs,qmg,qti,qtif,ras,rcl,rcu,rgb,rgba,rgf,ric,rif,riff,rix,rle,rli,rpf,rri,rsb,rsr,rtl,rvg,s2mv,sai,sdr,sfc,skitch,skm,spa,spc,spe,spp,spr,sprite,sprite2,ste,sup,t2b,targa,tb0,tbn,texture,tfc,tg4,thumb,tn,tpi,trif,tub,ufo,uga,ugoira,urt,v,vda,vic,vicar,viff,vna,vpe,vrimg,vrphoto,vss,wb0,wbc,wbd,wbm,wbmp,wbp,wbz,webp,wi,wic,wmp,wvl,xbm,xwd,ysp,zif,zvi,3fr,bay,cr3,cxi,eip,iiq,j6i,mef,mfw,mos,mrw,nef,nrw,orf,raf,rw2,rwl,rwz,sr2,srw,x3f,|||apk,bat,cgi,cmd,com,js,jse,gadget,msi,msu,pif,ps1,pwz,vbs,wsf,dll,8bi,crx,ext,h,nbm,nes,plugin,ppa,ppam,xla,xlam,xll,xpi,ani,cpl,deskthempack,diagcab,diagpkg,hlp,icl,lnk,msstyles,nomedia,ocx,reg,rom,scrshs,sys,theme,themepack,0xe,73k,89k,8ck,a6p,a7r,ac,actc,action,ahk,air,app,arscript,asb,azw2,ba_,beam,celx,cof,command,dek,dld,e_e,ebs,ebs2,ecf,eham,elf,epk,esh,ex_,ex4,ex5,exe1,exopc,ezs,fky,fpi,frs,gpe,gpu,ham,hms,hpf,iim,ipa,isu,jsf,jsx,kix,ksh,kx,lo,ls,mcr,mel,mio,mrc,mrp,ms,msl,mxe,n,ncl,nexe,ore,osx,otm,phar,plx,pwc,pyc,pyo,qit,qpx,rbx,rfu,rgs,rpj,rxe,scar,scpt,scptd,script,tiapp,tms,u3p,udf,upx,vbe,vbscript,vexe,vlx,vxp,wcm,widget,wiz,workflow,wpm,wsh,x86,xap,xbap,xlm,xqt,xys,zl9,8ba,8bc,8be,8bf,8bi8,8bl,8bs,8bx,8by,8li,aaui,aaxplugin,accda,accdu,acroplugin,aex,aip,alp,amxx,api,aplg,aplp,arx,asi,avx,ax,bav,bblm,blu,bmi,bri,brm,bzplug,ccip,cleo,codaplugin,component,cox,dfp,dlo,dlr,dlu,dpm,eaz,epk2,exv,fmplugin,fmx,fwaction,fwactionb,fzip,hvpl,iadaction,iadclass,iadpage,iadplug,iadstyle,ibplugin,ideplugin,jsxbin,kmm,lrmodule,lrplugin,mda,mde,mfx,milk,mmip,mode,module,mxaddon,mxp,ny,oex,oiv,osax,oxt,p,p64,plx64,q1q,q2q,q4q,q5r,q7q,q8r,q9r,q9s,qar,qtr,qtx,rbz,rhp,rock,rpi,rplib,rpln,rwplugin,safariextz,sparc,tgp,tko,tmbundle,vsix,vsl,vst3,wie,wll,wlz,wowsl,x32,xadd,xba,xcplugin,xlv,xnt,xsiaddon,zlb,zxp,208,2fs,386,3fs,73u,8cu,8xu,adm,adml,admx,aos,asec,bashrc,blf,bom,bud,c32,cgz,ci,cnt,cpq,crash,desklink,dev,dfu,diagcfg,dit,drpm,dvd,ebd,edj,efi,efires,emerald,escopy,etl,evt,evtx,ffa,ffl,ffx,firm,fl1,fota,fpbf,ftf,ftg,fts,gmmp,grl,group,h1s,hcd,hdmp,help,hhc,hhk,hiv,hpj,hsh,htt,hve,idi,ifw,im4p,ime,img3,inf_loc,ion,ioplist,ipod,iptheme,ius,jpn,kbd,kext,ko,kor,lfs,library-ms,lockfile,log1,log2,lpd,manifest,mapimail,mdmp,mi4,mlc,mydocs,nb0,nbh,nls,ntfs,odex,pk2,pnf,pol,ppd,prefpane,profile,prop,pwl,qky,qvm,rc1,rc2,rco,reglnk,rfw,ruf,rvp,saver,shd,shsh,sqm,swp,ta,tdz,thumbnails,timer,trashes,trx_dll,uce,vga,vgd,vx_,vxd,wdgt,webpnp,wer,wgz,wph,wpx,xfb,xrm-ms,|||aspx,cer,cfm,chm,crdownload,csr,download,htaccess,htm,html,jnlp,jsp,mht,mhtm,mhtml,url,webarchive,webloc,xhtml,xulasf,c,class,fla,java,lua,po,py,so,vc4,vcproj,vcxproj,wsc,xcodeproj,xsd,a4p,adr,alx,an,appcache,aro,asa,asax,ascx,ashx,asmx,atom,awm,axd,br,browser,btapp,bwp,cha,chat,codasite,con,crl,crt,cshtml,csp,der,dhtml,disco,discomap,dml,do,ece,edge,epibrw,esproj,ewp,fcgi,freeway,fwp,fwtb,fwtemplate,gne,har,hdm,hdml,htc,htx,hxs,hype,hypesymbol,idc,iqy,itms,itpc,iwdgt,jcz,jhtml,jspa,jspx,jst,jvs,jws,lasso,lbc,less,maff,mapx,mjs,mspx,muse,nod,nxg,nzb,oam,obml,obml15,obml16,ognc,olp,opml,oth,p12,p7b,p7c,pem,qbo,qrm,rflw,rhtml,rjs,rt,rw3,rwp,rwsw,rwtheme,saveddeck,scss,shtm,shtml,sitemap,sites,sites2,suck,swz,tvpi,tvvi,ucf,uhtml,vbd,vbhtml,vdw,vlp,vrml,vrt,vsdisco,wbs,wbxml,web,webhistory,website,wgp,whtt,wml,woa,wrf,wsdl,xbel,xbl,xfdl,xht,xhtm,xpd,xss,xul,xws,zfo,zhtml,zul,zvz,$01,4db,4th,a,aab,aar,addin,ads,agi,aia,aidl,alb,am4,am5,am6,am7,ane,anjuta,ap_,apa,applet,appx,appxsym,appxupload,arsc,artproj,as2proj,as3proj,asvf,au3,autoplay,awk,b,bas,basex,bb,bbc,bbproject,bbprojectd,bdsproj,bet,bluej,bos,bpr,bs2,bsc,bsh,btn,buildpath,bur,bytes,caproj,cbl,cbp,cc,ccgame,ccn,ccs,cd,cfc,clips,cls,clw,cob,config,cp,cpb,csi,csn,csproj,csx,ctxt,cu,cvsrc,cxp,cxx,d,daconfig,dart,dbml,dbo,dbpro,dbproj,dcp,dcproj,dcuil,ddp,dec,dep,deviceids,df1,dfk,dgml,dgsl,diff,dm1,dmd,dob,docset,dpk,dpkw,dres,dsgm,dsym,eba,ecp,edm,edml,edmx,el,elc,ent,eql,erl,escn,ex,exw,f2k,f90,f95,fbp,fbp7,fbz7,fce,fcl,fd,feature,fgl,filters,fimpp,for,forth,fpm,framework,frj,frx,fsi,fsl,fsproj,fsscript,fsx,fxc,fxcproj,fxml,fxpl,gameproj,gar,gbap,gbas,gbm,gch,gemspec,gfar,gitignore,gitkeep,glade,global,gm6,gm81,gmk,gmo,gmx,go,gorm,gradle,greenfoot,groovy,groupproj,gs3,gsproj,gszip,gvy,gwd,haml,handlebars,has,hcf,hh,hhh,hhp,hrl,hxx,hydra,i,iconset,idl,idt,ilk,iml,inc,inl,ino,ipch,ipp,isc,iwb,iws,iwz,jav,jcp,jdp,jed,jl,jlr,jnilib,jsfl,jsh,jsxinc,juk,kb,kct,kdevdlg,kdevelop,kdevprj,kdmp,kps,kt,kv,kvk,lang,lbi,lbs,lds,lgo,lhs,licenses,licx,lisp,livecode,loadtest,lol,lproj,lrdb,lsproj,ltb,luc,lxsproj,m4,magik,mak,markdown,mdzip,mer,mf,mk,ml,mo,mom,mpws,mq5,mrt,msha,mshc,mshi,msix,mv,mxml,myapp,natvis,nbc,ncb,ned,neko,nfm,nib,nim,nk,nqc,nsh,nsi,nsl,nuproj,nuspec,nvv,nw,nxc,o,oat,ob2,oca,octest,odl,omo,os,ow,owl,oxygene,patch,pb,pbg,pbxbtree,pbxproj,pbxuser,pcp,ph,pika,pjx,pkgdef,pkgundef,playground,plc,ple,pli,pn,pri,proto,psc,psm1,ptl,pwn,pxi,pyd,pyw,pyx,qml,qpr,qx,rav,rb,rbm,rbp,rbvcp,rbw,rbxs,rc,rdlc,rdoc,refresh,res,resjson,resources,resw,resx,rexx,rise,rkt,rls,rodl,rotest,rpy,rsrc,ru,rul,rwsnippet,s19,sas,sb2,sb3,sbproj,sc,scala,scratch,sdef,sed,set,slogo,sltng,smali,snippet,sol,spec,sqlproj,src,ss,ssi,storyboard,sud,suo,svn-base,swc,swd,swift,t,targets,tcl,td,tiprogram,tk,tld,tlh,tli,tmlanguage,tmpl,tmproj,tmproject,tns,tpk,tpu,tres,tscn,tt,tu,tur,twig,uft,ui,uml,umlclass,vala,var,vbg,vbp,vbproj,vbx,vbz,vc,vcp,vcx,vcxitems,vdm,vdp,vdproj,vgc,vhd,vhdl,vjp,vjsproj,vm,vpc,vsct,vsmacros,vsmdi,vsmproj,vspf,vsps,vspscc,vspx,vssscc,vsz,vtm,vtml,vtv,vwl,w,wapproj,wasm,wdgtproj,wdl,wdw,webtest,winmd,wiq,wixlib,wixmsp,wixmst,wixobj,wixout,wixpdb,wixproj,workbook,worksheet,workspace,wowproj,wsp,wxi,wxl,wxs,xaml,xamlx,xbf,xcappdata,xcarchive,xcconfig,xcode,xib,xojo_menu,xoml,xpp,xq,xql,xqm,xquery,xqy,xsx,xtb,yab,yaml,yml,yml2,ymp,ypr,|||b5t,b6t,bwi,bwt,dmg,i00,i01,i02,isz,md0,md1,md2,nrg,pdi,toast,2mg,adz,afm,ashdisc,atr,avhd,b5i,b6i,bwa,bws,bwz,ciso,cl5,cue,d64,d88,daa,dao,dax,dbr,disc,disk,dmgpart,dms,e01,ecm,eda,ede,edk,edq,eds,edv,eui,ex01,fdi,g41,gbi,gdrive,gi,gkh,hc,hdd,hfs,hfv,ibadr,ibb,ibdat,ibp,ibq,imz,ixa,k3b,l01,lx01,mbi,miniso,mrimg,nn,nri,p2g,p2i,partimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,conf,deskthemepack,ds_store,inf,plist,swb,thempack,cf,cfu,vrp,lgp,pff,efd,00,32x,3dsx,3dz,555,68k,8ld,a26,acww,acx,age3rec,age3sav,age3scn,age3xrec,age3xsav,age3yrec,age3ysav,am1,arch00,arp,ars,ash,ass,asset,ba2,bak1,bars,bb3,bdae,bf,bfg,bfm,bfs,bgz,bic,big,biq,blorb,blp,bls,bmd,bme,bmg,bng,bnr,bns,bnz,bo2,bo3,breff,breft,brlyt,brmdl,brres,brsar,brseq,brtex,brv,bs1,bsa,bsb,bsdiff,bsg,bsp,bus,bzw,carc,cbh,cbv,cdp2,cgf,chd,cm,cns,compiled,cos,course,cpn,crp,cty,d3dbsp,dat_mcr,dat_new,dazip,desc,diva,dm_68,dm_82,dm_83,dm_84,dnf,dns,dol,dpf,drm,duc,dun,dv2,dzip,e2gm,eepf,egm,eix,ek6,ekx,elm,eng,epc,escape,esg,esm,est_uax,evp,ewl,fbrb,fc1,fc2map,fcm,ff,fgd,fila,film_cpk,fl,flash,fld,fml,fnta,fomod,forge,fos,fpid,fpk,fpmb,fpmo,fpop,fps,frc,frw,frz,fs2,fsg,fssave,fst,fuk,fwd,g3x,galaxy,game,gamedata,gba,gbaskin,gbc,gbcskin,gblorb,gcf,gci,gcm,gct,gcz,gd,gdc,gdg,gdi,gdw,genome,gfx,gg,ggpack,ghb,gjd,glksave,gma,gme,gmres,gmv,god,goomod,gr2,gs0,gsba,gsc,gsx,gtworld,h3m,h4r,h5m,h5u,hat,he,he0,he1,he2,he4,hhsl,hi,hit,hmp,hof,hog,hoi4,honmod,hot,hqm,hum,hwd,hwmap,hws,hxm,i3pack,ib2,ib3,ibch,ibre,ibro,ibt,icmod,idx0,idx255,ifp,imga,inform,inv,ipl,ips,isr,itk,itr,iwd,j2i,j2l,j64,ja,jag,jap,jbeam,jcr,jg4,jgc,jigsaw,jkb,jmf,jrc,jrz,k2s,kag,kcl,kf2,kfs,kodu,kv6,kwreplay,l2r,l3d,laby,ldb,ldw,litemod,lk12,ll,lmp,lmu,lock,lod,love,lpb,lsw,ltg,luxb,lvl,lvlx,mae,maplet,mca,mcapm,mcpack,mcserver,mcworld,md3,menu,mgl,mgx,mii,mis,mp2m,mp2s,mpm,mpq,mrs,mul,n-gage,n3pmesh,n64,nar,narc,nav,naz,nbt,nca,ncer,ncf,ncgr,nclr,ndd,ndr,neosave,nfs11save,ngage,ngp,ngs,nl2script,nlelem,nlpx,nltrack,nlvm,nop,npa,nro,ns1,nsbca,nsbmd,nsbtx,nsbva,nscr,nsp,ntrk,ogz,omod,osk,osr,osu,ovh,ovl,p2m,p3t,papa,pbn,pbp,pcsav,pgn,phn,pk3,pk4,pkx,player,plr,pqhero,prk,properties,pssg,pwf,pxp,qwd,radq,rasunsoft,rbj,rbxl,rbxlx,rbxm,rbxmx,replay,ress,rfc,rfgs_pc,rfm,rgd,rgp,rgss2a,rgss3a,rgssad,rgt,rim,rkg,rkp,rofl,ros,rot,rp2,rpgmvm,rpgmvo,rpgmvp,rpgproject,rpgsave,rpkg,rpl,rpyc,rs2,rsdk,rton,rttex,rvdata,rvdata2,rvproj,rvproj2,rxdata,s2z,sad,sami,sc2archive,sc2assets,sc2bank,sc2data,sc2ma,sc2map,sc2mod,sc2replay,sc2save,sc4desc,sc4lot,schematic,scs,scworld,sd7,settings,sfar,sfo,sg0,sga,sgb,sgpbprj,sii,sims2pack,sims3,sims3pack,sli,smzip,splane,srm,stencyl,sv5,svs,taf,tbm,td6,tex0,tfr,tic,tiger,tim,tkr,tlk,tmod,tor,tp4,ts4script,ttarch,ttl,twt,tzarc,uasset,uc,ucl,udk,ukx,ulx,umap,umd,umod,umx,unf,unif,unity,unity3d,unityproj,unr,updatr,upk,ups,uqm,usa,usx,ut2,ut2mod,ut3,ut4mod,ut8,utc,utw,utx,uvx,uxx,v64,vbf,vcm,veh,vfs0,vgi,vhv,vmap,vmap_c,vmdl,vmv,vmx,vol,vvvvvv,vwp,vx2,w3g,w3m,w3n,w3x,w3z,wa2,wad,wagame,wal,wam,wbfs,wbt,wc6,weap,wgf,whirld,wl1,wl6,wldx,wmo,wolfquest,wop,world,wotmod,wotreplay,wowsreplay,wrpl,wtd,wtf,wu8,wxn,wz,xal,xan,xbe,xbsav,xci,xen,xex,xgdw,xgt,xmb,xnb,xom,xp2,xp3,xp4,xpk,xs,xtl,xvmconf,y3a,y3d,ycm,ydc,ydk,ydt,yfs,ytd,z1,z2,z2f,z2s,z3,z4,z5,z6,z64,z7,z8,zad,zblorb,zks,zmap,zs0,zs1,zs2,zs3,zs4,zs5,zs6,zs7,zs8,zs9,zsd,zsm,ztd,ztmp,zzz,256,8st,a2theme,a7p,aco,acrodata,acv,acw,adpp,ahl,ahs,ahu,ait,aiu,alv,aom,arg,asef,asl,asw,aswcs,asws,atc,ath,atn,atz,awcav,bau,bcmx,bgi,bitpim,bitsboard,blob,blt,blw,boot,bs7,bsxc,bsxp,btsearch,bxx,c2r,camp,cdrt,cex,chl,chx,clr,cmate,cmmtheme,cnf,comp,copreset,costyle,cpdx,cptm,csaplan,cskin,csplan,cui,cuix,dbb,dbg,dcst,ddf,deft,directory,dok,dpv,dr5,dsw,dtsconfig,duck,dxls,ecfg,eft,eftx,ehi,emm,emmt,enp,ens,enz,epr,eqf,eqp,etff,eum,ewprj,eww,example,exe4j,exportedui,eyetvp,eyetvsched,fat,fbt,fc,fcc,fdc,fe_launch,flst,fm3,fmod,fpl,frames,frr,fspy,ft,fth,ftp,ftpquota,fvp,fwt,fxb,gcsx,gid,gin,gliffy,gmw,godot,gqsx,gtkrc,gvimrc,gvswatch,h2p,hd3d,hdt,hfp,hme,how2,hpr,ht,iaf,icc,icm,icst,icursorfx,iddx,idf,idpp,ihw,iip,iit,ikf,ikmp,immodules,import,injb,inms,ipcc,ipynb,iros,irs,isp,iss,itt,ix,jdf,jkm,joy,kcb,kds,kfl,klc,kmf,kuip,kyb,kys,l4d,lbrn,lbu,lcc,lfo,lgt,lh3d,lily,lmc,lnst,loaders,look,lop,lrsmcol,lrtemplate,lva,lvf,lxcp,lxsopt,m2s,mailhost,mask,mcl,mgk,mlk,mns,mnu,mobirise,moef,mof,moti,motn,motr,mpt,mskn,msn,mst,mxskin,mycolors,ncfg,nd,ndc,ngrr,nji,nkp,np4,npfx,nsx,ntc,nts,nvp,nwv,obi,obt,oce,officeui,ofp,oif,ois,olk14pref,oms,onetoc,onetoc2,ops,options,opts,osdx,oss,otmu,otpu,otw,otwu,otz,ovpn,pctl,pdadj,pgp,pie,pio,pip,pmc,pmj,pmp,policy,pr,pref,prfpset,profimail,propdesc,props,ps1xml,psc1,pvs,pxb,q2d,q5q,q9q,qat,qss,qtp,qvpp,qvt,qxw,rcf,rct,rdo,rdp,rdr,rdw,resmoncfg,rfq,rgrid,rhr,rll,rmskin,rnx,rpb,rpe,rpk,rproj,rps,rpv,ruleset,rwstyle,s2ml,sgt,sif,ski,skin,skn,skz,sl,slt,smt,spfx,srs,sss,stb,sw2,t2c,tcls,tee,terminal,tfx,tgw,the,thmx,tll,tlo,tmtheme,tpark,tscproj,tsi,tsm,tsz,tts,tvtemplate,tw3,twc,typeit4me,uct,udcx,ugr,uis,user,utz,vbox,vcomps,vcpref,vcw,vim,vimrc,viz,vmac,vmba,vmc,vmcx,vmpl,vmtm,vmxf,vnc,vni,vph,vps,vqc,vsprops,vssettings,vstpreset,vsw,vtpr,wc,wcx,wcz,wfc,wfw,wif,wlvs,wme,wms,work,wzconfig,x4k,xcscheme,xct,xcu,xdr,xep,xes,xet,xev,xgs,xiz,xlb,xpl,xst,xtodvd,xtreme,xui,xur,xvm,xwk,ytt,zon,zpf,zvt,acfm,amfm,dfont,eot,euf,f3f,ffil,fot,gdr,gf,glif,lwfn,nftr,odttf,pfa,pfb,pfm,pmt,suit,t65,tfm,ttc,tte,vfb,vlw,vnf,woff,woff2,xfn,ytf,|||pkpass,grs,_eml,_nws,!bt,!qb,!sync,!ut,1,323,83p,8xp,aawdef,abr,ac$,acl,acs,add,aepkey,afploc,ahd,ahi,alt,aod,appup,aria2,auz,avastlic,avgdx,az!,bbl,bc!,bfc,bkmk,bli,bnd,bootskin,bp2,bp3,bqy,bst,bt!,buf,cache,calibre,cbds,cdf-ms,cerber3,cfl,chunk001,chw,clkk,clkt,clkw,clkx,cmm,contour,cp3,crc,crd,ctg,cul,cvr,dcover,dctmp,decrypt,desktop,disabled,dlm,dmx-info,drc,dskin,dstudio,dtapart,dwc,dwl,dwlibrary,ebn,edc,eek,ef2,egt,email,enf,enml,esd,event,ewnet,exd,extra,eyb,ezlog,ezw,fb!,feedback,ffu,file,fl3,flf,fmelic,fnd,fnlf,fpfv,frk,ftil,ftploc,fw,g1a,g3a,gau,glink,gly,gpg,gradients,gta,h1q,hdk,hdx,hlb,hlx,hmx,hxa,hxc,hxe,hxk,hxt,ical,icalendar,icma,icontainer,id,idlk,ifl,iix,imapmbox,imy,inca,indk,inetloc,ing,inlk,inm,iobit,ipsw,isn,itc,jad,jc,jc!,jcl,jcw,jms,jmt,jmx,jqz,jrs,khd,khi,kmr,kyr,lck,legal,letter,lic,licensekey,lid,link,linx,logonvista,logonxp,loov,lrc,lsn,lwtp,lxa,mab,mailtoloc,mbs,mc2,mco,md5,mdw,mfil,mgdatabase,mgo,mgt,mjdoc,mmo,mnl,mnx,montage,mpcpl,mrk,mta,mtd,mthd,mvi,na2,nav2,nch,nd5,ndl,new,nick,njb,nk2,nss,nth,nup,nvi,ob!,ook,opdownload,ost,otc,owg,owm,p10,p2p,p7m,p7r,pad,pando,partial,pdpcomp,plsk,ppk,psar,psi,pth,ptr,pvk,qds,qiz,qua,qwq,qxl,radiumkey2,rat,redir,reloc,rem,req,rfb,rfn,rfp,rmh,rov,rpmsg,rsa,rtc,rwlibrary,rxc,search-ms,sft,sfv,shs,skba,skindex,skr,slf,slupkg-ms,snf,snt,sr0,sslf,ssw,storymill,svn-work,swj,t$m,tbs,tcz,tec,tfil,tip,tla,tls,tmb,tnef,tnsp,tpkey,tpm,trace,tscdf,tstream,ttx,uls,unk,unknown,unl,upg,urr,vbt,vdjsend,ver,vir,vlcl,vmg,vmhf,vmhr,vmsg,vncloc,vor,vpa,vpc6,vpc7,wba,wcinv,wdseml,wgs,wje,wordlist,wrts,wsz,wtc,wul,wwd,wzmul,xensearch,xlnk,xnk,xslic,xwf,ybd,ymg,yps,z80,zm9,zml,ztf,ztr,zvpl,|||pas,bpl,dpr,dcu,dpl,dproj,|||\n"}

Yara Overview

Dropped Files

SourceRuleDescriptionAuthorStrings
C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.htaJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
    C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.htaJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
      C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.htaJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
        C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.htaJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
          C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.htaJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
            Click to see the 10 entries

            Memory Dumps

            SourceRuleDescriptionAuthorStrings
            00000002.00000002.596775343.00000000036B4000.00000004.00000001.sdmpJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
              00000000.00000002.348130497.0000000004DE0000.00000004.00000001.sdmpJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
                00000000.00000002.348121933.0000000004DD0000.00000004.00000001.sdmpJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
                  0000001A.00000003.407325119.0000000005E80000.00000004.00000001.sdmpJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
                    00000016.00000003.389950507.0000000005E90000.00000004.00000001.sdmpJoeSecurity_CryLockYara detected CryLock ransomwareJoe Security
                      Click to see the 4 entries

                      Sigma Overview

                      System Summary:

                      barindex
                      Sigma detected: Delete shadow copy via WMICShow sources
                      Source: Process startedAuthor: Joe Security: Data: Command: 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE', CommandLine: 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE', CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: 'C:\Users\user\appdata\local\temp\svcuwq.exe' , ParentImage: C:\Users\user\AppData\Local\Temp\svcuwq.exe, ParentProcessId: 6804, ProcessCommandLine: 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE', ProcessId: 4388

                      Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Found malware configurationShow sources
                      Source: 61b2f50b_by_Libranalysis.exe.6628.0.memstrMalware Configuration Extractor: CryLock {"Extensions": "ods,xar,xlr,xls,xlsb,xlsm,xlsx,xlt,xltm,xltx,asp,accdb,b2,crypt,crypt5,crypt6,crypt7,crypt8,crypt12,dat,db,dbf,dbx,kdc,log,mdb,mdf,sdf,sis,sql,awb,bin,cdi,cdr,css,csv,eap,efx,gam,gbr,ged,gtp,mpp,msc,mts,one,otf,nbk,nbp,ndb,prf,prj,rtp,sav,scppy,sgml,tax2010,tbl,tmp,ts,vcd,xml,xsl,xslt,1cd,epf,erf,^^^,$er,4dd,4dl,accdc,accde,accdr,accdt,accft,adb,ade,adf,adp,alf,ask,btr,cat,cdb,ckp,cma,cpd,crypt9,dacpac,dad,dadiagrams,daschema,db-shm,db-wal,db3,dbc,dbs,dbt,dbv,dcb,dct,dcx,ddl,dlis,dp1,dqy,dsk,dsn,dtsx,dxl,eco,ecx,edb,epim,exb,fcd,fdb,fic,fmp,fmp12,fmpsl,fol,fp3,fp4,fp5,fp7,fpt,frm,gdb,grdb,gwi,hdb,his,ib,idb,ihx,itdb,itw,jet,jtx,kdb,kexi,kexic,kexis,lgc,lwx,maf,maq,mar,marshal,mas,mav,mpd,mrg,mud,mwb,myd,ndf,nnt,nrmlib,ns2,ns3,ns4,nsf,nv,nv2,nwdb,nyf,odb,oqy,ora,orx,owc,p96,p97,pan,pdb,pdm,pnz,qry,qvd,rbf,rctd,rod,rodx,rpd,rsd,sas7bdat,sbf,scx,sdb,sdc,spq,sqlite,sqlite3,sqlitedb,te,teacher,temx,tmd,tps,trc,trm,udb,udl,usr,v12,vis,vpd,vvv,wdb,wmdb,wrk,xdb,xld,xmlff,{pb,~hm,17t,1pe,1ph,3dmdef,3dp,3dr,3dt,3dw,3me,3pe,4dv,4fs,5vw,73c,73l,8xg,8xk,8xs,8xv,a5l,a5w,a65,aam,aao,ab,ab1,ab3,abcd,abi,abkprj,abp,aby,aca,acc,acf,acg,acq,acr,acz,adcp,addism,adi,adif,adt,adu,adv,advs,adx,aes,afe,aff,aft,agd,aggr,aifb,alc,ald,aldf,ali,amb,amc,aml,amm,amsorm,an1,an8,anime,anme,ans,ansym,anx,apalbum,aph,aplibrary,arc,arff,arn,art,as,ashprj,asm,asnd,asr,ast,atf,atomsvc,ats,avc,avhdx,avj,avl,avp,aw,awbr,awdb,awg,azz,azzx,bafl,bar,baserproj,bc,bcc,bci,bcl,bcm,bct,bdc,bdf,bdic,bed,bfx,bgl,bgt,bho,bim,binary,bionix,bjo,bk,blb,bld,blg,bln,blockplt,blogthis,bluebutton,bm2,bms,bnk,bok,book,box,bpd,bpdx,bphys,bpj,bplx,bpm,brain,brd,brf,brl,brn,brs,brw,bsd,bsdl,btf,btif,btinstall,btm,bul,bvp,c3d,c4p,caf,camm,cap,capt,capx,car,cav,cawr,cbg,cbmap,cbz,cca,cch,ccld,ccp,cct,cdf,cdm,cdp,cdpz,cdx,cdxml,cef,cel,celtx,cfa,cfb,cfs,cfx,cgd,chg,chk,chr,cif,circ,ckt,cl2,classlist,clb,cld,clg,clix,clk,clkm,clks,clktk,clkv,clm,clp,clx,cm10,cm5,cmap,cmbl,cml,cmr,cms,cna,col,collab,contact,cpaa,cpf,cpk,cpmz,cptx,cram,crev,crtx,cry,cs,csa,ctb,ctf,ctl,ctm,ctp,ctproject,ctt,ctv,ctv3,cub,cube,cursorfx,curxptheme,cva,cvd,cvn,cwk,cww,cxa,cxd,cxf,cxr,cxt,cyo,cys,czi,czp,da2,daf,dal,dam,dap,das,dbd,dbgsym,dcf,dcl,dcm,dcmd,dcmf,dcpf,dcpr,ddb,ddc,ddcx,ddt,def,deproj,des,det,develve,deviceinfo,dex,dfm,dfproj,dgs,dhcd,dia,dict,dif,dig,dii,dip,dita,ditamap,ditaval,dkt,dl,dlc,dlt,dltemp,dm2,dmc,dmm,dmmx,dmo,dmpr,dmr,dmsp,dna,dng,dockzip,dot,dpb,dpn,dps,dpt,dpx,dr,drf,drl,drscan,dsb,dsc,dsd,dsl,dsx,dsy,dsz,dt,dtd,dtp,dtr,dupeguru,dvb,dvc,dvdproj,dvds,dvo,dwi,dws,e2p,eas,ebm,ebuild,ec0,ec3,ec4,ecc,ecl,ect,edat,edat2,edf,edfx,edg,edi,eep,ef,efp,eglib,egp,ekb,els,em,emb,embl,emd,emlxpart,emrg,emrg2,enc,enex,enl,enlx,enq,env,enw,epp,epw,er1,erd,erg,erp,ersx,es,es2,esb,ese,esp,esq,est,esx,et,ete,etng,ett,ev,ev3,ev3p,ev3s,evx,evy,ews,exif,exl,exm,exp,exx,f04,f06,fa,familyfile,far,fas,fasta,fbk,fbq,fcpbundle,fcpevent,fcpproject,fcpxdest,fcpxml,fcs,fct,fdf,fdm,fdt,fdx,fes,ffd,fff,ffindex,ffo
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: 61b2f50b_by_Libranalysis.exeVirustotal: Detection: 49%Perma Link
                      Source: 61b2f50b_by_Libranalysis.exeReversingLabs: Detection: 63%
                      Machine Learning detection for sampleShow sources
                      Source: 61b2f50b_by_Libranalysis.exeJoe Sandbox ML: detected
                      Source: 0.2.61b2f50b_by_Libranalysis.exe.400000.0.unpackAvira: Label: TR/ATRAPS.Gen
                      Source: 26.2.svcuwq.exe.400000.0.unpackAvira: Label: TR/ATRAPS.Gen
                      Source: 22.2.svcuwq.exe.400000.0.unpackAvira: Label: TR/ATRAPS.Gen
                      Source: 2.2.svcuwq.exe.400000.0.unpackAvira: Label: TR/ATRAPS.Gen
                      Source: 61b2f50b_by_Libranalysis.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, BYTES_REVERSED_LO, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, BYTES_REVERSED_HI, RELOCS_STRIPPED

                      Spreading:

                      barindex
                      Infects executable files (exe, dll, sys, html)Show sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Spreads via windows shares (copies files to share folders)Show sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: z:\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\100__Connections.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\customizations.xmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\102__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\MasterDatastore.xmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\0__HotSpot.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\101__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxmlJump to behavior

                      Networking:

                      barindex
                      Uses ping.exe to check the status of other devices and networksShow sources
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 0.0.0.0
                      Source: Joe Sandbox ViewIP Address: 0.0.0.0 0.0.0.0
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\appdata\local\application data\application data\application data\application data\application data\application data\application data\application data\application data\temporary internet files\how_to_decrypt.htaJump to behavior

                      Spam, unwanted Advertisements and Ransom Demands:

                      barindex
                      Found ransom note / readmeShow sources
                      Source: C:\Users\user\AppData\Local\Temp\how_to_decrypt.htaDropped file: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"><html><title>CryLock</title><hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application><script language="JavaScript">var ud=0;var op=0xc7bf30;var zoc=0;function document.onkeydown() { var alt=window.event.altKey; if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) { event.keyCode=0; event.cancelBubble=true; return false; } }function document.onblur(){alert('Attention! This important information for you!');}function ChangeTime(){var sd = new Date('May 4 2021 09:14:35');var dn = new Date();if (sd.getTime()<dn.getTime()){var dt=document.getElementById('pwr');dt.innerHTML='<font color="red" size="5"><b>Price is raised!</b></font>';dt.style.height=78;zoc=1;}else{var delta=sd.getTime()-dn.getTime();delta=new Date(delta);var dd=(delta.getUTCDate()-1)+((delta.getUTCMonth())*31);var hh=delta.getUTCHours();var mm=delta.getUTCMinutes();var ss=delta.getUTCSeconds();if (dd!=1){dd=dd+' days';}else{dd=dd+' day';}if (hh<10){hh='0'+hh;}if (mm<10){mm='0'+mm;}if (ss<10){ss='0'+ss;}var dt=document.getElementById('dt');dt.innerHTML='<font face="monospace" color="#c2c2c2" size="4"><b>'+dd+' '+hh+':'+mm+':'+ss+'</b></font>';}var sd = new Date('May 6 2021 09:14:35');dn = new Date();if (sd.getTime()<dn.getTime()){var dt=document.getElementById('lctw');dt.innerHTML='<font color="red" size="5"><b>Last chance to decrypt your files!</b></font>';zoc=2;}else{var delta=sd.getTime()-dn.getTime();delta=new Date(delta);var dd=(delta.getUTCDate()-1)+((delta.getUTCMonth())*31);var hh=delta.getUTCHours();var mm=delta.getUTCMinutes();var ss=delta.getUTCSeconds();if (dd!=1){dd=dd+' days';}else{dd=dd+' day';}if (hh<10){hh='0'+hh;}if (mm<10){mm='0'+mm;}if (ss<10){ss='0'+ss;}var dt=document.getElementById('et');dt.innerHTML='<font face="monospace" color="#c2c2c2" size="4"><b>'+dd+' '+hh+':'+mm+':'+ss+'</b></font>';}}function getRandomArbitrary(min, max) {min = Math.ceil(min);max = Math.floor(max);return Math.floor(Math.random() * (max - min)) + min;}function Rndom(){document.getElementById("blumid").focus();var bid=document.getElementById('blumid');var bem=document.getElementById('blummail');if (ud==0){op=op-0x10;}else{op=op+0x10;}if (op<=0xc00000){ud=1;}if (op>=0xc7bf30){ud=0;}bid.style.backgroundColor=op;bem.style.backgroundColor=op;var xx='';var i=0;while (i<19){xx=xx+getRandomArbitrary(0,2);i=i+1;}if (zoc==0){var dt=docJump to dropped file
                      Yara detected CryLock ransomwareShow sources
                      Source: Yara matchFile source: 00000002.00000002.596775343.00000000036B4000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.348130497.0000000004DE0000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.348121933.0000000004DD0000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000001A.00000003.407325119.0000000005E80000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000016.00000003.389950507.0000000005E90000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.348126087.0000000004DD8000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 61b2f50b_by_Libranalysis.exe PID: 6628, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: svcuwq.exe PID: 7404, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: svcuwq.exe PID: 6804, type: MEMORY
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Source: Yara matchFile source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, type: DROPPED
                      Deletes shadow drive data (may be related to ransomware)Show sources
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\vssadmin.exe vssadmin delete shadows /all /quiet
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic SHADOWCOPY DELETE
                      Source: 61b2f50b_by_Libranalysis.exe, 00000000.00000002.348121933.0000000004DD0000.00000004.00000001.sdmpBinary or memory string: vssadmin delete shadows /all /quiet
                      Source: 61b2f50b_by_Libranalysis.exe, 00000000.00000002.348121933.0000000004DD0000.00000004.00000001.sdmpBinary or memory string: #vssadmin delete shadows /all /quiet
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'Jump to behavior
                      Source: svcuwq.exe, 00000002.00000002.596538661.000000000162F000.00000004.00000020.sdmpBinary or memory string: "C:\Windows\System32\cmd.exe" /c "vssadmin delete shadows /all /quiet"
                      Source: svcuwq.exe, 00000002.00000002.596696200.0000000003690000.00000004.00000001.sdmpBinary or memory string: vssadmin delete shadows /all /quiet
                      Source: svcuwq.exe, 00000002.00000002.596696200.0000000003690000.00000004.00000001.sdmpBinary or memory string: #vssadmin delete shadows /all /quiet
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\vssadmin.exe vssadmin delete shadows /all /quietJump to behavior
                      Source: vssadmin.exe, 0000000B.00000002.369038384.0000000000B70000.00000004.00000020.sdmpBinary or memory string: C:\Users\user\Desktop\C:\Windows\SysWOW64\vssadmin.exevssadmin delete shadows /all /quietvssadmin delete shadows /all /quietWinsta0\Default=::=::\=C:=C:\Users\user\DesktopALLUSERSPROFILE=C:\ProgramDataAPPDATA=C:\Users\user\AppData\RoamingCommonProgramFiles=C:\Program Files (x86)\Common FilesCommonProgramFiles(x86)=C:\Program Files (x86)\Common FilesCommonProgramW6432=C:\Program Files\Common FilesCOMPUTERNAME=computerComSpec=C:\Windows\system32\cmd.exeDriverData=C:\Windows\System32\Drivers\DriverDataHOMEDRIVE=C:HOMEPATH=\Users\userLOCALAPPDATA=C:\Users\user\AppData\LocalLOGONSERVER=\\computerNUMBER_OF_PROCESSORS=4OneDrive=C:\Users\user\OneDriveOS=Windows_NTPath=C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsApps;PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSCPROCESSOR_ARCHITECTURE=x86PROCESSOR_ARCHITEW6432=AMD64PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 85 Stepping 7, GenuineIntelPROCESSOR_LEVEL=6PROCESSOR_REVISION=5507ProgramData=C:\ProgramDataProgramFiles=C:\Program Files (x86)ProgramFiles(x86)=C:\Program Files (x86)ProgramW6432=C:\Program FilesPROMPT=$P$GPSModulePath=C:\Program Files (x86)\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WindowsTEMP=C:\Users\user\AppData\Local\TempTMP=C:\Users\user\AppData\Local\TempUSERDOMAIN=VWDFPKGUSERDOMAIN_ROAMINGPROFILE=computerUSERNAME=userUSERPROFILE=C:\Users\userwindir=C:\Windows
                      Source: vssadmin.exe, 0000000B.00000002.369038384.0000000000B70000.00000004.00000020.sdmpBinary or memory string: vssadmin delete shadows /all /quiet
                      Source: vssadmin.exe, 0000000B.00000002.369038384.0000000000B70000.00000004.00000020.sdmpBinary or memory string: vssadmin delete shadows /all /quietV8
                      Source: vssadmin.exe, 0000000B.00000002.369165332.0000000000E10000.00000004.00000040.sdmpBinary or memory string: vssadmindeleteshadows/all/quiet
                      Source: vssadmin.exe, 0000000B.00000002.369031674.00000000009D0000.00000004.00000020.sdmpBinary or memory string: C:\Users\user\Desktop\C:\Windows\SysWOW64\vssadmin.exevssadmin delete shadows /all /quietvssadmin delete shadows /all /quietWinsta0\Default
                      Source: vssadmin.exe, 0000000B.00000002.369076596.0000000000B77000.00000004.00000020.sdmpBinary or memory string: - Code: ADMPROCC00001737- Call: ADMPROCC00001712- PID: 00007148- TID: 00007152- CMD: vssadmin delete shadows /all /quiet - User: Name: computer\user, SID:S-1-5-21-3853321935-2125563209-4053062332-1002
                      Source: vssadmin.exe, 0000000B.00000002.369076596.0000000000B77000.00000004.00000020.sdmpBinary or memory string: - Code: ADMPROCC00001737- Call: ADMPROCC00001712- PID: 00007148- TID: 00007152- CMD: vssadmin delete shadows /all /quiet - User: Name: computer\user, SID:S-1-5-21-3853321935-2125563209-4053062332-1002 T771
                      Source: vssadmin.exe, 0000000B.00000002.368792785.000000000057C000.00000004.00000001.sdmpBinary or memory string: - Code: ADMPROCC00001737- Call: ADMPROCC00001712- PID: 00007148- TID: 00007152- CMD: vssadmin delete shadows /all /quiet - User: Name: computer\user, SID:S-1-5-21-3853321935-2125563209-4053062332-1002 -
                      Source: vssadmin.exe, 0000000B.00000002.369118102.0000000000C70000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete ShadowStorage
                      Source: vssadmin.exe, 0000000B.00000002.369118102.0000000000C70000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete Shadows /Type=ClientAccessible /For=C:
                      Source: vssadmin.exe, 0000000B.00000002.369118102.0000000000C70000.00000002.00000001.sdmpBinary or memory string: vssadmin Delete Shadows
                      Source: vssadmin.exe, 0000000B.00000002.369118102.0000000000C70000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete Shadows /For=C: /Oldest
                      Source: vssadmin.exe, 0000000B.00000002.369118102.0000000000C70000.00000002.00000001.sdmpBinary or memory string: Example Usage: vssadmin Delete ShadowStorage /For=C: /On=D:
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic SHADOWCOPY DELETEJump to behavior
                      Source: svcuwq.exe, 00000016.00000003.389950507.0000000005E90000.00000004.00000001.sdmpBinary or memory string: vssadmin delete shadows /all /quiet
                      Source: svcuwq.exe, 00000016.00000003.389950507.0000000005E90000.00000004.00000001.sdmpBinary or memory string: #vssadmin delete shadows /all /quiet
                      Source: svcuwq.exe, 0000001A.00000003.407325119.0000000005E80000.00000004.00000001.sdmpBinary or memory string: vssadmin delete shadows /all /quiet
                      Source: svcuwq.exe, 0000001A.00000003.407325119.0000000005E80000.00000004.00000001.sdmpBinary or memory string: #vssadmin delete shadows /all /quiet
                      Writes many files with high entropyShow sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\ARM\S\11357\AdobeARM.msi entropy: 7.99780977557Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exe entropy: 7.99886528951Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\ARM\S\1742\AdobeARM.msi entropy: 7.99677730376Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exe entropy: 7.99881499028Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\ARM\S\ARM.msi entropy: 7.99759487298Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\AcroRdrDCUpd1901220034.msp entropy: 7.99974245466Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\AcroRead.msi entropy: 7.99756603806Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exe entropy: 7.99762684624Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\windows.uif_ondemand.xml.inbox entropy: 7.99960556583Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.privacy.diffbase entropy: 7.99948605157Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db entropy: 7.99070126047Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\OFFICE\MySharePoints.ico entropy: 7.99441187772Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\customizations.xml entropy: 7.99819864277Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime.xml entropy: 7.99895384572Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin entropy: 7.9998922687Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.5B entropy: 7.99920894526Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.67 entropy: 7.99951071177Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.6C entropy: 7.99775724891Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.79 entropy: 7.9953543765Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.7C entropy: 7.99861674169Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.7E entropy: 7.99909912847Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.80 entropy: 7.99928008624Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.87 entropy: 7.99904880612Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.A0 entropy: 7.99969644062Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.CE entropy: 7.99082206944Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Microsoft\Windows Defender\Scans\mpuserdb.db entropy: 7.9992879552Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Oracle\Java\installcache\baseimagefam8 entropy: 7.99963626362Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cab entropy: 7.99028296526Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi entropy: 7.99645773197Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi entropy: 7.99555221632Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{19F7E289-17B8-44EC-A099-927507B6F739}v14.21.27702\packages\vcRuntimeMinimum_x86\cab1.cab entropy: 7.99148726385Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{19F7E289-17B8-44EC-A099-927507B6F739}v14.21.27702\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi entropy: 7.99622786463Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe entropy: 7.99909779656Jump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\cab1.cab entropy: 7.99013059418Jump to dropped file

                      System Summary:

                      barindex
                      Source: 61b2f50b_by_Libranalysis.exe, 00000000.00000002.348504183.0000000005210000.00000002.00000001.sdmpBinary or memory string: System.OriginalFileName vs 61b2f50b_by_Libranalysis.exe
                      Source: 61b2f50b_by_Libranalysis.exe, 00000000.00000002.348100686.0000000003790000.00000002.00000001.sdmpBinary or memory string: originalfilename vs 61b2f50b_by_Libranalysis.exe
                      Source: 61b2f50b_by_Libranalysis.exe, 00000000.00000002.348100686.0000000003790000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamepropsys.dll.mui@ vs 61b2f50b_by_Libranalysis.exe
                      Source: 61b2f50b_by_Libranalysis.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, BYTES_REVERSED_LO, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, BYTES_REVERSED_HI, RELOCS_STRIPPED
                      Source: classification engineClassification label: mal100.rans.spre.troj.evad.winEXE@32/1029@0/2
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7104:120:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7076:120:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:992:120:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6836:120:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7160:120:WilError_01
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5780:120:WilError_01
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeMutant created: \Sessions\1\BaseNamedObjects\6492BED7-7C13DE55
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4400:120:WilError_01
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeFile created: c:\users\user\appdata\local\temp\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: 61b2f50b_by_Libranalysis.exeVirustotal: Detection: 49%
                      Source: 61b2f50b_by_Libranalysis.exeReversingLabs: Detection: 63%
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeFile read: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe'
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Users\user\AppData\Local\Temp\svcuwq.exe 'C:\Users\user\appdata\local\temp\svcuwq.exe'
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'ping 0.0.0.0&del 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe''
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 0.0.0.0
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'vssadmin delete shadows /all /quiet'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE BACKUP -keepVersions:0'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\vssadmin.exe vssadmin delete shadows /all /quiet
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic SHADOWCOPY DELETE
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\svcuwq.exe 'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222'
                      Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\svcuwq.exe 'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222'
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Users\user\AppData\Local\Temp\svcuwq.exe 'C:\Users\user\appdata\local\temp\svcuwq.exe' Jump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'ping 0.0.0.0&del 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe''Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'vssadmin delete shadows /all /quiet'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE BACKUP -keepVersions:0'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 0.0.0.0Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\vssadmin.exe vssadmin delete shadows /all /quietJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic SHADOWCOPY DELETEJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32Jump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeCode function: 0_3_04DD48DB push esp; iretd 0_3_04DD48DC
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeCode function: 0_3_04DD5DD5 push cs; iretd 0_3_04DD5DD8
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeCode function: 0_3_04DD61FB push 44E8CF44h; iretd 0_3_04DD6200
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeCode function: 0_3_04DD5378 pushfd ; iretd 0_3_04DD537A
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 2_3_03695378 pushfd ; iretd 2_3_0369537A
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 2_3_036961FB push 44E8CF44h; iretd 2_3_03696200
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 2_3_036948DB push esp; iretd 2_3_036948DC
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 2_3_03695DD5 push cs; iretd 2_3_03695DD8
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 22_3_05E961FB push 44E8CF44h; iretd 22_3_05E96200
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 22_3_05E948DB push esp; iretd 22_3_05E948DC
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 22_3_05E95DD5 push cs; iretd 22_3_05E95DD8
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 22_3_05E95378 pushfd ; iretd 22_3_05E9537A
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 26_3_05E861FB push 44E8CF44h; iretd 26_3_05E86200
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 26_3_05E848DB push esp; iretd 26_3_05E848DC
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 26_3_05E85DD5 push cs; iretd 26_3_05E85DD8
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeCode function: 26_3_05E85378 pushfd ; iretd 26_3_05E8537A

                      Persistence and Installation Behavior:

                      barindex
                      Drops executable to a common third party application directoryShow sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Infects executable files (exe, dll, sys, html)Show sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeSystem file written: C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exeJump to behavior
                      Uses bcdedit to modify the Windows boot settingsShow sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'Jump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeFile created: C:\Users\user\AppData\Local\Temp\svcuwq.exeJump to dropped file

                      Boot Survival:

                      barindex
                      Creates autostart registry keys with suspicious namesShow sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 6492BED7-7C13DE55Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\accessibility\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\accessories\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\autoit v3\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\java\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\maintenance\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\startup\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\system tools\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\accessories\system tools\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\administrative tools\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\autoit v3\extras\autoitx\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\autoit v3\extras\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\microsoft office 2016 tools\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\accessibility\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\accessories\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\maintenance\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\system tools\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\windows powershell\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\programs\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\documents and settings\default\start menu\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 6492BED7-7C13DE55Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 6492BED7-7C13DE55Jump to behavior

                      Hooking and other Techniques for Hiding and Protection:

                      barindex
                      Creates files in the recycle bin to hide itselfShow sources
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile created: c:\$recycle.bin\s-1-5-18\how_to_decrypt.htaJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exe TID: 6808Thread sleep count: 292 > 30Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exe TID: 6808Thread sleep time: -2920000s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exe TID: 6196Thread sleep count: 269 > 30Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exe TID: 6196Thread sleep time: -2690000s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exe TID: 6216Thread sleep count: 52 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeLast function: Thread delayed
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeLast function: Thread delayed
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\SysWOW64\PING.EXELast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile Volume queried: C:\Users\user\Desktop FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\100__Connections.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\customizations.xmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\102__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\MasterDatastore.xmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\0__HotSpot.provxmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeFile opened: c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\prov\runtime\101__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxmlJump to behavior
                      Source: svcuwq.exe, 0000001A.00000003.407250554.0000000005E9E000.00000004.00000001.sdmpBinary or memory string: bwi,bwt,dmg,i00,i01,i02,isz,md0,md1,md2,nrg,pdi,toast,2mg,adz,afm,ashdisc,atr,avhd,b5i,b6i,bwa,bws,bwz,ciso,cl5,cue,d64,d88,daa,dao,dax,dbr,disc,disk,dmgpart,dms,e01,ecm,eda,ede,edk,edq,eds,edv,eui,ex01,fdi,g41,gbi,gdrive,gi,gkh,hc,hdd,hfs,hfv,ibadr,ibb,ibdat,ibp,ibq,imz,ixa,k3b,l01,lx01,mbi,miniso,mrimg,nn,nri,p2g,p2i,partimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,u3p
                      Source: vssadmin.exe, 0000000B.00000002.369350581.00000000044D0000.00000002.00000001.sdmp, WMIC.exe, 00000013.00000002.371536262.00000000032A0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
                      Source: svcuwq.exeBinary or memory string: vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,conf,deskthemepack,ds_store,inf,plist,swb,thempack,cf,cfu,vrp,lgp,pff,efd,00,32x,3dsx,3dz,555,68k,8ld,a26,ac
                      Source: svcuwq.exe, 0000001A.00000003.407250554.0000000005E9E000.00000004.00000001.sdmpBinary or memory string: bwi,bwt,dmg,i00,i01,i02,isz,md0,md1,md2,nrg,pdi,toast,2mg,adz,afm,ashdisc,atr,avhd,b5i,b6i,bwa,bws,bwz,ciso,cl5,cue,d64,d88,daa,dao,dax,dbr,disc,disk,dmgpart,dms,e01,ecm,eda,ede,edk,edq,eds,edv,eui,ex01,fdi,g41,gbi,gdrive,gi,gkh,hc,hdd,hfs,hfv,ibadr,ibb,ibdat,ibp,ibq,imz,ixa,k3b,l01,lx01,mbi,miniso,mrimg,nn,nri,p2g,p2i,partimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,
                      Source: svcuwq.exeBinary or memory string: gi,gkh,hc,hdd,hfs,hfv,ibadr,ibb,ibdat,ibp,ibq,imz,ixa,k3b,l01,lx01,mbi,miniso,mrimg,nn,nri,p2g,p2i,partimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,w
                      Source: svcuwq.exeBinary or memory string: rtimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,conf,deskthemepac
                      Source: svcuwq.exeBinary or memory string: nri,p2g,p2i,partimg,pgd,qcow,qcow2,ratdvd,sco,sdsk,sqfs,st,t64,tao,tap,tzx,ufs,uibak,uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,con
                      Source: vssadmin.exe, 0000000B.00000002.369350581.00000000044D0000.00000002.00000001.sdmp, WMIC.exe, 00000013.00000002.371536262.00000000032A0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
                      Source: vssadmin.exe, 0000000B.00000002.369350581.00000000044D0000.00000002.00000001.sdmp, WMIC.exe, 00000013.00000002.371536262.00000000032A0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
                      Source: svcuwq.exeBinary or memory string: aporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,conf,deskthemepack,ds_store,inf,plist,swb,thempack,cf,cfu,vrp,lgp,pff,efd,00,32x,3dsx,3dz,555
                      Source: vssadmin.exe, 0000000B.00000002.369350581.00000000044D0000.00000002.00000001.sdmp, WMIC.exe, 00000013.00000002.371536262.00000000032A0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.
                      Source: svcuwq.exeBinary or memory string: uif,vaporcd,vc6,vc8,vco,vdi,vfd,vhdx,vmdk,vmwarevm,volarchive,wbi,wii,wil,wim,winclone,wmt,woz,wud,x64,xdi,xva,xvd,|||fnt,fon,torrent,magnet,sngw,ucm,application,appref-ms,conf,deskthemepack,ds_store,inf,plist,swb,thempack,cf,cfu,vrp,lgp,pff,efd,00,32x,3dsx,3d
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Users\user\AppData\Local\Temp\svcuwq.exe 'C:\Users\user\appdata\local\temp\svcuwq.exe' Jump to behavior
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'ping 0.0.0.0&del 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe''Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'vssadmin delete shadows /all /quiet'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE BACKUP -keepVersions:0'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 0.0.0.0Jump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\vssadmin.exe vssadmin delete shadows /all /quietJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic SHADOWCOPY DELETEJump to behavior
                      Source: svcuwq.exe, 00000002.00000002.596973894.0000000003B90000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
                      Source: svcuwq.exe, 00000002.00000002.596973894.0000000003B90000.00000002.00000001.sdmpBinary or memory string: Progman
                      Source: svcuwq.exe, 00000002.00000002.596973894.0000000003B90000.00000002.00000001.sdmpBinary or memory string: &Program Manager
                      Source: svcuwq.exe, 00000002.00000002.596973894.0000000003B90000.00000002.00000001.sdmpBinary or memory string: Progmanlock
                      Source: C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\svcuwq.exeQueries volume information: C:\ VolumeInformationJump to behavior

                      Mitre Att&ck Matrix

                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid AccountsWindows Management InstrumentationRegistry Run Keys / Startup Folder111Process Injection12Masquerading1OS Credential DumpingSecurity Software Discovery11Taint Shared Content2Data from Local SystemExfiltration Over Other Network MediumIngress Tool Transfer1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationInhibit System Recovery1
                      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder111Virtualization/Sandbox Evasion2LSASS MemoryVirtualization/Sandbox Evasion2Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection12Security Account ManagerProcess Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Hidden Files and Directories1NTDSRemote System Discovery11Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
                      Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information1LSA SecretsSystem Network Configuration Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
                      Replication Through Removable MediaLaunchdRc.commonRc.commonSoftware Packing1Cached Domain CredentialsFile and Directory Discovery2VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                      External Remote ServicesScheduled TaskStartup ItemsStartup ItemsFile Deletion1DCSyncSystem Information Discovery12Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact

                      Behavior Graph

                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 signatures2 2 Behavior Graph ID: 399791 Sample: 61b2f50b_by_Libranalysis Startdate: 29/04/2021 Architecture: WINDOWS Score: 100 79 Found malware configuration 2->79 81 Multi AV Scanner detection for submitted file 2->81 83 Found ransom note / readme 2->83 85 4 other signatures 2->85 8 61b2f50b_by_Libranalysis.exe 4 2->8         started        11 svcuwq.exe 2->11         started        13 svcuwq.exe 2->13         started        process3 file4 59 C:\Users\user\AppData\Local\Temp\svcuwq.exe, PE32 8->59 dropped 61 C:\Users\user\...\svcuwq.exe:Zone.Identifier, ASCII 8->61 dropped 63 C:\Users\user\AppData\...\how_to_decrypt.hta, HTML 8->63 dropped 15 svcuwq.exe 2 454 8->15         started        20 cmd.exe 1 8->20         started        process5 dnsIp6 65 192.168.2.1 unknown unknown 15->65 51 C:\ProgramData\Package Cache\...\cab1.cab, data 15->51 dropped 53 C:\ProgramData\...\vcredist_x86.exe, data 15->53 dropped 55 C:\ProgramData\...\vc_runtimeMinimum_x86.msi, data 15->55 dropped 57 48 other files (32 malicious) 15->57 dropped 69 Creates files in the recycle bin to hide itself 15->69 71 Creates autostart registry keys with suspicious names 15->71 73 Deletes shadow drive data (may be related to ransomware) 15->73 77 5 other signatures 15->77 22 cmd.exe 1 15->22         started        25 cmd.exe 1 15->25         started        27 cmd.exe 1 15->27         started        33 3 other processes 15->33 67 0.0.0.0 unknown unknown 20->67 75 Uses ping.exe to check the status of other devices and networks 20->75 29 conhost.exe 20->29         started        31 PING.EXE 1 20->31         started        file7 signatures8 process9 signatures10 87 Deletes shadow drive data (may be related to ransomware) 22->87 35 WMIC.exe 1 22->35         started        37 conhost.exe 22->37         started        39 conhost.exe 25->39         started        41 vssadmin.exe 1 25->41         started        43 conhost.exe 27->43         started        45 conhost.exe 33->45         started        47 conhost.exe 33->47         started        49 conhost.exe 33->49         started        process11

                      Screenshots

                      Thumbnails

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.

                      windows-stand

                      Antivirus, Machine Learning and Genetic Malware Detection

                      Initial Sample

                      SourceDetectionScannerLabelLink
                      61b2f50b_by_Libranalysis.exe49%VirustotalBrowse
                      61b2f50b_by_Libranalysis.exe64%ReversingLabsWin32.Ransomware.Buhtrap
                      61b2f50b_by_Libranalysis.exe100%Joe Sandbox ML

                      Dropped Files

                      No Antivirus matches

                      Unpacked PE Files

                      SourceDetectionScannerLabelLinkDownload
                      22.0.svcuwq.exe.400000.0.unpack100%AviraHEUR/AGEN.1134200Download File
                      2.0.svcuwq.exe.400000.0.unpack100%AviraHEUR/AGEN.1134200Download File
                      0.2.61b2f50b_by_Libranalysis.exe.400000.0.unpack100%AviraTR/ATRAPS.GenDownload File
                      26.0.svcuwq.exe.400000.0.unpack100%AviraHEUR/AGEN.1134200Download File
                      26.2.svcuwq.exe.400000.0.unpack100%AviraTR/ATRAPS.GenDownload File
                      22.2.svcuwq.exe.400000.0.unpack100%AviraTR/ATRAPS.GenDownload File
                      0.0.61b2f50b_by_Libranalysis.exe.400000.0.unpack100%AviraHEUR/AGEN.1134200Download File
                      2.2.svcuwq.exe.400000.0.unpack100%AviraTR/ATRAPS.GenDownload File

                      Domains

                      No Antivirus matches

                      URLs

                      No Antivirus matches

                      Domains and IPs

                      Contacted Domains

                      No contacted domains info

                      Contacted IPs

                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs

                      Public

                      IPDomainCountryFlagASNASN NameMalicious
                      0.0.0.0
                      unknownunknown
                      unknownunknowntrue

                      Private

                      IP
                      192.168.2.1

                      General Information

                      Joe Sandbox Version:32.0.0 Black Diamond
                      Analysis ID:399791
                      Start date:29.04.2021
                      Start time:09:13:33
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 13m 8s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Sample file name:61b2f50b_by_Libranalysis (renamed file extension from none to exe)
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:40
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal100.rans.spre.troj.evad.winEXE@32/1029@0/2
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:Failed
                      Cookbook Comments:
                      • Adjust boot time
                      • Enable AMSI
                      Warnings:
                      Show All
                      • Excluded IPs from analysis (whitelisted): 13.88.21.125, 52.147.198.201, 13.107.4.50, 168.61.161.212, 104.43.193.48, 20.50.102.62, 92.122.213.247, 92.122.213.249, 40.64.100.89, 20.54.26.129, 2.20.142.209, 2.20.142.210, 52.155.217.156, 184.30.20.56, 20.82.210.154
                      • Excluded domains from analysis (whitelisted): 70.2.168.192.in-addr.arpa, mw1eap.displaycatalog.md.mp.microsoft.com.akadns.net, displaycatalog-rp-uswest.md.mp.microsoft.com.akadns.net, 86.2.168.192.in-addr.arpa, 11.2.168.192.in-addr.arpa, 1.2.168.192.in-addr.arpa, 53.2.168.192.in-addr.arpa, b1ns.c-0001.c-msedge.net, 18.2.168.192.in-addr.arpa, fs-wildcard.microsoft.com.edgekey.net, 35.2.168.192.in-addr.arpa, 9.2.168.192.in-addr.arpa, 95.2.168.192.in-addr.arpa, 20.2.168.192.in-addr.arpa, 68.2.168.192.in-addr.arpa, 105.2.168.192.in-addr.arpa, consumerrp-displaycatalog-aks2eap-uswest.md.mp.microsoft.com.akadns.net, au-bg-shim.trafficmanager.net, 62.2.168.192.in-addr.arpa, 45.2.168.192.in-addr.arpa, 26.2.168.192.in-addr.arpa, 2.2.168.192.in-addr.arpa, ris-prod.trafficmanager.net, 19.2.168.192.in-addr.arpa, 54.2.168.192.in-addr.arpa, displaycatalog-uswesteap.md.mp.microsoft.com.akadns.net, skypedataprdcolcus15.cloudapp.net, 80.2.168.192.in-addr.arpa, ris.api.iris.microsoft.com, 96.2.168.192.in-addr.arpa, 77.2.168.192.in-addr.arpa, 34.2.168.192.in-addr.arpa, 69.2.168.192.in-addr.arpa, 27.2.168.192.in-addr.arpa, 61.2.168.192.in-addr.arpa, 104.2.168.192.in-addr.arpa, 3.2.168.192.in-addr.arpa, 93.2.168.192.in-addr.arpa, 79.2.168.192.in-addr.arpa, wu-fg-shim.trafficmanager.net, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, 55.2.168.192.in-addr.arpa, 72.2.168.192.in-addr.arpa, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, 60.2.168.192.in-addr.arpa, 16.2.168.192.in-addr.arpa, 28.2.168.192.in-addr.arpa, 22.2.168.192.in-addr.arpa, arc.trafficmanager.net, 43.2.168.192.in-addr.arpa, prod.fs.microsoft.com.akadns.net, 81.2.168.192.in-addr.arpa, 103.2.168.192.in-addr.arpa, 4.2.168.192.in-addr.arpa, displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, 10.2.168.192.in-addr.arpa, download.windowsupdate.com, 17.2.168.192.in-addr.arpa, a767.dscg3.akamai.net, 94.2.168.192.in-addr.arpa, 33.2.168.192.in-addr.arpa, 78.2.168.192.in-addr.arpa, 71.2.168.192.in-addr.arpa, skypedataprdcoleus16.cloudapp.net, 21.2.168.192.in-addr.arpa, 102.2.168.192.in-addr.arpa, skypedataprdcolwus15.cloudapp.net, 29.2.168.192.in-addr.arpa, 82.2.168.192.in-addr.arpa, 67.2.168.192.in-addr.arpa, 44.2.168.192.in-addr.arpa, displaycatalog-rp.md.mp.microsoft.com.akadns.net, 91.2.168.192.in-addr.arpa, arc.msn.com.nsatc.net, 23.2.168.192.in-addr.arpa, 5.2.168.192.in-addr.arpa, 32.2.168.192.in-addr.arpa, 74.2.168.192.in-addr.arpa, 39.2.168.192.in-addr.arpa, 56.2.168.192.in-addr.arpa, 14.2.168.192.in-addr.arpa, 99.2.168.192.in-addr.arpa, audownload.windowsupdate.nsatc.net, 89.2.168.192.in-addr.arpa, 83.2.168.192.in-addr.arpa, watson.telemetry.microsoft.com, 41.2.168.192.in-addr.arpa, 47.2.168.192.in-addr.arpa, 101.2.168.192.in-addr.arpa, 66.2.168.192.in-addr.arpa, 100.2.168.192.in-addr.arpa, 50.2.168.192.in-addr.arpa, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, 73.2.168.192.in-addr.arpa, 38.2.168.192.in-addr.arpa, skypedataprdcolcus17.cloudapp.net, 31.2.168.192.in-addr.arpa, 57.2.168.192.in-addr.arpa, 92.2.168.192.in-addr.arpa, 15.2.168.192.in-addr.arpa, blobcollector.events.data.trafficmanager.net, 42.2.168.192.in-addr.arpa, 84.2.168.192.in-addr.arpa, 46.2.168.192.in-addr.arpa, 65.2.168.192.in-addr.arpa, au.download.windowsupdate.com.edgesuite.net, 25.2.168.192.in-addr.arpa, 88.2.168.192.in-addr.arpa, 30.2.168.192.in-addr.arpa, 2-01-3cf7-0009.cdx.cedexis.net, 51.2.168.192.in-addr.arpa, a1449.dscg2.akamai.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, 37.2.168.192.in-addr.arpa, arc.msn.com, 58.2.168.192.in-addr.arpa, 76.2.168.192.in-addr.arpa, 97.2.168.192.in-addr.arpa, 12.2.168.192.in-addr.arpa, displaycatalog.mp.microsoft.com, 7.2.168.192.in-addr.arpa, img-prod-cms-rt-microsoft-com.akamaized.net, 85.2.168.192.in-addr.arpa, b1ns.au-msedge.net, 49.2.168.192.in-addr.arpa, 64.2.168.192.in-addr.arpa, 90.2.168.192.in-addr.arpa, 24.2.168.192.in-addr.arpa, 87.2.168.192.in-addr.arpa, c-0001.c-msedge.net, 52.2.168.192.in-addr.arpa, 59.2.168.192.in-addr.arpa, ctldl.windowsupdate.com, e1723.g.akamaiedge.net, 75.2.168.192.in-addr.arpa, 36.2.168.192.in-addr.arpa, 40.2.168.192.in-addr.arpa, 13.2.168.192.in-addr.arpa, 98.2.168.192.in-addr.arpa, 0.2.168.192.in-addr.arpa, 8.2.168.192.in-addr.arpa, 63.2.168.192.in-addr.arpa, 48.2.168.192.in-addr.arpa
                      • Report size exceeded maximum capacity and may have missing behavior information.
                      • Report size getting too big, too many NtCreateFile calls found.
                      • Report size getting too big, too many NtDeviceIoControlFile calls found.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryAttributesFile calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadFile calls found.
                      • Report size getting too big, too many NtSetInformationFile calls found.
                      • Report size getting too big, too many NtWriteFile calls found.

                      Simulations

                      Behavior and APIs

                      TimeTypeDescription
                      09:14:45AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run 6492BED7-7C13DE55 "C:\Users\user\appdata\local\temp\svcuwq.exe" -id "6492BED7-7C13DE55" -wid "222"
                      09:14:50API Interceptor1x Sleep call for process: WMIC.exe modified
                      09:14:53API Interceptor1656x Sleep call for process: svcuwq.exe modified
                      09:14:54AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run 6492BED7-7C13DE55 "C:\Users\user\appdata\local\temp\svcuwq.exe" -id "6492BED7-7C13DE55" -wid "222"

                      Joe Sandbox View / Context

                      IPs

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      0.0.0.0sclient-installer.exeGet hashmaliciousBrowse
                        svceaf.exeGet hashmaliciousBrowse
                          CardiologyWebInstaller.exeGet hashmaliciousBrowse
                            auto.exe.exeGet hashmaliciousBrowse
                              bbc.exeGet hashmaliciousBrowse
                                jericoni.exeGet hashmaliciousBrowse

                                  Domains

                                  No context

                                  ASN

                                  No context

                                  JA3 Fingerprints

                                  No context

                                  Dropped Files

                                  No context

                                  Created / dropped Files

                                  C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:true
                                  Yara Hits:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\$Recycle.Bin\S-1-5-18\how_to_decrypt.hta, Author: Joe Security
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1000\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1001\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1002\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\$Recycle.Bin\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\Reader_19.012.20034\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\S\11357\AdobeARM.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):100825
                                  Entropy (8bit):7.997809775573169
                                  Encrypted:true
                                  SSDEEP:1536:W7wT5mrer3ZHCCXQID3S9Fn6J56udpo6EFLg0+Vigg6c6QkWFhntZpc2si:WA5mg3xrtwF6v6ubREpg0QixOQk8hHp9
                                  MD5:E6D178FC466A19810120484BD517F896
                                  SHA1:11F52558F40C7BDC0C3D0DDE19FA0BB14128712D
                                  SHA-256:221F020C9B70C89A99C0186BDA7A513C8312F6F3381602720E02B341A209DC99
                                  SHA-512:003459D214A65E3340FC54649C67FBCDE41EA7E5976CFDC08B53E2A5BECCFC4327BC7A95D5E83DD865C5E90F52F951B822304DB4F08AD017C298105095C71808
                                  Malicious:true
                                  Preview: $;3.hx.m__NN........~~11..65..=4..>>....kk........{{.........MI..>?aa22........#..n.??-..9D..z...........P...5..?...Zqq.....9..p.....xx......##................II........UU....//..''~~....ggSS.......cc..00CC..{{==ZZ....11KK..::!!......55..........xx.....]]..bbII.......QQ00HH44bb....[[ww<<...........qqgg..................ddqq55......ll..77SS]]@@''.....qq......ll..;;88........CC>>..mm..ZZ................66jjCC....xxSS..NN......]]66<<yy..;;PP.....iiuu..@@.........66GG..{{..qq......pp$$..../-....EEu.....??ad//....PW((......))..............==......~~TD__........... 4...zz........&>..)0..............%8.......88..((3.==#........<EE..........__aI......V|..'....++.- ....`Q\\.........33l_....VV....h^....jj..XX.LL....*.00.... .....MM.. ..a ...O88.H..I....~....kk.AJJ.....E........llMLDD..&&]\....Q........II.P...22....m*~~-t......F0UU..**4o..D..................\\1S^^.o__T0...y..t...,K.............m............C,...UU.j..%Wbb....f..{z....%%.r..C....YY.00
                                  C:\ProgramData\Adobe\ARM\S\11357\AdobeARMHelper.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):212590
                                  Entropy (8bit):7.998865289508845
                                  Encrypted:true
                                  SSDEEP:6144:TgyN6mZAlhBoDiun/Drydj75d47GU6Ry6:jEuAlhBanAj75W7GU6RT
                                  MD5:F8308E60793EE272A36BCCD8F418F6BA
                                  SHA1:B4C0A4941250BF6C160C7012ACB38DA4008AF979
                                  SHA-256:EAD25DA65BB7F20ADA150CD41F29368565E66668AD425893BB9DF1EE74D7266A
                                  SHA-512:2B6D99F9A5900FC7C54DE61E06E670A3CF74CD235F8EA06B559ABB3CE22529E26CC5BB11E62E8D5314B2435A3789583D59EF7E80D16D3C111CAE7758415289AD
                                  Malicious:true
                                  Preview: ..OuvTT...X.._.v.... .22........''nn....WWPP!!++....oo../. EK.\...Q.M{.M.M8..@.omKC...\....AZ.a$...N...NR!l..b)............Lb.m..ll[C...4S...Gy...w...(.{....K[&...........J....7@?..Fx4L...T...;.c...R1..}.......?....33..+{.....n...vv....4.><..XPxx~..F....m...88.....<YY....ii`b............JJww..(...X\.j.5...9...RR&6................FF..~~..IE..t .......O....llee..H.Em....8p...'V...,,....!!!!....RR..DD}}..##..?I...||gg....**.FF>72....||..``....tt>>77zzffIgud($...'.........4..9=......??RR..+...J.......;.....|.@@.....}hh..<<..&&....y.BG........]......k..DD00....!a....no?.%%.0.S..W...T...$..ff{{......;{..N ..YZ_<,.Y..?...................yy;{HH.II..bb......JJNNSSzzQQ..33mm...<<..FF..TT##....**....ZZ..tt...........YY....&&||....^^..rr33....gg11..............kk..ff>>......;;..............$$......hh..::AA..qq,,66UU......{{......dd....^^....pp....||.................................jj....44.....ff..CC....55....GG..hhvv.......KK....II..PP..::......V
                                  C:\ProgramData\Adobe\ARM\S\11357\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\S\1742\AdobeARM.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):100825
                                  Entropy (8bit):7.996777303761806
                                  Encrypted:true
                                  SSDEEP:3072:B0DpwArcP/MPPPPjN2tx8E5AoGmIhrLv9XV:B0DpwArD4mE5A1hrLVl
                                  MD5:3DA4FC03DA8DB60372B4109674A5D51C
                                  SHA1:3EBC086AE2FAE7EB522B59A42286B14616A4E2D1
                                  SHA-256:F28E56E730A54D09BD69B7E8ED77B27551DF972257D076E14EB001F00462E5E7
                                  SHA-512:39E1D1F0BA1428D9D3B1876B853F5E414D3DAB64C665920B5AE29648D20BCF8E6EE4520FB840CFFF32FAD6D2912B4CDA495FFAF1D7B732CCCBF532201A564F42
                                  Malicious:true
                                  Preview: TK......;;**....... ...6../.YPKMRR@@==..XX..77....UU........rr&"@@.........uuO0...o...a...S~~......==....m...D...zMM......XX.....O....qqll++OO WW.. 3388__...aaQQ..##....;;OOHH.......!!................}}YY..........>>.......FF....ssqq........AAXX......YY..^^77..rr........88........88((@@..XX..ppII......aa,,....''>>zz22....................SS....hh]]....YY....@@....99......II..........PPjjAA....]]..........22SS.................GG...**..........||66....$$.......11....((........WW[[..}}..XXQQom ....P....ww*/........]]V^..........'.33!-ppty....\\..66......hh..CC....llOZ..!7..er........yy..oo..++....A\??..zz`...Ss......7....;**........ ...6....PPdMRRj@==..XX..77....{U........rru"...5}}....2.uu....Yo..|K...R~~....4.==`[eeRn..\a..@~MM]bvv..XXs2............(......YY1y...22..>>..44..gg...XY...44........l>...@...[.......}}@.55.O..m.ggP....U......L...[.....'G...AA..8[..q....cc.u11i.......w....gOO.vyy'Kkk.....l...y.^^..**.d...\\....UTDD#[cc:M......e...=G..
                                  C:\ProgramData\Adobe\ARM\S\1742\AdobeARMHelper.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):212590
                                  Entropy (8bit):7.998814990276202
                                  Encrypted:true
                                  SSDEEP:3072:4lxS+ys4BpQA/hPGBMI/jE5AO9oVPEyjaJyCz2lokm/yDB8O7FRu35/gQOz9bFrX:hXB6ABaqASoZEyjBCyy/xOhsgHJFegx
                                  MD5:ED43EF1E4EBDFEC213B79CE07C0C262A
                                  SHA1:D31BAEFAFC388779BE9A10F07B01F62E1F4310E9
                                  SHA-256:49FB8356B2FD07EEAD7EF29802423443A2D7B697590550362EA4671231F40069
                                  SHA-512:95B912AF61CCB18406C351E777CF5FBA68EBE553A205429ED6979C09F1B377B4B0B2729D43D7FF5E0C88325163604B6A015FCF2C2E61D2A33ED277B4C15EF96C
                                  Malicious:true
                                  Preview: E...@@cg.../.).fUU....:z........ff..UU77ff&&??yy......FF.'..,".P..I..I....T!54O.........{{.....ur..NI&B...K@"i...&&..LLYOK.m..v.(6....5Ms....^%...Q.."Iw.S..}..HigX.`....|j/.gP....3...w.zDp.zS0|.................#..........>{g+sw9..y%......a..YS..||..........:.......D...Q.....77..X]CC....Y\""<<CC...!..FBm.r.$&.H.#....eu..>.ee....MM..AA,,.....HD...Q....K..7.1........xx...........I..Vfk.ey...........((......II....rbm._.<<EEww||...)....qq......||....<<uu33...........B.....td....bb#'..ww..........225{..2'...'@X..T.....^^....//..--JJ&&m-..a......5.XUU.vFF....O..zz.....[[=}..m....&&. ..11L. ....o.ww........??9yXXY7UBVU.k.Q.F==Bt...Tcc.Y......++......-o....dd!!..''....ZZ......>>......YY....??....JJ....AA............__mm....mm>>..{{...........,,........]]^^......AA..rr......XX..............88....``zz99PP...........kk00ZZ....ee%%..........33((..^^..............GG}}ffff....TT....uu..qq..--..>>......ll.....//....BBEE....MM....??44gg..ll''\\..NNDDll......s
                                  C:\ProgramData\Adobe\ARM\S\1742\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\S\ARM.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):100795
                                  Entropy (8bit):7.997594872979037
                                  Encrypted:true
                                  SSDEEP:1536:BjV+znRLueoVQKKWU8tnQJEuuycW4ekv3ii+39IO/+mzmoQAluCMMFWOsgx:BjctAU86WuZRViSIyAAlz98Ox
                                  MD5:8940A67BABD3263AA2DA34699DBB0535
                                  SHA1:050611605C91D8647592AB68E31B8E0CEA3BBCD9
                                  SHA-256:D5AE2D06F26291C73D1E184E1E4E4AB18A617C76589DF4FA3FA8246CDDCC1829
                                  SHA-512:2C4CD8BA0F89FC53CF14F739EE922EE203BCEFB44F2230674381C563A142CF1AD6A9ABC1F7608116F660FDAD74D7CCD4745D7698762D45EE263E52F65E4D3FF2
                                  Malicious:true
                                  Preview: .......e..__ZZ88ee......(.....R[EC--..TT..[[DK....%%..cc......D@....77......jj _ss.2...3....""....n...^.//R...~....Z...Dtt.p..k.DD.b....TT....ZZ,,00......MM....%%....\\..[[AA..................55..{{tt..@@==....SS.....--pp..gg<<..WWxx44JJ..22..;;....]]]]..PP..77..ww55||``33......TTww..............pp,,..``..''..YY....77SS......qq.........mm..%%........zzaa..&&.......88.......11.........^^oo....>>..&&...99OO..rr......^^ll........HH......<<..##....mm..........tt........11..........^^.....ffXX.............E""..~~..uu..........W^..xr44...._SWW...........6&........JJ..ZZK_..fs.. 6......E]..7.}}..gg7,mm">..HU"":$..TK..oO..pQ&&Mo^^......II..==.9..cD......dd. 88nE{{....R}.. .ss......BBg0yy\n..wD++.&....{{........I....B....ss....[g33\aDDb\..kT.......MM....x;jj......XX......v>..<v55h.ll............4{..I.~~w&........,x..q$...AQQ..zz....mZZ.aaa:..q-MM.((-s..q.....$$......+HVV.J......u.....\4...G...nYYe...m...u...*D...jQQ..........$W..y.......>Frr.....88.......
                                  C:\ProgramData\Adobe\ARM\S\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\ARM\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\Setup\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\AcroRdrDCUpd1901220034.msp
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):25166825
                                  Entropy (8bit):7.999742454663624
                                  Encrypted:true
                                  SSDEEP:786432:/kVXFSHGiuJe9Gu3Q7T/cf7SHTGljzzG4666VZzztSZspnl:/kbLJ3uoLMSGzzG4666VZzztGO
                                  MD5:09139347548A3165617EC4A775DD6061
                                  SHA1:5BCDC1E2EC92506D15FE1A5E242364C01C8E6C69
                                  SHA-256:56430E774CE908F7D5A394401F9EC54DBE2A079787242522712D1D024A941DC4
                                  SHA-512:F8E38CF3D3C36F9BE5BDC0721E2B1872410F677A97AAFEBAC4A7932711D21CABC0F695E4F31224DD0EA9179D03D820DF7EDED034DDFFBB06C44EDD6FC616DC6D
                                  Malicious:true
                                  Preview: ..Z...O.00aagg....@@..))Ms}y....CE..ll...z.....76....ll....lo........^^..))eeVV.&??5...gLL..77..........w............L... ......6..U.......T...)...v...w.....`...d.... nn).66.|......I...l...(.99....I.NN...;..........r8.._gZZ..........mmPUmm.....m...1}--..;;..HH......%....``.....pp..ffT[....ww..jj,,..bb........--DD......yy..TT....cc.........//UUii))..55%%..ww..zz..hh..00..bb........ee....ff..ff....wwJJqq..bb......--pp......nn....oo......""GG..CC..<<!!...........55BB..PP..{{........$$ll........cc++..tt..........>>.....jj..--....::&&\\__..vv.........]]..SScc..ZZPP..}}..CCKKvv....nn..IIyyRR........pp....mm..mm....;;........]]**....hh....VVff......jj......qq..........++....[[..!!....qq....eePP..ww..88--....bb....))....%%....llpp..@@....__KK..UU00aagg....@@..))ssyy ..EE..ll..zz.....66....ll::..##........aa.....RR..]]......yy......JJ""........||....dduu....dd................{{..<<..EE..aa##................ii<<...........||77nnYY....??........''VV""..KK....xx..
                                  C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\AcroRead.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):100826
                                  Entropy (8bit):7.997566038063376
                                  Encrypted:true
                                  SSDEEP:3072:27QfyV2c3pcCgRgTzFkjS1CVQhVjvjSOPw8:lfkvck1kPQhVX9Pw8
                                  MD5:F139182E0E8F2517210E27E165319D4D
                                  SHA1:3D10A15F6014C1DC87CD46D697A51A9FB831D7A0
                                  SHA-256:3AD9BE1AB8B5D396F3666F97BD7C9CA6B7DF867F7DE2D8F6F80F2D2BC66F2590
                                  SHA-512:52D491DEEB4F19B6030148D44B6C49CDAA2BF3BB1312ECDA03BB704994F0118F7CE571939389C2006671905D78CD69D8E8048E36AF00FAC4E9C27E0856DBE036
                                  Malicious:true
                                  Preview: ^A.l..j.................*):;............?..UT....""....e]kk......44....cct....5++e.......R.....==....;......=...I3...:++....t.)).f...Z;;.....FF.........==5>..K?YY.."".=HH.....t........==...>N..?/...Saat....x..L...........U....ZZ2....!..BB......mm%%......%%;;\\....==..00....::..UUtt...............yy66..............!!............LL..!!;;....((==\\..rr......CCtt..>>............))++cc..}}qqss...ZZ}}....//......UU..;;..XX..==^^..CC..mm..ZZtt..llWW....ff//....||............55....,,--......||..;;TT..55.....6..;?++......))fa..M];;......FF.........==;5..;4YY.."" 1HH....my........==...VA..'?..ZCaa....ri..A]..........YF....ZZ.....5................yy.,.....*.....$$.....?..;............]@@.+oo..........ee..PP.5!!.........rr..9...a.]]mP......U...?..A..........\.[[.........NN.ee..gg0...b,....NNY.HHl......~~.66.........GG..$r.....I...........y"...@@t)[[...h7cc.k......n................AA..""`.NN.yy...%%.....]]..ss.....c..t.88....v.OO.....--.l...{{.a...o..
                                  C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\Data1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20806
                                  Entropy (8bit):7.98635194654416
                                  Encrypted:false
                                  SSDEEP:384:RO+sRIrvV0HnkR1po0NEGdlziT3BQ8pnQeuovxT0ilYiCjO4QQb:wR06HnkxdNVd9YrnQIZT7l6jOSb
                                  MD5:B33B2B491B2DA5091A73131A6F1C3594
                                  SHA1:35D1DE6168FD1198715286109693700ADDAB4894
                                  SHA-256:9AA01C2BD9ECA8330426AF7DD82ABBA24D9DE0C9E529AFE986B4EF3F3F426C69
                                  SHA-512:06E7E247E87FF2448D25CD1553C4493B06D2BB0F4D18A4B7FAAD0C3814074EEF347F0AA1B054C074B3797B1575B2CF5D322FADBDA289534D42D3344E4AA290AF
                                  Malicious:false
                                  Preview: .*..ss77.......#..........mq..6}QL.........ddm.............+X.XWb..7w...%.....>.x..........h#...g...UP6X.......P;...V>..t....<Mx:..`a..^^...c..^M....y2....$R...p3G81)B^]?T....+C.o-^L>EJ.r..J......ml..'nbB@b..kkK@.....'6...................oX._Nn.7..nL..~~..18V.....JK..04.+.pp%%...$$.'......M......VF......jh.....>....`c....[m..ET...HV.ag..MF..H....,.QBzH42.x....$%...........!!..Er..[{...............@....wi.##.......?.IE%,99.4w#,.."4.i....]..ptsD...........\:^_...L.......Ww?...U...]>.H[[......mZ.A....le.....kwik..I_....^^.2v......n....oh.......,.....6.:Jpm@Q...Unb:N.1..l...62Ct...;Tyc`..Pe............& ]...'.....04.CC.%..F\dxum........}u=`+ ...|.l...Mt.....8.[{...........nh....cu..4..c9@$......tpv.00Kg.a......{v......@O......oWXe_:O.&&.fy{..!.........^SK^R]..qwu~.........0..#..x6.vsws......bg}.Q..q0.f........f.......(r:6:x..wt...........}....U.......{R.UQ....Ma...4....99.C...J..vrv...L`...b`...........6.:R{rL{..$.{4*'.j.66
                                  C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}\setup.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):233244
                                  Entropy (8bit):7.99762684624481
                                  Encrypted:true
                                  SSDEEP:6144:uA7fsuRaYABaxQ4IV+UAqnE6a0qP+7hr56I5:rr5aYAUxQ4IVBnE6qGhAo
                                  MD5:D3C71A0E831E309FCE6478544BB80B2D
                                  SHA1:6ABDCA3862B4C24C74E284ED7FF8C480B0877EE8
                                  SHA-256:14E65F9F9571C3ABBA4456A34076C5822175AB75BF39EF5ECE07F76DC1BCB1DD
                                  SHA-512:DB33430B4058DAE0D4A55DF091AFA8F76C83BCCF1A67713E509175863BAEB7253FE2EEDC3B6F0E27E5487604A8A8E15741257F5855C26464B9DD1E5BEB8CE3DD
                                  Malicious:true
                                  Preview: i..OL......bo.&.==++....................NN.................+%.\.....7..o..j:;.UWUqy.......HS.............r9ccdJ......o.^:...q......:Z%..W<,H.|.id.9].ui.w...'..l..m*..P....I.6..V6.CH8.....u.!...9AE....:..,G.nG....{.O......,..r.Y2<.......CC__..||8h.......hQ.!!..nn.....'*VV..rr.3..BBB.KY.......4..9y..cs((.....&&..........cc..ZZ)-c-......A.........P@......dd...........*.a.!......o.../...[[EE..a.3...........2..4.DDDD...aa......xx..66GG......9y..44dd__..||......0d.]........cc....##]]..$...7;....2.....&&.>++...............%...../:...).......C...v.++..........#c>>.|..SF...:.....''....W..............Wnn.@......o7....{....?""tU....UU....)).........>>..NN........>>>>""......ZZ..yy==@@UU............kk::.....%%......22~~~~~~NN......))..II..rr......####....22aa..........00.. .......^^....~~44LL........&&..............;;..TT....zzff....11VV........hh....++........hh..WW22>>............ttVV........vv......####..pp$$HH..FF..........hh............DD....==22......<
                                  C:\ProgramData\Adobe\how_to_decrypt.hta
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:false
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\ProgramData\Microsoft Help\MS.DATABASECOMPARE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:MPEG ADTS, layer III, v1, 256 kbps, 32 kHz, Monaural
                                  Category:dropped
                                  Size (bytes):1136
                                  Entropy (8bit):7.169073771245988
                                  Encrypted:false
                                  SSDEEP:24:SOz5a/A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGE7RSVKfMlc9t:NmAd4M9/xJfAXxu/Ckhq
                                  MD5:4C0DD687E6A91E70FAF1C118E1FCE241
                                  SHA1:DD38F9FE46BA102EF294D2E22D86856E696BFE1C
                                  SHA-256:798AEC34998A87A066439A09971CD87B271F469222EB3BD69B9FE81FF69DF4E9
                                  SHA-512:38F81A9018A34E2701DD6330804FCE5345FC37BE3917867EE920E7276C3CFB1F5056B3C53EDAA9EC44C43736C36CD46DD0162B8E370DD17B6888C603C2B861E5
                                  Malicious:false
                                  Preview: ....LL^^..HHmm..vs..&.KK..........A.._{8..9t..N.....VVN.T5f...*K..-H,oI&................5...W.ru. A......W2M..xV;.......@8i:....HH......)(..WV....99%%##MM--..dd@.......t........Q.>Lb.D#.....f{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.WP.oQ..Q...r..}{.}{418}{000077000083000046000068000065000084000065000066000065000083000069000067000079000077
                                  C:\ProgramData\Microsoft Help\MS.EXCEL.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1042
                                  Entropy (8bit):7.250577601790079
                                  Encrypted:false
                                  SSDEEP:24:BqYAWsBD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPpulc9v:BqIs+Ad4M9/xJfAXxu3g
                                  MD5:495558E0E651120FE4F6F5CA8EFEB658
                                  SHA1:F177BF5375C0AFCE64CCAF9B88CE90F908047BF9
                                  SHA-256:E44502324B1E2B64BE8DA30E622F3C5962585EC9C9D512D57DAFFC936D6E2A40
                                  SHA-512:1BDFA4BB0A2E81DFE94DC3DEE21D98A9D05BC5E83D51C277AECAE8C0B184E7B4C28D7E9EE9CC48D5CE39B495CEE8F1F296C29600539C05FF42A30AB5F33B68FC
                                  Malicious:false
                                  Preview: x|..::ee....DA.....>4....f%0u....zz.Q+s^......}5..1b....0uT.......c+.I.E....JJ..)$ccde........]].....qqX^66_.......J&../l@z.W)y.....pO.,A.,...ka.3V.nNqY...yO=..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{P......$g.@..S|F}{.}{350}{0000770000830000460000690000880000670000690000760000460000490000540000460000490000480000510000510000460001040001200001
                                  C:\ProgramData\Microsoft Help\MS.GRAPH.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1042
                                  Entropy (8bit):7.237838271978743
                                  Encrypted:false
                                  SSDEEP:24:HZi2HEw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFi7lc9v:5iiwAd4M9/xJfAXxuP7g
                                  MD5:3635AD0377D29E0AF6CC3A699D69E7BD
                                  SHA1:166B838684D1256596AEAC5AC5CEC74E537F839E
                                  SHA-256:AC68A056CC6C76A002AF3761B2607B667E9CCC4E71EAF4DD97C5D51BD2F75E21
                                  SHA-512:F1944DECA7F6C260A4188A2CAB9E008B565D6E930BC36ADECAA78E1CF1CEBA961F99ECDD2AB810AA741E4501033AAB85914FDB73C5921C2AD7B0E9A8A0080DAB
                                  Malicious:false
                                  Preview: MI........!!!!....%%.%......T.r .~.f.l~..[.N.g&.7.Q....E...EE..y+j+&v.F.3{3..O.gggg...Q\XXon........99EEEEee......"........66......u%.s.k...............7.....=bT=.y%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{._..J/...[.Id}{.}{350}{0000770000830000460000710000820000650000800000720000460000490000540000460000490000480000510000510000460001040001200001
                                  C:\ProgramData\Microsoft Help\MS.GROOVE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1051
                                  Entropy (8bit):7.288003974870158
                                  Encrypted:false
                                  SSDEEP:24:I2NSMagUdG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHVrDlc9KT:I2AAuAd4M9/xJfAXxuOvH
                                  MD5:F8169B72AF729124BC2B589BF41BA9AC
                                  SHA1:DC89C65429E7D6FA045C83244AD8EB238C93E315
                                  SHA-256:04E1054B260CF4327039FD491B9083EFC078F7ABF2DA0A1424FDCF3C64901276
                                  SHA-512:BBAFEDBDB4B31CFC170B4E5B85CDD63FCF1A2E80658091E4A8B4FF13E3CA4EA3D0D85D182855485634C50E66CB2D73221E8782D4EDF0AE5361FE73BF094010B9
                                  Malicious:false
                                  Preview: d..ll..<<......:?JJX8....||7p..Y.:u.K........o=.[.(~7r..I...;/..U.\..N.T..v3+..Y:b.....TT..cj......ppww....zz~~pp............c...7t.......d..A ^3..1w.k.n...-...".(.~W{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...T..F*....?Z.E}{.}{356}{0000770000830000460000710000820000790000790000860000690000460000490000540000460000490000480000510000510000460001040
                                  C:\ProgramData\Microsoft Help\MS.LYNC.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1033
                                  Entropy (8bit):7.273315890786281
                                  Encrypted:false
                                  SSDEEP:24:GDQHL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKAlc91s:1HQAd4M9/xJfAXxujAOs
                                  MD5:94EC43F510FF74E2F7DE4BAA3823F23E
                                  SHA1:D6D3246BB0A87B8D3D92BF55B0FFE2E603AA9F3A
                                  SHA-256:42C54C700C44D787166BB794DA71D8DA693446FCF816F40D0CC2129DF7ED13D5
                                  SHA-512:3153953FC0D761638C1549AC7002EB4DAA6D2D92A13F5EAE3FCB5FE0345665C75095724556F6B2EF509CFD899B0FFAE55DEAD533A90B811C8666D87A4C88758E
                                  Malicious:false
                                  Preview: ......>>..>>....VV.R........u,...'7.........o'..1b-=..`,p)S..M..0x)q.DD....**..|x.......cc....{{1144ce..N.==..RR.q..........n..?M5T.Zzy?A(...y.ddD..P(....-..N...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{*..T......]{.:}{.}{344}{000077000083000046000076000089000078000067000046000049000054000046000049000048000051000051000046000104000120000110}{bNbWb
                                  C:\ProgramData\Microsoft Help\MS.LYNC_BASIC.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1087
                                  Entropy (8bit):7.194757857518225
                                  Encrypted:false
                                  SSDEEP:24:7/qt5XW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFfohlc9s:7uAd4M9/xJfAXxu8Mr
                                  MD5:F2B712D09220D8C90F4FA1785EBC9A28
                                  SHA1:A149EEEEC1A461FC3748BE89F0C9BF64778D4B6D
                                  SHA-256:97FF6870BE38F9AB3DD736E8B3C6B33AA3E561562021C5BBA172613E4E51AC39
                                  SHA-512:EDE00F594671F7675F0D45E4F62DB34D1F5AA4048CD4AB8255D3013E02F71E9A3C99C00CEADE4649A5247DCA9B5468C3BD0768D8FCE1DAFEFE70C052A095A387
                                  Malicious:false
                                  Preview: .99.............QQ.$$....v:.......l..U.Q...ff."{v8......F.n'.I.;....M,0...X.p>w4..W....$g.....Vv%....ttSS........>?TT..MM::..........B.ffvw44.c...A........p.*M..^?[6Bb-k<U...B1{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.... .oE..K...9}{.}{380}{0000770000830000460000760000890000780000670000950000660000650000830000730000670000460000490000540000460
                                  C:\ProgramData\Microsoft Help\MS.LYNC_ONLINE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1096
                                  Entropy (8bit):7.186607924902725
                                  Encrypted:false
                                  SSDEEP:24:QG2VYxK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQqlc99:QGMYtAd4M9/xJfAXxufqa
                                  MD5:EF8E2263EC347C72683541DB9D6C7234
                                  SHA1:74BA45BBF459F3FD4A52F584594A51E7D480D967
                                  SHA-256:7532D9B06DA6AF2D9E6CCD2A5AD54BBFD6F25D9E21DDE4D6F65726904F27E0BD
                                  SHA-512:79E585AEFD61018438A9B339B72AC7082147AD4C9F0EE3669F1AF5546BB956B240924DEA489DFA21F99BBB30228CE704B22DDFC050A699BB2DA0A2A29473E406
                                  Malicious:false
                                  Preview: ......AAqqqq??..up...hh....... n...U....L.B[.'bsm..c/.{5d'.R.X..p<._Q..........^..........[.....CE......Q5....B......^^..}}YX$$..11..........ff:<....44-,........c?.Y..v.E".d...lRr2t.k.j{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..*pH6.BOL..^..}{.}{386}{0000770000830000460000760000890000780000670000950000790000780000760000730000780000690000460000490000
                                  C:\ProgramData\Microsoft Help\MS.MSACCESS.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1069
                                  Entropy (8bit):7.267429851361406
                                  Encrypted:false
                                  SSDEEP:24:pkOknZG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXRmlc9a:KOOAd4M9/xJfAXxuUM9
                                  MD5:60E3A2BFA2D29674FDEE54EA2D83E955
                                  SHA1:07D9291FD06EC99F702DA7B110BD9EA5E5B4A90E
                                  SHA-256:320290D2BA0E90F6A4D0A6A9385239E147EBD2F3664DFB324BC0B76035690B7F
                                  SHA-512:CE46BB164ED5E7955833D2DD3672B60B598BE3C9A44B1EA27AD6BCEF85A57103FA43ACD33E16FA469CF77BBFE6D7278075035BD624D6206D0D6C9CB204A15232
                                  Malicious:false
                                  Preview: O......rr............ss..TT..s2....k.I..ZZ....Z.......D.%...{#..uu....8{..B.d7..g/..f5....%%.......((........zz......'!VVB.tt.........V.4b>........`.....@)...e...0.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{^.p.xL._.....v}{.}{368}{0000770000830000460000770000830000650000670000670000690000830000830000460000490000540000460000490000480000510
                                  C:\ProgramData\Microsoft Help\MS.MSOUC.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1042
                                  Entropy (8bit):7.28825247920425
                                  Encrypted:false
                                  SSDEEP:24:j+hc6gi1ttcpsv4Y84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaTm1+lc9v:56l3+puyAd4M9/xJfAXxu5TBg
                                  MD5:E1D548A0162F64900728FF9870F93B16
                                  SHA1:0060B312B46CEA6A25E6C190FC847DC1FDB75711
                                  SHA-256:DD0AE864FDC3C698E1086755B27F8ED79749A3A397C664A4400C2B81A003D4A4
                                  SHA-512:FFD4F86F81A425A037382494723675BF9CA0BAA53E64C06B09CC3B9FF5166A7836D7A692DFCAB9115E75DF052CC20B21F18148CB8DCB55E9E931941280CD7E98
                                  Malicious:false
                                  Preview: ..cc....\\..llcc..cc.......{6a2^..._.....B........[].n=..KK...U[..Z/l........<<!!..tt=<HH..[[....||MM..dd8>..E...QPxx..VV.EqK"~@..d...l.........h...\|$.*R...?=..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{'.kpy.....Eo...}{.}{350}{0000770000830000460000770000830000790000850000670000460000490000540000460000490000480000510000510000460001040001200001
                                  C:\ProgramData\Microsoft Help\MS.MSPUB.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1042
                                  Entropy (8bit):7.281191607889887
                                  Encrypted:false
                                  SSDEEP:24:OVUWn6Ir84tFoze4ytP6qfHSgC0fNSZBzfteJTQRc8lc9v:Op6VAd4M9/xJfAXxuqg
                                  MD5:E04900168294B6218828ED905C98AE33
                                  SHA1:6CC5FF2A0F0614DF02A7287811EBE6ADDC1D2BA4
                                  SHA-256:E4A8A22E074329A4DBBEDA60882C4FE3CD9EC31D3C5822F1898595E52D2F48DD
                                  SHA-512:239E4EE3C4F6AE9D805DC11607122AE642E3B37BD7294AAC5515B3E99D878DA3302B20749E1BFC32948B86E29E4AED60E669172693CFDDD2D7E84A82A12FC680
                                  Malicious:false
                                  Preview: d`dd......__..dd......TT.....[..L..........A...../....P..dv..(eE..I6c.C..P.[..G..aa22.............qqmmbb......ss.k..qp&&.j...f\]...B0..:].=\......E)f.&U:...n.......p,{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..n.MY.JC.5.]...}{.}{350}{0000770000830000460000770000830000800000850000660000460000490000540000460000490000480000510000510000460001040001200001
                                  C:\ProgramData\Microsoft Help\MS.ONENOTE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1060
                                  Entropy (8bit):7.25025562305059
                                  Encrypted:false
                                  SSDEEP:24:i3xtj4E/84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4lc9J:UxtjSAd4M9/xJfAXxu3W
                                  MD5:001D329AC4D383391F6BB2EB39795A9B
                                  SHA1:34C3D1828E632E087D901823432A51DF8B7A95E3
                                  SHA-256:24A0E8FFCF924BAC652176D893D143C7F2E611D2CD777BB249130B59D11A36DF
                                  SHA-512:8DB583EA15B3714B0DDA461158799CD111B876E224351B2DA3EAEEAAE384D3AFFA7A92C30B657E0C01477D7FA16993513BDA759987B6E5BA6E03C7453B2EB8BB
                                  Malicious:false
                                  Preview: sw..........44..vs......,"....6x.S....H......=sA....P.....}5._.......j$..c-.....{U.A.,.yy..............88<<....22NN......L..%%.....#.@...^,....X*.~.`..#ed...|.d1.gO[#..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.5..[$..q.:.Q..}{.}{362}{0000770000830000460000790000780000690000780000790000840000690000460000490000540000460000490000480000510000510000
                                  C:\ProgramData\Microsoft Help\MS.OUTLOOK.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1060
                                  Entropy (8bit):7.2700673134499185
                                  Encrypted:false
                                  SSDEEP:24:IG7dQOfpd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrsIlc9J:IGqkpOAd4M9/xJfAXxuYW
                                  MD5:CB3600275F9360D179FC2B957ABD7CC5
                                  SHA1:D5434557162B8529B2B97887C07BFB115B24E60D
                                  SHA-256:71AE4AD212E86A4EBEA3B8F082A1F861B57310DEAC4F0BAECC79E9CD5513CEF8
                                  SHA-512:B94F110FE1948A25EAD5E2038195740F617A781D14112F6287672593179EAA4EC46CB34B968B4EE09F86BA93744B9CCED529A090B7D4933442989414A0E60664
                                  Malicious:false
                                  Preview: ..................LLW1<<2<...s&r&.......II......R......J.Z.....XX.X.5a.........V..Bx+......gg..aa.........]]..RR..``@Fyy!.YY...."Nww.......bK,t.......+m.e... SlL).s.Wo{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....6H......&}{.}{362}{0000770000830000460000790000850000840000760000790000790000750000460000490000540000460000490000480000510000510000
                                  C:\ProgramData\Microsoft Help\MS.POWERPNT.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1069
                                  Entropy (8bit):7.20279983969139
                                  Encrypted:false
                                  SSDEEP:24:L85pekCO84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvqlc9a:456Ad4M9/xJfAXxuSq9
                                  MD5:6A0673ABD513181F9A03AD00A5F3D376
                                  SHA1:4283CC3F72A6B6ADE34CF770359983457ECCF291
                                  SHA-256:B6A12DAC37682FE722D0F3A28147C08B11F50C36AFAB9DE67B2965D84F51035E
                                  SHA-512:3E451212BF9A36483F31E5DA60E16647407B76B1677DAFD1105D582A077541E9EEFC402EF817ACD41AC8210F8B1887638AF9DD932715649EE0B28F8818B6DAC9
                                  Malicious:false
                                  Preview: ...((WWooRR33..x}...........I..[..'uN..W.~f...~.<k...@..|(..T....Y..$$..O..k.d6...V..p^...M.00....ff...`a..bcDD..YYKK....II<:..F..."#.....*i..$x&v^,X7u...O.7Z'.....`..{.Bb..=E{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..|'!.7..$4.z^#}{.}{368}{0000770000830000460000800000790000870000690000820000800000780000840000460000490000540000460000490000480000510
                                  C:\ProgramData\Microsoft Help\MS.SETLANG.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1060
                                  Entropy (8bit):7.2577955418986075
                                  Encrypted:false
                                  SSDEEP:24:jugXKGR684tFoze4ytP6qfHSgC0fNSZBzfteJTQReMIlc9J:6gaKAd4M9/xJfAXxux1W
                                  MD5:9012451105C5CF8BF49DFD1C6FC3E855
                                  SHA1:6FC1E06177E9712D18886D1F17756E4445D42491
                                  SHA-256:B11F55ED645999DB9886C603417F65E911385FF4D032B85B4D94480F60A8E664
                                  SHA-512:30C4829007D9D32BD4D72C1D5B89548731DB3A405B5D4C76FED034F9E94ED7479F05B1D0C5C8BFE76ADF5F53597899720EB82C47D9C4B6617372A9408EE954F1
                                  Malicious:false
                                  Preview: ....RR......\\ee36LL.... .\i,.....<{..WW..|(F....`.8..m5...xxv%w2.V\...z4......UU.. ccuxTT......UU......HHaammz|..LZZ....6Z..Z.Vl.-}K9....k.......3Ve..6..u.Hp{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...,.'.`...../F}{.}{362}{0000770000830000460000830000690000840000760000650000780000710000460000490000540000460000490000480000510000510000
                                  C:\ProgramData\Microsoft Help\MS.SKYPEFB.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1060
                                  Entropy (8bit):7.2493454441747796
                                  Encrypted:false
                                  SSDEEP:24:AS71E9Lq684tFoze4ytP6qfHSgC0fNSZBzfteJTQR8Mlc9J:0OAd4M9/xJfAXxunMW
                                  MD5:04DE2FCF6B1FE29685F7FEA0CB2606A0
                                  SHA1:27088A10937A349FF399358B4AE2714FF54500F3
                                  SHA-256:F213E38E01CF11A96626339C0A2B2962A94FA3F20F2B259BD8651346CF595E45
                                  SHA-512:F700E7E5B1B8AFA606558926E3E751D5B505B812721F89353057270964E5DE48C99E3072320FD65E30764191A58A77AF427F0689347CFCD14C37507A900C66D9
                                  Malicious:false
                                  Preview: okccee<<..pp........ FII.......O.......6 .....s*...Y.Q.......!r......q:.........._...........;;.....................hh.6.........5vyC.<l.....[)..g....L%..r.6E..Me.i.4{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...k...BL......}{.}{362}{0000770000830000460000830000750000890000800000690000700000660000460000490000540000460000490000480000510000510000
                                  C:\ProgramData\Microsoft Help\MS.SKYPEFB_BASIC.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1114
                                  Entropy (8bit):7.149595151615629
                                  Encrypted:false
                                  SSDEEP:24:8nS8/YZpU938G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUSBGohlc9H:ziYkZmAd4M9/xJfAXxuoBno
                                  MD5:35630D7313DAB6301CE14187B0236DF6
                                  SHA1:6AC3D719A103520533D6C95F513386EA7C38CD80
                                  SHA-256:EC0F0E3B6C732E63833BF938F06ED04116CF533033A06A0E9C3F227FC66B702D
                                  SHA-512:4A90CAAB8CC4322F9D5D37F430FEB6984C38977F6289106F0556AE1D753ECBE723EA23D41DF9287C1A35BD45DDB78D6DFA002F68A0EDC05D0030AE0D6FD5185E
                                  Malicious:false
                                  Preview: ..66qq............''>.......F.I.T...K...?}...@......G.......l3..S.`3.......x+....._.y ._.....n,.T.Ke,.@....@=n....nn((....)(..'&....KK//..KK??.....?......B.........K$..U'../B.'{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.{..D.3...w....}{.}{398}{0000770000830000460000830000750000890000800000690000700000660000950000660000650000830000730000
                                  C:\ProgramData\Microsoft Help\MS.SKYPEFB_ONLINE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1123
                                  Entropy (8bit):7.153699669211827
                                  Encrypted:false
                                  SSDEEP:24:mp7yT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2BKlc9ST:2eYAd4M9/xJfAXxuhBKDT
                                  MD5:CDA2B62A3E1321F3CE51DA1536CA7CCE
                                  SHA1:337D5A2ABF5E3498B3E93727A5787D92A9DADA02
                                  SHA-256:FF40177E90C476BA0A304A70B7FCC4ED3133E3467A21688044E26996273888EA
                                  SHA-512:6654C03CA2796190375550574048E2AA58E6D52FB3D2F2FD57ED3A927DEE2C59E5844F9B581F7DC56C9C4F565D5F73368DF4874249875BAFD892E6247085CFFC
                                  Malicious:false
                                  Preview: H..``....ss.......J....LL...w...3u....m".e)..b,.G*.HHQ.2y....J.&`V.a>..k%j&.....>|4p(.>...g4.>g..:={.T..L..p9w9....+c-u.......cc..............OO..GG......GG.!....##..CC8{.;A.....e~....*G{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Z.{.Zvr.....s..}{.}{404}{0000770000830000460000830000750000890000800000690000700000660000950000790000780000760000730
                                  C:\ProgramData\Microsoft Help\MS.SKYPEFB_ONLINEG.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1132
                                  Entropy (8bit):7.117392283539281
                                  Encrypted:false
                                  SSDEEP:24:lzC84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/1Balc9h:l7Ad4M9/xJfAXxuu1Bae
                                  MD5:6672CD15480F323BF10F2EB43C853B7B
                                  SHA1:478498DB15B36FB58DB8B693491034AB7DDF8DD2
                                  SHA-256:DC726E4ED4FB0016DB27EFC2DD6D709957F627362495A15A4376902B8E84EE20
                                  SHA-512:A08FAD0B22173D52B0DFEBB23520C3C11916721F68713F7027EF8B89F9E9F968520DF7B6ABA48FDABB2A5AD06DBB15495559581E08B74F3B23B0D7344276CC6A
                                  Malicious:false
                                  Preview: ..........ffII$$..ii7.UU.....6}8a-}<y.(j..W n9u...3vN........W~'Q.....L...g)..0yy7......=n.....D.U...0u.....EN...q=......-..Z.$w%%--............55......ll..FF.......KJ..\0..;x.3....?M....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.q.53w0..pSo.I..}{.}{410}{0000770000830000460000830000750000890000800000690000700000660000950000790000780000760000
                                  C:\ProgramData\Microsoft Help\MS.SPREADSHEETCOMPARE.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1163
                                  Entropy (8bit):7.103119644379118
                                  Encrypted:false
                                  SSDEEP:24:HdvMQYuA9RA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuLPX9Mlc9CT:9vMIAjxAd4M9/xJfAXxuJLvCTT
                                  MD5:00B15BF68ADA06BEB32409CA30DDAE9D
                                  SHA1:988504DC4FC7BE09C6012A70C410FB252B9EDF94
                                  SHA-256:67CBE1781110ADDD7A43CA48259C3E35EEBC3A129820F6AFCA37846BF15C84FA
                                  SHA-512:CF9A8E27C7D0783FC408FF94F0B3840EA3D960EA5E3AABDEA457425D27C5702BCE8F1804F3D7447C14A8FC19522B600241D854D102D0DC8CD84FA455A7D780E5
                                  Malicious:false
                                  Preview: 4CC................p.--bFpp*y.g5.h)E.<o.P!d_.j>.......T.M.@lBB.B.....p.]9....s....>Q`.K;..%WV3.....T4....Z*`....5Q.t..B'....k....ph....d,E=......GGkkng..........,,......vv...JJr.SS'& ......T.+{...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.e....{W.>.I-...}{.}{436}{000077000083000046000083000080000082000069000065000068000083000072000069000
                                  C:\ProgramData\Microsoft Help\MS.WINWORD.16.1033.hxn
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1060
                                  Entropy (8bit):7.232245834297046
                                  Encrypted:false
                                  SSDEEP:24:ZMc2gG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkulc9J:Cch7Ad4M9/xJfAXxuWW
                                  MD5:243B72FC3D572C55DC9C23AD8B94315E
                                  SHA1:4DFE32D31553B225E6B8B76541C4FBFACC92D7C7
                                  SHA-256:A5C767BCBF04284D1DBEA05A8F2F4AA17799C98D7D3FEC61B81E8A326D6892A6
                                  SHA-512:EC93354900806BBF310DA58449463AEE2B75B6E6CA7F26303D0FE2C2F6BB09EAB651E73981680D1D57992B83ACA4FA47C516F123CD459588B20B46781BDBC892
                                  Malicious:false
                                  Preview: ......BB............b.11...._.."u...A.zl..Q..S..g0G.F...0....}PF^^k<...R........M...0c**''.....#@@#"99..44&&......VV..??R.SS54......0s......}.,^......Z6*O.fF......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...r...5.......}{.}{362}{0000770000830000460000870000730000780000870000790000820000680000460000490000540000460000490000480000510000510000
                                  C:\ProgramData\Microsoft Help\nslist.hxl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3939
                                  Entropy (8bit):7.911673463154437
                                  Encrypted:false
                                  SSDEEP:96:M/TAN+GnT4QFsEjd3Y8Pa/oez4npBAXQho:AcNdTl5C/oO4MIo
                                  MD5:28F4F7560BC17AE3E78918A4B0DCC664
                                  SHA1:5AB0A43CAC043E97F3A111ED4F4764588CB3A5D7
                                  SHA-256:E7805F62A0646F7AD4ADA6F0E7421E61A204565652C4010A18B63107971476E8
                                  SHA-512:59DDDC45C84F855F8F0A80758AFD6E6AB22C4B926C1985FFAB802C59B341897666F719154FD50D8A1FCD8C74B9BFE0AF9D256603493351CAFE5D6E0DA792F267
                                  Malicious:false
                                  Preview: ..YY....ZZ....qq.....2.......B.T...J"q......].B%vBl..*._qQ`...6.0......@z...y.c.P7......D.....&C....Me...2....p,I.0Y.j0B*E......$.O..o.-N...=r.m9_...i.....r....._l.).W..'t|=...%`...(wJ.^...p^...y:g...N..........D+X>.oLl..fI*<Y)Z\/.).....PaA.1p5x.s.<P.a.E-5.Ll........(.CnKk......j....!..Mp..<L.....HH.."">sN....W....PK."g./cR..,./......;.ff..yC............[6Dds5Y0.c............$....|...-BU&.l.B6..'h.f......F#....jr.$Mv........}L.$..+...c,......F..J.....Zn@....(kV0..?rU<P3.......|}.~^...M....f.....W...?.S{..-CY>#O.....z.8...-..eT..,./...._...~..p.......~..;K%'..Jw..pD....A...c'... a.]$eo<....[....N}8..TesEXv.0..Jy2.&....F|B.H.6DL#.S!.....X....B.............~3...u.A.l.....0h'.b.....y....Z<S5.k.r.tE....T..m1...u)......q.....y..5X...G5...&E..R|...+H}#........B-a..l...Uu,h...O.....L..vV|T-h....{.:I......9Kz."..r_..6f|....p...x.jJs;..4Ddf.......UUf+W.....Z....X.....:.U...W..O.q!.[6dW.. ...0S}..
                                  C:\ProgramData\Microsoft\Crypto\SystemKeys\8161c532f4be2453f4e2b357fecb49ca_d06ed635-68f6-4e9a-955c-4899f5f57b9a
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1944
                                  Entropy (8bit):7.055133148010718
                                  Encrypted:false
                                  SSDEEP:48:uH8QC/62b7V8RW9NYMCAd4M9/xJfAXxuqQfJ7SHlcbWDgW:u1CvVMW/YMdpBAXQqQh7SHI0
                                  MD5:100F90553A0F749659B1DC5AA0C39E5F
                                  SHA1:B19FBAFF8A9FF7DDC132C67C2758F4BF98D82981
                                  SHA-256:0ED077C202423ACD98E25B6C0631F20CD0E72A93E08A02E7759223D7B6B2A824
                                  SHA-512:5B01DAB45BF3BD25E77F8F24F0967F14E085567FA561C4DD7DC4FC61465ED78D8F1DB7FA8D1CCC2F8631184F1D5CFE3B4E5AD8298798071F938C396B7AD3C1E4
                                  Malicious:false
                                  Preview: ...HH..g/....x{q*..F.10......11....OO__--..i[y....p..Q0...kF8.n]xJ...,.Vfs.....O*\i.4..,........6S..r.....`.j....MM..ggll..fvQQ..::,am.a.y....oN+.j.8a.........RX..[[..{{..az..!s..tE..;8ggDD..ggmm<<..01ED...~....D..q.=..f..FcE..(l@....x0.8l7=..Fw.E...1..-.Rh.K=cBC_.A0...NeF<.j...R..4B.K.7......g.b.Z.D..w..uB...A..`I.#A.+...e.i.Zi....o].../..;...2q..y.A.mb6......{....d..8.._PP.........t.. }.......xo%...g2.y.......K...'$.....G..wQRU..N.h,u.........o3...@.xU..G......i.*...qa5q 7...!!..~P......U#..z..7...H1{[K..a...W2T&....r.G4CC...45..+...p.s."..>~.GXO..S.H..k&G ....FF..9.00.........-.0..2..d......h..s..r.~.A8....z:..fb.4.~3Bz.F]..O.'i..3+Qe..r.)..`.n@F.SR...._.k..E6....Tp[w~..L.jj......_E.;A..K....iv.H......@...L.\o...t.N.......g..9.b..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e
                                  C:\ProgramData\Microsoft\Diagnosis\DownloadedScenarios\windows.uif_ondemand.xml.inbox
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):545385
                                  Entropy (8bit):7.999605565828722
                                  Encrypted:true
                                  SSDEEP:12288:hvqliJbQyXw2g63AbSV5ms5/kj4br6Sztpvq:hwEQyg2g6QbSnP5/kkbrLzC
                                  MD5:55E7E00BD4C0B4678832CCDEC08D73CB
                                  SHA1:623C030479C0FFDBE42447B55C072714E06B31FB
                                  SHA-256:98BE945966501B59ED8B0AF7C2A81A5D19800C01C03C22B8F2C171AF55EE9C85
                                  SHA-512:CAC2752BD84AB5D774E85536B1C6173710F9F5AFFCA9FF247EE65F105B25066481CBD3E3B701932FBC4297A8DA49C24AE5E8DB0173F6210D4D9FDE489C2EABEA
                                  Malicious:true
                                  Preview: C.L..g1....d{....I........1#....KxLz..pv.....X|i02....y-..... 22..F...6#....._J.................~knli hc.Q.mm......^..MX~c..dz3&....W_@.@.........hr......pC......L*......7-.....(.......*638..<3....z{..S`/...>D..+.xRiuaq..RA......rr11%j....mv..+;...........T..^\....hn..[D...]...C.H..302+$${-....3a.....V.75M].... &EJ......+M...h)?.......FR.....[R.. =M]:L..ik6:MV....VH....>9HW....dhe~..th..\ZSX1!_R..kmQL*5@\QS......EP..../a..SS..n#........GG.......8>.%..ID"7hn....'8............Ojy........//.F..........JJ..55.......!6.[...........Ey.*......PW....-...+}~M./...................h........]]....JH..........Gab+y..hb..'w=2....zc-&.......N..VHU.....CD.............N.....a,...z>.....................~}cx..DS..."........R......$.....&:..ww9.k&..IIvv........k~..........46;d@S..bn....eh..........35........99...c@G.....~~..ag.ca.....@H..#!T.....r.....SR/...A...&...xx..~~B^OM\Nx}..buhn.jm99\\PP..LLHH6z..............ylm,cp......Hbpp||.......N...!3:u
                                  C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\telemetry.ASM-WindowsDefault.json.bk
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1515
                                  Entropy (8bit):7.338482223549025
                                  Encrypted:false
                                  SSDEEP:24:w0pOGu1sU/WQXiE8TdQlslZlZq84tFoze4ytP6qfHSgC0fNSZBzfteJTQRC4qGUl:POGAsOWdvqyZjPAd4M9/xJfAXxuP4zha
                                  MD5:2CAA18ACD61B0FCB5774F64F30DCACAF
                                  SHA1:4040565218C21D6A534C804D99C24F87DB88A9F3
                                  SHA-256:D5BB83AA1C9B7B36B69AA18845AA580606FC71AC9476C654B281AC18E7F3AE39
                                  SHA-512:B18EA73EBB1215FC79D3B2FC5BFED3FD2D17E6053F8FAA7B6150CB14AE3B89073A345E539E2686E30827EED87780DB1CEAFA4F4B4E8ED04AFEB2A705A3457345
                                  Malicious:false
                                  Preview: .t^..................-'*7.......DL...~.j.................?#mz...$>........DDII.........@Q7>....J)`...u}N\.......1-&1j..4.n~!/VQ88..............nf....h.l....LD....4&0-pyuf..JRzx....cI##!#.............................prMEly......#*..]L....%$..'...ik........-0.........XXfx/Lhl....."08%..^M......FG..@a2.22$&!?..+3..C^n.yp...QZ..|bU/............}a...............""..v.....j$YVG........GR;R....4#..../5ar......11..`...]&.~%X......AW.r..YE.........ig..ii....XC.........,Oxj......um..@R...1....,(..rn.."[.....@U..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;
                                  C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2652
                                  Entropy (8bit):7.828244374473361
                                  Encrypted:false
                                  SSDEEP:48:5X9gvHR4WZIHQtREgkSQF6SuViB+2Unl0W4NA4pYt3AqoAd4M9/xJfAXxu3BB:t9gvHDZsQUgRi6DLlGvApBAXQb
                                  MD5:18EE4BD718F394C27A9162F56932C394
                                  SHA1:517B728AF9F8CAF9C60F1B8F693510ACAC716216
                                  SHA-256:883FBC7B143E841116DD1E70839E448F15D920246D2E845DEF253F1B6CCCB949
                                  SHA-512:1157ADCA66892D15A87B29152FAD85DDE9D9051F71108488F56DF627136A23C57F256FEAA59DCB996A6FA5FB1050070AF9F05D6A91BFBD4C72B6E1DEE3E73B81
                                  Malicious:false
                                  Preview: @07.._......._.....+...!#...HH......nm....qw.jn..>"....DM..................@....b-...165h:`....nm........R%..ff=Dvc....2/.........ue{......FDBJ...Mkq.........../)......EE........0IH]ik../2....GZ....s.x|..@W.h..H]..fh..05.........ll.......+)........kd.........{.....#%.o.....q}....11...............QQ....nzSP..jw....Y]J[..zs....[G....y.............ZH.AF..a|W...&>...I..>?"7....}(.........|~..@9........JIKL..ga7W37....(!..A]..!4............PQ6B....%|.{z....e1....=&.BGD~fPS.EBB.V......Lf......aa`uE_..abpw.b..'G......@I|.85....kco~bi.....~u..4 CM.....7".....z.aa...M..YW..jj..H?.....h}ik/2......SN....."9)&..XQ..........=;....YQ$4.............HJ..NF.....+,F[..)J]Y.........LZQI..DE........r|vq...........W.......]^..c~..a.oq....*G..`}....RG.....<912XS..0*|]..}}........*?....lo......b......BP.....35.A..j?..PV....*|K^..y1B.g5N.{{#v.........N9..xx.s..36pq...........pz......9?...n....#Y...[3.......VR...........-..df"#..+>..O[DG25.......GN.f......]........
                                  C:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\utc.privacy.diffbase
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):906828
                                  Entropy (8bit):7.999486051565347
                                  Encrypted:true
                                  SSDEEP:24576:CJRjFfHsae6NT3pzwa2KNpIqa1WxySow01:uRj5nnT3JZFpIL1ocw4
                                  MD5:7AD72719B17E7CFF3B5A39EB64EAC867
                                  SHA1:BFD1383E6483B5794C97754D97E824D9B95B49FE
                                  SHA-256:8EA03F56D8505D502936114EC285E30B821A0691A6774A8A0192871D9F1C3C29
                                  SHA-512:FE9D1A3A457239134CE114E425FB9AE368A8D48804FAF4D849E24009DF68C453D8A2FED11C5BF452256DEF8A59DCD4334B0EF36D8C1064773519F80829EAB405
                                  Malicious:true
                                  Preview: .......66..nz..V.........UB....KIG....-xm..........ce.....8+.......H_...ui..4&.....e....SI....)~...KM....2..`bl}.._Z...Y.KWR...NR....DB0~[F...hy..'0..........;:0y...._C-:.Xgj..8/..53.........G["(....O.ao.....b......................TOx|x~...0H......[Y..}hI.3:........5f.......8%yxc0..;.....97......Q.r{.....QBYS....no....FG..0..........HGi-...P.....n)5|EH......k/RA7=.^1<....1>...^..S......ee....m{.....&(NI....>|.3"dy>7..`jy)?(......`fXT..+.LL..MLM^!:..'=..n.4!.......SB....$%..2q.........~x..N........@AC.PE.xz..]P! ...K......6r..]J_.tn..<3."lbeDU....;=.....X..Y}........`(...@vs..U..81...X......4|....#0...T..d#../...%)..................55....#..a@1'|m........+h-+....V0.............vu...@\.T......w...O.H.......gh9?../%=r|i>-mplm..R...TV......hu...Kk-UI.......[..1b>)JU.....o..../*......&1......wp........}~..[.B^......fc.....#jur^.SE....}a..........xa.....Q...N}.0!V].......t2..^.........itz)..7(~x".`A.9##..'&..AV.....}h..]ThI
                                  C:\ProgramData\Microsoft\Diagnosis\OfflineSettings\offlineblocklist.json
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):887
                                  Entropy (8bit):7.0704203164802255
                                  Encrypted:false
                                  SSDEEP:24:hW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRf1+4FeERBz9K:hLAd4M9/xJfAXxuS44FeERBU
                                  MD5:952A1C0B6921BFB6C99DABF38822FCD3
                                  SHA1:21A3E8E97C72095C00D5BF77820AB0EFFF5E375E
                                  SHA-256:33D5B0E998B75AC17D67FA296D830F558386DB62B9121BB8BE60D753A596DC72
                                  SHA-512:3A4FA524BD3C041D15716FEA6CD76E65907D3F55BA850706F1C83C9B9DC6935E2B184489868CF11ADEC856BEFF01CA1763363CEC2AD4C1212FEAD58EC8CD321B
                                  Malicious:false
                                  Preview: [..........4={ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....p5.vg.o.W\<}{.}{31}{000111000102000102000108000105000110000101000098000108000111000099000107000108000105000115000116000046000106000115000111000110}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Diagnosis\WindowsAnalytics\analyticsevents.dat
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1299
                                  Entropy (8bit):7.513559865404532
                                  Encrypted:false
                                  SSDEEP:24:cd6LxdEIRlS4GmPFt08S/Gffaf08H+84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7n:ccLJRljH7CQfaf0SAd4M9/xJfAXxuTfA
                                  MD5:791393DCF2634BEE117FFB8950637730
                                  SHA1:33EDFA0C243A324401468FEB3AF5BE69D0DBB55E
                                  SHA-256:A39D8A09B6D92520B058E4420900087525B563148997288879015CD0B30B18DE
                                  SHA-512:B2C7AF14D257718CC68450A4AA2437CE6F87B55544F9A1E1B02D3629D77B22BC50FC50D42112A6491E5ACB698D3CAE2440F4C6FE5536CB8BE6882130677323D9
                                  Malicious:false
                                  Preview: 5,;*!."[F..k..........@Ik]......Z]fB.....',v....:&..'./.lN........NS..1.......AY.:TK_X......GN.X|B39.......2;................PR25..}l..qx.Tj *....!.>6|Q..../&...#)!..../.......KV....~b_V.Np..9!#~...."...& ...Z..2ypJmHoCF..L$q6....yeYKX!......!\..eb....?.............mkx...........fq4+...+...................+!...P..ES..:7.buIT....VGi4...........5ce.....5$)....y.Y..........&!......[];<.....*%.....^ ........CN....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{.....
                                  C:\ProgramData\Microsoft\IdentityCRL\INT\wlidsvcconfig.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):7224
                                  Entropy (8bit):7.952478614555991
                                  Encrypted:false
                                  SSDEEP:96:a6JCCr7NFunJaTQUyFieuIxwnMLN5is57zpYT4ArMiktlCablk33xdqzpBAXQXl:a6VrxFnVycevwlcYoiiJlk33xdqQU
                                  MD5:51606F6FC8A2A15E6CB27C10D725C876
                                  SHA1:FC74C1492CBDCFC96C78AF17FFAD6F66E07DE244
                                  SHA-256:E14A4CCE5D7A52A41038EBA760045399B65D18E4573F12AC1DED26A6B59A690C
                                  SHA-512:850ED7E0CDC025351ECE28A7BA50FE76AB5C5E0EE902DA501620659478AFD0FCF6582B162F817472F9C731888DB13F54987C8DA9784C7BA962FFDF99F77BC608
                                  Malicious:false
                                  Preview: .....->..wq_.8+...........8'}{ l....................LLm'ddhh5l+oR...2/||]B6?a6......vw..CF.hD........R.....VP.......]HHJ.....,f..O......jf.....VJ..h2...S..%%....?@..;%`|..........MM....Y.K...kv....l}q8.\tc...I.Y!&+n....K............mj..W...>...&&......gf.p?DX..36`=.....)...]+-........hh[[..@E.........TA@.NS}d....:ly~F.p.69..)*.............F`..ZU...j........TT<>..x%cU..9>`t.... }..XG-+93......0vU...J@.........VZH..Hkj...q{nOmp.;....UW.............`j......}x..Tc.....-ko..jk....7jDh....3...KA;:CL......+..A..MM............FCL.^h....u}d~W.}~JJ..D............;9..T...}{..cR......<1..//....7jUb...."...KA;:CA.....&.....FP......3..TvJKMBjN....&)??..a-....................H`..p\..wy..ce.....8A..yvWc..&5uT.....y..Z^=tRR.....:'.....@..........yLK@bi0....*+7$@E)t9................fc.wz..QS..rg....GEad..[Vtg..8.rs...h$...j..*.......vt....bP......:*..q|a..."n...kkdhsg......"/............;9..T...MW..}7..<MA/..,/....c}F2...u~.....|NM..../r87..g......?*....~f
                                  C:\ProgramData\Microsoft\IdentityCRL\production\wlidsvcconfig.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):7202
                                  Entropy (8bit):7.949757911679584
                                  Encrypted:false
                                  SSDEEP:192:+v/hgxwKBkxpO8+ikWPCrORQO3AC6c17H:Y/whBeItrO21C317H
                                  MD5:DF2A4D642EB51691D4B3E844A2609A6C
                                  SHA1:D308BD4FED17D94D2A84A58EDFEDFBA76A596A84
                                  SHA-256:D9399122E3D71294E8F8DBD268FD5D6B230D7456E9B0BB04A625B580EB65BA2A
                                  SHA-512:6D543C8D8B18ED34D9A0DCD4ACC5D991D6490B77ECABB1CC48BF0702A7A58763EFAED58EB27B2E50050C7AD47268335B6CE27C082E0CD1272A262E0F0EB6CAE5
                                  Malicious:false
                                  Preview: 65...n}..vp..BQ0.CAFM..yt....53.....<!fd.........^..xz......t>........M..UH..ls...B...*$z{.....Vz..........|2"189..p#dw..acN[*(G...n4r8.........1lHL......ZQ].DKz33..GA.,?....= ..qv.......glV....lq..GEPA..*=....>.....`%rwvx=i........,2...ZAF......(00.... no.SH....D...S.).......]..vkml...6.........km......,i|aqhsd...BEU...._A\_4<......>-..M.iOqw......[.8?......df....nX......QS.....ze......`s..K..WAR........S..P...\].~..;1......RR..FC.Y......njbh..O@.......3....~h=>fuDy..F\...()B;...._H...............k.>?....sNJB/5...GBC7^7<.....]\......_L......2...JP.O....w..UYFU..XP.....TT...32.vnhnb&5/.LDNT...N.....HSRC#.........XM.......>...Y...{.....:..!..ih1'Qvgd...3DU@b............276kDh..<2.0..YN*..,.....^K.Y^.\X*;..lew-...T......RB.....GB....w...Z[....@O....jy.;.....b.KJ.iuxBN...._z......]\......?#..IU..{h.....VE........w(=<a.<<..........bo..->..!|.5........}^..r..U..t.......f4.....juZW-h.fMLA=L;^A.....B0m......]..........t5&j10..........5h...j
                                  C:\ProgramData\Microsoft\MF\Active.GRL
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):8295
                                  Entropy (8bit):7.918155553169514
                                  Encrypted:false
                                  SSDEEP:192:+zHvIjkOOX3nVkMbs4r71zG4rHd53dJTas3d8E0rHGINDzXhDmEbVq/V9:+HX3nOJN83dks3d8PHvNZDLqN9
                                  MD5:7E5BEB61E9AACD0B911AEA9A5AA0B48E
                                  SHA1:945B714D87713676E98923693FB41F9FC09F99FC
                                  SHA-256:09261EBD4972D28AC6A56225C22C6FD966B6399EF173C3E7236B8D2A555F2E71
                                  SHA-512:129E71291C050084C3AE523E76590D14CB16F4C084BC5F8D4933B726DB6EF1CAEECB896232780B7FEC523A721F6D58EBD82051FC9674E42D1E4ED9FFACFF12B5
                                  Malicious:false
                                  Preview: D....s?......>..I!..zz "..WVIIf>NN................ ....||....kj...........A ........g..G...P.........(..o.>...Et&=2.;.4e..[2.,....M...k5x...|.~]....n..+.:.T...V..9..|.3.48..be.8'?...'.5........g..\GI.........r........!Y...R.h-.;.]@Y....D........'e;....._...0q...?........V.Qi......7qFp.PfEE...........k... ..W.3.((..::""....]]..aa...........ffSS........tt..........iioo..77......ff__......//....11ll>>~~..99......}}qqMM{{TT..xx..........++....LLPP//..::TTYYHH....LL..gg....ww....CCuuWWLL@@..........))..NN............))...........TTzzkk....~~......jj......\\.........gg................oorr..........<<KK......++....--.............))..88bb..TTnn..ZZ//......kk....""WW??CC..ll....''99mm....IIeeqq...........KK......<<..{{ssff||....GG.......XX....__..11....99<<..oo......VVyy..??................CC55NN....EE..``........**77....JJ..........NNII......))....!!\\.................XX.....##....TTmm..44TT..SS..qqrr..==......................SS))gg......RR....yy;;^^.
                                  C:\ProgramData\Microsoft\MF\Pending.GRL
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):8301
                                  Entropy (8bit):7.923938647536568
                                  Encrypted:false
                                  SSDEEP:192:eyNZ1Z33BHjhLPD7XMUQ+EKegNOFVS/roLdu3AV39:eCZXUx+EHgK0g8u9
                                  MD5:7D2F6BF077F94FCF1D241E371490B73C
                                  SHA1:1658F46EA718ADD1C30A5D64853F6DA8CC0CD03D
                                  SHA-256:B450174D990B443960BF2C0BAB3113D252CCDF23B33AE42BC224E970D316137F
                                  SHA-512:F885E984D2AFE9739A779E34F4C4D0F40350A2D2CA174EE654787A8E1250A5FDFE12B16B5A7013E4364E7654FB53C3B2CFD53F78481FFF89882093A6C483C976
                                  Malicious:false
                                  Preview: c..q6.....FG......+C....ee..??..ddi1..... !..=<......w.........3]\....&&xy....'.W.39s...qm1..-.f~.............A.hCyH...!.s.Cfw...D.C..D.......N...XR5,._.Fw.;xcq..Q.....*..&.....,...$.L~..!.......n.....C.k.WgQ..I.,..*u..q77...|.0xB..#r..m,I.Ks1t..Y......$.\....Z!..5w5y<....G*l..}<..........^h.........U..e%%.s..`(B.UU..ffpp........ss..\\.....//......yyII....QQ]]RR........(( uu......WWrr....""LLzzff0000CC..oooo....tt@@tt....))......LL............55......77......!!tt<<..gg.......PPee\\....OO##..~~SS....MM....MM................::EE..FF........33 ..VV....\\................**....55....YYOO....................uuuu.....................KK..........ZZ//...........||....wwnnAA..__..........ccpp....SS......//99..rrdd..{{ ............PP..--XX............\\GG..JJ......OO......WWHH..}}jj==....,,..gg....((]]......ffaa....||..??..~~........yy..VV......kk88__//..hh....ss........................mm..hhxx[[....dd..OO==.......88 ..DD88..nn&&YY....vvff**JJ..LLxxNN......cc....M
                                  C:\ProgramData\Microsoft\Network\Downloader\edb.chk
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4886
                                  Entropy (8bit):7.89059616282763
                                  Encrypted:false
                                  SSDEEP:96:GLuSnkjl1u6Fp/CSZADOeG5bTO0PziuNCP25UNM9NNP5lL9vT4y15pBAXQP:GucdSZ0GRO3uX52M9XP5lL9v0vA
                                  MD5:9D157AD595F0152873770A65E4CC5233
                                  SHA1:A8CADC60021A7F46C2107DA6E084FDCDAD08CF81
                                  SHA-256:3D74A0E2DCC1B7CD159F11353D7C44EB4B2EDA2C979790824A63D9D4B2AC5E72
                                  SHA-512:B44B0A4BA74E7F8659A1497FEFF553D1B453DC22CD6FBB86DEE6E3444F3E989F98EFC5B2308F465AA10180358792D8A3E4D1661C2A73A3E4001111E9F1EFFA80
                                  Malicious:false
                                  Preview: ...h......22.........X.............!!..88....}>..#......2pe4.oK.......Ry....@wv]+2......n2==........VV..aa..``......^^WW........bb>>LL....!!88..aaKKyy..wwNN==cc.......^^.........""..MM......11jj......YY++....II......<<..GG**..==............................qq..KK..kk....44QQww.............qq\\__00............KG......XR..{g\N9+......^F..............qq......yy......!!++88..........qq..vv..UU..............&&22..pp..oo..==....00......HH..zz.....??WW........yybb..LL......88..aannyy==wwWW==uu.......^^........``""..MM......11......==++.... ..........pp**..=<......C...a.00.}....t5........$$........44..wwZZ..........qqKK__..............**bb``EE11zz....ee66..........bb......++qq\\..yyPP....!!jj88....dd....qqGGvv..UU...............22..pp..ooee==!!.............uu.......WW........bb..LL--....88KKaa..yyNNwwzz==qq.......^^.......WW""..MMqq....11((..,,..++........##.....;;**..==....YY..::....22..KK33;;{{..++......""......hh.............ee..jj..MM....;;..........@@.
                                  C:\ProgramData\Microsoft\Network\Downloader\edbres00001.jrs
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):75849
                                  Entropy (8bit):7.9823634657407
                                  Encrypted:false
                                  SSDEEP:1536:TvZvp73ljaY4CJLFHulSKK9x1R59J9G6XdP3PTlffflY4BdFNx:Tvn73lmW1F8o7ZJB3LlvTrx
                                  MD5:750412E753DA8A302D515AD2FCC5CD0C
                                  SHA1:7540BC9A4C00973B45DF2CFB1EBC47E355E07012
                                  SHA-256:8D0F16FE548B9D8D17F8E476BE52C7F9223341CF8A47C38DD8CB3E592DFBB826
                                  SHA-512:04C4BCECC7EA72BA465BCFBEE0CCB9C39030D095CE0FA8F29C4CFF2F1147026052E23BDD3ABF7A3C4181329B34FD5C2DB67FECE2C000E644DE65334EBF0B5E5E
                                  Malicious:false
                                  Preview: gg....llCC....ff........ ..........""..~~XX....gg....llCC....ff........ ..........EEZZ..jj......ii............UU.. ..""BB..GG....!!88"" %%..........((...55 ......||..&&++..................RR....55..}}33ff....aa....rr..........??vv....ss..nn....YY....aa..22''SS..PP.........tt..oo..............``................++AA....^^....ff......ii88....XX..77........AA..tt...... ....::............--&&VV..%%....//......))..--..{{....44..ss..;;.. .............mmaa..]]........mm//....]].................""KK^^00......yy............................rr..!!pp55DD..--........eerr....II............WW..''aa....qq??!!......22..{{...............``......aa..................uu))cc**..%%....oo..::....XX<<..JJ........;;77tt..ccUUee......##..........//....II....==..{{.....OOvv22..FFII..bbEE....II$$......ttxx....cc..ll..<<..ZZWW......rr....ee..;;........oo%%......gg....dd....zz..ddSSxx..........--....//~~AA~~..MM..pp....vv77....||qq......<<..xx...DDKK33GG......ff..bb....II.......``
                                  C:\ProgramData\Microsoft\Network\Downloader\edbres00002.jrs
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):75849
                                  Entropy (8bit):7.984050098563431
                                  Encrypted:false
                                  SSDEEP:1536:7HpBLJFfgmz3ooPmKl/3GMZVx5h/zIBmVV5tDtRIj61HZZZZZZZ3zzRNrT9M0hgB:7HpBLJVgKlJ9ftDhlZZZZZZZLaerzi
                                  MD5:94423F0A103AF3D9F8D93E37350BA044
                                  SHA1:60F6FFBB874AD86033CBFC1286F4A1973E96C40F
                                  SHA-256:973EF2A59EE8372CE7B00A4E4E9AA21E8B49E355534EB11AB7EEDEE0297F9886
                                  SHA-512:8C83B6532A9A07DF4E5F3640F115F7DE3EEA7BA05977BC8AFFCCB4BA72DACCE7F5784446C9B1F4C4A46C01912498D22DFDACC6663C36D28A895B5A9B3B02F5FF
                                  Malicious:false
                                  Preview: ..........??..``77....99........--..jj........vv....jj..JJ??......ZZDD]]..FF....AAOO..55hh99..FF....{{..))..........&&..^^EE**))..................dd....xx......ll........,,{{qq........~~rruu..cc..CC..^^....rrii//......UU......II..EE......ww..BB....%%.........jj..;;ZZ..EEqq..jj......................~~......--QQgg""JJ......jjnn....ee;;......~~....99XX..SS....XX..zzEE....>>..--22MM...........<<vvFF.............gg....??WW........OOKK..""..55DD..gg..GG}}....II..........\\....EEPP....rr88....__CC....77UU..66..gg....ZZ.....%%..VV....gg%%.............LLpp......((.....::..++{{......nn....ooSS.....ee((..2222.....ss....MM.......((......[[.....aaYY..UU..YY..>>......GG..FF........gg......\\..LLMM......NN33........ZZ....--UU..\\..ZZ........oonn^^......==ii....bb......hh..FF==....((;;oo..@@..........{{..||..ttSS..ff......00ff..}}.."".. TT....@@ZZ..$$..00gg.....tt..TT..nn..%%bb....__!!..RRKK))RRxxAAddCC.......ff..??........hh........xx....eeRR......mmCC..............
                                  C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):394008
                                  Entropy (8bit):7.990701260473595
                                  Encrypted:true
                                  SSDEEP:6144:6EDymvE7KAtuFE7vR4pHUuvP4bTHXudX54KgApcAc2txvXDteeLtfFNq4k2x1aCl:BYeXERAHUtbT3Q5VimteehTP1aCl
                                  MD5:22D9F8DF4891B720ACFC9E429D39FD7C
                                  SHA1:EDFF5845EBFD099F09BDB5B48B0F5264C0C0EC92
                                  SHA-256:8A34E837EB8A230839D2DF5536B798479B893B1DC62CCD8E0197C1A0F8E7E229
                                  SHA-512:FA6461BD01FE9C136DFC13973F6976A19B011C3F0DF4F2B859FEA924DAADBF2336A7346B880909CC3490AB9686AA9D92DEC15E208CCCF4E9345ABF413F558DEE
                                  Malicious:true
                                  Preview: ..ss..v.7..SS..........H..uS0.....n5?..33..CC........eekk......hz..:..*ap...g..!....5.....*.....pq......C.%@.b_....|v......~~VV__MM..,,;;..yy..!!..PP..........[[............00....NN.. ......&&jj....//..11..........TT//\.1s..TTPD..cc.........vvWW..EE\\....KK....JJ.....HH....33....UU....,,..44..OO>>........--..((........((.....=/)..........]]GG..HH........KKFF>>33....<<........kkaaNN..................//....55..qq........\\..&&ff..........vv%%||..~~........))..hhyy..99..PP...aa..33..@@....8.44......{{NN....88................11........zz....\\==....PP..^^....99......=.})..^C....@@KK......JJ..*.L.GStf...I....rrTT..QQ....44aaLL....~~..dd--..SSEE..........//.................YYHHJJ..**..nn++7733..``QQ..JJRR...........``DD..........66....^^//....FFHH..TT]]......PP....11....::jjuu.......qq....MM..33....[[nn............22....NN.......>>.......%%**]]..)).................FF..mm66....77UU....++....nn.....FF....nn77jjgg....ww......LL^^....ll....88......ggxx88>>......))<<..{
                                  C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):8989
                                  Entropy (8bit):7.934102466321391
                                  Encrypted:false
                                  SSDEEP:192:eqeuSvIcfVxOhZ968F7ssrHTEerRCAzW7FvwJD5x8r4:d4+t5rHTzRzW7FqD5xI4
                                  MD5:0B0B82AC143322CF81C582CFF7EAF8E8
                                  SHA1:82A75706EECD168E09CD516D0FC03C8E661A9B6F
                                  SHA-256:C397FAFE7F97D638E076BB2E966615119CAE9D74761387401E92CBE9A86A8937
                                  SHA-512:7B5BE7975A385EFF4577C225FC8CAD40E2973E446A47A34890D80A87EFE1FBA2020C32D6BCB2603F9C663853F66E9324127379551C17DDDC36FF9EA4B3F59631
                                  Malicious:false
                                  Preview: .v..}qqss...&&.....CC..44..FFZZ..67....&......%..................llPK....TL[#1B_.<kS.~(;.....n......::..]]....q......]@'...JJ....LL....yy..............RR..==.............gg....[[33..EE............??....44.................--..xx..........xxcc......88''..&&....vv..dd..HH...oo..........**..''RR......##RR..,,..33...........!!ee..66......;;..II....llxx............bb||.............UU//..zz..66pp.......IIzz....**..ee.......dd............99......$$....kk..,,XXgg..__\\...tt.....AAVV..~~.........................##..&&__..QQ55--33.........??....((pp....ZZ..jjCC..oo........ff..??..ee..``..........22....mm..UU........55..AABB......22aaAAMM....UU..KK......00....--......aa..ee..XXww........??....ZZ..))......BB..$$99....zz__......GG]]....ggRR%%....WWCCBB..........''NN......AA....ZZOO........bb.......++..,,..GG.......;;.............II..RR||aa..dd..::%%QQQQRR......ff....UU....TTll........++........((........99QQ33LL..22..FF99..33..XX||77..bb&&......ZZ00....((II........
                                  C:\ProgramData\Microsoft\OFFICE\AssetLibrary.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3559
                                  Entropy (8bit):7.862279796095701
                                  Encrypted:false
                                  SSDEEP:96:uNqznFhiIR08Mc+rWDDQHnp+wN2wraVgBpBAXQ1:uNGgIScw6Zm6V/C
                                  MD5:8A35935C77C2F6272290CB03180D6D93
                                  SHA1:5A6AF772BD7B318A25A4D1570EBC3C0BEFEF3E41
                                  SHA-256:E72EA3666C2E441D0BE29B66E64D5F129DF8CB4ED79C17BCE9B93951C473C7D3
                                  SHA-512:8B555358B4B79DB416280DBA863F0CFD6B14831D1B37D928460D3477664290B32454CADCA2CDC9B4CE5613516C5BF30A890FE5035F16EFC77373E0F81C10C6E8
                                  Malicious:false
                                  Preview: 99......../....wQEExxII..wW....3.nn.?AABb..........ee.........11.............GG........66..//....((....VV............::..aaww==..gg.........gg.................. ((99........II........hhII........++..??AA::ZZ..........eeuuHH....WW..........MMmm??............EE....YY....((...................''ff\\77..........oo..........ZZ..........bb%% VV;;..JJUU........zz..........BB%%YY......TT....................66..44.................NN....__......//..''....ff......==88..II\\....kk............r..:y.I..6C...Y..b.6.......77>..?.b..(.rxX......qq..QQoo....tt3366..[[xx}}..**..oo..``......tt........UU3311QQJJnn.......6..g.J...X....*..#.9.=...G.>xg...bb..v1.Q...q*..F................[[mm......pp......UU++>>............ff........JJ..77....(.r.R..<77..>>.......S.^..........e..Hk.:...yy..g..0..ZZ....!!....22......uuTTVV......++....**OO..........mm......%%...........?>.D2.........d...Q...Z...4Ee./4>..~z#.........v..\....??ff....hh......tt......ee||.....--........[[mm^^
                                  C:\ProgramData\Microsoft\OFFICE\DocumentRepository.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):13488
                                  Entropy (8bit):7.968713680716458
                                  Encrypted:false
                                  SSDEEP:192:PhUtxLOdNIw79v0L1WZlEF99w7VoaNt5hAiEYfx5YycD5eRSdytbb4Qe:PhUtxLcpU1BgVoa35Oex5eD51dqk
                                  MD5:BB9EFA5E56D81253F75709613CAD2F3E
                                  SHA1:188FF63704F687005DD9A5DE6652D2ADB5BE4ED9
                                  SHA-256:620E7F7AC1039B1329B007C2A86BCD49F0D87FAF7D34CC13C6474543B4C12C43
                                  SHA-512:B2936C21EFD2A5BDCD0B5357EEBE30ECE69DC55DA033700A046C4F248CA3A3625B619097DC7519E3D59F7B032F88659482B4BBD1C602C83D9D3121AB94BB73A4
                                  Malicious:false
                                  Preview: ........BR..uq........<<...........^..ww..YXgc....j99..bbML..D.{{....oo....j....h22TT((.....z}}O3..cc........%%......ii..........~~QQ}}10..b....C..w_.....U5''..37..mmP.........mm......''00...{..TT.Q._.r)).O....gg..Z.KKg.UU......Z.6.3...u.-.......{ff....ll..Z*..::....ccGG......3C...... ..hh....kk........`.....44FF33 ...j,,uu..?2..>9.f......ss...k`..".HH...XX.......a..pt.}.q..fi..--............W ..""........PP......Neeb.....11.........>>..E...nn..44,,~~oo..||......`a....OO..~~........''..;;yy........ll....WW..Occ........66..hhUUbb...(~~..UU....o.[[....vv ....yy@@...`.j......Q!......ll??.............ii......bb43Y).........55......af...*...yyE5............22..^..S...[..h`}.r.1.$....^.......q\.=.i..S.}...I.....]&LW[....@8.O?...K.(..G._"x.k.*.p..A1....."..COn.`.......m...w..............3Z..:Je..{.V..<:V...-.&...m.N>.!1N....R^......|HWI............s40.'ooO....0...<<.....?....y../e.....ff...`......P. 0%B..H.21..am3H.m.K...m...j..t........9@A.^e^.6Q..2.
                                  C:\ProgramData\Microsoft\OFFICE\MySharePoints.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):50850
                                  Entropy (8bit):7.9944118777218565
                                  Encrypted:true
                                  SSDEEP:768:arL3bwuPzntacEUgYEceKxh587CjpvuObyap1rBCkgBOwl0X68dWtEHu8ZNkTk3t:GFrntacEUdx1gC1vUWPgBOweKc1ZNz
                                  MD5:FF2A6F2D5D3F28DB621C91E4EE1CEB91
                                  SHA1:B1531ED90DC6C18A03CD3063ACDD83C86A2EE836
                                  SHA-256:405E6F880548B2D167811FD53EFAA44145266DC1043A0EB33B19CB0E6CE2BC70
                                  SHA-512:AFC0FD499EEFFF22C0337EB4EB2EB8E0CFCE864B129B74D060291B0FF91AAC5A5F7FF30CE4803BF778E0A2B419295CF94E57E29DD15A9FCA4B660F4F7A291BEB
                                  Malicious:true
                                  Preview: .....554$76...f99........ko.....?TT..CC..go..//.Ott.....go.....ww..jjrsQY6[##................c<....33..0.b^KKHz\\..........]]. ......bc.'^..........ED....))..no..!!ONaA.t..LS}|........z:KK.._[......mm33..~~....22....ww.....j.RR..y..]....S.......5..G.==Z..#...#P.....i..(||..rr..<<............kk....$$..............FFuu..::^^+[1H......ff}}...j.m..GGSSii..\\...,.*......yyL}!.p......wt//..4......K{JK....kH......ff11.A...x?..<L..99?I..u...z.........B.....WP..2D.E..6Q...fa..Q%A.[....S#16..3E!.......>9.......?...l.....BN.....Q!dcoo\\.*U....,+..aan.{.........*9;;.[.....Vf....?...V..%"...\,.l.=...-KL..Xh.|=..}.rq.z..V5b.5%x...99.#j-..4rrz.n.......C7qq...e4...MMFp-lFF...}............y..0]]..WW....II.K.U....vvUU..yy.b.-....PP..zz%%!.EM.......nnDDn...JJffKK......xx........[..v..1QP=.'&..10..qp.^..+.^_....*....OON.;...........6..b.RS..jk.H......w...............5BC~.....'&]...j...#.ho....Ck@@wg....&&......11.#.......JJPP....22~~.........X.u..luu.e....!!..[...
                                  C:\ProgramData\Microsoft\OFFICE\MySite.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):13416
                                  Entropy (8bit):7.888334226554382
                                  Encrypted:false
                                  SSDEEP:384:ES9A7lb2G5RDjhXcXr6Racm7tcKMbgkg8:ES9q26lhXcXuRaF7vigkg8
                                  MD5:2E9329B5922AC12435B0F24DC11A3417
                                  SHA1:DC5CF1EAF167F32FDFEECBDE4E5EE6B4A59041DD
                                  SHA-256:5158928C4C5023EFC262C8CD51A403E462F3FE493FD63C2A1AA7297F3EF595F1
                                  SHA-512:84FD2701F52849828CC2B248AB6B0A94E79EC5348F389279AC4A666E9F2BFE9C01F79C3179ABB9FD695B1CE725438C0D12D250C98AF38E61EF01AC592CB25EE3
                                  Malicious:false
                                  Preview: ....AH........v.........xhhh...j....HH..sccc..Kb..~...eede...k....DD......O.__.F[[OO....;3........<<=<lL..EE.b..ee.....3....`C....\\]\).4X...NHHoG..sC}}..on9=...........UUHH........__.. . ....a..a.q....Q.\\....a.HH......rEE....C....gg++77....yy55jj.........88....qq!!..66..IB..7<yy..KK..pp--..GJ..?4 .HAA[S.DDD..DD...O..OL.rr=55............mm....0p..07......."""p.....nb...*%.AAA--AA}}}/gg_[uu=...uz....cc.....pp..ffn.................``....'.........................."""".."".........k..--AA}}}}EE}}WWWW..WW....cc.....%%..........@.OO..OO....``........................8................***]....cccc..cc____gg__uuu...W.....I...........fff...D.8888K{......BB.......e....V.................x......3.****..**ccc.--A.___\TTl.uuuu..uu....cc.w....44..ffff..ff888O........qq.B..mm..mm.....................CC...w..".***)....cf66w<PX.__(EE}.uuuv..F...9r..0...%%.0fffe..U.8=mm....z...``.z.....]......8......8.........UU.3;***]....ccck<<X.__...o...uu...W.......@w..^^..||.ff...D.
                                  C:\ProgramData\Microsoft\OFFICE\SharePointPortalSite.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:VISX image file
                                  Category:dropped
                                  Size (bytes):13500
                                  Entropy (8bit):7.967068401489181
                                  Encrypted:false
                                  SSDEEP:384:qQ730CTlTpeO7i/gCnUP+4SOVTNdkpbqjjCXA:/7jTPC14SkdQbqjUA
                                  MD5:1CBDF828E7BC6F13FE6DC050AACF4E24
                                  SHA1:5E23DA6F06A436B3C8F4AFEDC69F7D82CA55AC0F
                                  SHA-256:9466CD9DBEF8258A5B065B976FB3E6524BE338F1129923B6FCDA07141AD3CCB0
                                  SHA-512:B90C2852CBB935740EB30724DC26CD761EB13B8A118781AC2F251F4339599EE4D9E5C1DE4B6F2FAEE90BA3C8DEBF41863356704CE42FB1FBFD209DF9F84F0FF0
                                  Malicious:false
                                  Preview: UU..]T.......c..V.....hx..~z."...A``..3#VW............23+#g.....00hh......t.qqe.%%88....&.g.....``tt.....00.aLL....z{Jj....c@......ML...auu........""..%%...((...W....EE.......... ..ee...[......W..XX%..kBB..hho....`..O.............R.%..QQ :.jj..UU....I9....gg..KK......''$T..SS..gg....22yy........qz...+........{{.....V......=0TT...SS....33.|..FMZYv.ww....GG..gg...o.....B::......||.....FF....L{..nfJJQQ..ee....--.....d...??..55ddII..<<...T.SSss...............=:....PP..dd""TTKK....>>......::........//}}......UU..}}........((..kk.0......CC..........__..VV....EE<<..F.............mm..FFk.....ttcc....qq$$.......y....cc....7@.........{x.af.Y......zz..tsdc.......Eb...HZZ...p..x.....`.*......\J....o.t....|.j......]....]W......b..{X..m....40....afE5c....O...V.......966..$....m..j.'....'.....R"S.'`g....N@......]......7K..D.JCi....#2....q....5.DCN............FA{..4...=.[..MWW..Z[.Z...F..' .}.."b/5.}..dD66k.......'.m......UXX.K...y...9$$..jj.vz...s&y..{x.
                                  C:\ProgramData\Microsoft\OFFICE\SharePointTeamSite.ico
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:SoftQuad DESC or font file binary
                                  Category:dropped
                                  Size (bytes):13488
                                  Entropy (8bit):7.970499621998936
                                  Encrypted:false
                                  SSDEEP:192:DRRpdHJISTrH3Aj/ha+5M07G8P5v64qyTPqNc2sX9ghaNbclrmOhzol:DDwjJa+imG8PF64nPCcrXKFlrmOK
                                  MD5:9E1054195FE1F89FEE320A104F940293
                                  SHA1:3692E32A3CF7F8599E74A1FDCD816B4D0A4D9D19
                                  SHA-256:AA366E7A87EE3E3545E671E9EC809CD6E6BB5A065D3D846C8DB41BEE0F58B28A
                                  SHA-512:FBC029CC366A661ECFE1D32C7F40ED29BC60D891C5B2DC5CAC281DB3168DF0B6458DAC03A492594294F89A239EFD5F9290A0EDEE2B655BA21FBC8CAA09EC7857
                                  Malicious:false
                                  Preview: ........ee.......>>..'700GG.. ..<<!!..OO.....:..oo......Hee..NNDD.......p...]....kk..%-"O...jjOO..z{~^.k...x.........2.!....88))....4...0x..>.......4T..yx............VV....dd....::......C.Z.LL...C.!..9.... .......S..;..#..$.J..j.......oo..w.yyII....hh..uu..~~....qq....||VV1:....%%00nn........laLL....<{%%...CC..CCss....:.0.....-}......==.{{NB..;{..;<?oss..ss..W...uq.%...mbG..........BB........MB....RR....50..`c......x}......................ff.........................44..CC..CC"Z...................~85..ee..QQ..QT..jj..jj.Z......SS........GG..]]......BB.....s++CC..CC..ff..ffdd.Y..............NNk...;;.rrr'.....L.dda.............-..ZZ...............`++<<....N.88..mm<<....mllVV..e..;;.nnqq_(..}.II]]..n..&..g.08....&&.pXX.......l...-.u^^G0{{e.))==........hx.....ii.qOO;;....\MhhbrS....%%.V%%....:.......aGG....Y....]]4.....TD.vHHJ=..h.......^_yyL.B.]]....8NN]]!...UU..cc.2$$....E....<.......5.NN.x..-......&.......b..T#..v.BB........EE..x....h..=.
                                  C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.256652929134781
                                  Encrypted:false
                                  SSDEEP:24:VdfsSfCb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvPY+rDPv4W5y:nvrAd4M9/xJfAXxu2Fhc
                                  MD5:95EC81ECC67B3C8B39BA448F92C2E834
                                  SHA1:8D41C0A90F469C9229CA55FC3CCE6947B9DD2719
                                  SHA-256:8461C25EB66078531F9276919DC7AA8ED4E69C0545658206B362BF4F1BD1A37F
                                  SHA-512:27CA4EA4A0D276337AA3E0D8FC976D7884EE44F9FAB1E13052DFCA8DD336ECF9552C24EA0BAFEF7D8A76A51C775C32BBF3A99EAE09CB7A5ACA1CAEBB58F9D363
                                  Malicious:false
                                  Preview: ?kt.....j<TC..>?RM..ZH3v~sT_...t.........-lZ..QYfh+,{n...:....cJSI1e..QP..2a......qvdd..~...XJ..= .....pvP>bn..,\to.0@HY[zK..9&w{:.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..3.........M}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1102
                                  Entropy (8bit):7.525614714693802
                                  Encrypted:false
                                  SSDEEP:24:KrrjiUyx4Cs6vaw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNT3W5Wg:KXKhs6ChAd4M9/xJfAXxu+m8g
                                  MD5:1214B5D313E86DF71F46CB9358CF315F
                                  SHA1:A7B9D5C27E34259256F1F77D10EB9B36AFAF585A
                                  SHA-256:51054BC80B4566073FCA8EAA806873B56D340C2B7D2C921FC0642A7719C57296
                                  SHA-512:95EBA616A46434BB0E6FF6753739B9445B8EE6224B8B51A0D864D1123FCEF0E2867871DA96A9D2E2E31A8B596F910F053909811FDAE54F8A09AEEF77F1172FEE
                                  Malicious:false
                                  Preview: =i.-.JZ[.D..SI................tW...pe..cP."aM..KEfa.....='.............'9.....H7........mppqJ|.....DF......xiuhsz..7*\Yxg...S..........R........n>..:=...{y..(=......ti5j..6-....5Y,,......~A........on......UJ....9.V|........%"..`f..,=....D..........}.6CC..........YY......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{$sp.;..........}{.}{579}{0000
                                  C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1797
                                  Entropy (8bit):7.609063499638708
                                  Encrypted:false
                                  SSDEEP:48:wTQHjw3reG/R35nJFpyFw4Ad4M9/xJfAXxufzKPhfV:BHAre8R35nJbiw7pBAXQ7y
                                  MD5:4D72AF5F82E76D929F56F6043C172FCF
                                  SHA1:248D45D71FC49C94BEEAFD843E9C1D6089B92C3B
                                  SHA-256:DD2C347559C8618C2B515190B675C3C83B600C63C0834A474866A842615D814B
                                  SHA-512:7D430F885948BA821A30809215A0959890AD5AABA51B634B8734D5F47CB64B8332CD7BDAF4D1AA8B40ADC12FB0C267DD4DD2E24B6EDB43F74747DD9CB1235E67
                                  Malicious:false
                                  Preview: ...^...8n..........<.....NE..+q.,>;.KIWPejSV.........S.....4..N.....HR....$'....2....KX.............'...eu.@s2.88..6=1"..XIto........VM?nvYN....||..~~E....k|........0=zo.....z....eb..........ve......hu9zGJ......;<>* <vqQQ.......V...JY..ctlv........vi......zf..33....xx.....81GT......-0.WLA.........k^..XY;6ORH...JJ....VVkk..B^....fd....~y...WW^K.wf......PO..49......P_EH.N.%%...E.:}......DDWWll^^..?#....;9{jzaVQnd(|...].vg\A....ebMM..DD..55..dd.........3$..NT..^.......5.&4|L..0+.>,;..I..9............77..OO99vj6'vi..{wP.........-:CZ....+)..ep$)'2....vg.....Zi.+CC....YY......&&..qmo~..s=R^.<ZRggj........v.....}x9,....|clk....[....).6AA....@@......&&.....{hL[re.......}}....99BB....88YJ........~e16...,..||..xx66....$8.T........{a....NIYYCC....((DD... zs..[L....^C........E..........D..J...5!;b`x1f.@.>e..T.....KKOO........AA..#|..........KV@...WBkt-.ww.....iC..ff..EE..QQAA....0;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}M
                                  C:\ProgramData\Microsoft\Provisioning\{18dcffd4-37d6-4bc6-87e0-4266fdbb8e49}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2078
                                  Entropy (8bit):7.740929713303079
                                  Encrypted:false
                                  SSDEEP:48:s7oJPJJkTP4fUfpX05uk+LqrwzloCYAd4M9/xJfAXxuMiWR1UB8AU:soTJkTP4fUtG6urgDpBAXQM91h
                                  MD5:8068238F93D229FAA5E0E03319083865
                                  SHA1:BB80F2837C9F4302F07F02EED08693AF94A941C7
                                  SHA-256:72B1513F8E24BE6FF4807FE6EB06CD66D716B81A273AC58A5294A6C4CE31A611
                                  SHA-512:442C8910D5D650D7A42557050FA5E9E30559B16FDC2C78C0F35A56C6C519DA830A8E721E6200FC6F00FC0F5CAFF6307806E1DEB4816AB610B708C9261E1949AD
                                  Malicious:false
                                  Preview: .......H.KX.....,?......1=~s.....3x..()..........?.....DW.......w]....'/SU./....T.....l"....J...'/...<6......b,...16..$ ...........v....J..`~....ZZ...2H...........w%...........*.h8....LD...'*..Pz..;'..t|.!9......xe....;;..'4.......4UU`|=.xy..P.'8...{a..7......7..Qwdm.H......W^.......9 ...*..........bl........WK8....\..,.SB8u<;....8.../)..ML...N..//U:......?l......X..6.92..6$@...{f......JH......c><!C\................NI..yj..us....zP..AA4(.......dd.......wd..-yWzujN`....2.........,$..25......MMhh:R</......"3..oE...AA..LL..s_..EXRT..4<.....-/.....S!2......!!....HH66...1$..@g...\DC..))..((...VEOM..[N......ww....pp..nB....GA.[..EM..Vi..vT1<....4...v1I?....P@`o."....zz.......WD.......wDW}//..ll~~0,.............gg....uu........OB....v...J.7E..av.....+4..:3...F_.VLJHhyFA...........l....CR3...1j..XXAA....zi.....n....tttt!= [....inkX........>...xwG...EE....pp....^\./# .....ss.........QS....."{.u9.3..............L.....1.....~~`|~......8dg..?
                                  C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.264287746379861
                                  Encrypted:false
                                  SSDEEP:24:hrn084tFoze4ytP6qfHSgC0fNSZBzfteJTQRvgY+rDPv4W5y:PAd4M9/xJfAXxuYQhc
                                  MD5:7C8D6B81EDDBC09B92B0113D0E84FA07
                                  SHA1:12D62644EC6C0B8F584A4A58BCE9487C04BD7E97
                                  SHA-256:8B7465297079F8851C729E6E27BA4FE7218BCE381B882B6BC6A03CB645DFAA7C
                                  SHA-512:05DBA7DB3C23504E319DE08D860637A5894B447B0B2778F5C23E2E09B3E9B35F066A267EF5F761A542B39F02292C75A6EB6365197F803049667447F5E3760ED3
                                  Malicious:false
                                  Preview: ...<{..Q.2%..+4..QC....yr.............L`.w]SUR...../,6......n:.9SR....m~NP,0.....v......2!..FGdX..Z\.j}q..E5vmQl........nq..Ifqlp/{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....r.....(..5&}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):935
                                  Entropy (8bit):7.369675646349792
                                  Encrypted:false
                                  SSDEEP:24:JLeGPJZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8M13W5d:VJKAd4M9/xJfAXxunM1mD
                                  MD5:5E3B2C23412CE70836E1F6F0C210C6F7
                                  SHA1:D43923E32FB234E6DBCBAE7826A9A7587AC3C0E6
                                  SHA-256:F0EC1C65F4E02242CEA743DFBD7B6ACBFB545D791FCC11F73ACA0B3FD4A6513A
                                  SHA-512:F10BE4784DEC24A414165BFF07706E14DA95B250DE93DA331B2F793B1C5FD3EEF7520749FB900BFF49C554209952E320A0D4BA995EBC80305A9201CB6040B6E1
                                  Malicious:false
                                  Preview: ..{vu+>....ML06.~m.a....BN..5*.......).m..>1pb'4....B~......CT..UT............s_..AO.......=..Y-.....-0....uw?...ts..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......y.daU.K.=.}{.}{244}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...{{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\Prov\RunTime\0__Power_Controls.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1076
                                  Entropy (8bit):7.201203140910871
                                  Encrypted:false
                                  SSDEEP:24:E1+khLiq5g3c84tFoze4ytP6qfHSgC0fNSZBzfteJTQRnK2bBB/+/+JgW52:E1+OydAd4M9/xJfAXxueKeBGGfo
                                  MD5:49AFD23E01403CC99B99E8F7EAE7A3C8
                                  SHA1:97679C57C928D888990AD218498F4B21D24B1A3C
                                  SHA-256:83F3D5972BAA7833FF2841DA60A909FCEA072DD9C451DB51590E0CB9E4AE17A1
                                  SHA-512:3279CD39DED94E4187607721A9164BD16D442837DC8F20A99252FF0AB8F45F75D18CE94432E2FBDB857D2B887320E55414D667F74F43D18D16688CC6A49E68AB
                                  Malicious:false
                                  Preview: #w...EPQ....XBDE..c|'5..%(T_..U.@...>+....|s..:9.......ihkl9rN_.Euh............+...!=..uf..@Q.....u....U..........>">5...............$|.v$<............r-SZ+8..va.......GR..{W{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...e...PZd.0..e}{.}{359}{000048000095000095000080000111000119000101000114000095000067000111000110000116000114000111000108000115000046000112
                                  C:\ProgramData\Microsoft\Provisioning\{1e05dd5d-a022-46c5-963c-b20de341170f}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.454566617731171
                                  Encrypted:false
                                  SSDEEP:24:kgLxR9v+RIuPF/o4yfQdqT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGRWRFjUBNX:rLZ+y8dyY1Ad4M9/xJfAXxuvWR1UB8m
                                  MD5:232B5DCC9CB9C43E0492C778AE2B9B22
                                  SHA1:9C2E5799C0ED9B9390EAF240BF082905EEE570A8
                                  SHA-256:9DC793A8EC19E56E123B06CEE94763E1060DA56B6E0C628EFD518A4DA08165E2
                                  SHA-512:2DCFE69834D74B04B994DD9FDA42C3BD662E93E730DF818FDF9AA4CA7C022370778ECE4C64AB41D4F83D38236399FF459C8DFF0D00061B47E3C19395FDDDA37B
                                  Malicious:false
                                  Preview: ...BA]H.^6%....{(....*(......2-#"..'=....?TCDgl..................EY..U]....yxuzO.....}34c..,e+ ..tf..GM.. <..c-...52....$@@GR/..ys<>"L76..?v......?8..EE..[!V.}(4e.+b..++.7.C..O@...Z......cc......JG......2...w.........0........................djf...%%..f...........{H......bePPss..............SO5'..yA..<....|{..**..uz...".r('..IIee...nx...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.282800455391157
                                  Encrypted:false
                                  SSDEEP:24:j+U3KJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRReY+rDPv4W5y:iiK6Ad4M9/xJfAXxuHhc
                                  MD5:8B1FB7027FEF9D59B11342B5460239E3
                                  SHA1:E0143BE3E64540CDAD0A0D7FEFEA6BE2637A2928
                                  SHA-256:33F2E76163A9C19314CD3B368A6BE9A808D47F96F916E59B881FB044405D0136
                                  SHA-512:2E40B97F98B7E7053B76512540F1C4FBB38AF68D4171F292F3A872BEE55C9FF8A9F318A2E43037231C96D05527857EF2088B6259056DC18154601698F7F75DEB
                                  Malicious:false
                                  Preview: ...u......KQ.....r`........UM. 2........&.W_..(/RG....nt..cJ..+.......f5L_....34XX..xy.............+-....K.....uw&.......HgMP${{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..iC6.....L....}}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):938
                                  Entropy (8bit):7.396264363718458
                                  Encrypted:false
                                  SSDEEP:24:WqUzv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYFyV3W5/s:BUzkAd4M9/xJfAXxuNamhs
                                  MD5:4ABD20555C0BF0F83D413E61D47565EF
                                  SHA1:630457F2AE3C8ACE96FDA4B92BB0747F2FC364CF
                                  SHA-256:FD2F13EB2AD94E3C9D19706EC66CDF48CFB7B496E83FBBC9347B03CF43D7B76A
                                  SHA-512:7D53774758304284961B3D7372CCD3AD3872F61447DCBE1AEE82BF4E03B364E83D55986C66512DA818E3C5795BB10ED345CA6F0A1EA784C4B0F818ACCF519E02
                                  Malicious:false
                                  Preview: ...;....]J..XY........@K07..}*m.&3..$..>gK.&....i|WQ..a{...Ar.....ev$:..... _..,#....c~....L.aLj...y{........it.'O{..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..G..K...N.x.3.`}{.}{251}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...~{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2532
                                  Entropy (8bit):7.766457098209389
                                  Encrypted:false
                                  SSDEEP:48:eNx+81V6lUiyCyDWt7cZ7D9YBjsyKFAd4M9/xJfAXxuHJWKPhfh:qxDGIBEI7DOjbpBAXQou
                                  MD5:ED65B5846EC9EFC5F39E7AE80D0B6A83
                                  SHA1:8B1FE2D469B669C6D88A08FA80E988018B74F5B6
                                  SHA-256:874836ADAC1D0451128CD1C2EA97CF870BFA1420B603690E0931BE2AAE841095
                                  SHA-512:983FBA3F430C13D26F9B11C47C5791524F9776A660A0EF0432DD0F22CB79DEEFDF83C560BE52A55AF44F424325827C9622A564D9AEA9D572D73CC8348B47A655
                                  Malicious:false
                                  Preview: 4../,..g+..<=...e{~|.......5*..G...x+zo....TUX....[F..Oyi.;fNL......RU..HC..vq...'.PC....`z..f%zw..UJ..........__..\U.......*7...)<..;.;)....8...++......TVTE......w#*#..&T..6<.../J`..DD--..t.{hKI.............0!..zs...;kA......::....^M.........."v....~...........{{..........A..............fk-8...........NO....../..!..AA..77........57...y~`j.......5<N.<<? ..........`o...H.....>j8l.............))....',.......ST.."v....|.....) (4..""..........>>....4k....VA..tn.......GX............d`)#ml_C....AA......II....[[AA.YVE.69`h......ul....................tszk64.....gM....qq33kk..bbrr*6....\.59X.L*.1......#4..k3.......)<NG..G.e..]Jb`........bb..**....FF77...!2KI......xr....==))..........ee..ib..UW............P.wUQ......g1....GG....99..kk..zz88..teMR.......oZID..><..>'5mnyBO....SF}pMX......~|.....@@....&&tt......]].........3k..-.........>'...."%..RW..WZ3&..cd..fd........~~##....||FF....!=.+"..tc..xb..M.....66..99>>QQ..XXGG.Ibko|..l{....`#v{i|..cN...<GOD^...'.
                                  C:\ProgramData\Microsoft\Provisioning\{23cb517f-5073-4e96-a202-7fe6122a2271}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2484
                                  Entropy (8bit):7.7710877709588395
                                  Encrypted:false
                                  SSDEEP:48:dciBCGaIZFguIL3T4eo/wt0hVIpB8dgtLYIewjdeAd4M9/xJfAXxujWR1UB8D:SGH/gXLsv2LY+pBAXQ21B
                                  MD5:5C982D404D328C40C6B1C9F17AC07410
                                  SHA1:260212C71341E3369A364A06C01F05A907D25A8C
                                  SHA-256:81362B27D2269AF0047C76A3C48506D40D1FDF1DA99C31336157361E3143E594
                                  SHA-512:3120F4F7D81F2868DAC628D03CAB45F18A4AD010EC1DCB6E99E1F36439F09025DC88B7273336082F7AA97A7522913B3BBBEAA69BF87F170AFC1BE500C20BD675
                                  Malicious:false
                                  Preview: cEAba....."#........FM..6;......?t..]\...}......zL....JY@Uce...............;:.pj-..-/.\.....EN..L^....0-a}..O...o.DC..15H,...GE......edXW.K.R\B=!EB..TT..d.......PTQ..`y......EG..NM....;h....}n....+......6XP..............}P..EH...`ln5.............~`o|..UT...M.....................b~..............,+..oo........6K......^^ww......OM.`..[MJyAk...NLQ[.....CM.....4.bbho...hi......h<...q}G.73....*#d=......PZ]E....ip....2;)5....VV.....~z.......J61..GG..@(n}....]nbH..;;....@u..HY,E..n@../%...........VV??soN{....,.ep...<<....VV..>>...KF......s.-u?\..{:.n....? ........**uu....\@*Q.=206.YLM\,..U............OM..II....'...RC.G.........m~..kq'.......KKWK.3......QDFu.:..__((ggIU. ......Q.....q_..'.ho@H....x...ZZ..}}..h].....:........dd.2.)``LK..."}Wff..66ssye...C.....GG..rr..........~9ni{{>>........^^.y....fo...ss....--....((@@....a}...?..................hX........hiV[..w0..uubb....22UU............I].............EZuV............,,..%%99......KKWWrrH'....YPFu.:.._
                                  C:\ProgramData\Microsoft\Provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.286893020646666
                                  Encrypted:false
                                  SSDEEP:24:Cej684tFoze4ytP6qfHSgC0fNSZBzfteJTQRrYCY+rDPv4W5y:nLAd4M9/xJfAXxulGhc
                                  MD5:7B9A95BCAD6E9F4712549B222328FBEC
                                  SHA1:60840145969F1A085402919DBEB666CB570B4BE0
                                  SHA-256:F8142568BB47999F6D5F06E8CA314E6319A832AB881F396F32CF9B700AC6DB20
                                  SHA-512:BA89530C2630DDF3324E02A4926C2249025528CBB34450124C10CFBD40AB9BA9CBCFEB8068E862789BFFF203BB105ABD834B2F09288F9A61654B7AB9A6CD8177
                                  Malicious:false
                                  Preview: a5>.....fq+1KJ.................lyPM..........zo........5...y-......Y.......RU...{..,#bp..pm...`g..{...8`....+%-@B......jf$.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...3x........}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1027
                                  Entropy (8bit):7.474170602122376
                                  Encrypted:false
                                  SSDEEP:24:NDfsjezs3rh84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfH13W5ZT:NDfs7OAd4M9/xJfAXxummjT
                                  MD5:581233A346C3806CCD56C3B1D1F52B3D
                                  SHA1:2BB8BCA742E5761D74589750ADA750EDBB761BED
                                  SHA-256:318908489BA3E9DEFB97AC52F4A1EC1A73EBD4D3F25555DBE4257E6C8A6DFE5C
                                  SHA-512:B768CC7C026C0C69E40BF4BAF125480C6F356A1D905AC0ED3831EDEB1AE8C2500B7ECDA77DDBE44E7DD01C8C1C33AF177ED73DF220382F25AFE7FBD04126E5FB
                                  Malicious:false
                                  Preview: .,(JI..f*_L#"...M|oku..4?manc=4..,-....no%".a.......xe......CE.l{..xyqnTK"0..`J...>........pM..`.....)4EK..$&.................{*bdHS..0c...yl..24VI..........yn>Z..O...........5.bXtpd]s.......X[........O{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.U./.N&O#?T.6..}{.}{428}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWb
                                  C:\ProgramData\Microsoft\Provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1352
                                  Entropy (8bit):7.43742713273277
                                  Encrypted:false
                                  SSDEEP:24:obpwPlQJjffZa2ByxVxGrd84tFoze4ytP6qfHSgC0fNSZBzfteJTQREFK2QG+JgO:olUaTox0OAd4M9/xJfAXxudKPhff
                                  MD5:DF3744AC344FE23D40AE4B123ED9102E
                                  SHA1:1F5479A33EA63A2E44247D290E1B5A853148872F
                                  SHA-256:DD448B471867D2E8ED66E44BAA980FBFBB09E8A4023A4BCE4C73796A473261B3
                                  SHA-512:C9CE85E69B1A027CFB20926A556396CEC45E8B77C0C58E63F69BA34D3303E0543D9D8447D699A72F69A48DA9B4F89432F5FF6608A5572917B1B37EAB5B7957C3
                                  Malicious:false
                                  Preview: I.T.4s..1g 7}g..........,!........._J...."-........NR.......4%...hw`z......).W}...YJcaPA.......HA.........Lfgg............ '..8l..........qv.......Q]T..7 h.../2.m......0.hmNT..]Z``11....^.....GP..HR^C.JG 5.1m[..........5577.......A?6..I^fq..ns......(;}q.................FFTT.SNG......lvRO...\IHW..+&....,-..ZW#>......[[..........>"....ZXl}F]........90D.QQ....JG..N...JETY.V.aa.......IkXrX.......11..dd....XK......HO^T<h..1i.~..vk.......ll..qq,,00{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...
                                  C:\ProgramData\Microsoft\Provisioning\{268c43e1-aa2b-4036-86ef-8cda98a0c2fe}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1671
                                  Entropy (8bit):7.630856317863664
                                  Encrypted:false
                                  SSDEEP:48:c/Pti4ouL0a9xMNF7OzsH7Ad4M9/xJfAXxuaWR1UB81:cHtdoO0aHo5ipBAXQV1z
                                  MD5:F265924961BCAC972EABB17B39D67A35
                                  SHA1:150CC7D31712EDC1543E94D0561DF5F16CA67B7F
                                  SHA-256:8E39CE22CE129A24C886D9D1DDDD6E4D546255D472AED9F9515E19BA43D1277A
                                  SHA-512:F5D260DD185D26E83120EBB6CAEEB6A648DA626BF532FEDA25DB192033BB059961D5FE69584EA260A08A9500FF9ADA013CFB6C3B65DA9240A92F9EFF9D0B8C7D
                                  Malicious:false
                                  Preview: ..5r..8n..kq..5*7(8*Q...`k..<f.....5(.....:0........-)xc4)..q<oh""M!`b82fd....86..MP..VQ.K......?aIm..kw.....<......V..n...IA..8p&.3;IG[...EW.(.....WZ....pw...Z..S.gc$!~k..h#.jo...g6.....}.........>....@@v..vq..B<........R..@L....ll....ox^Ded..6(XKN}..agh8..QQ..3@..>)......~t......h{.......%~..``..>P..i<AM.S2=j?....qq..FP...m......lp+T..oe.......Ufq[..(...CD...R..3.XG(/N.......V.....qx......3-..TL..AC<%~d:<..`i........8G.....9"..........NN....tv..!...LLAA..A]..SF...h....#.....xYAL~o..kl..:&jm((&&((QQ..3[..<>......).......tt..........,1.........\N>.GJ....pO..$c..49..........(.))..))aa..B9..........1. ...............du..`u+p......66tt66.............s..mAY9.~BYL81...1..HJ...........^Y..\\....{{...:........,wbe..OO""......EP..........(4..JY@B@G).@j66..:&l[....../(vv......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l.
                                  C:\ProgramData\Microsoft\Provisioning\{33d78dbc-3db7-4398-8533-000d7c02e5d1}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.2647385331229275
                                  Encrypted:false
                                  SSDEEP:24:QH5BTcLGb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAwY+rDPv4W5y:QH5BTFgAd4M9/xJfAXxudghc
                                  MD5:A1CED4C50C33D9546887AA4213680482
                                  SHA1:4179D5CBADCE91393E6748BC154659A22535F642
                                  SHA-256:2BCE8890D5547340DAC92FA093E6BF40B7A0AA951379DA8B20B1E92577F65B56
                                  SHA-512:288AF0A60114E5B5DCC723A75B88817C7D726101BF558E28CDBB8BF6B5CA873207F6F333F5D58EE2DE1203716352C6A4CD7FBC6D870855DC54E70B466DFA1374
                                  Malicious:false
                                  Preview: Z..v+l..3e..!;........9|......`:...........hD......6#db....DU..-7..5.54...8+..iuTSPPZ%..........`a..^Y][..zvY..kazgZ?7.._n.cPO.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.[(W.$.r...=....}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{33d78dbc-3db7-4398-8533-000d7c02e5d1}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):938
                                  Entropy (8bit):7.388238589836864
                                  Encrypted:false
                                  SSDEEP:24:S7SGNitQH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfj3W5/s:SjkycAd4M9/xJfAXxu0mhs
                                  MD5:2C5915BF150F8B11F6E49ACC867E8700
                                  SHA1:43D31CB854173BBD50F433AAD2E99945AA2CC22C
                                  SHA-256:F43FB9B7AC341F0E9603ECEDAD4F3E753301BA31188C8605B7D1B0CD00B43ECA
                                  SHA-512:F9B77C45A521E0C6F0948D950970E0741B63DF56D3CB92123A9400C61420CFCEAE31EAA396646CB5DC28C6B84B9151918B9FC7F7BA92D6AC72456ACECF8C7190
                                  Malicious:false
                                  Preview: ...aK......tn........0u.......GZ.......Gt....*"MC..MX...%........lj.I.....RU......>1....1,?>.................N....EX\U..NS{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.c.,.....b.P+Bv.}{.}{251}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...~{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{33d78dbc-3db7-4398-8533-000d7c02e5d1}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1317
                                  Entropy (8bit):7.45818376431341
                                  Encrypted:false
                                  SSDEEP:24:8645L9l68SSAW5wsGy884tFoze4ytP6qfHSgC0fNSZBzfteJTQRhK2QG+JgW50:8vLvSNo9Ad4M9/xJfAXxuQKPhfu
                                  MD5:A4ED7340312587DB41B41C95F7E1AB06
                                  SHA1:49528AC3004D5B76B6D7D2349622A34864DDF4BD
                                  SHA-256:DAAF30D5155AF042E8F5712FA67387FED77C95C92E3A890F600133497914EE25
                                  SHA-512:88876715A629AA3414CDFCD2D2E356AC99D83025E9027CCF577D99C407370D7B7CA666F68C436FF252EB9A5ECB941A25C281973975F1EFF1B515BCE085172CB3
                                  Malicious:false
                                  Preview: .*...-8+g->32,*....;%....($..w~NQSR._.4>m..j`..?>....h~.....%3x%WU..xb..mj....R.ST\\.......@W<&..R........8-..in++TT....%6(?...........hw....&v}NIcdd++....):!#..SHEBdnI.+"u-...:06m....uu,,..TH..</kiN_..$#............{rc2..=.''.............gv....>4...&~......zP....A]EB""..VV....33q.............0s..+>~a:...xp.%wvfg..c8....``..''....``......WUj{............UD;2.OllD[....cz.V.........C..GC#w...Gt)...11..aa--ZZ..th..ev....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s..
                                  C:\ProgramData\Microsoft\Provisioning\{33d78dbc-3db7-4398-8533-000d7c02e5d1}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1575
                                  Entropy (8bit):7.598597464085505
                                  Encrypted:false
                                  SSDEEP:48:lxcWYeX6PDE4QctI0J8Ad4M9/xJfAXxus8WR1UB8W:3RYeX6rHtI0JHpBAXQa1s
                                  MD5:CCB8372D952A41C96A36BB915DA11DF8
                                  SHA1:B54BB8E5A88F3416233B772AAD60D9ACD764C308
                                  SHA-256:A8518F0D47DC2CEACD53770B3E15321BADB4B4FD234BD0D67D505EB1DB33E23D
                                  SHA-512:F92B32309DAAF6477528E1BA695E6EE11CA8759C220A3E9DD855CBE954B8EB690AE6DFC490C0D9025B9310388ADD967CB11A5933340EAA803D00A4800BDD7B20
                                  Malicious:false
                                  Preview: X.6....Wqf'=......VD........D...........Rd....ay......,(..%8DEW.CD00;W.......4..p~..~......t ..Q\...4...wk...\;7-z..LF{c.........HN......a90/..[hZpAA~bty.....TBC..........06....|(.JLN.R.....k....!!....l7..TFo3K}....PDz.yrPE.#...............EY3.....9i..OCc...a{\]..........?4....j1........Ld.......'2..6.00..........%.HM.%....JV.^...C..#.n.x5ruTT....../.JKzu.9>..=R......-~......">..;0.....?PZ..4(...]DF.............cy...........so2......j.qw.....+.....~K.....wp........r......E../0(...u_......07.......uu....vt`GDQ 1..T~..]]..LLCC......(5"$..nA....%.XZ...................YY..cp..?*L].=..h325""....[[...<i|..CpDn..zz5)....*(..KxpZ..zz)5...|s....BB.......M^......u8;<......00qq.ara....ABI B.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F
                                  C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.256614259082154
                                  Encrypted:false
                                  SSDEEP:24:V8E+4o84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAzY+rDPv4W5y:N+45Ad4M9/xJfAXxuthc
                                  MD5:19B244E151F428A1F3649B74A1DC4026
                                  SHA1:D19B53EE2ECC1F8593AB643AFCB36BB416A0DE84
                                  SHA-256:36D7DD5C9D0D65CA90042E5D28DB1E0D7302E927678C716CD53ACA81A22003A5
                                  SHA-512:1C0F12928BB2A21E971DE46A38EEFBF902C0C75B71EE20F829D8A4CF80C2393BB1AE7FB081A74071DFB244434C62F42F6BD1C75EDA924313B7CBA550C81A899C
                                  Malicious:false
                                  Preview: C......Q.SDNT..TK..5'.]:7..\[...@RVC..xKbT...........!....FoCY..'........x.vv.YX..PBh{jw... 34..*DNB.....#...fdkZIU..DH.=....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{&-Gt.I...=......}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1112
                                  Entropy (8bit):7.5208818849310655
                                  Encrypted:false
                                  SSDEEP:24:VJdEtwV6OuGqL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRnD3W51:tEtxGqQAd4M9/xJfAXxumDmX
                                  MD5:89DE5FCDCBEFBB4877C727FA569D2CC7
                                  SHA1:2A4A75C3FDED688D58E4C9E761061C550C53E55B
                                  SHA-256:AFE41D0E2F34EB07C75A0B1C55EBA8580B7F275258F8D950F82FC4D63FAD6DA4
                                  SHA-512:BE98A9304E3F41C75442511BDCF8B3BACF144713BCADFBBA3542E94B76DECF1A65CC731033A522B167A1AEB2D75E7103608BC481FC405F8518152706EAA21901
                                  Malicious:false
                                  Preview: P..K.bc._8/..........PEH..LK....&3.....%.GO..Y^...."......B..-,....JY..MQHOgg_ QP....h{.......dI......7wbv8...<!........"=....vl_]...;g....';...|{...U..z_1$mr^R..F[....YB-...9UKK....V{....hr..|a=3....P~qS..pc..,.-.....AI....5 24.........T.......|JJJ..bvn[3)...zz.....5..U.....5 ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{V_..%k.K/g}4.m}{.}
                                  C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1798
                                  Entropy (8bit):7.62487832571905
                                  Encrypted:false
                                  SSDEEP:48:NHqK/jat6w8jCG+moKXD03BLAd4M9/xJfAXxuZKPhfjaZ:NHqK/2Iw/G/oKXdpBAXQZIs
                                  MD5:2A0CD76714F85F47E2016C61975D800D
                                  SHA1:DF8EE6FE38C2990C937ADD50AC7F51BE9DF4D726
                                  SHA-256:E77DDB012380C4D62841A38177D01011EB6065F344F8887376E959685004C4D9
                                  SHA-512:E42AB02E20BD6A6D5B99F207E46B716C111F00DFE11B6B407A91BC9DF039A49A606C655E0CFCEDA23A738E7930165D9C97C4654E2798E8A046915504F341CCA2
                                  Malicious:false
                                  Preview: .8<sp=(.:):;.....`b0;?3ty........\F5f..w}....7o....xe<......Q....f`cd....0m....`?%,}n6!RE[A.....,9....qd......((_.81..#4...................).........lgQB....(/....+s}.30eo:a...*..""..........)2.....md.C..SB..18N.@s........ee....(;rp.......B..u-......pw??..{{..BB...Kmd....SDkq............/'..kj+*......DwnDHH**..<<..YY......QSN_..inlf....!y....O.zz.............Si:..-)..X.y>;.rXcc++......##..........1*.....LxqV..b....HA1-..ee..ss..............+8............7"......8>........?#......FF..,,mm..66.........|t..jH....[.....yi....r`.^........Vyc....}.....++...]]``II""..DDPPK......^V...%zMMT.......IOEW.Q......A.2y.....20......00..vv77}}..ii....ne..AC...}z;1Kx4.......jj........y5BK........JW...++......pp....?,..%6fd......bh.>cIRR..OO..aa....IZ.......bh.... x.....b`.]*w..JS..MV..M@..9j76...M...dW......~~..}}..[[.......,..`{34........~oyd7>-1`gOO....ppss.......O...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}
                                  C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\Prov\RunTime\1__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2040
                                  Entropy (8bit):7.680659722475138
                                  Encrypted:false
                                  SSDEEP:48:9gJAA0SZQ9kj6PtrcubS4NSjvxScAd4M9/xJfAXxuWkPPhfH:9eAA0d9kj6Pau7SVwpBAXQWkh
                                  MD5:BF77057155F94E99D60C0B1A1010612C
                                  SHA1:D505611533BEB64084F30E649D1320CC37C59FDF
                                  SHA-256:E18FAC93737DD69C1E7E8E07A7B3917BABC2EF42ECC81FDD946B6529C9790705
                                  SHA-512:B4C79541AD56E854CE94836E6A4F3E60279FEE502BEC56EDD31BA5E61ABE669BBED4F2D2ADC2F6606709680B1A0578D489790D64A3BCE2690EA110A2BDB6A9DC
                                  Malicious:false
                                  Preview: V?;.....3 ........wi..}vCO..le.....C..l?.........v.......h^..|!......qw......?b.....[7>........VK..ID....................lCT}j......:71$..../........QZ......3(KL..W.LE.E......].....00PPWW6*..GT........mg?k.. x.n'6@].....%.........zf...............SZI...3:EP\@............&&.Lsz........)4a"XU 5`..!......FG..85....kX....$$....YY..0;S@LN..az..!uU\T..........m==0NW.......Q.F......r&j-......^^..uu......EY...........J@G..'.T..zk,1......--..........aa..TT0o........TI....4!.....ZF......&,$%NR34HH..ii....ooII....$$?s.................9obo....ml..dvD..j`ui`\.`+..31....'6..ff44....kk..pp..EE....6%1|.!..ez.......8K.......qp..VD...|iV_.J.^G]20..\^bscdkk..^^..66++....~~..,'...VG..eb..}N..YY22..bb....................X_;1...d<......#.......g`hh....**..pp........................C...............'..5~..wu....%"....>>.......**..RR2~%6:w..............E...?/.........}t...QKom..@B..G@......<<..ddwwNN......QB......JM`jPc.9........55......s`..YN........UU......ttff....29...
                                  C:\ProgramData\Microsoft\Provisioning\{3742e5e8-6d9d-473b-99a6-8ecc0f43548a}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3066
                                  Entropy (8bit):7.845764964419439
                                  Encrypted:false
                                  SSDEEP:48:0uQMUR8cUvXyr3CBNjgXPxN8tt7vsBN51JvV3WM7M4sRD035PkJwYAd4M9/xJfAv:7UYvsfxett7vsntNl7cR43htpBAXQa1x
                                  MD5:77E5FB4982FF1F001E8D31CF3EC71C76
                                  SHA1:6B2B1B4A88CB388D66689DD9BA00603BC82BFED3
                                  SHA-256:8BB6548D3D2F54FD2C9B2A3BBD753CD8D5CEBF76D628AA0987A781C0C88248F3
                                  SHA-512:CD3D0E31811F155B1DD3804D8C214D4E03BAC7E5BFB49D555EA6400E5A268297D0E53AD4ACAEDF399C4FBB95986772F9B05D6BFF8C5FAE2B4412E4BBE8098024
                                  Malicious:false
                                  Preview: .pt....U.uf10CE..h{\B....R^JGcj......ou....H#..t.........TG..F@.3.<....{J......@.\I)+...uiW................8:.......ts9D....ca.wrs..x1)nxf(4..ii..H=O5..........[....'#.W,,..'271.y+..L@..6%YT....ee..%...a.iq.......zs/r.,.................CY..YV..?,.=..& P.in........BU..SF.fv|..&:....bZrykMOF7lBE..KK2\mb.D..H5...ILK''..d.....OM...........k...ysIK....s}iZ.....4......x ;:C^....K......._[^OUI..........}e_.`b..si........Y^||...Q..qj..6-..srR.PW...kk..dw......!....ww..xM^KwfC*..}...Fv....Y..7!...HH....UI.+........J..FF......^^...s.......i....._<2.].\*@M!1........Zp((..MMmm......9;..@Uo~!.Ys..HH..so;@....l&..uu.......uS@_]..iDze..7.'.......>.....WF.....MQJM......<<...iz..uRj...cP..yy....~~....Hd7=...(w9....ezp^..MO..{b..{x.....5@jee..........oC....KM.]....qn.....]..SAb.=......c....op..`o..__........F=....(...]L]n~T%%......9%-.wb..g@../t..VV....................bn.....7v..!1........CD..ff....))..i.76..KV....fjV......qMH]..EZ.............57....KKuuaa..->Xm..J
                                  C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.262456310129973
                                  Encrypted:false
                                  SSDEEP:24:iKX8a/pw84tFoze4ytP6qfHSgC0fNSZBzfteJTQReKAY+rDPv4W5y:iclAd4M9/xJfAXxuxRhc
                                  MD5:914FDE1BC044CDE3B4835991FB0F2356
                                  SHA1:3DB5228D4F19EC9794396C04E754D92D5DBD0367
                                  SHA-256:088D418E613E46A29FD12F73B2BF066494C5A214AD49AFFD65509F65C06EB019
                                  SHA-512:DF430FD3767B19CBF2F6626C24AED070538528D04DE025DC5B49C6F33D1FD8860AB833AB2261E1B47772A681D9283B4BA6A2B53FF6368A5586B970C5F06BCCFE
                                  Malicious:false
                                  Preview: ..@.L....W..: ....[D...M -en34_..B<.rg..<...9.....UR|iqwlQ...?........yxMK_...jt]A?8ff...YV.m....=<.........|$......pr:...-2BN.)....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...F..e...?.$. .}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):938
                                  Entropy (8bit):7.4045191944329165
                                  Encrypted:false
                                  SSDEEP:24:uYucRW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaT3W5/s:uYVRLAd4M9/xJfAXxujmhs
                                  MD5:587D52A5293B9F9E79B6B8E27036A8BE
                                  SHA1:C5CA8F8A86C3B9053096F7D8FC03447D2C90E5D7
                                  SHA-256:ED3704F3E77A29F12FC51D23ABA201A9C322C3F1B0A496EEEBCE762F69407893
                                  SHA-512:72266AB6DB74B30CD3F77EEFF6FE52B98FBD24ECFCF962B6963CD7CBACCC86CA4E6273D23861D11EBF562F97161863B794AD677FC34FA87D4A435DD8A33E12CD
                                  Malicious:false
                                  Preview: .m.[....@ds......*5..D.bo;0%"T....QD..QbUcOc7?..x........7&n+..tu../|..KU../(..........mp..b6.!{nIVik?&..O............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{!.yH.w.M..a..4[}{.}{251}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...~{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2540
                                  Entropy (8bit):7.747847393838103
                                  Encrypted:false
                                  SSDEEP:48:ifSuX076CVTewQZh35VvC1QlrR72X8bTfvxDAd4M9/xJfAXxumkKPhfp:VRGCBewQr5YuzDTXx6pBAXQmkm
                                  MD5:C68F9D81D04C94D6F5229725E03789F9
                                  SHA1:3B42F405255FF118663EEC94D6F9E5D517005502
                                  SHA-256:F27C7E99447BBE157C236E51BEEB75634EA6C4BFBC7CEC57C8AFA326C15549CE
                                  SHA-512:1C8BCC514B650528BD65CCC091F2E99AA3982C30D5369F599700C55D7692A647B6DE71D4F155D636CEF41BFFFD1DFF7CBC79D59EA19F28AF2A9C2AED3F33BC3E
                                  Malicious:false
                                  Preview: 8........}nVW....N]@^MO..R^......UT....A...("....^y"....5.bTGQ...CZ..QW..md29X......le..l{0'....?|......}s..so..^^....BK........%8-nHE...........8.............bsjq25..i=.._............ZZ..........|mYBru..U.md.].bsJW........==...**=!EN8+..:+......N.JC+s@ )<^O..?#.........<<77....L_..UB..nsw4....ktjZncem.!}|.......|V<<.......EE....... 1..52..q%i`u-....9oii...W..nw..dy.....N............=.%......oo::))........mo.?lwin....SZ..........2fa''.......vvkkCC/p..........TIh+.#4!.....'-85..66NY......!=....XX...qq..OO))cc++....-`..]U+4..xO.....U..m}..TD..N[....c;;p....j}wu..%"....gg........pp............<#y^..Y@<{........]...QD...^^...MO......EB....!!...................BY%"........KK..........!!!=7<fuPR....CD..._.....|!9.............dc..99!!...................Vzu]U.........n8di^N..|h..`uEP..1i.Xa{.............oo............../c(;..o`bj....gP..%b?i...... 4.T..K^=4.<w....NY\^....!!..33.............\W..QS........Tg........<<^^!!.....RY....@Q..FA..B.I@s+.#5.......NY.
                                  C:\ProgramData\Microsoft\Provisioning\{7a30a9be-737f-47a1-a541-6e7b0761ed19}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2514
                                  Entropy (8bit):7.783565669597722
                                  Encrypted:false
                                  SSDEEP:48:akcZvWbQ7r849pCnqvkVBBQlHsWoTbXBXdpekfiPAd4M9/xJfAXxuefWR1UB81:akcZ4Q7j9gnawBBQGWgbfpuOpBAXQeCh
                                  MD5:D27B2F3489364D3A4FA21BAAA4D13162
                                  SHA1:81CD6E7D9D281FFA4F4C4952F45034CFB1B1E381
                                  SHA-256:E43F98523352389AE2551F8ABF2B959AE52100DFFA45613323A0CCCE5B64F536
                                  SHA-512:A9C9E645018D23A9AD29CCA03ABE85A11FDB61952AB5464D50CF66F9CA8B9EFA440E829741F02C86D70667B8DDD1E7330881197D7093ABF1A08D47BF39646990
                                  Malicious:false
                                  Preview: 351....~2..CB...N..6(..$/........S.....8?....92......%'....17..=.eO.........>.........._.....<4........>,$j...e>9yr..[?G@.........q..#,..........kk.c.~.G..^.....9h..<j.....ir...45..E.....4.....,0.....C[3$.......@.sP..ub..6W...F..cc....VA..PQ....9*]nz{...Dqv..........ZOz.......5'~m'.7<..................ZU..52..55.\..CUkix...LZ.4..IUC<-/..OM..........DX..VV61vb.23......z.1!....V...*;....C..........R.....d~06..MD..fa..cc5J........RO...\[..BB..`sJH...0........KW.!......#z../.....;*.J......GGjj....U@xiQvxmG...CC!!....uu%%..:;cn..^_7Y...+HmC....................oo../3.....^yh}....8.77}}::......../ez}2255..(;h].........RR....</h`..Xk..ee.......6....:......>qq..((~~..RgDQ..}Jp6........mj`hDF>/..!!//......................FF..6.]].....!Ak......mmDX%...(d..........nn..O#JI...^YDD++.....................HH77...........ATDU.........ZZ.......}}...$]P..'.......or............EEhh....JJ..QRDP....YR......JX....0=kf32..:=dd........UUEE............../.zP...
                                  C:\ProgramData\Microsoft\Provisioning\{8d196d7f-3eef-48ad-8bea-be749f12d3ad}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.270670320676479
                                  Encrypted:false
                                  SSDEEP:24:h0gw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsNxY+rDPv4W5y:hxhAd4M9/xJfAXxuNNDhc
                                  MD5:CA2AFDDFCF4CD9DAFFAA1EF8DD8DAF70
                                  SHA1:447E3C15D93953CB99F2E6E4E4B47C2F63BC7E67
                                  SHA-256:E0CE1D117DE8AF081F32EBF6B782A7E407E2E2A11DDFDEF4A9E86215A5139FB5
                                  SHA-512:A4777FC0E5C5A0931CB9B28B616146B9BF63FBB7C8FD9DF8377C370EFBBF5561977F5A8A4483719A8D1B812B96A17411003711CC9F0B84E9331F21A6DBB09442
                                  Malicious:false
                                  Preview: ].<...vw:l....3,...Y...mfFAj0.O..:/.."...]q../!]Z.. &[f..ZK.....PxKpq...):....JM...................71.tuy..<L...*.....6a}......|a..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...."f.L%....94}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{8d196d7f-3eef-48ad-8bea-be749f12d3ad}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):942
                                  Entropy (8bit):7.396368631423441
                                  Encrypted:false
                                  SSDEEP:24:FzWLTBP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRbHf3W5Q:FzW3WAd4M9/xJfAXxu4/mO
                                  MD5:5F3DEA550A5D63AB53B553E18C447C8C
                                  SHA1:71700D596342E133EC963AEA43AC096EA095C402
                                  SHA-256:FDEC9D2B663646529E593360B7D2B3767EE32DB7164D21FA48EA86D41E4A5E4D
                                  SHA-512:CEA49A7B1EEA29FDBFE8EB024DDCD0A71CF48E98B83D542A98F6130B48ECE206AACDC7C445DDD66BA6D665E3060C03BB416D84A3E1029CC34719E00C5BA0372A
                                  Malicious:false
                                  Preview: ..aO.01P.H_..BC..ze*8k.ty...........-.Oy..+#....LY...8.....F......;h(;VH..X_..3LGF2=.m:)..........xg.......[C0`q.....=?"..XG{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{c.im.;.hPZ.d..F.}{.}{258}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{8d196d7f-3eef-48ad-8bea-be749f12d3ad}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.032547255763964
                                  Encrypted:false
                                  SSDEEP:24:4sHDaItSk5hZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdK2bKXO+jUBtwFp+JgW8:4U/hKAd4M9/xJfAXxusKFxUByF0f8
                                  MD5:B0B9786ED4CD77E2E809B66FAE31C6B9
                                  SHA1:346D7B671F8BBE8D7183D9FA69D10C00ED0E60FF
                                  SHA-256:242AB4F44D3C64D7B8FF41D324706652EC17F984C0BE3EEBFD5A5FBCB1CD213D
                                  SHA-512:6B21A34C37016616466F13CC653342F462B23E9CF1597EA7B89023F244FD7FAC8B98A3058AACD348EB9D47277D7FD45687AB089A0B0C07AA66CF6955BDEE0FDF
                                  Malicious:false
                                  Preview: Q..}...~.xl{........-?....OD..P....{n..@GVYy|....KT..?n.. '.A..B................1......):.}...OHu......\3..H,#...ff......nl......^.mdo7......HO..PP.......QF..rh..0s.............<..CO..ON#...{pxdDC........a>............e&....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...<itb..p..[}{.}{463}{00004800009500009500008000011100011900010100011400009500006900
                                  C:\ProgramData\Microsoft\Provisioning\{8d196d7f-3eef-48ad-8bea-be749f12d3ad}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1277
                                  Entropy (8bit):7.5018627054278975
                                  Encrypted:false
                                  SSDEEP:24:peixgZQx82VLAF+30A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmCWRFjUBNW5y:pe6gSx82BAc3WAd4M9/xJfAXxuzCWR1e
                                  MD5:32AAAA069562C4795950A1599D29DE75
                                  SHA1:1CB002F6179EE12D259859C61A93CF22B81C6E68
                                  SHA-256:BA94B5576AADAC90BDC959AF6722A958CC4044FC71BBA927D12255A582DBCBF2
                                  SHA-512:2E4D12805F50F6D295C7FFA4EACFC26E37D6F236D5B97AC4979BDFB177429E3D1BF3F5656047E67C0013B6331FD8FFFA81BD62EEE67BD2BADF09ADF1520FCB74
                                  Malicious:false
                                  Preview: ........|oz{\ZQ.......|w....;$..t?..../(_4....AE.$......dqpv1,...?#hY........KD.V..rp\...........dv/O#)..';.....z...")..E!..@=....57O!.....T.........ii...$g..!....UV....l6...a....q&..0b.._L....Pz..IU?.........-Fjawb...).....OdSZ*-O.......G...C\ 5..m?..EI>eKL**..b... :....~`.....%#..wp..MM..5,..r_..B1..LQLP.....+..Ce..7l....vv)G69...........................*......j'%..}.:.......Nd}a..eeMJ.....a|.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{
                                  C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.288778059105463
                                  Encrypted:false
                                  SSDEEP:24:CgzzSz84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhY+rDPv4W5y:Cg/S4Ad4M9/xJfAXxukhc
                                  MD5:C3194773F6DC1236C710B7489CD50C8E
                                  SHA1:3CF211E9CF512F7546B7C5BCEF04883D3163DABF
                                  SHA-256:BD47E4813F0B1204A954D96EA8DFDE367CC95ABF83E85311C276426E9DB6E551
                                  SHA-512:D84F87B520682F2AAFCE29693ECD10414378B0E4E0C195D6495EDDEDFD2021F4FC4FC8AC688432B6FB21B190A9955AFB3D08CE36B2B6605F6AAA8731FAB1946D
                                  Malicious:false
                                  Preview: ...e...h>K\SION..5*|nl)\Q......b5..........6...#-..........q`..lv...jk..>mQB\B....WW..tu;4........X_,*..-!.t.PK..........ktei......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{[.w..J..,U..'..(}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):942
                                  Entropy (8bit):7.408108868330486
                                  Encrypted:false
                                  SSDEEP:24:SWhc184tFoze4ytP6qfHSgC0fNSZBzfteJTQR2e3W5Q:jcGAd4M9/xJfAXxuPemO
                                  MD5:1B8FC75D58E007DE2DDBC5A95277D87A
                                  SHA1:4888B9AB8CD9943809BD2FD24798E624C432DC46
                                  SHA-256:990DE1304B4E10EE68D8E0575C422CE2CC4BC51D30DE6350E71A1B535C38F16D
                                  SHA-512:DC5A546549DD31FB3D38BB39DB4EA728FD4B149EEEA16D53151F3382340DBF9BCC15E9FE95AC0F02A21DE9452407B705CEEADFEBEDF1A625C8A19C9C9A6E1355
                                  Malicious:false
                                  Preview: $p...................~s)"43..............OGdj...ec......:....z|I.H[NP............`r.=..............'>]H|2h.?......#>% ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.+..?.OD6.4...y}{.}{258}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.060464122549108
                                  Encrypted:false
                                  SSDEEP:24:Fjqpm9jNPeaT84tFoze4ytP6qfHSgC0fNSZBzfteJTQReK2bKXO+jUBtwFp+JgW1:FWp8PCAd4M9/xJfAXxuHKFxUByF0f1
                                  MD5:B45148F33313EB10496D454AE8196A61
                                  SHA1:6475DE76E032C7E8B0BE02734C381FEB84ACDAD8
                                  SHA-256:347EC63A8FBD53DD6C428754654263FA8392F4C6E5376474566C97CFC98649EA
                                  SHA-512:2D87D4D8FD8626C17C640AE218C2B8E3422510F80246A91A9C0EBA7C5C8DAB5D325DFAFC734385F637D7B42EF3DA4211A2484949DE94E2F4D46838C731E456B0
                                  Malicious:false
                                  Preview: .+5.....................[P.............'"....|c..)x)(.....]....3)..qv.......<..XS..*([J../(..d0......."F..&......DW..J[..x..........g...wkTS~~..FF}"3:L_..ox....._R....Mf...J|B_EI..45.*..K@=!.......''5j.......1+..b!..|i..`KTC....-0.......3..4<...L<...aa....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.p....IW.O.f...}{.}{539}{000048000095000095000080
                                  C:\ProgramData\Microsoft\Provisioning\{8fb7d64e-70fc-4f9d-89ee-d486817534df}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1303
                                  Entropy (8bit):7.515280797381403
                                  Encrypted:false
                                  SSDEEP:24:WXql/tSpT1RfFwiTCi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRa8WRFjUBNW5E:uql/t4fFbTEAd4M9/xJfAXxuF8WR1UBt
                                  MD5:79A0865C6522A4F6F85E2B401BCDB55A
                                  SHA1:8A5550E80B48D64BDBB834F38D8245504822A56D
                                  SHA-256:2925DD86ADB88FA0EFC944E1E77068C2F9124DD4A2FABD3BB6AE0433C8CDA138
                                  SHA-512:E7CECC0931645B8E4DFF0CEBAAEBC1F3C79FDCCF41BB2E73B4A92C51EAAF67762F4B264A1341265CE5581986C923884094328B25B33E63120002BBEF56F74F5B
                                  Malicious:false
                                  Preview: ...12J_$h....:<.Mve......Q]....!>.......FAB).......'........ga.......pA91& ...."-.U4!...X............!<$8.......WP..51.....FD....w....!..i.MS....AAjj..:@............].....]]G...@N...../<........p_~v.....2Y...4.UR....ec..el...]Yh+"....Y..[W................ms......=;0`g`....T'........D7..yd{g..yj1............,,.pS\..............4/=+{yn... 6......z...v|......{u..hB..oY....j~Q......$#.)9WZq}z$]Ypa....X.>2.......?azx....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]
                                  C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.281517765600619
                                  Encrypted:false
                                  SSDEEP:24:2yd+oK/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmY+rDPv4W5y:2Y+h0Ad4M9/xJfAXxuFhc
                                  MD5:773DE660C2465FED596E9D3B5BAE384D
                                  SHA1:F83953C0D72755F72BAFA1547FC66CC0F15794BC
                                  SHA-256:16B97EDC8AF8D49FDA7BCB8F64F9B4FEB7B30C35C8DCDB435B4E45655250BB07
                                  SHA-512:E14494A249295DC4A66840DD14FC79625B1FBDA1316C8CA96FF89ABF52309783F7C2B972CFA82FA1B50B53D25C8F6238C9EF12EE2410BF2339C8CB7D9E58C041
                                  Malicious:false
                                  Preview: .J..d#..Q.>)wm..>!.....`m....^...as......zL.....mj....oR.....9QK...wv...[.._A=!af&&.ed....s`ydGFg[.....o:6.l.........3/......w({ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{3,.P..Q.Ff.7...}}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1043
                                  Entropy (8bit):7.473096390071743
                                  Encrypted:false
                                  SSDEEP:24:0KyfY++xemk0584tFoze4ytP6qfHSgC0fNSZBzfteJTQRg3W5pT:l1++km7qAd4M9/xJfAXxujmTT
                                  MD5:810D7C973255A4718491D97EB78F9C6D
                                  SHA1:800ED667F02D569038C95E87FFF8C8835A5A7A3A
                                  SHA-256:879602161940FE3081EDE942C991038C083004DB61D68860F0C5C9B18917E0FD
                                  SHA-512:1474092D21CAC64377E0FAA96E0E3E0CB64BECF4ADB86F8AC79F668119CABA077525DB64B5B9D9E586D69C18473E1D4E4E44D3C4FD5346F405594848566B4303
                                  Malicious:false
                                  Preview: .\X# EP].=...........13..XT................x......&5....4......mz....!>'8.........2....z}2'HNDy7&...H.].sn....ca..................hs.L....... q@.@..Z...Y...J:^...<:..............)1BU..?4...(........"...........}hN.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{iQ{&N.U.U.E...S}{.}{460}{000082000117000110000084000105000109000101000046000120000109000
                                  C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1806
                                  Entropy (8bit):7.424016905233114
                                  Encrypted:false
                                  SSDEEP:48:fFg+UvK4rVk3s1gl/BYaAd4M9/xJfAXxuLKFxUByF0fqpZ:fFg+Rqk1l0pBAXQLI9h
                                  MD5:7A87F8BDAC60C8E04B712E69F2FA67D6
                                  SHA1:D4C7FAFC4758EF30B8E4B36BCD002B8F9AAA646E
                                  SHA-256:D5D7EFD03B5A25EE591F1B5622AD54BCC9E3B3EA986D80E78BC2E8E3FDC865EA
                                  SHA-512:4BDB27547178EEED6DEEB8ED27D5FA44A84949E2A7698926D8469D3714018750CBAEE55305F84BDFB381F7D80E2E78617DE1DB9F2654E1E875B9F330A8784DF4
                                  Malicious:false
                                  Preview: .rv........WV..j9....hj..UYHE2;....$o..f5.........[.......^h9/.X....3)nh..~wSX....zz.......OX...........hf..9%.......E..^M....VL6+.B..|i....L^(xGtIcFF..th92..........)#0d.._..x4?/:..mj..........9>..../.....dd....rakiXI......b6....9V..Y\.:......|v&:Y^ll..22....p/w~bqL[TC...3G...^K....,-....Y^...........w(W^BQOX..+1..!b'*..XG.......YYCCtt..tt..&j..........Dqda.....3...+)..#:........[Y..QD..........D.....:...bb%%JJ.....bs..Y...K...5=..+3..........u-9)...>;_JV[................&&........-1..^A5{..Z.`.....c{...E75,;..*rj|..vtFCDQ....7(..4%wuw'...0Pz..88>>..........s`6!..LV..W.IN......**.......0#..2%rh........D[.uSej'=5(..s~..<;\\??00..CC..zzS...C.....qn..........JK......,t........Z_..6;........MO....xK....XX......%9}l.._...._..u}Ui....+.OM.....?/..zx......,9[D......,|......RR....mm..zz..te..p>..d<{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I7
                                  C:\ProgramData\Microsoft\Provisioning\{99b095d8-5959-4820-bea7-7448c8427b4e}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1979
                                  Entropy (8bit):7.734273344812381
                                  Encrypted:false
                                  SSDEEP:48:PxhzkiNICrMRbMV+GCToJI/AWEyNBjJX58Ad4M9/xJfAXxuqWR1UB88:5miN0Rb7bEW/AWHNB9X5HpBAXQl12
                                  MD5:77A711D81B9C546D275BD4BD58605233
                                  SHA1:4824CFF73CBC93F1BAB06DA953048D27D3BDD6B7
                                  SHA-256:67DF7A45557F9D9F711DE99997B41363048F1930E4AF7A69E8998072744B7F78
                                  SHA-512:BB6B301FA7FBC6242D1FAB459DD7917B9B56AB282F7577B39D2D0B3106F5F8DC35F1C9BA5221A7789B3CE3BD37D9AFE87433DD94394E04E56DFE8081C1389539
                                  Malicious:false
                                  Preview: ..................VI..K...gl......`u..]nh^.=RX...-WQ......2/'&.VQ......%/..^rOG...lmJW..(/..}m..[W.@..ET~b..U.......[QE].HBH....CE...]U..p(...6...RR)5...D66.....S^F......(*..FB......$F@3f/~W...}.........&*V...yk...ZM}c=.PM......hC..ib......( Gt;......../...ls........JKL...ii......lJ.....fwnr...U.......6.....5).7wr......),....\\OS..j{&k..........55....JB][....t{d=?8.......>7;h..xz..........GU^.dnPM....7y20...x...........rs(/.N......Rd..........ql...MM..vj.......N....ZZjj.{..G..7<#......Ex..-8Yo..........mm//gglp........#69bHOMM................ih....m5'U....C.bw,%......nY...T.........77..ee.......7&........ZZ--....FF"J.....(U@ixEv/.--.......Yu5?............@.hz........Rm.........IV$>...&..BB......\@..PR.0..;*........{{zfp.....p:\[.........(==,p=..UU..<<M'XK....h[..88..__......Mz...4...]]....G[..qd..8.E..............8-....ud.2= .;.ll..ll..F=........x5....>>OOttt.4%..NG_.8?......xx......-.:.......PP..]AdO...aV`......:;..n` +....RR==..""..
                                  C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.257852787982194
                                  Encrypted:false
                                  SSDEEP:24:Bu5VyI84tFoze4ytP6qfHSgC0fNSZBzfteJTQRiY+rDPv4W5y:QCAd4M9/xJfAXxuBhc
                                  MD5:D2CD4D8CE5362163FCDB7033A0DCDE4B
                                  SHA1:4CBE803604D48CFC51E13DC9BA12629DB467F69E
                                  SHA-256:121E45384A2264DD53F180740522B9BA37B005D1C41ABA9BCCCC644ADEA9AAA3
                                  SHA-512:4ADF7B3B4AC8342D32849A50E00F0A6286D34E9A892512D7F493A52C9E2662B1325AAAFF4D431247D19E59AE0A910CF01621B94AFAAD0B7B3EBFA85D3964A1F1
                                  Malicious:false
                                  Preview: ..|.........<=ls..GU-hCN....!{.W/=........w[..MC..U@.(..NT...}g..Pc..wqs ....8$....i.......AR....{G..vpY7..u-S#....yq..}Lg{..Q]o@...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{f.>..H..z....I}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1043
                                  Entropy (8bit):7.4587302416068955
                                  Encrypted:false
                                  SSDEEP:24:ORbUs66A7+aeGC84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJV3W5pT:ybUs6rv5Ad4M9/xJfAXxuIVmTT
                                  MD5:39098D3AA09DD8AC259C09DBD73BB21A
                                  SHA1:33532322653C1DC0CC89406330AECCAE64432A43
                                  SHA-256:8EB4DD687D09EC583836DA1479D26B480BF2C75E899E65D81753FA8C0FC46678
                                  SHA-512:5AD381ECB03F43AA321AB724704831DA4720590D20C74270A2BF6B660BE618815B958BD5F05BFE5020ECDAF810A9C96E642A71136210DA2434D5F2A6A3013AF4
                                  Malicious:false
                                  Preview: ...RQ..........RA....',KG..hasl...mw......,#AS..`}....af....}j........+9s@.....=@HIG........7&...N..X....23sq....70=).7...P.Y...2oRI........._..NA...0d..?o....OZA.=;.46......UQ....ltDS....sf.?..<8..*,..>7............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.o.k6W...q.....}{.}{460}{000082000117000110000084000105000109000101000046000120000109000
                                  C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4525
                                  Entropy (8bit):7.832823695840866
                                  Encrypted:false
                                  SSDEEP:96:TDySB5tf7x0F0bwEpYU+HIGkeyuOqIRFWGyi6NZpBAXQDRI9i:Xyytf7xZYU+7Cuv4WGyi+S39i
                                  MD5:F3FA0B712B2E00816B51B92B55FB0F90
                                  SHA1:BCE262726492706D8A1B72BD6DEE2F15050927F6
                                  SHA-256:B152952D54084DF0ABCFC950178E7209E9EBE1A364EE0C3BBDBA68B4541C0B3A
                                  SHA-512:59F012903682C5033066602F78D8516B3B3DDB002B46D2693AACE1DB96E8731F996D3F7B4E53E7786D2928D494E599CA28186E3F85E111B2662DAD70862DB3CF
                                  Malicious:false
                                  Preview: p$g..]10.....'&qnkt......nit.W.?-8-..............&w..-*.....^.........JI..,.<..2....)+kz....ak:n.....m}.?....ey......gv....YS...........16.......B........%?..n-..OZ....PG..Rd......pq2._Q............~!) ....dsSI...FK..|c}Zgz......1==....XX...............90|$.....!#WzI\......//qq66..a>....[L../5.......KTMAY?..nD,,@@.................sh..........va...)OW..Bs"1..J[....LK......ee..nn.....L..=p..RZZE..km..~f..........E....SA..k~OZ...D.)3........EE''..KK......*fs`..p...D[>...J}`o...-..............d<wd....1uj......A..........KZ..66....$$''..{{$$.kx.....wkt.....+..]V.6sh..yF.......R~s..vi....wu{~{nP]{n..........S`..HH..ww...............kg.....13gQ...........z!.......diN^..zs..13..k~]P5 .....'%m=...-..99HH66LL............A........-.EA..= ..9.hui\..\f....ip.A..jj..S./:h}PYs+.C....bu..DU-*....6622..>>..E.....ANldYF,.............ds."....}dn6..T^L^..........F...sq....+:....{{$$..**....22j&..........2.`m.#HG......PAOp..9...49jz2-..9;.............
                                  C:\ProgramData\Microsoft\Provisioning\{9aec5bda-1e87-46b3-bb96-1a01c606555e}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4536
                                  Entropy (8bit):7.890956586078823
                                  Encrypted:false
                                  SSDEEP:96:t1kzOW6xSnNuJN1Bg73toBOl0XLv3THFwWhOewrwhpBAXQ0s1l:t1kCBxSnyz/NXLv3xjwka+l
                                  MD5:AB998F9B5157E372C3E18DE0E5A11380
                                  SHA1:83C6CEEF5B40863278B38F927FB2BC80B88D685A
                                  SHA-256:0F1A22A3D0B2AD930B07F95273912685CDF6A0CEC3664657984D55085FEC8DCA
                                  SHA-512:D788F4E4E7F1E811C2DF5FD84700EF0C2592D3F6CBE16DA7BBBB2887EF488091DDDF994014C70994A5C6739F51B8878362184473B8A9BFF659080FC24A370B58
                                  Malicious:false
                                  Preview: .....c/....PV<o0#...{p......nq! o$BX..ST..*-LG..4...NL....PV..9.............{z......uw5{.1-..?4..."B....JV4&?q....wp.......y.hj....s...%*O...YG..,+.....p..|>......O...9 ..... /kw..r ..ji....3 ....3.rr2..... N.....=6&3pL....?*..-.FO...Y..NS.....w..b9......^4....{z....FUO|45..-}..||...xa....I\l.{q....xjQB....!.-$l7wp..~~.."-C...X%..J.........hs.............4.....rx!#..-%..bQ....\j....^Jr*.~....kl.W....>2'yd`....18. ,E.......R.....PJ..in.....JJ...d'!OT....UH`a:w)........f....af.............ZO...v/..`m...0....ix....-%..oh....uuVV.......................bb~b..w}......76>....@RjH..*8....:9...w.........Cp+.iiee....nr.}..MO.......)XrMM!!OO``..Mx0%m|..,9.....!!......x.VW....IHY7.....(0..b^....._V.../..2j....N_<;MM88..##..@SZo........+p......PP.......CR.(Q{$$..2.8C........QQ..JV..ir>1u?..}}......kev....KH......CCZZkk&&!I..KI.....`N........A`..+:....75.?..zz......h{gR...........oo....3/...........))......nr....M.....mm..}}55...6=........ljxS..,w........DD.
                                  C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.240290686371769
                                  Encrypted:false
                                  SSDEEP:24:ZLQwY4n+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtY+rDPv4W5y:ZkYnTAd4M9/xJfAXxu4hc
                                  MD5:D09F4A4453439CCC6103C47B75043E2D
                                  SHA1:190B0A32140935222318E196378E077A920A8569
                                  SHA-256:B5A4050DDDB3B185860DC4654B07AFCB1FEBA78FCF21393DD4A46928F3AE73DE
                                  SHA-512:1312E1665F9F0B5099DDAC7C2F6177C2673C5B88FF156F30D803897FAE3DB9C0D3C6B305CDE58DF3DEB4ED96F0460CD4B79B8C23D7837F27DE79D0A4F2EA4DE5
                                  Malicious:false
                                  Preview: x,z..-,..DS!;tu....i{q449ibx.........4.Gq..S[..Z]xm...!....T}..........o<..<"..^Y.....`o..XK....sOPW@FK%...D.}...0...vG......fI-0"}{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.M........=?.&..}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):938
                                  Entropy (8bit):7.374630336768148
                                  Encrypted:false
                                  SSDEEP:24:v2ylOO084tFoze4ytP6qfHSgC0fNSZBzfteJTQRIl3W5/s:vr9Ad4M9/xJfAXxu7lmhs
                                  MD5:67D5941C552347DFEA0DFC77D033CE24
                                  SHA1:DED7425025EDD1FF3B617C4022293E71F18D48DB
                                  SHA-256:BE9BE7E0F8CD1B48E4428C30956329D95533835B6A4566887DD6F95A2ACB1DAF
                                  SHA-512:A78E8244B602F1B7DCA0B13013F60F308323FEBBA4D3876B52BE3FD7CE3DE5E3D69C3E73D01C76EA49E988B1EC748221B5BDB8E82BB210B80643109ABAFE4B63
                                  Malicious:false
                                  Preview: ...X.N...P......#<....z?.......q&%7............X_k~-+..|fzk...,{zhn.PC..LPEB......mb..}nXE..$.K.?._J.....VC.=NPA.....0..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{(....K..4..A.B$}{.}{251}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...~{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1790
                                  Entropy (8bit):7.628159977182057
                                  Encrypted:false
                                  SSDEEP:48:YNUmt8X9UIqZxXtrVls/4NmaAd4M9/xJfAXxu/KPhf4:7Gjxdhla48pBAXQ/H
                                  MD5:D4A6B076BF74C24999E4064D350D160C
                                  SHA1:1C506D92692E2FB1C70D0FB5DD0E79F99B6CCA5E
                                  SHA-256:D0DE69A005CA636CD27CA34A50801EEE19D600C22A1702F0165C569046F4813C
                                  SHA-512:D1C9BD186DBF31A4E2100F8FB6092BE9D7A237361195FFE4BECBD49863A6DF4E44C5A65AAA8FA10214AD6AA3985C75E377E4A5FF7E702AD22A2786AE472E4FEE
                                  Malicious:false
                                  Preview: #..LOat......^X..............ih.(2#p.. *..BC.._...LQiZ0...O...?&..........I*-jj]....;,..\F...^........!4.........R[......lvDY$gal.....3..c3N}.9..\\WKT_..omM\xc....*~gnQ..........3..UUJJ....2!EG..7,.....+...A9HBS.......::....ZZ..SX..XZ$5..dcGM..BKH.....dW.0......88..EY.......n..LK.......v}ME.+;,ZF..ILBO....VV....!!......C.......8/ :.......A^..|/..hh........K...KE....\..J/)..s$?#..zzll.....##....h7jcPCDS........$)..........*oTg7...==DD...........=6..IK%4..NI..1e%,X......HL..`a......PPmm....ee==....<<m!.........2.;.B[1vH...?/C\..31MH..........QS.~..............qq....33&:..........lfS......'>*rN_...........&m....MZDF4%.x......ee22.......yj..FUvt..3(ni..eVyS}}00....ss.......A............{&)...........JJdw..WDsq....:=..iZ....!!..........?,zxET..jm.....p(OUB.h:13..a<...9a....p}[..J...M.L!'....1.ff....ww77.....c......toaf..................dd..TT...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.
                                  C:\ProgramData\Microsoft\Provisioning\{9df6a4ed-fc16-48bf-8b24-6e2ad2bfcfea}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1925
                                  Entropy (8bit):7.65396144089057
                                  Encrypted:false
                                  SSDEEP:48:VOnXZBbqp314yW2ZUSoSMAd4M9/xJfAXxuvWR1UB8u:V4XZBbE31RW2mSoS3pBAXQS1U
                                  MD5:714C463E8ECE38C46187969E7DF381C8
                                  SHA1:42949D07D634FBE0D4529005EF979D4EEA7E3D70
                                  SHA-256:5A45A1AC556971C751763B1E191623013697EA369ADF6B64E40C8668C84D85D2
                                  SHA-512:0D07D593413F34763B289D01F1AF878DF5A657F3A0268192FCBE99244895BA45AF426542B8519A85D4418D893A1C68CACA38B08F6A4126E3C5FDD6CD62D62C64
                                  Malicious:false
                                  Preview: m9. ..q'......NQ.....M....JM..`7.......26.ci0(Aq..d...(3....^......fd....<..........8'$#_...OB48.E...a}..+r....8...|d...i.......b*..5=...}bi{o\..HH.....V.O.o:..1z....kg.. 5...n="q.OK....&g(N...yy..~...[...WE..zL..=:VB...{,G&l`:aZ]..00..h.............ut...Oru..SS.....iD!4.|....*6......`k..&/....OO...f..........O..<<{{....8ge~...qg.3Sy..]"HJeo..hD....aR]w-1....dcwc..@A..C\.)i="2..48..ok..QM.....D...]W^F....";..db16.......KKS,..YBAE....hi<q|{__..ll.......o\;.....yyHT..ATkz..;b[8...<..BS...'.....QQ''...:....cD8-4o......yy.....2M..ux........h0....S.0F..XHHWO\{t9.....yy..{{_C.j..$&..]H....;......HT"Y>-}.......pp2!n[.....I...........EM..'.00.......*h}..uB$1%...ss......;'.,..M\..2t....<.."..x.....yhZ]&&..bb77....1$VG.$..Xk..ggsseeso..gg..zn".....??..55....."n....OO..FF....}."!T^Y.!&..||11...........TI......;;..--..77......z......YY......PPii......<7;31...a}........hh..33..zz..$$...On8?..S.vF..`h2.5=....q|T[......0......''YY............\j..61...........66
                                  C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.243082437111945
                                  Encrypted:false
                                  SSDEEP:24:0hf84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjY+rDPv4W5y:02Ad4M9/xJfAXxuGhc
                                  MD5:BED102CD604544E366A92F5CC8924726
                                  SHA1:4CD2B0DCE9EFE5A0B49D064735C24A8ED4D69F81
                                  SHA-256:8E2BD1956F8B2F8F1D0B4DC60F68DF3AF5684EAA4A2C41CF9A70E94C6CDF4CE4
                                  SHA-512:62286BAEC200E35DD7BF5E9F02CA7E13EFFCCB9A9BC3107D55D7BC2E5D86A69983971A5EBA72F44615EC2B9C67178137A745ACC36A59675B370D9689A2A51CDB
                                  Malicious:false
                                  Preview: ...`'KJ......101....<P.......j=....@]L.7...~v..ST..DB\aYC..pY[A..L...qw.,....mq..55...#,......gf..`g..........2.=5..........Bm...R{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x}.rIB/.........}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1043
                                  Entropy (8bit):7.468313604712189
                                  Encrypted:false
                                  SSDEEP:24:bxFpN+MGkv484tFoze4ytP6qfHSgC0fNSZBzfteJTQRiA3W5pT:VFpTtJAd4M9/xJfAXxuGmTT
                                  MD5:A8AE2DDA652E259A22D2A9B32A2B180F
                                  SHA1:75C14024085487454012340441CF15FEA2A4907E
                                  SHA-256:1169D266A039A1649FEC87B22241FCE826AA9275D4E0105E998B56EDB31562B6
                                  SHA-512:78BCE46F536779C22B9EE23EB1380575F98F61584AE6B05E02881506C616692FEA7286CFC6ABDDB942353C2DE2CCAF27BA26EB4A6019F3951189CF5BB920A6CB
                                  Malicious:false
                                  Preview: 2..lo..........8+SM..t...m`..../..C"8.......FI..%6[F....WP....xb..<#..|n.-....3.pxU[..&3....."+q)....cm..*(..sspw......!l..`2D...8#....*)..Q...0y...V..r"zz....6jDB<K....4A..Yc..f_C,.........^K....!%bw"$..el+,.B....)<X.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{@,.dC...Y.n.4.D}{.}{460}{000082000117000110000084000105000109000101000046000120000109000
                                  C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1799
                                  Entropy (8bit):7.428849367766107
                                  Encrypted:false
                                  SSDEEP:48:N07Z2pgOBa+3dkgAd4M9/xJfAXxuWKFxUByF0f3:NwNHzpBAXQWI9O
                                  MD5:E17DFAE9D3931710C047F7BDA42B764A
                                  SHA1:48A51F13E68004BBA509D3A7A82789B6A4024D92
                                  SHA-256:8DC45EBD2409244BD63BC9B445420276DDF97CC6C87B45607B803273CCF6F8EB
                                  SHA-512:C3A649DA9747C0AA84970AF166F46305D05A79B30A7DCDE1953FF0726E9B6B5DEE6109D472937B7A2FCA8B5A7474761A047C36BE658DC3EC939D08C0BFC195D1
                                  Malicious:false
                                  Preview: .zE..X..4b.....~a\C.m.M.....+qq&........P_X]efRY..xd....=:..rc..ex..................uf.....07..o;QX.....nm^.......PC]_}lNU..hb.MDU...|d..5)dc.............ER..`}.....~a(.*=OQ.........`Kvx..3/.................g}uh..M@........#?..$$..\\DDtt6i....i~...........GX9.if..n|.Jy..TThh.....4(........-*........vfk"".....gg.........66.D....ej..wh..#&0................I....,.8=..YTXMuj..=,y{Z.mb,...LL..((....}}NRRC....................ZC........."/..}bCD@Q................ii..#?VG...Zq}.V..!.S{..PG....6!d}.Y*<....up]H........ZK....BM}N..TT....}}YY@\5y=4\O?(....= .\.x..}}........W^......wm..Q....._@..#1..............88cc.....4;..mr....,. 3........$3@Y........36........LKIX....69................`q..u;R^ x.....&......l{cz[.M]H@........./0........DK..$.....77......."3POp>...M.jT~$.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....
                                  C:\ProgramData\Microsoft\Provisioning\{b0b9123d-7d7f-4c6b-9973-ceced46f2a09}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1970
                                  Entropy (8bit):7.715898912936976
                                  Encrypted:false
                                  SSDEEP:48:z+jYPl+7CFeFr9d6RNtwdc7daeAd4M9/xJfAXxuuWR1UB8P:z+jql+xFRUtwzpBAXQ51t
                                  MD5:6AB14B2B994FCA485D7181EC79276A53
                                  SHA1:E60AB8AE4828C9C54871FE4B4885AD376EB55795
                                  SHA-256:25E2BAC617A34A5D9AEBBADBE69A104EC93B54B362AB3FDB3A8075DD7962EA20
                                  SHA-512:E7B66EFDA8A1CBCBA01C901203BCB923D208C0DB976AE18D7752365722ABC44AC6E3EFAD64EE43F1A5EB87FB70AE211133AE12FE9BFB84AB66058BB26E43AF54
                                  Malicious:false
                                  Preview: .ok........db...KU....BO81..pq|7......~...enx|.1............Ra..-1....F@:...5:..........h!#(....`.KA....TF....9>)".{6Rvqz.......v.()?0R.......pwOO...E?...G....A...6g...T.Xhh[_,b....RP.Eu$...94......... (......CHep...OK....Ja..9>...dk..$.........EY%...VP$t!>......HR........2...........O^...............Gt.!YY4(..KN3=....>;...#ff......XK.!7&..$#..Rc..ecRt..t{F.....#LM\........[v!..........#c......4&..?=...RY.......!;........44PL.(..UW..ZO............QMLy....+f..........?W..,..U....2.................O|&.................>.wb.....hhff::..HH.g! P]2/VW....K........4............vo.......?..==""GG....=............ss..oo}}..1Y....#.#6UD...VV.....''@\zV..F[..Q.*.ME..a^l~........Ze@C.....n~.....Yj.!::...............8.....0....pp.....qsf,......EE..gR......mj......[1):..|f...<''UU}}@\..`u......}N....XX..``..vC..HY...].=...<)"QXeX....cU[Q.....?.aK..aa< ......F`.......99dd@@a.UDuh....fauu..jj......^F\K.....UU..qqXX........j\c~....iheN4:...<Ak88....//...
                                  C:\ProgramData\Microsoft\Provisioning\{bf56ce5a-946b-45b5-858a-1794eb0125e2}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.267533751664659
                                  Encrypted:false
                                  SSDEEP:24:e0tAP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRbY+rDPv4W5y:gEAd4M9/xJfAXxu6hc
                                  MD5:3E18F7503FE944958CECAD8B4C694B27
                                  SHA1:AF9C2A99DFAC2062334012155C6D403B08F1DDBF
                                  SHA-256:A6B1D7FA86DE78288CFC30E28BABE4DDC8D98E0570AEDD82012FE5D9EEBA17EA
                                  SHA-512:1A012CBF7774BC609D7E5B9BFBE03E24795794CF78EEB9853EDAC902F31D70155E2BC26B3E13215800A1BE0B7C52AA6ECF57B5E2AEC1587D594BF6AD9A4A6A43
                                  Malicious:false
                                  Preview: .U..v1..c5..,6XY,3#<.....$/....../:..h[....RZ........_b.. 1..3)...L|}..+x..np......c.a`IF..2!....~By~..L"......!)....FZ..!-;.IT..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{H.......,....0.}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{bf56ce5a-946b-45b5-858a-1794eb0125e2}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1162
                                  Entropy (8bit):7.540140269664523
                                  Encrypted:false
                                  SSDEEP:24:2M15Oyho7b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRE93W5n:UgAd4M9/xJfAXxu99mF
                                  MD5:33E5A7467E57CC31F7F21F67AC7695A1
                                  SHA1:2925101838A20454A8D396135432BEB7349303BD
                                  SHA-256:50A8687B1C86A876ED3F56BD91DC3A62BA62F494C20BF12B9DB7C4763E9DB156
                                  SHA-512:3BB598625B61CC910EE3E555473B2E90EF99BBF75FC6E09621FC64EE54B9B37B286167D76CC10ECFB219F6038E91443D2604D580367A72AD96C64EE67A5C2A80
                                  Malicious:false
                                  Preview: #ws....R.....wv%:)6(:........k1.yxj!4wjkX_i.:4<3=/(;.................WH[DZHT........879+,?*7noRdu!Ux.............3.) 4.5(PU...AA..TRRIS..;$<km1$1\X^B]]Z.......qs.2'2nqAM.....L..........\c..9.Qn..(2+u..ekhi..9...J\..uQBI-&..rg...>,....lg8...+clg.o........gn="f[..RM"2..o\+...Bn......0%.../....r*........NLH~>>TS............vp'<..7d]E{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{bf56ce5a-946b-45b5-858a-1794eb0125e2}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1580
                                  Entropy (8bit):7.551152536661819
                                  Encrypted:false
                                  SSDEEP:48:HKNeC5nlwRDyBbyiAd4M9/xJfAXxuJKPhfl:Hkb5nlkIgpBAXQJq
                                  MD5:C86C32F75E2769B400C9361010F4C03A
                                  SHA1:C6B1A514ECDD3F3DDF08FF068980ACA3D2278732
                                  SHA-256:44132342A555998C43D7821AA42A70F34F373586DE50CFFC622F441BED4B9459
                                  SHA-512:842131210EEE8417307CE844664A89EB4F7BE3AAAB655E817E6FE09B17A9BC7A13FA59084CC9121C93522A7E8CEEACC16F924E36CB3B214AA8DDF942A7C4D31E
                                  Malicious:false
                                  Preview: ...dgQDG.....BD..wd........(%..ivHI+`lv..............yd....,:............"+..1l....n1yp....tc....1r........xd..VVzzy&...&1L[..,1J._RCV..{D..}-....EElp..5&9;9(&=........._E7...."y|O..{{..........8)..!&...M+"t,...ex...l_....xxjj..zf....;91 <'..,&.]..=e.nYJ1)..X.).9.//77ee!!..ey...mo.............V\-..w.tA..a}......FZCDGG..nn....DD..'x....xo.......J49....yv........5/:h......-4...../|.........ss..jjss..LL....#0 7..+1..|?6;....tB..`gz?...)..WW......%%..eyW\..ln.......r&....~....\_CT...b]=8?%PL..88RR....xxKK....cc......R.....@b..*3)nD...(8...........7o k......64......LL......cc.....eeu9...Z..5=-2...:F_....{k.........;..p(.: ....uw..............dd..VV...%.......OT{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X......
                                  C:\ProgramData\Microsoft\Provisioning\{bf56ce5a-946b-45b5-858a-1794eb0125e2}\Prov\RunTime\1__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Sub-key -
                                  Category:dropped
                                  Size (bytes):1580
                                  Entropy (8bit):7.558853371203727
                                  Encrypted:false
                                  SSDEEP:24:1Zk7TP8XQzkvUMVsqtuca84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5P2QG+JgW57:rk7QXdvUMVaaAd4M9/xJfAXxuGPPhfl
                                  MD5:A83411D3AF0CF16635F9756AFEBEE618
                                  SHA1:C1FB0B7B1F896B0CD28355908FBE6E00F9EBB0C2
                                  SHA-256:B8C600A7DB98F8C1F06CD2DE75A70D34D305331A1A1E3C8F10B9062812716177
                                  SHA-512:848E1EB527AF587195635D281693E6D4CA0C05877C53C78AFBBE6C3BEAE57E3AE3E984576FFF39F5F45EAF65A2599522D0E4A17BB6FE28A1BDAD8009D68A4655
                                  Malicious:false
                                  Preview: .......=...........mo..@L...........j9........M.......bTv`...rk../)..AH...F.......9*....~dnsb!HE#6......rn.........6%......^...;...yF~lh8Fu.#..77-1SX....*;*1.....C....t.?<..X...gM....@@..*9..3".......pyK.........W..$...........U^):........m9..n6m.m~.........#..nn..CC.......qs..g|..82y-..~&+Z[P.......c......1-..77DD..##WW$$........6!_HIS..^.cn#6....Q.b6..:%....\.8e..06.....BK.K....WP.................3:..ub..QKTI..DIK^rm..jjBEw2=...??TT....BB......]A....!#.......=i(!v.F#Z_0.....yr...+HM......tt........uu..77.......U.1>nf......;"6q.......y=........H.1+..ox......00||.........66..pp..8+..../'......zc.N.^.........)<..KB.L....dfSD.....XX......VV......//..ib..TV..7,{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X......
                                  C:\ProgramData\Microsoft\Provisioning\{bf56ce5a-946b-45b5-858a-1794eb0125e2}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2634
                                  Entropy (8bit):7.815389774903678
                                  Encrypted:false
                                  SSDEEP:48:TtyxFRIvXw+EcPhbY3iLd2HJ5qPiOnorxPaAd4M9/xJfAXxuHWR1UB8t:Qmvg+EaNY3iRi5q6KorxdpBAXQK1f
                                  MD5:CAC889BDD8B3593E97FB6C334CB1958D
                                  SHA1:367659EA65D67957818E019A51D1410F33E374E5
                                  SHA-256:9BC15E6D286776D7F4553B45BAF3A1DB0F291F3862DDAA7569B7980B33035B2A
                                  SHA-512:BB1152FB074745A1394ACEA308815F9642B697A67DA72C6D9B9FFDEDE681B2E64C7B723888D0E3184D21A4ADAF72C97047D56E7AF6BA6F32D19B5C6997CD6E05
                                  Malicious:false
                                  Preview: .JN......WD|}42S.........TX.........ml61H#....nj..........ex..cIui~Oyq..).kj......!#.F..th.N..)![Ip.....pl......t......m....j..%/...sr...K6q....LK..66....W....v:2?7cip2eow..H.......?m...T.......`J{{......O!.....h...DMS.Cvud....~m/....3)...$8.........`.....CB .v\..ui'.AJ..) .M-.HY...\-M..BU....zI,.PP..8............\vmm.2..kz.YJwV..+f..jj.lyH........3<I.z}!!.........GE.Y.|`.g@K..#1.Pt~8%.....Wjh......`d.K9$&9......c&..6.....Fp....bq@U.......9......4...cr.....>>..@@L$>-...Yt..`G;*........>.....eO...........\\bbtt....SQ..xmXI....YY..zz..BB< ....7*WQ$jR} (...].....,'..j:....;+....cc........$?...0*`i....O^fa......jj<<..l........U;.......>)....OF....JC?=....+swg..vg]Z..{{..gg..qb...........@....BB..~~........mJpe..\o..??FF!!..!!....mg....d*mBgoGX."/#5#...+ ..R..s..P@.........M;..............?..!!,,..,,##==..rs........d<H:nv..........HuW^8:....E...........$$................xm....TT......~m......7............J......f?.........ht.......zz..f...?=".,9Q@1..
                                  C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.260608574272184
                                  Encrypted:false
                                  SSDEEP:24:dRmN4bWw3684tFoze4ytP6qfHSgC0fNSZBzfteJTQRgY+rDPv4W5y:/mAx3fAd4M9/xJfAXxu3hc
                                  MD5:8E3CC3C8F063016263FE3F20AFA0999C
                                  SHA1:96C64443BAC6082ADEFF8B33761E76D9C693D7DA
                                  SHA-256:D82DDDBA31453915B3FC5F3C7D728F69E4C867498D934D21F049DE032A114A4C
                                  SHA-512:6A16DB62DF914458B744AECE53EB0009F3AD8EAB23E710387DF4A5B76A1E9EC073DFD4CF171C462947CF0BFADC5F2584C4031649669741785A5B6E08E80F739C
                                  Malicious:false
                                  Preview: D..X.[..C...@Z........P.....,+:`-z......4....1........=;Uh..pa?...+.kXYX*,W.\O......ii5J....%7......,...06....1Aqj..bj..bS...0<.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....==.!..%..tA}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1086
                                  Entropy (8bit):7.5097431908198695
                                  Encrypted:false
                                  SSDEEP:24:4nXmLNfhQ1Vd+Cpxm+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRj33W5L:kY8mCpxmTAd4M9/xJfAXxuc3m5
                                  MD5:1FC18901A170B1BA66C55B74B2F9E5BD
                                  SHA1:43FC72C4AC68C08F028CD161E5EB180825C32C50
                                  SHA-256:CDE05057577C3DBFE9C68FCF432C7248FA5DA003C4F683BA5150E041AAEEDABD
                                  SHA-512:C12DC079CD0876E92D19B260322A2483DB85C5A1EA2EDE708F90CD33493BD2EEA8623B3A0DB95F88B6ED81C2F78EEBEDF16EE5D339C45D7CF6714B4D0FC2CB4D
                                  Malicious:false
                                  Preview: .W.......ou..................O]FS>#....Nb....)......8IS..v3Ra)(..N.cp!?.....TU.......]\.*...........ATH.w.........rw....p|...DK.....A............%%.DFIl......:'d;..@[1.,$|...#...cN..qf......vz....3.../$"|..5;fg......{Y0=m.VK.>..V.............)...w|.Z....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.DY5..B..C.R..^}{.}{546}{00008200011700011000
                                  C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):7.142155443885578
                                  Encrypted:false
                                  SSDEEP:24:DrbykALpVS2BA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFOK2bKXO+jUBtwFp+Ji:DrbuLpJxAd4M9/xJfAXxueOKFxUByF08
                                  MD5:0BBC33E48D76A969E390E070CC69E4FA
                                  SHA1:1DF698AED0A1A8E43DDE4D6F40B40AF0295CD9BF
                                  SHA-256:9CB65AD2853E142055CAE469C1B64732449935850260CE617C1DECCCA060B554
                                  SHA-512:B43ABA037EA1F258D240A80100B6639DE189052AB58B55BB24999E165FB2CD232C268A80408AC9122E041A9B2C87EC91A54C2A8B110E14322B16725F557B87FC
                                  Malicious:false
                                  Preview: ,....rg..|o#"......\B........4+..)blv?l 5ak.....R..9/..bQ..-;z'*(...............xx........5/..`#XU....xv..:&..[[ss..;2PCJ]..@Z...Zkf............aK..KK..........@[y~[Q!u...V1..'2Jv&!....06.1el|{.O+.u_......">..~m+)..OT......ZSd<......34....cc......81......G]...G...j...2....5>..Lcky....##..vv...........IX.... *h<...__M....AA......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2
                                  C:\ProgramData\Microsoft\Provisioning\{c5dc3753-b6c8-4057-b396-bf13d769311c}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1685
                                  Entropy (8bit):7.674455177976348
                                  Encrypted:false
                                  SSDEEP:48:AUbLzqwkiYqgfOAd4M9/xJfAXxu7tWR1UB8b:AUbLzqwHYqgfBpBAXQ7E19
                                  MD5:4268DE5669BC4B2B85B266742E824BBA
                                  SHA1:84CA1C22055EE19E73C824A97FF034760F266D71
                                  SHA-256:D30E85F7A58E609C8359CAD9CC89EF431A83AF095C7EF81359C28D7FF5ECB985
                                  SHA-512:9F7C1DA694ECC5AE81B3B20B73ABC15798A2E06F0CB5E3DC3D4E2F5E39EF642DA075A8DC1E90397FA0A8EF0CE864AAB907C87D63D2C1FCECE4665BAE5A9D21E1
                                  Malicious:false
                                  Preview: ...M..........QPgx.....\;6....s)D..........-.......PV3(IM..#>...C.....v......uY..FH...:'......[VW[...<-..HA..TX............~....>8.......................I...|x...T.ZO..........VR..a2..tv.`!............@L......!}..h.[Em[7*.......MC..6[live...w....55!=[hJK.......Y 7?%...9iC==\@....Wq...@d@Q......@ tm...;....aK.....&.......:..xK........o~*g.=iH+:..ho%%ra..!)(.......H.ur...k........SF..a/c4EYF.SX.......7*....h&.....AJ......SI........:SS........$7....extG.......Mxoz..w:....KK~~//d.......: ?Vt.....&........jc{Qmj....eb..........F...OMNi......;.88......uibN..f{rtJ....sl....VtobTF...../ht.v{....N^..................%...NH...ZR........ZF\x....:j.....<#SB....o;^(:...oh..xb....%''6}z....gg....ARi\....vQ:/.UcdUU......RR.....+..... .bH11..^^....YE|PoeSN...W......a^:(..KFPB..HwEF.......uj.......-..99ee{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.w
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.268118437587813
                                  Encrypted:false
                                  SSDEEP:24:4OYFP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYRY+rDPv4W5y:4OiEAd4M9/xJfAXxujhc
                                  MD5:B34AA59A6ECDC692D8EDC711E4DC6D62
                                  SHA1:C1AE6D9230AFD514445966D33EEFF99685068C46
                                  SHA-256:07A5B0899B748AD29B1863B428176E99E3D785C1E4F95F4A17D0947B93B55027
                                  SHA-512:DF8A6A1ABE5C3875D9DE326B00EE98074C69C71CCA0608FD4C7FE6C75A817DC5A2B980E21BAC7C9B8F8AE2F949F8ED73F75C9FFE1086EC4504935A9EC0D99715
                                  Malicious:false
                                  Preview: &rI...lm.....z{FY..bp..........h?`r`ujw$.....$,HF......_b`z......g3.:10..a2.............ZH......A}..........z ;tIV^...9G[{dXT.....O{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.D..+h.|"c.....}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):212126
                                  Entropy (8bit):7.998953845719651
                                  Encrypted:true
                                  SSDEEP:6144:9s1lc8PdtMGyTOVnqIp1EqmMbMxbesRxR:9CVtMI5EqmMbibesXR
                                  MD5:9E0A7D8746D15FEC2994E48C454D8793
                                  SHA1:3A3E2DCD5157AC4CCC43E570CA665C09F79311A0
                                  SHA-256:C9722A496ED05BB833CC4566D356B112D7FB035E97042280909EF14BB3720FFF
                                  SHA-512:8950A34CBE9051DDED4AB1DC69D0D14A25FAF06A0C089194F0400A59CAE63DA029B7579682A2060906F18E677E34CAFA982A119F63E6EDF37B1A257A6E540C21
                                  Malicious:true
                                  Preview: r=9....f*DWcbY_.@S....29....gn.....xb....+T....N\......Iu..=;.DSqk......kydW.-JV.2...q.........f...........uC//"%..................Y`tr.j=.U$v_P]].....[}...5i....cahqb...KqMI....._D..(3../2@N.........Y.....6"..Q^.!Rx\@Ki.v..........z"V.+6......>.II..T@,...L......\..;%......=u..O.../}(z.Mec!1t.xm`<........V#... ..+.?Q..................GF...?.........)w..EV...R.?\..ZU....|^P[_VK(....>9....:;..W.(.........................V..o#............J0oy+....h;........./2......I............z4.}...bv.t@B_^[..*-..$p..^@.......^...RM..43I.'{..[Y..XM..OCp_..)v..hs..........HH..........pN~o....xT7;..bh;1h.hu..)#[\3.....13TMRG.)D....ADJ^t...*5NLik........:.......7V....08df....~.n!......ahbg.<..54:3......JO..%&5|.......b`..f1.......9.....[R....^O....`8..:'......Yo.....,F\e(.....ENmp..HJBZ[.........."v....Q..J....;=..[YLU..Fa/.......nr..........$.......HO..._(......q...cl..I@hB..."..Q...TZ.....8........."|HZ.......Q.f........X........G......ZE...orT[<5....)
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\0__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1003
                                  Entropy (8bit):7.29908878553886
                                  Encrypted:false
                                  SSDEEP:24:u284tFoze4ytP6qfHSgC0fNSZBzfteJTQRqDR2gkMJ+JgW5z:urAd4M9/xJfAXxulDR2gkMUft
                                  MD5:87AF82B6415CE643667BE56CB56D512E
                                  SHA1:B4049A8F217A6C4852BC3786B12587B42D25E582
                                  SHA-256:AD22C23DBFAE991F7D0F30DB89EE8929AD2E17C5A3AD51B519476AB3E8DCCF9A
                                  SHA-512:9CB34CDA65624A9DB7E640259FCEDA2961924A1D42FD44F930AFB47E3023E342AD60CDC82C6EED9A08F1B8C92DFCFD461B1F5E5636C906F406DBD563A295304D
                                  Malicious:false
                                  Preview: ...../:.B....DB.........q}OB%,,3$%4..........32.V.BT2/(......wu.........v...OHO...SZ..0'.......ob........|c.X4...??&:......................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...?..j..o.}r.'.}{.}{296}{000048000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTEND
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\100__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.36587565936491
                                  Encrypted:false
                                  SSDEEP:24:e4LPudkQGlYB6dXA031xjzT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7GOBBpFUP:1K4lUOL311zYAd4M9/xJfAXxuTOBpFUP
                                  MD5:9EE5F26F8B192852DFBEAB65B3192AE1
                                  SHA1:30DE51B1C045877E63AA7B67B9D8ED39321D7313
                                  SHA-256:3D82ACEF9B4A22CBCE17BC069E1AC73638B52BC58C198DFD8FDE6D5E74D52560
                                  SHA-512:276A7556E07BD55DB379CF5B291011711D46F5B1B6F0A060D71ED16C4A0A4FED99D389D38D819073CA936DFEBBB578EAD17A4694B09AB8DF3AA09E16B85EAEA6
                                  Malicious:false
                                  Preview: ...=......9.: ..5*..GU!d85mf............!.63..|w4+..r#<=....[J..../0..VW=:..+'..rX.....l.......>4.V_{#../.qqIPEVlG& [W.Iz..MM_C83..qs*;..52|v.M..........W3.....e?.I........i......klAA((vv\.....pg..'=wj.M@5 ..\}.%..BH....AHG^..2bKx........MQ.. ?r<......h`.633...".(G]..FN....0).......kk^]g*IK.Y.....;...]....................p<le....XO..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\101__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.79722048204507
                                  Encrypted:false
                                  SSDEEP:24:nte5GPXM5rUkPww84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBNUzfXF2tDFvy8Bpi:AwKAkPqAd4M9/xJfAXxuYM158B0f7
                                  MD5:F4A1398E3F0D54EEC8794B4DC0A05393
                                  SHA1:D72F0AD527CAA3C7257CD90B8FBEF762D99BC2AC
                                  SHA-256:C9B1BDBA5B81A72E997540F9B0AD9F2D702386A600B213FB08B1291113E2720B
                                  SHA-512:12CD30EC59AE317718A7D0DC681C233A3D719B382C7B9C26FAF8D8EB5450EEC3F42D6683F1B47C1F22FC75F200E6C6278FBDEE7FEC7CA21EE3AECF7755BBB8F3
                                  Malicious:false
                                  Preview: .../hbcq'........0/..........%..hz......;4OJ{x......7f..ur.R?........:;....84....|`NE........pw.......!S..........#frA%.....ne......-*\Vm9$-..U6..cr.Z......BBUI........6-MJ..k?FO.....J....h#OKRG...n!45..MC]...p ..,|:e..dN..__......:8(9d.fa.../&....(.FF....r............M.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.pF.a}..<A!x..l.}{.}{574}{000049
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\102__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.676317017965418
                                  Encrypted:false
                                  SSDEEP:24:GMBH784tFoze4ytP6qfHSgC0fNSZBzfteJTQRdGHUzfXF2tDFvy8BXCL+JgW5ps:GMqAd4M9/xJfAXxuVG158B5fI
                                  MD5:68F9F777F9EE03EC1A4AB0BAACFCD3AE
                                  SHA1:C01A82E0BEC9C9198928431F2ABE649B4D5920A4
                                  SHA-256:17100C1C4E685F5BFC21C30E46028FD2C1BBBBC19CBFD4031B8A40CA535E6834
                                  SHA-512:80C62B2DA817B1CA5A69EE190EFD0567359D3A9CBE8C3E9FF2F462D7C09EECD75919F24DABF78BFAFF6F839F1481A137FC57E82E3566153DD8AED38DFD063F90
                                  Malicious:false
                                  Preview: ..{.....->yx.y.....df..84~s....\])b....J_ak......{ ..3.Kx...}.,5..ce..bk',.......ZSn}xo]J1+............PE..NI......4'....z`$9.S..vc..Rt...._CVQ......=b..XK..4#..-0a"s~..#<..[zhl......~j..fa66..JJ...Qpy.......yd.L....<#TX......z.UI........\\..|0..l!....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...|.uG."A...}{.}{524}{0000490000480000500000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\103__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1330
                                  Entropy (8bit):6.720754502305616
                                  Encrypted:false
                                  SSDEEP:24:wJZxF4hGX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKBoUzfXF2tDFvyv2+JgW5a:6/ARAd4M9/xJfAXxu/T15vRfU
                                  MD5:BECF711FDE95D26B21179A73441C08B4
                                  SHA1:AF64610A677D11E3C7CDAC1FC7EA667D38F1D62F
                                  SHA-256:F5EF16438811037D82935C1C4CD4EA7B10BBCE8CC5CFFBD0FF55B0781141E39A
                                  SHA-512:8338B6765C90957A05E8ED54EBED5E6F94FF07EBCA7247819722349E980827401AD29E574E4D6F395D64F5F60892B21DC887E897FC47A4497CF9BB53A58D2EB7
                                  Malicious:false
                                  Preview: .D.v....j<TC\F"#..%:qc.....-*=g#t]Ocv......`e........$uUT......&{;&..?%......nb@s....FU..O^....|v....^...:*L(.......[P......5...=7.......=$..>n..........WD`b.........jc..aGP....^Ozg...Bq!...{{......ve....hs<;?5..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..............w}{.}{447}{0000490000480000510000950000950000670001010001080001080001170001080000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\104__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1523
                                  Entropy (8bit):7.50347461006534
                                  Encrypted:false
                                  SSDEEP:24:Fj0gWwiiT8Jz6cIaOkLbz1F84tFoze4ytP6qfHSgC0fNSZBzfteJTQRanBlBBpFT:FAzwHTZcIaOMbJWAd4M9/xJfAXxu3B3B
                                  MD5:CE6FFE177D8BD2C7A222B3788B33E2E3
                                  SHA1:E3AFA73992B8EAE1F5B1F716D323E1B037D22822
                                  SHA-256:91F067879D6A51AA4BD941485AD3DD660C0667579995DEEEDEFD06E2F8CCE5B4
                                  SHA-512:B0FD1650C26108E3D85027E2645A5D2995C83CA6C871013C988EA164A417FF7136828356B7AF7F150D0E26C9556B6A239B1E5854EF63E2EA277CC851463A2203
                                  Malicious:false
                                  Preview: .N.O...B.h.......YF@RP...........]HRP........_T`....R.......Z6+................PL....ln....(/..P...z"...........5.rt......'.}}PL..........-'P.....K*.........]&...kb.....&....Y/..........'1 R).t^......>5....N_....!u=4.MR4}n:.....t~......../3......HHPPL..........."#9...?.....a^43.>..A...........]L[G5$XZ....- ....^Y...................1"13..9"......~T........C\._..J.......Jv,`b4........9}..ZOBK4l.W....o*........GGfz6'..G.[W_.T2..s2........Kz.....jn..;.......\.....|9,#..W}]]XX..KZ..Q...<d..26......vf;$..._......M@BW#<............JJ...E..p=3<..{d.........gb..G.....hw.G.....NRGE.....C................(*tq{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\105__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.403760505217232
                                  Encrypted:false
                                  SSDEEP:24:GNv1ayD8W0Cn4bPWHyDVcP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQ2RTNGBBpI:GJI60VbWccEAd4M9/xJfAXxuGdN2BpFa
                                  MD5:8F397AC2C29763FD95F56EDF423F53C7
                                  SHA1:2D39BAB50DC3818DC9144B12C6DBBC54DA14DF6E
                                  SHA-256:32F18968D4E8FB0602A1498BBA14019D45606811C3356360E9EE8564A2F5EB08
                                  SHA-512:5747F23510747CED6A1E239D3BCC9CDC6CC4BB791AF5778921112DF7BEAB1580B5847C7DC8FF085FB18FF0FF3FED72D5A0E143A85F267BF0AD32AC1A2F57604B
                                  Malicious:false
                                  Preview: ...C&a..;m~i....vize1#.........I.....'%\[NA....83kt......(/....................Aru_....zizx....8?"(.......`F.......,[]FJ...6\vvv..+ DWDF........2f'..B]0..L'....A3n{nywr..H~{oc........n...faKKww...LGN....3$?%;&%fQ\U@............<.......]ArNd..;;;;os..9&k%s.?g......'/.*....zY.....:...5".........\W.b&yl5 AHM.H.../(..................avqf.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\106__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1265
                                  Entropy (8bit):7.375685188257482
                                  Encrypted:false
                                  SSDEEP:24:9wS6eZC4M0mDFdkJGVRA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTmvuDcsBBpFl:eX2M/JdkJGzxAd4M9/xJfAXxuemGDhB1
                                  MD5:2124405D0BB10D05A126B6C46CCA22E8
                                  SHA1:BFAF674857BA3A4BAE290CE14B3B61C4E4367F85
                                  SHA-256:91D7CE30359331A6EDF4E423F57F939DBB4A495B51411C0FB5914E50A6582F8F
                                  SHA-512:E9E12EEDD4152531CC15BFC641DC6511444D932924F728EC90774FB34799C3F5D7449E1AD3D2492BF4F08D66ADAA472AC284E61450AD46371BACA3E139BA2854
                                  Malicious:false
                                  Preview: bpt....i%JYihUS..*9..*(..95nc4=TK..].G]....DN....`8y"`v..;...rd.." ZC;!db........%%..U\'4..0'..YD..YT_J,3........%(.....UC#?VQDD)).J........XE.W..*?2-.d2........LG#Q.......8S..0;3A5 2%..._+.3'P'.._@^3..........MMM...'4>)....@].S..%0..&.Pu......4........'.....yy..6*.....D.?ZVT<&...<..PF....OU".....w`..9a..4.......................K..16.t{.-....``vj......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\107__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.784616734439496
                                  Encrypted:false
                                  SSDEEP:24:6tSABO2X84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYxkUzfXF2tDFvy8Bp+JgW5n:60ABO2sAd4M9/xJfAXxujv158B0fF
                                  MD5:CE0E9A7015E2239975016223323AE133
                                  SHA1:A53F34689A4BAACCF28DD8981C1C3C23E8D15583
                                  SHA-256:0C143D344CB9D2E4FBC93B061284C4C8311DDB66F82365743B90F6FE9B140180
                                  SHA-512:74108ABC6B9BC178A37121B74A82EB09B2AAEF9824DA4950DDA7F4B5ECC59B20286CDEA68E2EFDBFF52D9F90D481D154E035DA73624DB8AAEFB123D1AC240603
                                  Malicious:false
                                  Preview: .@.f!...DDShr..wh.....gj....z .xj......cl..DGib..A]..KJ?8q:O^....fy~d..+,&%EI4.U.ey.......0+......2@......RS..R.6.......en..20ud.......V...\.::...^...>..%%....H[..0!..mj...M.....p"...b)..4!..-(A._^....g3.J...B......'xx.....;0xk..SBJQ..IC.."+..49.........ynpJ..2/'..^..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{"D.+.(..."+...}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\108__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.71007606473447
                                  Encrypted:false
                                  SSDEEP:24:mU/0tkMm2AbywVYK84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/i5hUzfXF2tDFvye:SkMm2AbqvAd4M9/xJfAXxumi5Q158B5V
                                  MD5:C7602C1036BA92F74F19D804AAF84877
                                  SHA1:705A0DC83D8F9DD30417F8B49F3CA93FFD0AA104
                                  SHA-256:704F1A385E5BA30C20F78AEC4A1F913753077E99F9342128F6ECD30A6CBE7D17
                                  SHA-512:98A8DA2FBD7E34C563CDF203FC129E16B7296B36CF491F4703EC8F6E53EEAA30D9C472FCF0648BF98CD0C8FB17FCB11E6E2DE109D2A03F73247DB769B18C98EF
                                  Malicious:false
                                  Preview: .......W......}b9&..H......._.8o....zx..r}rwuv..:%..T.&'..F....T..MR.......&*Qb.#]A........=&..-'..OF......*N.5...........}.........D..x .$-CZ.......~~..*64?....sb....?k...~......>..uh...........kw29......NU......\U..._(pf.....%..........]].......>2{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..:.I...&!-...=}{.}{522}{00004900004800005600009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\109__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.6950437980710635
                                  Encrypted:false
                                  SSDEEP:24:wtnwlkks84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjNXg/VUzfXF2tDFvyv2+JgWQ:swlkktAd4M9/xJfAXxuAgs15vRfQ
                                  MD5:6F5F780EB2081270D76DF6F4A786D2DC
                                  SHA1:73AFF3AFAA3FC3C2DC6B3709D22BFEB42DFA4405
                                  SHA-256:1CFF04347FE8E032DBD7748A7B404F28F1ED68F9BCD86D8A22D42C4BFA3156F7
                                  SHA-512:DD3408B06D9AB30514939E192F86E852DEB0E334E4BD92E0EF25C165EADF5437A608AFF99ABC7C63919D3ED99DFF995D4CBF5C91C5C125D8D0C647B40C0035AC
                                  Malicious:false
                                  Preview: ........I.7 ..XY..!>......PWG..U......"-@E....GX..,}`a...O......WH~dbcni......{Q..*!(;`b........,%0hy.....j@uu......GE....|{@J.....PYY@{v..{HOe......;0..ZX..JQ61...of.D..5.....+6HA_.uF%.....$8....Q@d...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{JB...l(:.k....Ko}{.}{439}{00004900004800005700009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\10__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.387594372083005
                                  Encrypted:false
                                  SSDEEP:24:sF1Zz2o9Yx7l384tFoze4ytP6qfHSgC0fNSZBzfteJTQR5KBBpFUBQ+JgW5I:sN2o9e7lMAd4M9/xJfAXxuU6BpFUBvfS
                                  MD5:BE0C9CCA59A11BDF0595264FF0B6F58A
                                  SHA1:175B45AA6F2AD433117B21683CD2509E26220FAF
                                  SHA-256:DCF1CD75BD91799371714AA3D660B734C861FFDD2F5A2FD0C1E8CD07698B3405
                                  SHA-512:C3DC213B3AC6A39C08043197280CE15EB4021B5BD2B6B03D28FFA8EB0DFC54B1F940A65094E8AF77B827317C31D0905961283F6D04B201A01F8B6F8682DE50AF
                                  Malicious:false
                                  Preview: .|x....[...ml..V.8+......=1....EZUT....y*........T. {......zL.............YPv}.M..gg3lT]YJ.......+h...'8FH..ha=$zw ...; ..< ..LL...Ct}......si...O..*?...0..6?.............../lx.}HZ..N#......URss.....DCJ..xo..{aORq2....GX..$...t~LCDdsz2+.........AA.............g><..80..../9............pi......X.*ngr....d<..,*...EJ|O.....]................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\110__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.393563853667182
                                  Encrypted:false
                                  SSDEEP:24:dSs3gpQNN7UrM9R1sEkw84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5NZrBBpFUBQq:H3gpQN1AMNzkhAd4M9/xJfAXxuCZ1BpM
                                  MD5:09283FD25CF14D38CB67C309013AB77A
                                  SHA1:D36F6B961002C9423613EBFDBC7078810077B538
                                  SHA-256:28164B2C7E9DFCDFE0B655DA7C1578BB124034F6FE7B57E81B0FF567A60164B1
                                  SHA-512:CDBCF33B772654BBDAAF64804BF5AF627B3A738CEFE4CDDAC491D6737ACF70C38382D61E70E2F9794C6DE128775ECA0D49CDF3A4DE707E5E365949C44CF23141
                                  Malicious:false
                                  Preview: +..&y>...... :...`VI....q|...../x........MBZ_C@..gx...GF..o$..."?HW....st......Dnyeod~mSQ.....pz.Y....#B....;;......OI..`1..pZ..nr..dw........hb.KBC..d......#f.....<..(`...(&HB...R^HH..[V."4}.Yj....BB....3 ..................\...DKbh^x66....*6....cc......yjW.P_....h...xq....99....yC....1g|qn~*5../>..........S^.............n..$$..kk............dc..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\111__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:Encore unsupported executable not stripped - version 21521
                                  Category:dropped
                                  Size (bytes):1380
                                  Entropy (8bit):6.602573426536069
                                  Encrypted:false
                                  SSDEEP:24:RA6k6pkG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzOZq3UzfXF2tA63yrb+JgW5w:CT7Ad4M9/xJfAXxu8OZq21EY6fu
                                  MD5:11CFD1ADAE261455CF064EB8F18D896A
                                  SHA1:D0A918303DE98551E56BA418BA7F6629114D11F7
                                  SHA-256:842EC1679E772D4C7924B4BDE07C8FAB77C034691C51C086FE671A43C26591D9
                                  SHA-512:9C835E6C76961DC325C452E2266180CBB0D7F36E7A6E275C9A4524079CDE5C5CF14F0CC604E8EB11989C6C00409FA87F426EF759D59715F5318A475F9953D491
                                  Malicious:false
                                  Preview: U...]....O..lv{z.......T..5>\[..........96vsdgU^)6..&w.....&7E...^Aa{..}z....Pc..GLIZ..%4..&!XR[...U.@/.....2..................v"...E$..2+..x(..kA..99......HJ........\U.U...lV.5.........+*...gg....29....9(..vq...Q..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....k..o.a...Y1}{.}{451}{00004900004900004900009500009500006700010100010800010800011700010800
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\112__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2055
                                  Entropy (8bit):7.6844715508859816
                                  Encrypted:false
                                  SSDEEP:48:SQGT5ePY1YGq5ElUoPtfGWyAd4M9/xJfAXxu7ZSBpFUBvf0:SQKeAeM5GWtpBAXQ7Z+N
                                  MD5:99EE36F4771DD433F89A811016CDBDAB
                                  SHA1:45A44FE491DEC2206A1A70483B77EF45488863A7
                                  SHA-256:11CC7D1BC404EA043460A999800405C07BE6018675773D401CCB6FDFE9E351A3
                                  SHA-512:6815643154EBCAC672BBD6A56CD94B2A8C8B23472FDB90477807C1844BD30BBD57EAFA3A8D07BD84A8C40B4A66A7CEFE3284879C35C39DAA5E751BA0825AEC81
                                  Malicious:false
                                  Preview: Z.p....g1~i..ML......H.....AFZ...^K........bi......! ...I..m0..3,.............jv....@B...........%DBP.......Bi..DH...........qb75XI@[..W]s'............KX..T@H?.........TH..33nn..Q.XQ.."5.......k~b}...........PI..=mTg......c._N......N..|nl....jD55"4.......(......@YW.A.L[71.........NK......]B...5..omn.{|..33nn....QB..5$........;;.............P3PK..<..H.......ra.K....N..HJL>9.%*h[Mg..NNG[9(.....I..v..].s%...........KX........~|..9,58....`g<'ELOM....aa..........uz2:.............Y....9^......H]:3J.......L....3]w..%%vj7&..N...,t...._Iu@..NMqs............N....WSMT..dq.tulrE...%&y{...O.T.. 5.........|9.p............._H..&<......... GN....BXOR].#...8'evo.......`......az{vJ#i..qTg..........KX..........|(..(pc.....vp'(BH..\\.. 3.........;;c/........... !uR...,.......]g".J......._ZJ_y#..+a=tg#......,t....K...]n4.ssJJ..........OX.....Zmj..||..q= 3.V..~vsljG..IC..ca..........z+>......~y....PR....ooJJ[[....D...BJ.................$/.....42..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\113__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.274055637971655
                                  Encrypted:false
                                  SSDEEP:24:f521uWjxKuVLM4184tFoze4ytP6qfHSgC0fNSZBzfteJTQReZZhBBpFUBQ+JgW5e:nyGAd4M9/xJfAXxuNZZTBpFUBvfk
                                  MD5:4261CCCEB1770B3523646D72235C6ECF
                                  SHA1:331045A4C347F25122808C249941BFB9F87EF695
                                  SHA-256:95D60048B02EBD995DF3C71075D45C9783D6B9D30839A99290B0E14CC597F611
                                  SHA-512:CFA7CD2582EB8767D7AA87B3B772E39AB6FD4E92B32EC8A41F543AF27B36360A16BB953B7291781A75DB442783994F5B0D6281A7AD5BADEF84885BC51CECF932
                                  Malicious:false
                                  Preview: ...nm5 *f;(..ecG..=|bom..."..bk..yx4.uo..9,..m`}|i1p+(>dys@..{mY.|~=$$>..#$..hc....rrq...?,..i~{axe1r946#po..SOLE`y>3?...?$...2..,,rrq...?,..i~{axe1r946#po..mbNL,$.7# ..&d..<(.SA...d........22,,rrq..'?,..i~@Zxe1r94..po..z_..oe4;....!8?2T...,.CC..GG......U........ou............BX....ki...... u........`o....'2ID.;.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\114__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.346030394809917
                                  Encrypted:false
                                  SSDEEP:24:v7cvi2yUtCL9SPQt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZZkBBpFUBQ+JgW5t:zSWMAd4M9/xJfAXxu4ZMBpFUBvfv
                                  MD5:58D99F914AD3E621019DC0720084896E
                                  SHA1:8B3FA2B6486BB3E38625AFEE9569C8F5DDA2CDA1
                                  SHA-256:3421FB02D0ACF3DBB66828A6EC67FDCB233BCC57B440E282CD05D454EBF8F5C1
                                  SHA-512:070223C3EF9088269F633296E8F9A114FE2BB37894C32EE6A815285EF124D1B72C156F334BEE830DDB6A4F0D06B46102A31D7257B26EC60DFB0CBA80081DE469
                                  Malicious:false
                                  Preview: .R....*|............V...NE..S..(.............|..9&............R/2.........DH6.......m~..@Q..$#T^s'...I.GUEc}}=$..sXMK...]#.%.........75fwJQ9>..C.3:..%SJMB&]V'+..[S........#xl2E....<Q\K..0,kl....\\${......%2..1,........dARGICXW..}t.7.......<..AAuu..GV...IE[.C&....P~jj^H......>.....CTQH............f".....'..k:..07.Eje..(.uu..dx5y........mw.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\115__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.361169698193128
                                  Encrypted:false
                                  SSDEEP:24:nzqE59JwSw/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkrfZjBBpFUBQ+JgW5KT:zqE5Y0Ad4M9/xJfAXxuH7Z9BpFUBvfy
                                  MD5:53FE3F48B0A350B13FE30FD590193478
                                  SHA1:6E7ACDCDFFBAB455022E6A6FC84FB79FDAE46645
                                  SHA-256:A5DBBCB549D54D3EDE3097EFEB5133EF650BEE056E5A70E9558CDF5F6704A2F8
                                  SHA-512:E0D37FA079C6BB2BE35059F083756F6FC07A0ABC8165E4C56F288AE87A2559A929A68DC72CCA70D3F560FD390A3B6337CAAD3C07C046D1453C224C981899838D
                                  Malicious:false
                                  Preview: _....>+#opc..][......TV@K........I.@Z..mg49.....F..DY...+..,q...........-&..@G55...............?2#6......v{b......un....mj....j5..CPBU.._E...*'..a~.........YZ8+{0W;..BN*3.>gGK]]......{mM?o\........5>..+)........J.R[x .l..........dB..2+....@G.........jy....]U.....pW.....TT.........S.BO....RU....)8!#.......op..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\116__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1219
                                  Entropy (8bit):7.360617195195894
                                  Encrypted:false
                                  SSDEEP:24:81G7j15uscJ34Jmp84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwVRZ0csBBpFUBQ+e:X1zVAd4M9/xJfAXxufRZ0hBpFUBvfG
                                  MD5:0697E7F907F01A38C4347B888807D708
                                  SHA1:C40B8261F8C9144E2E9A9F5177B85304CC679FC7
                                  SHA-256:B7420BDF8E77C78974603B0F289AF7933687ECE1C7862C66501B9640CAB658AB
                                  SHA-512:947369849B69B8C4580293C48D277385F532FABD70CEE083F698D75CF070CA0D10642C8BF37ABE36D47CC0559AB2D13081C5B0DBED2B4486AB4E5CDBCF2D7D95
                                  Malicious:false
                                  Preview: ...LO..-a..LMdbJ.kx.......jg....yx.......:0....5m..K]..N}....\..........GNMFw*"%..........K\..8%....VC............."........TStt...O...>)....OR.ZWta....sv.Or}CK..ij..s1m[..n.O]OP.....\@......TT{$ZS2!..l{ :..)j..A^....WBXR......vo....2.@jZZ..))....%:?q...[>........bbK]....+1hGld;92%..9a............y`%,..a+>w..}h....S.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\117__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1464
                                  Entropy (8bit):7.469009343515092
                                  Encrypted:false
                                  SSDEEP:24:nOfEKifvByGRl7utC6YfTmMlra8PnEsMDcxgD284tFoze4ytP6qfHSgC0fNSZBzz:nOfEKifoGKtC3Tm0nErAx4rAd4M9/xJU
                                  MD5:8B89BD263AAE3B42176974A666E26168
                                  SHA1:25ED9EE1494D57A389CC1DF3DFEDBE3F4753EAA6
                                  SHA-256:F40C8623FA0BB02FAF1C36513737F1C47B26CA3E6BA36CFF964E366A40EB5B6A
                                  SHA-512:8A0240822296ADC159C71C4C98CE7344861853D2F829074A6D9545C920BD1E4F51663471684B1E90773CAB38C46A12FFFBDBF87D43DFC5E78ADCDBCF10334CB7
                                  Malicious:false
                                  Preview: v?;....q=..pq..B...................w<SI....{q$)HI..Q.........."....='..8?.....Pqvzz...BQ..ny..~c......op......<%..zM...../3......(wv............CN"7...1`s.\m.WUPW39"-.....-(v<bT.....*59T.9......66gg&y...."5fq..a|y:..*?....Da..t~{t.3.....Cp..11##992.SB.._.....!D......^p.....+..='!.'/?=.......[....{?K^../&n6.....8}...*.3....6*.......{l?%OR6k..77..wwc/...Hs|..............^G.........yld{..)2..............uf....YF.......5"...q.NhI.[O...BW..0h.f`07...+..9..@@:&........S!..$;qg...wt..#4..._.......WYF....}d.....HVu g5................d<r#71{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\118__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.344112174601905
                                  Encrypted:false
                                  SSDEEP:24:YfLZqHDohTDCl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMZoBBpFUBQ+JgW5E:Y1qjqe2Ad4M9/xJfAXxuhZgBpFUBvf+
                                  MD5:55D25E2E7159D6BEAAA98910AB59D135
                                  SHA1:273CAAAF4A9799349D7457C01C38EF80513E8A5F
                                  SHA-256:5AD8EDADCBA9E58CFD9CB0C99F99EC37EE16F9E910AE2A2138E1BEED0387D259
                                  SHA-512:6763F4E0205832328208DC76D8755D4FF336D54C7450C3B318677B765A5CE303CCCA83844F1FCAD9E2E92885A3A4D351E4B97FEF85469DC9A82CF636D00BC7A0
                                  Malicious:false
                                  Preview: -......`,AR..USs wd..13.%..|qof..TU..........tu......gz......].......WQ.....k6............5"kq.................6;5.g}.... <......E.......xb.........ze...nqe..[6.......q(..{{YBbo$M..u.o\..EE..................bk.....1....SY..............==..jjT....^Q)!`..hde....{Y?9..:...mW...'qCN...........RW...#..*5 '....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\119__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.375330753395914
                                  Encrypted:false
                                  SSDEEP:24:mnT5SVczwakl84tFoze4ytP6qfHSgC0fNSZBzfteJTQReZl/VBBpFUBQ+JgW51:mnTEt2Ad4M9/xJfAXxunZlvBpFUBvfX
                                  MD5:1AA70E3A174E8F17CB28F33BC1F61401
                                  SHA1:00074A0FAD76C33BEE30E6E8F2FB2ABD9F908833
                                  SHA-256:2D5C69162804D28C2089488E66CFC9C4C84B3E0BCA31B74A3CD6F14555202331
                                  SHA-512:F40B8285D2C91739CFBF75EF7CC27D0ACCF20A2C2F7F70EB72024F81B22A63DCB3DDA04762612022FB29223D01B8A192730053DB45FE6C852118ADFBC1DE69E5
                                  Malicious:false
                                  Preview: .z...nor$..E_XY..vd.D1<..`g.W.[..j...JM......odxgplU.[Z.....,q.....ih......cI....dw8:zk....<6.Hmd........UL.................CPhj..QJ..RX....4B..*).....YN#.....3>H..BN[[..EH....Gt/.........KIud..........,J......p.@JiOWW..JYDX07..++MM...............ed.."+..........?........aqZEEB#2jv?...........%)P.nh..72..........yb......{|..))bb..?4`sTV....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\11__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1521
                                  Entropy (8bit):7.504403334856311
                                  Encrypted:false
                                  SSDEEP:24:1bUpApxj1nF4nxB7MtNrpm3s45NlkSSZyBR84tFoze4ytP6qfHSgC0fNSZBzfteK:1b9j1nF4nXMQsU5SZyBiAd4M9/xJfAXj
                                  MD5:B7651EBD47FBE30F97C07A40DA20468E
                                  SHA1:AF6DB7527042300F4D6E6E0E737678F1DC80B313
                                  SHA-256:7B94D7ECCE722F434C9BFF70133242324E76BBFBBE52D4FEF7557BF237182B76
                                  SHA-512:A761D4F0189F7F371F1E53ABDE106A2AB7FEAD4F5874A0A07505C6B115CF990D40951DC68A37860EC8BB797A2421E9376198F20AFD4D89E293956AD173B47218
                                  Malicious:false
                                  Preview: ...y............6):%..........T{,-?..............................................CH3 31...................##:#....f`{w.KWd......CHcpca...................6,01...........!$,d.I...............................]G@].I......dEVsJ_YS.... ))0..........+++7.........TK.....NFOa........................................STR;<5p....bHHH................GZP..................."9/mg[z..AV...]0#02..............LNAPEBhheeee....].^Q...............(po................]Z\.......%................XG5x.}b)?I|z`5602.......A.)(.OA^..{.OVCD{n.D..wi...fe..uqQ.........j2...-*f#.....4RR..TH........^)..1.AMX...'*..........}tza+"..J.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\120__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.389689251371517
                                  Encrypted:false
                                  SSDEEP:24:Lg1L+524mS0bjAkFBipiZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGfBBpFUBQ+6:B24mS7oKAd4M9/xJfAXxujJBpFUBvfS
                                  MD5:6045FC8245DDDE655C4751771C460995
                                  SHA1:06664249553F36BBDA54AC41B3984666F309C91A
                                  SHA-256:AFF6586D82A65957E3BE4A59BC1F615EAC86549CEFC2E6CEE9F5B52176601323
                                  SHA-512:39688BD5342A11232CB0365706E4CD29037F740CAAF24EF2F31567820D24F4A548241DBF4D0295FFBB7E7F8A5BA0E8793BFE400F6CEC6BC02FC91D44A4062C85
                                  Malicious:false
                                  Preview: [..ab.....................[RTK..........W]..cb..S.XN/2H{....h5.......,+W^...E..##*u )..ynds........]B..G[/&........................iz....|f......*?....*!.....rlquR$......g|..m.......2....vj..pcQS+:......X.u|.I~...Rq/).......ipEV\@x.....22...o|.....ctcb...........\[..R^.Z.........../(..in;9...ehCV.`..UNkbVT....LLjj55..-&..zx..lw.....dN&&..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\121__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.810680162230986
                                  Encrypted:false
                                  SSDEEP:24:zMRUEfHt5rOkH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRv3gUzfXF2tDFvy8Bp+d:k5fNtOkcAd4M9/xJfAXxuk37158B0fF
                                  MD5:CF00FDA73DF7836086F83559C978551E
                                  SHA1:6DA4C3E1C8A9E01DA67ABBEB6DE8BF2883D8888B
                                  SHA-256:8C08B3F094E7761D3EBAEA66D8486ED2BA78D59C3F0A5D5472C13781407F8346
                                  SHA-512:75DE2751809BBA55CA99F9DB6461C331D91CF4A9B435C6671210DAA333F541B9D6045DE8206ECA37689335E67C0B5E003F7E589E9DCC017A85003198C3C4346B
                                  Malicious:false
                                  Preview: ....;|qp.mz..........4q....urC.F..._J..QV/ [^)*_TVI...98:=&m,=....nq..QP....?.^t......=?.........G..Z..g....g}....J..=.'......BQ........Y.....x ...Z........c..........EBhbS...9a.9b....L..im>+*x;>$k#"fx....R........+..**..........8).....\.-$..ID.......=.`....dZGV.b<5.r..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..z...C.>sR....}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\122__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.705382507140261
                                  Encrypted:false
                                  SSDEEP:24:z9jbpvt84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4E2UzfXF2tDFvy8BXCL+JgW5v:h8Ad4M9/xJfAXxuxER158B5ft
                                  MD5:9F8ED31087ABDFAFE25C30F6CCB2DD7C
                                  SHA1:41838D4CEDDE73133F6CB362087122B5A5CD60EE
                                  SHA-256:2377988DBD0C49CC24EA0C693C48FC715C08D628327099E8D9D610AF3FEB1426
                                  SHA-512:07A99C0711EDF496311F7A00CB3CB104E4523264FC0B2F3AD1001175BD23EBD80EB799C998D019053558EB9FC4983598A4F2924C07B069578B145EE6A0FD1405
                                  Malicious:false
                                  Preview: V..PS.*+<j....HI..$;%7.......@ w......vq!.$!x{.....gfDCu>.........cb?812..#.................F.....tzj..=....vj......ud..|{flg3~wH..n...........5555iu\W....CRWL....I.jc.....................ii..""< .....2#yb.......'.$"F1?)gg...~MKaww....TT..n.xg.^R{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{%.....0..=.5....}{.}{522}{00004900005000005000009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\123__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.68995633977637
                                  Encrypted:false
                                  SSDEEP:24:gwhC2I2PRQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRlF5VUzfXF2tDFvyv2+JgW6:hhCv8BAd4M9/xJfAXxuMTk15vRfBs
                                  MD5:EA05E2C6744B483A96B175F6CE3D8A4C
                                  SHA1:ED233C2B872E3A6C1843B49A67F38C966FD8EEC0
                                  SHA-256:54E2AF2902DBD76F49F1744A04C28BAFB3FF3750CC5A25850AAD080461046F5F
                                  SHA-512:76C5BE00D409C492FB0A1A1E7CF21A7ACCC007C7668C3B822801797ED317DC014180956ECE819F65A58519992FA751B4C40946576B2293931630B3B8F420F07D
                                  Malicious:false
                                  Preview: c7...Y/...fq^D....!>....6;?4..6l........vy....W\....H...=:.Q.....D[..DC..ma....pl..>-ca..cx.....}to7]2k{.n...........LNM\....|vN...!y...'hqty...5.%............0!..<;..7c...V$PG..Fx......l_T~rr......38....#2+0BE..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{C$......|.....x}{.}{442}{000049000050000051000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\124__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):7.4294602196019675
                                  Encrypted:false
                                  SSDEEP:24:e8X76ENnUjaEkOcveM0m8cI84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpYBBpFUBL:e8Xfgarv908Ad4M9/xJfAXxuQQBpFUBL
                                  MD5:5B7C15804AC67A9899233C46B75774D9
                                  SHA1:4D29740E5DA3DF734D4F18EED65A4FF704C9D122
                                  SHA-256:88AEACABA7094B37AAA2548DD006B30E55EDB6791C9D32F0A2BDB37E8792491D
                                  SHA-512:3D82EA36F49EF447D5AD24BCC49203D7951C8F1009252B27B9795702BCDE7C590BD498340FEAFCC9F77C7B82059452FE116137221EBECB5A7523875B87E9015D
                                  Malicious:false
                                  Preview: .2.cb..{a....YF..H.2?.....@.!3..wu............SO..-,..D.....c~..bxNO........w]...... "..3(..`j.py.u.0".2..............:...B^..........KAO.[R~&}...>9...(...v"....... y, ..G\...../].<.#....?#..~m....LW..|v...........gh]W..XX..VE5):=..ZZ//ZZ.........(7REGF......RR..?8.....R......CD.........z{.@{p\...MXgr..a9$u............DD..ui.J.........._.....tt..._L=p}r/'....,:J@.9..oxxa.........~s..ju..-6.......ii{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\125__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.362584723668688
                                  Encrypted:false
                                  SSDEEP:24:R6SAAHWI292NsWtbzbRCJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRB3BBpFUBQ+6:3AA2I2dkzbRAd4M9/xJfAXxuMRBpFUBS
                                  MD5:D937E73F2BAF1847A62E95CCA01942B6
                                  SHA1:E8E4880C3081AE79C48CD6FD1FBC3B0B65628668
                                  SHA-256:0A63FB4123C42BE246F35CEE51F6709755C91741028D73FABA44D211DEBCE5CC
                                  SHA-512:4A6DDA05004C0F8658422C2A1D9EFAEED3B92BFD5DF082469E081327E1EE428083F7A9CE40BF3E43BB0F4E8B88CB909CD500BA7A6BA0F6DADC8AF5D045C8838E
                                  Malicious:false
                                  Preview: x..bw|0..-,........\^..W[....hwon...."7t~XU[Z.......}K/9.....|f....EL^U......:ev.............~sMX.............:..az3%..ni...^.........uo..J...7"..fW....cv.....C..5+OK.......2?......)....[[plsx 3jh..vm.........FR4....HN....eCYY.........((..&&..M^..S\............................Ifk..SL.....#TA....*?OB2'......81df..52""WW..uf....GE.....:0....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\126__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1484
                                  Entropy (8bit):7.484418735331296
                                  Encrypted:false
                                  SSDEEP:24:z1WpizkDK3YwFW+wHNSA4xJX9h84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4gXcs6:z12izBIwfwHAAYiAd4M9/xJfAXxuLgh0
                                  MD5:991B3984A3FE8ED00DFFA2FEC93DBA4E
                                  SHA1:D6A27E767B19EFD501CD4F421C935469BAEF2E3D
                                  SHA-256:011C1CF3E8355BA32C8B6A7ADB35A24A2E8392EF42C20F792B4C21AD43723A44
                                  SHA-512:BBE951EE11949257656ACB2B1CDEB52A507D40ABA56E71B29F403450F212A437DC0357EE00806C7DCA1E5A8ED8E31CEB1419A8F30D48D36031429673EF6C629D
                                  Malicious:false
                                  Preview: .}y..cvT.o|kj.............18.......N.......;:....SN.>9....Ib`}d..hn....v}y$$#...D..CPRE..2(....he.j..ekht............;'......)vgn</-:RE..........mr.<..2}.....F\wryd.@.....^E..>W@V.z..Oeee....%.'4..UD$?%"..................0...@YH[zfURLL......=q............:...,.............W.......(+d+.........../0af:!........22......S@SQ..cx....qBeOUUUUnr.....R.f.(3vnWk..`mjz..pc............z|~y.....!................a....O.C...0 ..TMr0.?=..WB..LY3,.......CROH.......FU..../'...!WWMU......Y@(p..<)......zwqdsl......57..pw....ee.Q#0L.................%szw..1..44;:j<....3)}-{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\127__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.358573659758341
                                  Encrypted:false
                                  SSDEEP:24:cVCtb47kqL4bzDNM84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+dRBBpFUBQ+JgW5Q:CCtb47kqL4b7Ad4M9/xJfAXxu3dDBpFv
                                  MD5:8CA8F700250E45CB5C869EDD21370418
                                  SHA1:9456F1233DFE8CA90DE7E5DB0E40D1BDE4B5F370
                                  SHA-256:104CAB30CB136F1AFC125DBDAD914809DAD2853A10091EDAAB34F30C480E0654
                                  SHA-512:868DD7FE9AB71C176C4F7AA2A582A6FBB77CD87496CA17BEB6A6B790FA83549CD558232813711C6E589076E95420428AFBC8D59867127AC6F02879743568EF81
                                  Malicious:false
                                  Preview: ....N[,`....lj.@..y{.....@I..CBF....4!;1..ed...I....vE....h5..0)[A......mf.W..22_...tgmz..A[QL..m`)<]B....U\..,!....AZoyyeLK::....LE......7*............}t.......>"Q....t.Y.bT...~......j{g{..KKoo...O[RJY`w.....U....!>..Up............obm=.".)......]A....._Sb:S6..mwrzn@..\J..-+wmEj80><RE...h#.......]......zi....8-}h..q)m<..wp....9..1............w`+<..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\128__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1487
                                  Entropy (8bit):7.517259657821522
                                  Encrypted:false
                                  SSDEEP:24:i0LN+SivRBe2YfGyOoXA5wQyyWfzcrSwHG84tFoze4ytP6qfHSgC0fNSZBzfteJT:BLDMLyKiAWMAd4M9/xJfAXxu88BpFUBK
                                  MD5:5A6CDB0CAFA604BDF5524F3B80653F09
                                  SHA1:E65C90E982EF922335C4D38283F5661F9CAA72B7
                                  SHA-256:664E146D09584613A23B0B70B31F1188EF9B98640AFA2D19FB6EBC8087A425E1
                                  SHA-512:303DCDFCB9301D7F3CFCAB2033137F77B2E9E0DB33F24F527F71FE851E5F1DEC050B2AE37CA37C6AFFC20E836A0042F5DA242BEB8B56570ACC0DC2FD6DFDC815
                                  Malicious:false
                                  Preview: t 6.......>$76.....@?2....V.s$xj..B@cd..PUJIfm....y(....|7?...SLF\KJ>9..OC.._uye..jyKI....(/..g3..-u.g.....Y@....pv1=2cs@..]]....GT..<-....OE.T@I.........3........%|....6-...g..............hc....bsPK.....BQX......zY.......=GG....MQ......UUMMD.7$7z5:...."#.?u|......jUHO....,k.........ZT..'('mzgt|...Hn*........d5..jm.)&..|V@@.....^..L_.........G..xxgg.......rzyf..DR:0..VT?(jsz"@S,......'2....KP......34....__.P..~3..JB..vo.5.......|$...I...k/xm.....J....8?....7_u..aa4(....O....s...POV@<...wt......D.n.L.45u$....lhy`fa..d4.......jhY]"fg#PE....d<.....F.....*...gg....ZE{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\129__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.784444840566737
                                  Encrypted:false
                                  SSDEEP:24:2+vORtywOeK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRoup/VUzfXF2tDFvy8Bp+U:TYt4GAd4M9/xJfAXxu9ups158B0fc
                                  MD5:38305A973B5FC4152746D017EE606A26
                                  SHA1:998C25C4D3DC629AF7D60001C8C27CA10108997B
                                  SHA-256:9FE7C7AA0690FE1A17BA5A6D5A0B4D32F6FF4397A35DFC9239E43FBB4FAEB308
                                  SHA-512:D568FC84E8E8050131E287D93F6D1131E7D77D3015CEDFE852D892ED960969783B4C6E686B3BCA48EDFF4D530CC8C35F949AC5B1AD70AF0B13FB2AA7A073D9A3
                                  Malicious:false
                                  Preview: .NJHK..@.JYgf....m~FX#!}v..~s..ls..^.`z.M..oe..()*r.^H(5......OMy`f|hn?8..........k4..8+..2%G]....}pqd............+"..[\..IIY.<5..gp..D^...Fjg.....AW......((..NN.......<+..............VCB_...?l#*...O...\.......?k..ge...........!!.C...............0%[D.3:..- V....2....++....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{N.?mv.....YL}j.}{.}{564}{00004900005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\12__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1381
                                  Entropy (8bit):6.647544330454282
                                  Encrypted:false
                                  SSDEEP:24:argfTg4hnPbHO84tFoze4ytP6qfHSgC0fNSZBzfteJTQRppzUzfXF2tA63yrb+Jz:arg7RAd4M9/xJfAXxu2y1EY6fB
                                  MD5:0C23ADAF2B9057BF8E769DF32D9EBC2F
                                  SHA1:7B6BFEE2A608D01BDA13401C9CD35D8017970DC7
                                  SHA-256:D4A2F54AE6BB44F48197933636006F98F487273E7CC4DBFD11A2BCC9E11F1346
                                  SHA-512:B14AB5724B21724340875924FF700632E039B6E7CC64F86DF2F29E442B8F6942C9F2DB7FCAE584104DE3BF507BA5448A34E60C0736D4051E2EDFC621CA3953CC
                                  Malicious:false
                                  Preview: BBFyz.....sr..........id....+*.Z@Z...T^..fg........=.9....#!....Y_..T].......\.!(..MZ..SI................]Z[[..[...BQL[..tn.....+>........GT.."%.......of........+6..0=..JU!.........34....!&......``.....yn..$>..(kNC..6)co..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{d..wc.........$}{.}{464}{0000490000500000950000950000670001010001080001080001170001080
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\130__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.681293635339587
                                  Encrypted:false
                                  SSDEEP:24:TE4zzpVjeo84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhQUzfXF2tDFvy8BXCL+Jg+:jzLje5Ad4M9/xJfAXxuor158B5fP
                                  MD5:ED6A767354DCD95BA85E42077B71E64E
                                  SHA1:309A280A9049944771C255DCE96C16244FBBB7C4
                                  SHA-256:FF8EC8DAEA3EC65C05CFE039CD5ACBDB3F08686D4516E8E37806198B095136EC
                                  SHA-512:C9ADCB24CE0DEAC7376938280C4F203D16274C4641CDC4BC678D1E566F5162BF939850BBAC8EC05781B5E7C4B81D4564FE77D0A062E916105618074347359349
                                  Malicious:false
                                  Preview: .:.]...D.2%....MRKT..1tbo2934{! w..]H......05..7<..`|E.ML...WF......>$..{|..ei..............:!.....kb.......mFu..................>4H."+^.T5..d}...Yj..xx............5...93....................Fu$.==SS.................18.>8...((p}..eVhB..kk..........b,{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..R..MFQ.=[P. }{.}{519}{0000490000510000480000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\131__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.695486106574192
                                  Encrypted:false
                                  SSDEEP:24:xopDKHur84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+PUzfXF2tDFvyv2+JgW5r:0BwAd4M9/xJfAXxuL+15vRf1
                                  MD5:DC532FEED2E1D52AB027CB0FEF90D8D9
                                  SHA1:27C6F48B2682C329A78DCCBCC8B5FCFA5BBE4672
                                  SHA-256:EC2552BB8701CCB0D3B030D39644C504EF5FF9E522F11BAF391CBE47ADF77A6D
                                  SHA-512:D57F31A1B17880211816572D725984CB80C5A38D20E45982D7A094460CA4B01EA86D58378640C41F6FF0159A1A90E716115D4891382DF2282BAC5FC87EC621F3
                                  Malicious:false
                                  Preview: .....qd.~mBC53X...tjNLmf:6../&..^_.qk.....`mZ[......24....[zx......TS......DC........i~CT..9$......GX....SO.......R......../5..C.0=.....=...7${g....ZZ$$..........t7......_j..swm[......kw8?....KKll..81....;,....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{/.I;.*.BB.......}{.}{441}{0000490000510000490000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\132__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.371706541920759
                                  Encrypted:false
                                  SSDEEP:24:KU3W/aIC/7U84tFoze4ytP6qfHSgC0fNSZBzfteJTQRj5BBpFUBQ+JgW5P:KUkCT1Ad4M9/xJfAXxuSbBpFUBvfN
                                  MD5:EC9E690C8AAA4FCD36F03B25B54C1C19
                                  SHA1:4FBD5CDFB3DD88B3FDFA5B6B54D0BA627BDAE9F8
                                  SHA-256:9ADFB44061E7029EA8C97867FDEA7940D054B395B74F7D24830F8BD90044826D
                                  SHA-512:BECE1F101AF845F5BABA989216368AE2A30DDEFC4755896E637C206D59713A7CF97DBBF78DF739D7CFFD8D41FF8C41F3849262CAE9A84ADCA5E550F6CCDCD910
                                  Malicious:false
                                  Preview: O...i.MLW.....)(juXGbp....u~...........('..............\[^...4i..:%.._^.x^]^Rs@2...K@dw..2#<':=dn......a..{]33..N].4..jf.5...EE..$/DWsq..ybKLhb..u|..~...I[..ru....og'...TSw?7.VBu.9+.`..`w....SS.....P.........}`........]|Mh........:3....F.................OCU.!D\^....P~....Fe...>.....fq..G.C.....aj.@.j...........U.P_..j@..//:&.ah.."5.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\133__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1483
                                  Entropy (8bit):7.523073268776449
                                  Encrypted:false
                                  SSDEEP:24:8+m9NKFmksJWa74qeLBqpCQ584tFoze4ytP6qfHSgC0fNSZBzfteJTQRH3uqBBpF:9EzYxrQqAd4M9/xJfAXxuY+aBpFUBvfW
                                  MD5:7DB8036FF65E388C83F67D330C6AD9F7
                                  SHA1:DA76E3999E8E7BB9B7929BDADC9799C85A183FDA
                                  SHA-256:B6CCACB28EAF47559CACB082918F2E11F24F9B047162CEA407A0917026743885
                                  SHA-512:359B45D77D770B3AB3467685BE72463A051B154BD180F298095FEFCB8F2450AA3678F8260B8AA98E4A44B1AB3E864FCE3D3023184F09DF5D01C85412F3CB8AF1
                                  Malicious:false
                                  Preview: .*...}|..VA........;~p}..fa...kyTA....T[`ex{..SL.....oh...e8....IS*+.....&.....&-ev....@[....s'..O.....gg:#..,.US..:k}NeONNVJ..zi..VGnu....e1XQm5......Aw..LK.VI.MYj..."=*G..rclp..mmUUjj...........H.XUDQ....>.PE..bm.-...._R9i............yhhw......#!..........aB..........TC.....L....]V._..p*......Q\..nq..'<....*;..99........WD....&=[\aks@......l}.............5...0=..@_..i-...............IzNd....@\>/..&h...R..#'..z=.....qn....rp..vc....5*Y^lwmd.....99AA......VY*"tk.....nL.......cnRB..6`.....BxdMOWM.........88._...VR......fs.._J&9kl....qshy....99%6jatg....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\134__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.8082838866146975
                                  Encrypted:false
                                  SSDEEP:24:zXwmszFURP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwJqZ7UzfXF2tDFvy8Bp+JA:zXwMREAd4M9/xJfAXxuZqZK158B0fW
                                  MD5:30FA9D323ED91AD03DF2E48CC68BD347
                                  SHA1:0B163323518353AE118D0D1992EE73DD5F1DEDAF
                                  SHA-256:4412F3E9ED35A4C83C4A46DAD34AA5C23E8044F9E37B60A3EC8212905BD00D95
                                  SHA-512:1FD497DAC78127D67EF439B8026DA67B7C57DAFFB79D8414678EFE20AE796E065F5E0342FE45E93E427C99C06C3D1254F7F0E504965C4D21B1B0B8204EBCC8B3
                                  Malicious:false
                                  Preview: ...TW.....DECE..........EH....lm?t..9jMX....VWX............................?8..p/ZS..........J...rmb@..&<..[\(!.........'.%6..*=.................plTS....+t..5&........t7fk....=%.W.....[.fosj..........$r....8`8:..rn..mmKK.......VExotc..3....GR&9m......-pRg..EAFp..TS{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..........b....}{.}{560}{0000490000510
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\135__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.6846016317210655
                                  Encrypted:false
                                  SSDEEP:24:6jYDs+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRccUzfXF2tDFvy8BXCL+JgW5e:eYDsAd4M9/xJfAXxuJX158B5fk
                                  MD5:90D90E04DD60A65037D63D88A774700C
                                  SHA1:5AB50F871971E486F607CCB7DABF7D7E1DC61D3A
                                  SHA-256:55A0E3A77974A1C134E85BA4404F8E3195EA0FFB95F4EE5C33D7AFA66B020886
                                  SHA-512:258A6D31243D20073CBEBFD50EE8B3452C3A2C3DF7A9B06D6F153DC7F0E178108059D438CDF87A09518EB29D3567048C55D5AAD2500A11ACB24896FA0831BBAD
                                  Malicious:false
                                  Preview: .CGEF9,....z{F@.....hc........^_.Z....."(wz..s+........y$tv8!?%)/\[90SXS.wp..;d..(;AV......a".................. -$6%@W......].......aG....9*.........1n09..W@..0*...........Ed..aW....(<......zz..ww;d......W@.....7:..LS..aaeo.$...+,KK........[...E.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{gs...)%..<..l4.}{.}{517}{00004900005100005300009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\136__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.700390585925123
                                  Encrypted:false
                                  SSDEEP:24:mYQMZe4084tFoze4ytP6qfHSgC0fNSZBzfteJTQR0uhtcsUzfXF2tDFvyv2+JgWM:mw3Ad4M9/xJfAXxuShtG15vRfM
                                  MD5:C417E58FFC96A5FBF13DAD1DE9036C3E
                                  SHA1:958FF19945FD8C55C1764E5F40E4BDB40F706696
                                  SHA-256:10AD671071159189C313A35B0881241C30656331F2012105C945BAC908AF5C85
                                  SHA-512:D50778490781994296C492186B4A0ED2997CE991A8A46A016CF71C75263B56F045D14AD299358878C1DECA391FADFAEF8E602DD8E95D234F9CE394A8B89D08D8
                                  Malicious:false
                                  Preview: ....:}..d2,;......wh............Cr`......~qPU..29.........S.-<..gz..+1MLpw..[W............kz......._V!y.2"s.[hRx992......... ;&!...KB...18....v&?.Lf..tt....kx.....5-*/%.YP.M.d....dZ....ZS.&.Xr!!..4(....df..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....P..3U.l.}{.}{431}{000049000051000054000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\137__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1483
                                  Entropy (8bit):7.521343842169319
                                  Encrypted:false
                                  SSDEEP:24:50ek8IAmo8kQr/WvotSGBdZWC6rtEzsY84tFoze4ytP6qfHSgC0fNSZBzfteJTQg:50ek8IAmo1QbWxGBH4izspAd4M9/xJfP
                                  MD5:DE30B429FB44B1008BF5E07C1DDB9825
                                  SHA1:2EEE88E01D62BF12E0575E8133C1463D5174A1BE
                                  SHA-256:EFA601225D1274436B3BE3A56280BB0229BC7FA933F7FBC8C263A03254212406
                                  SHA-512:B14154D9247F835FF94BB8F33A3A34FA2772EB65B04141A539027561E24C3390952D0C6F6FCB505D4BB6E7F9D95075716051D012205078E70DCCEC2B56419E81
                                  Malicious:false
                                  Preview: P. ..L-,(~......KT#<..f#..ne...I.QC....?8....QR......L.......;*.W........VQ..2>Dw:.....?,..."9Z]..P..............+8W|..../~?...[[">FMl...wf....DN2fBKP..z[B....\G...R.....`r>!..PGq`...bb....y&........IS...&+.....x]...... .,%.......:......jj....m#^R..F#..{a..<.LL....f`....^\.....M.... 7....ck.//....&3.......)..LE......ww........</......43............"3.`........YA.....@........._........=l..fa.......ww..QM....s=6:<dk.:>\U...3>.......A.M../*YL.... ?.............VVmmI.'4...!)..._]...+...#r#u$).o.`.00...@,0..PJ.........mm^......sq........34..........HH%%..t...{y..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\138__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1455
                                  Entropy (8bit):7.480328718677606
                                  Encrypted:false
                                  SSDEEP:24:4cWtlZ+uGxXgThb2pQtVmg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRqBDC+R/BBP:4DZ+uGuIpQ7cAd4M9/xJfAXxudm+RpBP
                                  MD5:F586EBDE7262B6E747F676638695652A
                                  SHA1:8C430F88A4EAB6A14AE42DD3F08C71734C16F39C
                                  SHA-256:5DEFA28A4EDC08A0E04D69B07A362516C6E6B19D19C5597C4314865ED2BFFE46
                                  SHA-512:07F64939E5F3FB7D4C936B6325F0B4A73F3F47A11DC18EC13CFA28DEA05A59223788EDED459E730B1B8A40AA50A803BC5EC616A54F2940AD892FC98125F8E1DF
                                  Malicious:false
                                  Preview: .....Jpq..W@........!3....~u?8.J."0yl....5:..vu]V..ht8iTU......A...D[nt..[\.....%..1-....pr"3....?5t ^W..v.....@@..kx..'!co.Oh[.&MMA]../<.........T(!...t.......'<-*...:..5Bas..Z7k|..< ..!!..........8/..ZG>}.....................#s..(.qq......AP..U..........;..BT.*....6...}...>':b..ID-(.........J..kb......(-....MXpoG@OT............EE......46..QJ' ....Hb..b~....,b...@.....7)eU...?/....j.cv3&..g?/~....j/..Cp......MQQ@..C.YU|$n.....$cY.UX..ezvo...qs.......MR..f}.........ddHH.M..(eif'/..x]GE]A............'7.......a7....NT./..Y.&........31..4g{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;......
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\139__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.4247869932909225
                                  Encrypted:false
                                  SSDEEP:24:sNQKbpDbj5CqT84tFoze4ytP6qfHSgC0fNSZBzfteJTQROZq/VBBpFUBQ+JgW5G:S/NHEqYAd4M9/xJfAXxuzqvBpFUBvfs
                                  MD5:24F4BCB8435B9EC9FE14D3140EDF386A
                                  SHA1:590FEC852A02C7B64915A511B4C13BA16FEE7B91
                                  SHA-256:E46FB61A4F2D2A7F99E216ECBDC85E12BCCD5D62609A2EE6C89D264FDB4032B3
                                  SHA-512:4930B9DBBC2352A500FB2327A60C96F2F9814775101433051520DB4F1329B811AD6DD1D4BA77F23029A5700E1319BE2706A28909A84BB713A13F4ED840780D01
                                  Malicious:false
                                  Preview: n....BW......TR......prHC..HE..>!..J...#p....+&......Gt.(...sq..bxBD............3l......gp.....]S^OZ............Gp..xc....,+..oo..`i......z`4)7t......[b...29....d....`.-2..ox^(f?..dd..bog...H:.......rn$/):.............k.iz@c..0?kamK....`s....JJ....KK-a........%:..&'..[y.....,....6: g......iv..\...QT......W.....grV_.h9.._X..\S..mG...so........zm..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\13__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1382
                                  Entropy (8bit):6.812784993774151
                                  Encrypted:false
                                  SSDEEP:24:Jy6upVX84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0H0UzfXF2tDFvy8Bp+JgW5ug:JyTpGAd4M9/xJfAXxuv/158B0fh
                                  MD5:2C1C6BE515F3EE11003313C917EE5C69
                                  SHA1:F419D5F68C86FC2198F94A2D9E85F6564B9BEEE5
                                  SHA-256:A61A9AEC6C3D2FC775A56CC89ADE2CDB65694866C1E5C17F00F0501537CC9284
                                  SHA-512:E71A844B367FF51CAD10D4C69C0FD503BCE25462BD281801EC375666F8EECFF241ACE171A6D6A6816F4C25F4C7B0863145FA9D4CB12EC999BBC2EEA711A0B899
                                  Malicious:false
                                  Preview: n:.-.54.&1..qpC\......NC....i3.G..at..ST....dg......._....V....J..OP......ba....Akwk=6.......<;...H.....7*.....g`.N}T~....sx~m...........L......LL...:.%...==..........fa........`;.T....ko.....M.wv&82<+...6f..W..G.:..hhFFEE..ne,?(*........`4.."z....XX....A>..oU_a..&/{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.4[..I~4n...j,.}{.}{563}{000049000051
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\140__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.362789991557292
                                  Encrypted:false
                                  SSDEEP:24:ug2j+Qw+umIOIY5Dp3W84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5utBBpFUBQ+Jt:u9CqupOX1Ad4M9/xJfAXxuBvBpFUBvf7
                                  MD5:B872D8343F8886155D06669B4C96D775
                                  SHA1:E02D98BC8A06AAC9F25901BADFB0A574F4D2CFEF
                                  SHA-256:35F29BEBA07D90EE86E2B74FB76B958F638F4FCFD2D04185876C347DD9E12D8E
                                  SHA-512:2DC317208E7102BC68CA63A47930BF4100F5E78320B7EA5D7F2F503A3AE6455C7ECF26A6B3D68B2319BB1072024204544A8C0802EE73B0955FE4CFEFAA75159B
                                  Malicious:false
                                  Preview: ....[...........hw..ew.........ug..+)]ZnaJO.......g6..?8... }..{d..[Z..SP..;.cI%9HC..b`......4>..PY*r.............).......6cI..IU.........T^..............>\_.]...eeyb.....s.9.,HH....,?......BE.......s`................1-pw..tt..bb+gJY............~w..!'...1...6....M.............l`..OJ........ru......`q.....$$..;0pc..9(..IN......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\141__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.772500031782038
                                  Encrypted:false
                                  SSDEEP:24:Whe2BWRCF0684tFoze4ytP6qfHSgC0fNSZBzfteJTQRWuUzfXF2tDFvy8Bp+JgWF:W0i0fAd4M9/xJfAXxuXZ158B0fF
                                  MD5:F2584C6EF7E415FC63140FC15885469F
                                  SHA1:3D69FAB9F6AC3F3C129E5F79883A65A721941086
                                  SHA-256:F09A0BA565BA2AB6D4C0F49024928D8976BC0A8C90F585CDE9489A95BDDEF651
                                  SHA-512:4F836A5C906EA7006DA5FDFCEF683CC2E127689CB061D57C8B53FC9C0ACB62DD80AFC311365E1CFF998B50E4176BE023912B8569A1570C0E4110FD239E8311DC
                                  Malicious:false
                                  Preview: ..@.....@..1+..SL....X...P[....H3!ep......-("!..4+{gA....2y....SN.1......dg....Ak..k`m~....*1.....Z..4l#QXE..'=......8.7rr..]VFU........CIl8..o7d....z+..Xr.........y{..6-PW.......R.\E....H.$o....<n.. oa`....M......`0|#......@@....+ ..rp..........qx..1<..''..9*...........|u...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......uj)z..6..}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\142__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.706700035038936
                                  Encrypted:false
                                  SSDEEP:24:TIT64rPi+XYYgkhys7o84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaVpvy3UzfXF29:T9MiVYas75Ad4M9/xJfAXxuzv158B5ft
                                  MD5:6FB99763E4FF9AF1F38F94001BD9D353
                                  SHA1:80D5B615413C8140AC97ED4DCFCD42B1A85A2461
                                  SHA-256:623E0FC624D421E1F573A3DA9BE3DF9D030B77DB26FA453B05E31F0F95E8425E
                                  SHA-512:1264516E843E0B696357BAE91C77289E8E1D0B223E7EF74D6F392E2F42C03CED43FF2DAC3D49E8A3E99D91374776288FD525C2D92825A983A0BF7A3FBF9E5641
                                  Malicious:false
                                  Preview: ..Z.>y]\L.....45....UG;~*'0;.........inEJ..)*~u[D..Z.....D....':4+mw....abJF....:&...........@JY.../wy....................\.xq-u..!8$).$..%....4(..................5m?M...(..........6..77zz......$7....xcUR..9m...OIQ&..99&+OD../.IIFF66..zf.n.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....n+.U.{...Z.}{.}{522}{00004900005200005000009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\143__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.719140167999185
                                  Encrypted:false
                                  SSDEEP:24:7SngA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5jUzfXF2tDFvyv2+JgW5r:7SngxAd4M9/xJfAXxuUi15vRf1
                                  MD5:719FACCE12247A063554D9BF8D953456
                                  SHA1:60C169DAAE5CA5B7C74A2AA1ECCB03BF2E0B8AF5
                                  SHA-256:8200F938F510438F8CF1A968683FD092F60BBE445829E83DEA7D9296C9C41996
                                  SHA-512:9EFD5348093166B42CC7753B5CE0F4742503835263C77C6668E7E87D21556FE4909D38D0651DEBA2C0AB4D4E6C9962CADF112AAC918F8FE92872A9914EE13773
                                  Malicious:false
                                  Preview: B..ij..^...YX..g4]N...........}b..\.{at'..|v..>?..u..............LVec........#$....) ......YC..9z..}h..XV.........|#.............S......(.........................QF..%8N.YT..A^`UBchl..^^....ui....OO......ng?,.9..='C^{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..p?H.9.jS.'...}{.}{441}{0000490000520000510000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\144__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1535
                                  Entropy (8bit):7.532956390675233
                                  Encrypted:false
                                  SSDEEP:24:Ybo2aHPaYFMtFzawuhRljEwd84tFoze4ytP6qfHSgC0fNSZBzfteJTQReRJ/RSBt:YaHP6TghHjfOAd4M9/xJfAXxudRxRSB/
                                  MD5:2B1D0BB4AD4C8921EEDFE66131BD537F
                                  SHA1:E69EA824FE982922678F08F635E8A4387F6E566E
                                  SHA-256:14229541884FFAC96840FE252C35EC47C6B9C874A2D65E03D1088B6993F2AC8F
                                  SHA-512:F785BD89E590A7CA2A735142F90BCAE6347571AB1C966DEAF327C875A68D22BFBBA4E1AFCF31C29EFF2A1F7D0B39B263FA9D2A4437D0816493D117471B701743
                                  Malicious:false
                                  Preview: +..Y.NWV.....=<...............C..BW......tq]^..JUC_..VW...:+C.YDc|*0XY..............`s'%............E.}XJ..vv...=.....n?S`..CC...%..sq..~e......HA..B6....89.........._){"p|;;.....txnA3.:~T..^BW\....M\wl......xq.}.........q{Bd<<:#..G[;<........n"QB...........PY..........d^P\..W.[V..TK..../>..N_;s3{.S.............f#fiM~..........L_va..si..,q......==Q....C.. (..S~..u......]D..BQ....#6..........TV=,Y^DD.....DN]|1YV..............\.'S....d!..56[+......a:!e1$.;...X.ENH......l_:............S..?;......q|DT..>'L...KI......ozgx..{`......QVffII..B...l!WX....Fc......,1..X.y/.................8".CV...+#-8ffm:.R.....RY[Z_mx..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.B
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\145__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1500
                                  Entropy (8bit):7.516513082891626
                                  Encrypted:false
                                  SSDEEP:24:Yia9G+mKy0DlgXGqHdup103mwT76vY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGg:yJBy05I3Hkr03OAd4M9/xJfAXxuPDRTE
                                  MD5:03BD65C897712B0A4AA6B340BAF9653B
                                  SHA1:910C6DADF3997B4D457737E05FBE5C2F2B053FCA
                                  SHA-256:F66AE14660A54E9A1A096469917183B6DA4685E0D829B3E2646C120C67E429F8
                                  SHA-512:864737609F2933969120610AEA4CBCCB3C2A40BC5ECF18CA6B7A9DEA7A4A9306ED4C469321BCCE67B390E313FBEBF43B9E98D29F31AA2B740BD53A2B30B1DEBC
                                  Malicious:false
                                  Preview: .=9......S@.....pn13biGK..'.a~...uoL.........8.HU9.....'z........KL.....~~/pofVE..,;5/...94............./.....$24(..LL..?`..[Hl{.........ZO..Xu}r..6[..............LDuZZX.p.....z....9T......KL....jj!~{r..sd..qk..0s....sl...2xm........B[.........}}......EZ...6n....f|......FP<.US....|ty{|k...O_...FQ")..q5VC.....[17z}.....aKxx33wk.) ......................9t"-........xr..fd......PCWU..85..2-........vq....KK.....2vyog,3JS..BW/-.....t..#<~.........@%#..=x..=...mm.......S............1NTspb`_H.....A,-.Wtk........!4._......................Q...%`..$.........DUHW...I1F{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\146__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1209
                                  Entropy (8bit):7.350830491987481
                                  Encrypted:false
                                  SSDEEP:24:+cRum5zKjs68ms84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFtruWcsBBpFUBQ+JgB:num5zCVRtAd4M9/xJfAXxuGqWhBpFUBA
                                  MD5:EC74DB7C47C1A449BE878DB73EDB3390
                                  SHA1:7CA66F9C3E8AB5DEC5C03C11F2C5ACFB23BCC802
                                  SHA-256:090CBA7B2EC26F0CA6CD678E8A56C885E3A366F106AEFE4488E599C5796C5399
                                  SHA-512:5BFAAD65AE15DCA7B5F1C72C37AAC52B04CE6B649EE2F6E3E657011BDF93E02BFD16EDD530AEF2BD3EA5B6B64DF70578A12FE21536DA6B0C9F2E8C25F8C61316
                                  Malicious:false
                                  Preview: T..=>5 ..jy.....%6......DH......HI...f5}hhb..|}t,..............CZ..pv........34"".G!(..........6u..sf......sz..)$k\.........__..XQ......\F....P]taUJ.....}..GJ..........wz....o..5...&&........q`]F..82.Pt}...6%................"%....88ww..QB.\S..........PYwU..xx..;<.":6,k......,3......;*....H]..1$\C$#AZ81zx{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{4
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\147__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.774679347347021
                                  Encrypted:false
                                  SSDEEP:24:HmhiQsXY+Vjk0zhaSx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRRuHUzfXF2tDFB:Hmhi3XY+VIkhUAd4M9/xJfAXxu4RuG1U
                                  MD5:1A7249760EF180CDB3440797B42FD0D0
                                  SHA1:9E68D033A475754299FF55D6D182F0FCE79521CB
                                  SHA-256:5F28A78519179C5B2E9F97B3265BD0F9511E1C1944C54200FC98A5BB35D648EB
                                  SHA-512:C783B63D7E5A3C1B924F24A57BCB5617EBAE61DDC23D22083B86D8E2F28682EA4A7BC05789409B30EFFE8A488DA66A18CB151B799397696A77128DA3BA9BDE24
                                  Malicious:false
                                  Preview: .D@.....R....us....!?<>ZQ..al...............ZW....ucA\.!qG...CDF..........HC......*uKB..l{......y:....y[..VL..ho"+plVQ}}..:e..wd....g}xe.....HW.,H^..}a............h{TC/8..NS.NC..UJ8 ...Z.E\.....H..7~).....Z...L..[Y......bb....HH3l...ox..../l...........M.Qd}\{.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.K...3g...1%.f![}{.}{564}{00004900005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\148__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.711414087010728
                                  Encrypted:false
                                  SSDEEP:24:RyYWf9CnYrbi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHGUzfXF2tDFvy8BXCL+X:RWfNAd4M9/xJfAXxuOh158B5fP
                                  MD5:0303E53955CC63B0204A8A5CFE29AF34
                                  SHA1:1E22358BE664F950A8DB47033ACA56EF10290C05
                                  SHA-256:08E2A963187F277E66BC2CB30CE4BAA3353E09C1933F374F6F7F852AA3056F14
                                  SHA-512:BBB04214DD64BC01287B3C9D2CB2DF69697A44782A04A0E4B11B41A61AAECA40180DAE7BD49E753EDB01825CCBE108914BBD96AE6D1421BE1B6D38E0933AC29D
                                  Malicious:false
                                  Preview: ..6..ed4b......%`..>9n4....7"#!..%*..RQ......9hLM..M....T......*+....6:.LzPplT_..........'-3g...{........]]...._Lnl......ys.z@I....%,......4==ss......$&J[......J.?6.....Rh......W^.Bq;...GG......kx.....LK$...i1CE.mESdd- ....kA........\M....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.J.k...#dg.....}{.}{519}{0000490000520000560000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\149__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Sub-key -
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.67547261051112
                                  Encrypted:false
                                  SSDEEP:24:9/Z6K7woaD84tFoze4ytP6qfHSgC0fNSZBzfteJTQROf/VUzfXF2tDFvyv2+JgWR:f6KvaIAd4M9/xJfAXxuXfs15vRfR
                                  MD5:502D7AA0C0AA5DAE4AE6A838FA9E09C8
                                  SHA1:A61B552E83AFB44A0E1936033B61BE6960B3E733
                                  SHA-256:259A89F9F0C6F2E3EE3E3FB132678B94EB18DCCB0ED39F3570843668385042C4
                                  SHA-512:B6E00F1A44EB79EF303FEC6D56DC683684563E751D48C781123B2C8CDBFA7DED59664720AA72FFDF4570E6F21D009C3EC94CA91A78ABC76AA79B0F4BC19EBC9A
                                  Malicious:false
                                  Preview: ./+........23..o<..$:..mfamjg..&9.....B.....id^_n6.......%..{m8e......BD..18.%6kSTIIR.;2......PJ....7:............@@yy....1"...........BW......)0..;'....NN..=b..4'VA..\F......gr......BF.5yy......pw......aa.......'0{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.N..:p..[.j.y.a}{.}{433}{00004900005200005700009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\14__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.695318165979428
                                  Encrypted:false
                                  SSDEEP:24:qxghQimMhOGDx84tFoze4ytP6qfHSgC0fNSZBzfteJTQR81mxUzfXF2tDFvy8BX9:qxwK0OzAd4M9/xJfAXxuB1mg158B5fP
                                  MD5:77A964ED48CE4CA7573149A485DC9DAD
                                  SHA1:6F27EBEECB9DEFC07D214120905C951627008EC6
                                  SHA-256:2973850570B96815EE4580AA1653FADCC316F0A127833FB4CA205664AFEF79B7
                                  SHA-512:9B7539F5CCD48ECFFBC4B32B51200E0B19B305918BA6487E02E7B426305397E10514C33EC137E28F4B9C4138728313DCDC516E66634F5E9F1C0BB3DDCD509637
                                  Malicious:false
                                  Preview: .4\.....PG......2 ....LG...=j.m....lk......`k..A].....I..1l-0b}....IN+(...;....,?..HY5...!+z.-$.#L..7SDwcI......XK..du..af..H.v.D.J+T],5...HeV..HH..#?..>-..rc+0\[..6b..g?..6!......-0@IC...Ka..;;\\..GL..eg..KP(/..]."+..............`J......DD.....a/{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{3.H......{...Y}{.}{519}{0000490000520000950000950000670001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\150__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.377575572998004
                                  Encrypted:false
                                  SSDEEP:24:9pg2etizEdisqvG+xZBg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRY0dBBpFUBQ+d:g4zEdVkG+jBRAd4M9/xJfAXxu5mBpFUn
                                  MD5:9CAA3169E59D0F6D5E1AEE1CFAE7EF3D
                                  SHA1:F871D9071BBF5CE74BE1E0D1857F96CCEBCDF3B8
                                  SHA-256:16D4B6D02AFCCCFEC6269CFF7D165C3DD3277B2B0CE0CBF1C40CABFD176DEA43
                                  SHA-512:4FF566F4F4C0802665A62158C3205A28049EF75DF5E05B76E0643ACDC8AFE0E8979C5E53C73C6319E1A211FBEC5AD4EE1414063F3050AB579EDB00D174CACD45
                                  Malicious:false
                                  Preview: ...T....Kl{....7(>!....XU....%..PSA..,.16........SL..*{....>u...SN....+*=:sp...'dN....3 ....>%Z]xre1..!y]<....... 3......W.<...ww..(#......ho...xq.J....r`T\Yv..MB...(<z...ezY4..5$..8?..44...V..'4......xen->3AT..../.at5?......'*.#.).....aa..CR..^..........H@....K]kH"$.......[L..c;.....|w...SF..@I...O..KL.....'aaJJ....uf..I^..NS.Eho{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\151__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1471
                                  Entropy (8bit):7.487880936162637
                                  Encrypted:false
                                  SSDEEP:24:COt8kvg60fyg6VxnIdzvTh7NF3rAr8wMh84tFoze4ytP6qfHSgC0fNSZBzfteJT/:C4v/0fy/V6drThxF3rArhMyAd4M9/xJv
                                  MD5:1D3B68AD194E5C7D90DE979038D3A600
                                  SHA1:E1F5BF40DB85C35061669193379B7D5866BC052E
                                  SHA-256:A26C42359D614926A496D7B4430509B93C9F6EABD6F4C6A44AC2C61BD15B3168
                                  SHA-512:4F940717EE98B9D2F72754ED32F704A6B16FEDDC6E784A401677A91B5322B1BF3AC516F4D85A796ADB578ABBBDA9663EC105406C7B63AF402F98F151E33ECCEA
                                  Malicious:false
                                  Preview: ...@~9,-.GTC..............}zs).................A^8$2c..<;..............sp{w...................a581T..r...............g6*....................a581T..v.............Phx2....ikfi.V .`tx..mvir.vam|.........[......."5.4...OBK^.......)#,#....)0)$k;..^ttt.............DF..08..77v``C[]..<.jb........x3..]J..3i.....2;..#h\.@U..HAF.*{....L...............{h.....!<....\\cc...PCr?..GO...& 6........vo......>+FK.......le..2#....KK...}n#n..|tLS=$s^....avLUd<7\.%.......6?M.............w]..%%....._..?g.n.........EF....4-....B..=lNQbb..........lm...*.N.....1u!e{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\152__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1220
                                  Entropy (8bit):7.362574310144786
                                  Encrypted:false
                                  SSDEEP:24:s1w3iA6Hg6j3GYO84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkfBBpFUBQ+JgW5eg:/S+izjAd4M9/xJfAXxu5JBpFUBvfR
                                  MD5:C44949C5D12279810FBF86F9432EC191
                                  SHA1:6CCA3AF612C2A661E5E42B07A9BFAAD8A0019740
                                  SHA-256:FD66439DC920231A7783D4FFCA9D7A50A4F83913ABCC61C59C8FC54B58D54A9B
                                  SHA-512:0CB803F5F2FF4D7493F23941B9C86FC558F8C88560F291CBCFCFA1DEC5BF3B76D4064DE99BE4EBD28AC4533C7B19DEF929A2D2318B6AC7952949185968864CE3
                                  Malicious:false
                                  Preview: ..{.{<.....`z..? ..ew....#$.C.I[/:......TQ<?......E...Y^....>cex..BXut..8;..^m..nr....UW|m.......S...............[pkm..q %...ZZ...../-......J@..../wT"CD.....;............gm..%|....kp.......bQzP....|`*!..\^.........E<5.......9usXW\VjL.. 9}n.2[\nn....__.........yf..SR.?..`fLL........,k.V[xh..>9......x%BC....$!..ux..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\153__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.3714654076005885
                                  Encrypted:false
                                  SSDEEP:24:ebowqPAIEWdAjHA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvBgBBpFUBQ+JgW5E:7wqP33S1Ad4M9/xJfAXxuYBIBpFUBvf+
                                  MD5:834BFD0058FA2FA84FCE47812B99B2BF
                                  SHA1:74BBC695E15F2887D1826A3FE15BA185AAE3C309
                                  SHA-256:3F7B97E8A037CD040C5CF7B0A7418CF26098CE75F41D2D8BDE29247BB6F8B1BB
                                  SHA-512:AECE4516A68C1850171372E9493BE3129F9977271B41B3F3DB03D0961EFB0BC18B0895CF29CF63DCABE59BC5E819DC8F752480E44CEA6A6F7AAE262C3B6B1B5C
                                  Malicious:false
                                  Preview: ...QRU@f*../.\Z..........+&zsC\..q:...R\I..%(....P.=+..S`....#~..@Y7-..jmel..L."%66.M..2!<+....~c.v{..........FK......cu <{|88...el....tcNT......,9D[..hc..og2.hj&)|1..2&..]O......ap........HHb=......<+HR!<@.,!...../......XWZz.......L....__............n6....VL....SS2$. ....2.QY..ct:#@...z`..{pu#....ng..)/nio*{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\154__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1217
                                  Entropy (8bit):7.3352779819636575
                                  Encrypted:false
                                  SSDEEP:24:03fBcJ/2bYTRyYEY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRImdBBpFUBQ+JgW5S:03JMOGRspAd4M9/xJfAXxu1mfBpFUBvw
                                  MD5:3632F631A8DDB6D8C0FBB56FB4EB3A2D
                                  SHA1:94CCBC7AD13DF1B5D8EC243C67387AA7D59AAA59
                                  SHA-256:DCE48CBAEBD16FE6371DB93CC6342FB731FECBC0CA1B2A6C03B7D5C02EB9DD49
                                  SHA-512:657F0FC995687CA17F8AAA80EAC918E36FA565452667EB33993DCE489681D122527650D98D6822959DEFBD3AAA83DDD35AF18FC9ADFE997EA5DD553C4C0B234B
                                  Malicious:false
                                  Preview: #/+>=gr..>-..mkO.BQ..........'>!DE...l?.............rA....R...'>%?PV......W.....................he..............%.....4(..oo.........re...3pID*?MR+.....=I+"GD..m`....dK..........i....+F........XX.....4=2!..yn....@........bGmx..}r.1......x(Cp/.YY....ey......%).J\9_]..FN.;...hK.....05=..MZ.fd<.....NE6`....7"NG.q {ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\155__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.811628958737793
                                  Encrypted:false
                                  SSDEEP:24:IEZfk+4r9mOr84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYeUzfXF2tDFvy8Bp+Jgc:M+IGAd4M9/xJfAXxuRJ158B0fF
                                  MD5:88F43DCDDCE21C23621C50C910A80DEA
                                  SHA1:2A074ED4569F8503465CEBDCEDBEBF7D40683F29
                                  SHA-256:ABA706A57A9D50DE08B44E5F5EDAB178D36821022AF842F995F02CC705F3230B
                                  SHA-512:3F843988FE64C67856648AD7D7A976B2684ECB6767715046982F4E02214D585C0D5B2D44AC8FA20E8B1A82A36637E44D2B68A43135924DA76A3C717FF438075D
                                  Malicious:false
                                  Preview: ..>..A...F....BC..xgJX.........g0WE..tv......30+ ..PLU.VW..|7.........ml..'$gk..dN.....^\......|v].......rm.....U.~M....nr........~e.....AV_}%......)...CC..........M\.... *......;b...O.........L..b-...,".TR.....U...Pc....``....")H[[Y....................x.w`..zD..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......[...o..6}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\156__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.693924713953812
                                  Encrypted:false
                                  SSDEEP:24:y8U8YMmW5FSwbvKU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSrcsUzfXF2tDFvye:yF8dvRLK1Ad4M9/xJfAXxunrG158B5ft
                                  MD5:ABE1C81D49FCF20692D574284972D043
                                  SHA1:B85F60A28E631C6C6BED5AAB0791CB8550E0EDA6
                                  SHA-256:7E9213E1982168371AD24DC722B2902EF863AD94C8157AC1E535EBA98E80BC11
                                  SHA-512:6D31C2794BA6F116CEDBCDB68FEA1763A8A2A6C640E46A0E071EADBECBBDE2548B535AB1667C7FDE8156AC6DDD1085DC80D8900C008414CA5F71A7651404FCF9
                                  Malicious:false
                                  Preview: ...L...J......fy..:($aGJ....V..ew8-..........!*1........C........='........CpdN..ODL_..N_.....P.&/....H,..........>-...........r{.@..GN.....M~..HH..........`ghbk?@If>J82%Rh.4..TI..P....!gg....FM....!0..Y^gm....>IPFLL........99....XDN_.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x...<z.dBo'..w'U}{.}{522}{00004900005300005400009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\157__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.704484984535671
                                  Encrypted:false
                                  SSDEEP:24:xXW3bqsUCF84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwGkV78UzfXF2tDFvyv2+JV:xXnCWAd4M9/xJfAXxuXn7315vRf3
                                  MD5:33DC076FCE33BDABECD6E8512771D152
                                  SHA1:4DB9E475EDAE1059B4FC1A12617E7F8EB09EB8F7
                                  SHA-256:A27BA8C1A38A0771859CC28353E6851027480DCD6D53505BD589888FB38A7629
                                  SHA-512:5A43A7E6C42DD149848EB98078F4B2AB6E524CD563B545D6F0444C7EFB47403227A7494F21BF5C0734A2DDC4DFB96C51D4C68B5701CBC4515699335C59B593D6
                                  Malicious:false
                                  Preview: U..?<....ev$%F@{(..........7:..3,..'l..>m%0ND....P.D........)..E...MT.....|u#(S.;<..c<....av..si..p3..........22zz~!@I..er.......49?*..................\\K...+8TCh......P....>!.....'99%"..............4k..cpYN..`z...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{X.....~..(h.].Q.}{.}{444}{00004900005300005500009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\158__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1524
                                  Entropy (8bit):7.525661937491
                                  Encrypted:false
                                  SSDEEP:24:R4yoDUMEEBi/IFFPOS8ambd7erGUhQMcgxNZW84tFoze4ytP6qfHSgC0fNSZBzfE:RPt3ITg9d7LMcSjLAd4M9/xJfAXxu3ys
                                  MD5:4460D7968FBA2CEF74A2BC589174E088
                                  SHA1:28B21285E9D0E2B67119BEC626BBA545E6DBEAD6
                                  SHA-256:09ABD03D75C0C4D9510BC8A133B9D06D31496CF8AAD24DE1CBE4FBAC1C82A51E
                                  SHA-512:7BE86D1044E6DE77752C7B9FA61C78544FF1E2A3B3BBB6AD1C706B05D902CC9ECF4488F26B157F880C06571C6F4363C39C6513387F01E18AA88F1CA3D0C6F30C
                                  Malicious:false
                                  Preview: .fb..yl.dw....;h>-a...MF..wz..{dKJ.CYQ...%/..pq!y..EX..$....75......UR$-.....yyF.........YC...B\QFS.........&+..|f)2J\5).......81M^........D...1$..........5=.=..{}b.x!........,E...p!.....BB........}l.......jc.q...Ij.....%.SSMTve........VV66.......'/......Cd_V&.42..Hw....".................zk6t".[...zo......i8 &.....3...PP......*9..............TT../ctg./ 4<C\..cu........<dwd........J_..MJ..cj................wx..>!xY....3$Y@p(.....,<w$..............{#a0nh..=x....."%%[[........bn..Y2..) 6q.bo$4c|UL.Nx8..?:....I\..IN^E.........&&...OIZ.....c|..RP..5.]@8=..[.OB...........&$..l<..?s...........|x......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\159__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.364714594636571
                                  Encrypted:false
                                  SSDEEP:24:gbx4UtKtXfmr84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/4R4/VBBpFUBQ+JgW5b:TLXfbAd4M9/xJfAXxuPR4vBpFUBvfJ
                                  MD5:6A00285F5CC08B3647647FAC3B409623
                                  SHA1:098DA241DC888FDE5B55A8073755E4DA88328C38
                                  SHA-256:D4C34340657B5031C0512DC51C53907B5088EABB1399EEF1D6BDBA19861D0D58
                                  SHA-512:504ECFD57AC932A54597BC41DA8816BA3F017C0B78A354DB88C3E2288BD4CBDC69F41BD54C8C93F6B38CA7FC7718447706283070881DFD3D0D50D9F66815472B
                                  Malicious:false
                                  Preview: tx...qp....+1....#<..[.....WPA....J_......OJ..83....u$..lk....D.."=......TX.........KIap.........#B..........Yr....+z....22........J[TO....G....V2YN.\.9T_..&.cW..F@..CZVcc.....s..p...zPss....7<l...xiaz..;1.;2.K-......NAfl..nn.....EBggii{{.........MEZEny.................IEO.`649....2&..../*....LYIV..>%..JH-<ni........5>3 ....nu....Gt.<22{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\15__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):6.750712293146686
                                  Encrypted:false
                                  SSDEEP:24:AF29dpoxFlotM84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJ/8iUzfXF2tDFvyv2+7:AFe7ntNAd4M9/xJfAXxui8N15vRfj
                                  MD5:5E93E1C5BFC287FA86FB0DBBE0604425
                                  SHA1:B4F9381ABC98C12AE8E365B415143A467D050D36
                                  SHA-256:2DFA2E3C0B9D8AC29555F5F268063C81AC31F0D29FBBF73802E43C4F7361C158
                                  SHA-512:50D955C68D92C8747E89FA0E23DDC8D5742D41573BD48C47C27D6A56A55BD24F91C55A5C7860A45B7D5BEB411B6CD70F5CFE572208B7A17C25ADE2EEB0ACF09A
                                  Malicious:false
                                  Preview: M......c/......8kUF........al..:%....&<...@J....)q,w..HU...]K..Y[....................o|....wmSNV.......VX....16kk==...zids....;&..m`..........................(?.............:.rvUc..y~AUiu..}}KK00...E;24'....?%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{$..........[.S..}{.}{437}{000049000053000095000095000067000101000108000108000117000108000097000114000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\160__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1704
                                  Entropy (8bit):7.613074429087987
                                  Encrypted:false
                                  SSDEEP:48:WrzomwgdwW8CrSYcDvlTRFGZAd4M9/xJfAXxuZ3FBpFUBvfSZ:HQkeSrM4pBAXQZ3/rZ
                                  MD5:0BF0FB57943DDBB2EA2FA5BED7589822
                                  SHA1:BF00CBDC4D95E86EDA48021683B20877E2C2F8F0
                                  SHA-256:FF8D13A1F328C6C0A4994E863B67DC9D6D4D067A59860FA4A72D79DCD819C553
                                  SHA-512:138DB7ACC63326BE34E9B68C02E601616B08BAA493D00BE13709B7E80B5836C19BB1337F8E5E1C63806569ADB36F9809516A9C14FF815B6DCEA01F8B9FCF9DD8
                                  Malicious:false
                                  Preview: 7D@....\.........fu..mo....p}..rm..t?..A.....WZ.....tbRO<.Aw..../-....-+mj......aa.@......~d....OB[N;$r|b~}t....vA..VM....aa..R...UF....?%SN.<....6)oRVY..........h1..<<..nc.......5.:......GL......OTkl..N....H.....PV..MG......7$....QQ..ll$$.S..4y....YFw`@A.;OF........DC.&....5ceh%5....3<....H.....ha........N96....CC??...Z......9.......}}QQ.....y4....sl..BT...8.......C..RPil...............ni..GG.....u8..&.hw......i|`b....S.................>9vm..tvJ[......]]p<...;4.....ue.._H...K..zi....&udA]....................64M\......22*fJY.........0%......_.@+Cezl....DQ...._...{|.cl..~T....!=..d{......)[.......ZT..r.....hg..fd.....fsVIy~..;2..)8....GG......c. /........_CFd..UP.A.S..#3[Dt"..~(..~|.......go..TT..*...uq..vt..........=:6-EL....16ZZ..``.B........$;,...jE....MZ~g...T...'E...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\161__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.800950044038139
                                  Encrypted:false
                                  SSDEEP:24:km59aPVj5w6lrb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsqZ3cUzfXF2tDFvy83:PolrgAd4M9/xJfAXxu6Z3X158B0fW
                                  MD5:A2D1DE6A59B76A813718F36C80787365
                                  SHA1:E8C71B4AF7CA7F95567AFE81B0B24D988E7B2C77
                                  SHA-256:D0AC8E433253D713F34385021F33FC181DC3E59CDEA2B4635FA4C11EFAB24EF2
                                  SHA-512:529A26E6A57158777FD49DAF2B71F3C9AA56C00156497B327FA52A1AF54200A453571454A5FEA45312E35FFE9C411DB4D0D4F36A96071E8606B557EFE16ECABF
                                  Malicious:false
                                  Preview: .y}56...Y....b1....<>....he..iv?>m&.............W.....;.!7.[..Y@VL)/........ru........#4.......XUat........ec=:....g`..88.G......}j..TI. -`u......?8........??{$#*~m..va.....Y..u`po......B....}.......]...&20f...Q..*(8 ..9>jj..88......xk..DS...........k.MD_Fm`[..#De>:......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...75.......T\.}{.}{560}{0000490000540
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\162__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.674775753086077
                                  Encrypted:false
                                  SSDEEP:24:xsh/nZcxY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRr3iUzfXF2tDFvy8BXCL+Jgt:xsh/uxpAd4M9/xJfAXxu63N158B5fk
                                  MD5:8CC5070009E5A463EA29ED3BB8069D98
                                  SHA1:87A25E7D6F33E2D2520B032F7B16AA8C70B9120F
                                  SHA-256:31A9692FC02BA400E9A941C7E78D11C302B36D43A6B58998B0AE870905FF9FE7
                                  SHA-512:492F1A599BECFF95974A2E9C942DAFAC5E861F354BC1F1A15315937A8A62DB4101588836500F2B5A439CFBFF126256795EEDD20DE5D271A11FC9B49BE63D958C
                                  Malicious:false
                                  Preview: ....$1.(;......tg$:..LG48.. )..Z[..IS't%0..TY.~.v-..MPuFgQ..0mrp..CE......Q...LL.....6!......!b......FS......]]v)le../8.....34w......Pv{{......' ......`?..WD..w`.....L....b}.J>...XnHH..CW@\....HH...;d..KX........e&..6#........{q.zG[............qbc.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....3l.O../..}{.}{517}{00004900005400005000009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\163__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.699186830312804
                                  Encrypted:false
                                  SSDEEP:24:ZaqAA3BwWsTbV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRB23xUzfXF2tDFvyv2+E:ZHClWAd4M9/xJfAXxuZ3g15vRfM
                                  MD5:B807CA904F6B3EA4BD425D75DB2F1E2E
                                  SHA1:B38A20E5547580B35E4E2365AAD9EC4D9F18795D
                                  SHA-256:89F01FD302E806DADC55858BF115F47E790C559496E67C3A0BEFF99E5B88E431
                                  SHA-512:FDA0F47FED6403B4FB6A7E8DEC48B65878149D52AD8BF9D29ECE3FCB194454FEF925CF11C2D35455F28798750FAA558367C31CA75F3C8DFE7272E9D9DCBDD091
                                  Malicious:false
                                  Preview: ..9..;:..8"tu..gx...m`{p....#tbp..31...........1]A....=:*adu^..........VUZV....ey........._X`j..I@"z&Iaq...>....OSbi..DF....07...+..g?.h.......Y.......ey..,?..FW..LK.....`8W%....Hv..uh...].*.1....xx..SX......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..'..^.Z..y..}{.}{431}{000049000054000051000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\164__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2048
                                  Entropy (8bit):7.699961545315859
                                  Encrypted:false
                                  SSDEEP:48:g/E5/w67AZ3DhfPJPwJWjfAd4M9/xJfAXxulC3cBpFUBvfh:QERw67AZnY++pBAXQlC3ow
                                  MD5:24B4D0CD93BB8FFC50D41F4EC2361F5F
                                  SHA1:C46BF8D26C9597F6D57177450BAE28B39FC6C73F
                                  SHA-256:831EC0D101C013A9AF84EC77EBCFC83358D965263ADE7CD3C955CDCE867DFFB7
                                  SHA-512:35E9A01E080CC54A38E954F483C891DF51AB1BDADBBBD3BB3CD3D8AF580A3B06080BD8C2F7D12D7EB510BA9B964D0AC41F9576709698995AC26729EDC3F63085
                                  Malicious:false
                                  Preview: fz~.-...U.._^....@^..........op......MX.."/WV..KFP/2......I..`y........YR-p....o0.."1..h..........@_..PYjs....0*.... <....d;......NY...........mx......[.Uc...vZH..B/FQyh^BINdd..ii......_H.....r1....:%..IlOZFL..TtR[.7..a1-.`J.............?3.M.tca..NF.%.........=...............[.........=;hor75:.......< 1};2!2....CY^C%x.........dwh%..ld-2Q|..+!qP......V.............HW....KBsq7&.................YF....@W.7...<(..yxxs.hG...ZXGB.......8?KPW^....urXX..22=q`sK...og? $=eH..ZX.................\m<.......,Mggg.........*&...IN....2.A[khHJ......\M.Kml......._F..........X.......X.*nH]H]|u4l$urtQV.^dkzI..ii.....N].....ex..''...\W^WD..RE^D6+.HgjcvWH.....QB.....ozX/l~ez..`w%4FZ........O...............YL..........*.dmy`yt......<<>>so#2..\.KGO.d...z`GO....`vvU..ou^q}u[Y$3RK[.....UA..................~o..88........................bb.......w{s+>].....7M........zi.]XM_J...EZ.+-{|f#!..+eO""""MQAP..X.................3A..!!.......E@3&3>..........i
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\165__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.629911376234814
                                  Encrypted:false
                                  SSDEEP:24:C28TvioPgkAuE84tFoze4ytP6qfHSgC0fNSZBzfteJTQR53zUzfXF2tA63yrb+JY:2zijkAOAd4M9/xJfAXxu03y1EY6fi
                                  MD5:D86187F35918C2E974F78263F44CF3D5
                                  SHA1:16F730B02162D35D47C8F8C33BC774F616871B3E
                                  SHA-256:5887C1F03D8D48A1A385537A622CA35A3641407B261D6CC8BBBCA486D29B3092
                                  SHA-512:21B52EF355355D5EED2F77E3AFEED97E88E42869E3956F6FB581C98BBD5A2D38DB30BE83E87A9552B0BC6649E292F2B9B38D1ED9823FE05976D24842FC38E9B0
                                  Malicious:false
                                  Preview: r&..p7.....JP..xg....<y..sx..z H.i{~k....rw............V.;*........hi.)......&......EG.?........ha..|.6&.vE......xsve..........O.................aK..aaosYR..,.m|..ruv|.D...........pm..b3m^+..............._X:0b6SZ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....|.~....G...}{.}{459}{0000490000540000530000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\166__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1280
                                  Entropy (8bit):7.3944071164311245
                                  Encrypted:false
                                  SSDEEP:24:wgXOMw4Cux3J184tFoze4ytP6qfHSgC0fNSZBzfteJTQRqR3EcsBBpFUBQ+JgW5v:vXOOaAd4M9/xJfAXxuP3EhBpFUBvft
                                  MD5:7C6839E3ED5B1BC818FD39D91D44452F
                                  SHA1:DF23CF0E51DF0E0C49D98884500166BE935C28BD
                                  SHA-256:1866B4707FDA73AE9923F9C3893F0CE327272A59A9F622C36A59043901BFB61E
                                  SHA-512:A31A333BC35A60C8F2568E103B3FD2D62B3378EA85715422BDAE8C93F4D8EC5C43108A8F70BF66A9A220EB8B3D8375BFF46DA55A191E60859508C64D470AE1CF
                                  Malicious:false
                                  Preview: x,'..45._..&<..FYYF..@.cn.....M.M......}zt{(-....LS.....16.L]S.......yx......5.....EN..B@~oqj.......u-(I....NN......JL..x)..+.jj....l....?$16ak.....R$ni......H[.."nzLym....@-..........==22a>..>-QF...........qP-.ZO.... .#*..?2_...KK""....ud}b.D..c;H-........[[....<:..Vy.... 7...E...c{..*a$(..A<)|i....M........zI.'77......EL.........52dd........K....-.......?=...z"{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\167__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.367703458844404
                                  Encrypted:false
                                  SSDEEP:24:v9kpik7Qj93AVvCUnF1MC84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/c31BBpFUBS:vikkOc6UnF1MHAd4M9/xJfAXxu6c3HBH
                                  MD5:73ADCA14C86B2ADA831971605CC6FD8B
                                  SHA1:259F66213DFEAC45F7CD56C5CD9237B54E85F128
                                  SHA-256:6E2B7CA313E9068DE655EBBB29FDD3AC35FE575A3CAFF91A72274CC8A39A465E
                                  SHA-512:EF7189BFD394DFF50CFE8E3367B678309552018CBB132C7782CBFDD37D011C0B0DC3353A9CA07FF4FF9DAA5B8ECCA42B886438FB488A6594F9843E796021393B
                                  Malicious:false
                                  Preview: .SW..............JH.........W.......u......V........I.....pi........', }NI...[,%6%4#8/.........0/....90....*...........[[PP5jI@/<...F\..._......[L.....v...W[.....VZMM.....fOY.....&$$FF..sx......$?g`..8l............'-8.[[,5..iu..........A._L.....3,SD....[R....1.....#/%b..LA..ivX__N....=v..60P...6rH]...]..X..KL..?0Ve....ii7+t8..uf7 \KCYUH{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\168__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.356082721479813
                                  Encrypted:false
                                  SSDEEP:24:OGLDQvXIqOJmyguIMG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRE34BBpFUBQ+JgS:Z0PIRYyguIM7Ad4M9/xJfAXxuR3wBpFm
                                  MD5:7FC30E779C618579336CACB39781F6DC
                                  SHA1:8773F32F9FFBBD15616149E07A729FD731587CFB
                                  SHA-256:3CC0E391CB3CE2137F3917F58FE58CCAB709DA42F4D3CA48C536AFD34DE54637
                                  SHA-512:0EF17AD2C751C10DDDCEFEFE5CBD44B82CCAF82B75661088AC2A2B37488203EB5435518DF8D404438B4E5B81B3588A8AB5C64F22977B3BB8134755F8BE1EC63C
                                  Malicious:false
                                  Preview: .D~..D...........a~);.....JM.J..mxge..5:..?<.....@...&!D.GV.....HRA@WP..GK..V|.....KI..RU..5a...F..~lRtOO......1=/~............b`.......(|..G.....5(PZyq....#, pH~DP..0"...{l(9............SZ....xoG]...TJG....fG....FL....of....OQb..cc..NN..}lhw.Os..]8......Yw..h~........|~..G^@...g}4#T_"t2v"7....'.q ...........((....'k....0'....)4...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\169__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.362362883102047
                                  Encrypted:false
                                  SSDEEP:24:FpWA1JWm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTN31/VBBpFUBQ+JgW5t:uq6Ad4M9/xJfAXxu4N31vBpFUBvfv
                                  MD5:9F96D32AA5AB5A52CF9E663465821478
                                  SHA1:FE40ADD48FD489CF3FFAA1FD4D37B0EC5DFDCF81
                                  SHA-256:6AE1A781E0461ED29FA620824E1E662FDB923AE3BF7481009821A8BD63A29F88
                                  SHA-512:A9421761190AF7308F68E34D5CC1C06A50710EA3E629FF163E312F9AA999169E97D0957C02358E129770513C8469EE3E7AE2E34C8CB17404D4EC93AE46DB37EB
                                  Malicious:false
                                  Preview: B..i..kj......@A......}8................../*........rs......[..(7.....JI:68.}W..~uBQ....f}....(|...A...8.""...._t..xt.rA(.gg............nd.4=..[H/h............T.....1F....-@....4(......NN./&>-....NT....s~6#..xYuP..J@LC......,!............}l...\FJ#{..NL..YQ...........`O..-/J]..r*....(p.....W...uw..GR....,3..$?..AC....JJ......ib=.......ur..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\16__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3412
                                  Entropy (8bit):7.8129109256424245
                                  Encrypted:false
                                  SSDEEP:96:X3bUU6GxwNyTVfqfh9fm/Jg3kjpBAXQVn3T1:UjyT8fXL3kgGj1
                                  MD5:96827BB17903C810D9F439EB78767D9E
                                  SHA1:9B0306DF22AA06E030487AF092D8DE524FEEFF94
                                  SHA-256:3A08FD9181D43EA8370F13BE2AA6B623E70A8FAE37BDDA6853D7A012B7CF1B01
                                  SHA-512:0EABEB15C703859D2302515466238021999ABFE9AF5E472B85CB234C8A5FD76F1158F939D6140D7574D1E5F7343FDADE8079F0C2C65B3C97614DF6894A8FE7EC
                                  Malicious:false
                                  Preview: 2)-..\I"n.....6%.............YX\............k3@.....Ve{M..e8;9..../)HO....b?.....H.........evk......;5';..8!.......5[M....((RRN.'.h{.....................CEBD[V.........PKTYn...6DXkQ{..$$$892.=TVAP...#)j>....O)..........x^........8?....LL++...~3o`5=.....!......OO......^.......3,..$$..8!......EP.....ur=xNA..3.YY..G[E.....YNZM...../(..==BB.U.........|Q....~_....rkA. 3....OZ..............1 WPXX..//......ld..jK.............LJ..WV....@H......!4........EG........<<.}n..?7.....>XMeg$3..G.T?F`f$..r6peMX..I..MK..^.yv......99os..=".....H:..WH..`U....&$....V...V.`a.R......xaRUmx.Ksr..y,/}|...{.7s._..ZO..y!.hn...r}....gg..h$:3..AV...e&;._X11...DM..ZM..PJ-0.....$;.?..<o..........x.......M@..&0c...9.uu....U^L_46BS'<..#).K3:{#h....:42R]..x^..ip..>"....rr...{7IZ*g<3....1&DE.<...1rt__..EB..XT..O85....|z !..,;..............UN....+:..QQ......6=WD..BS_D&!_UkXpZjj..jvn.8'..+'4l.z..ZB..r>.}p....cp...&3QX"zp!..KL.T69l_..rr11....^A.XT..}<*....l|rm<.;:..:.......
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\170__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.351946660721372
                                  Encrypted:false
                                  SSDEEP:24:3SPq+SS44G+v0FN84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1gBMBBpFUBQ+JgW5b:wHSS6+v0YAd4M9/xJfAXxupBkBpFUBvR
                                  MD5:9DB1F79D2FD3F9F328108747A2F4E02D
                                  SHA1:65486FC3CF3D8873C6C100496076260AFF4DCB68
                                  SHA-256:9EE6FAFC3BD2FDC9EAE5ECA47269B8DEA1F1A5408BC295A3B3000B586216CB5F
                                  SHA-512:D9B6B76FAD7E075D4B676AF4055E263706C9C5F99FEF9271D9881F3D564269B98988321173B56B2A06CD2D2DB9E696DADEDF92E9CE53F1C6E36B819C495EB686
                                  Malicious:false
                                  Preview: ..Ob%..b4ny-7...........mfg`.2em.rg..........DO)6..t%<="%..q`........25....2.Dn......9;xi....xr..zs....(....ev2...BN?nM~>.......qbdf....).'-*~:3q)k.cxgg....CK@b....2b....h.qc....#4vg..........ELqb..ynKQ?".BO....-.Gb....69....{bheN.......wwmm...n......@<Y..........OY..........HJ1&ax.....FQ.......`u....71..d!GH$.........h$le+8..........52{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\171__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1321
                                  Entropy (8bit):7.4014740448837495
                                  Encrypted:false
                                  SSDEEP:24:Y2CqImRD/Muik14g5x7W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRskrBBpFUBQ+I:Y2CKkutug5ZAd4M9/xJfAXxu61BpFUBw
                                  MD5:E6188F80101EF98A13458227EB3EB2FA
                                  SHA1:71C849C6780971F5BF8A6F2925A7FB73C0B38EBF
                                  SHA-256:91C83907266F39CB8031D0BC5696530F03053E3F87FACD41E26F5EED1AD63B1F
                                  SHA-512:5910AE0A98C22620442905CBFB5D6802E052B9A93DF001D1C0E82FECF839CF82CF3F0BAA3DB361DF27B027947CEA0E09ACDA82BA002BA1031AB1FF4584FFD778
                                  Malicious:false
                                  Preview: ......G..Z[GA.7$..........ih.R...H 5..id..O..uuc...;......rpSJ....JM>7...ff..............d'...ls..HT......LVD_..UIDCXX.....4'.9H_....XU..fyZ{10)9.#.d....DF..........aW..%R....c.erSB..MJ.......CJ....mzA[...V[ep..|]%.wbbh.!.. ).....WGt..\\%%JJ.... ?+e.......UO4<......+...pjAn;3AC..JS.X........+q....511~.Sj.MXgn@....?8..`o....""xx...r{&5..[LBX...............e(....2-..v`1;Qp-/..............2'.........Q@..{{{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\172__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.778369173380065
                                  Encrypted:false
                                  SSDEEP:24:YDGV/6n5zfst1Q84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5FUzfXF2tDFvy8Bp+d:f6n5zfYBAd4M9/xJfAXxuMU158B0fF
                                  MD5:29C9D96E11A1EEA1C028BC9720C1459B
                                  SHA1:0070FBC73EE50609B230AC31E55D20E6BCD8F8FF
                                  SHA-256:F3FBA2B89E848570AC1EBD24AEFFA59ABBE7BAF8DD33028977068F5A63BEB4AD
                                  SHA-512:5F10B54FAD353C3D4A802C23B17AE61F166A4CB05F778C7349DDD89195BD7C5FE9624F50593C012654AA68B6F35088ECC954289D9023CD39F08730C7B2E35D51
                                  Malicious:false
                                  Preview: .i..../y......JU..TF.X~saj..0j9n..;...........|wyf..i8..QV.G...T..<#XB67..PS7;./yS..29..IK.....CI..i`M......isML..U...........^M#!.........2;^...rr..Q..3U.@@....ZQ....\G....H......h:,(.]...............T..E...._..9NdLL.......}n..{j....."vpyD.$)Qw........}GIwkzql...AM{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{eD.FR.g..r5u.G..}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\173__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.700505943871658
                                  Encrypted:false
                                  SSDEEP:24:Nuwjn7Tf2084tFoze4ytP6qfHSgC0fNSZBzfteJTQRHHmUzfXF2tDFvy8BXCL+J7:NJjyAd4M9/xJfAXxu2B158B5ft
                                  MD5:AD08093A69C8A80EF547D4C1373BE996
                                  SHA1:936766DF81B274168C06F8B009F171647126842D
                                  SHA-256:2CDA8830EE4B9B12E64DFE71E80F817BD146AB298FA88B2D979FDEEEE40A1DEB
                                  SHA-512:84C8A46752730E5D0519450C4FE3DA11CFD2014D95E29E346728A1CF959F9C625EF462D024B698FA3B558AC3AB44C20431C9AD36FC9D78883F9F535F298497FD
                                  Malicious:false
                                  Preview: ...hi....fqSIhi....UG..2?$/.......ep.,]Zzu....1:EZ..G.bc34y2....jw......WP..q}rA./mq....9;....:=..2f....}..U1O|..g{..O\MO..|g....._...'.......X.............WD....!:wp......C.5"././..HU09..jYKaHH..TT....9;..ir....P...V.ior.!7GG+&.......--..~bGV}b@.\P{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{2..[....D:dk.Q._}{.}{522}{00004900005500005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\174__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.701608813762196
                                  Encrypted:false
                                  SSDEEP:24:cmlzv/VY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvIZX3UzfXF2tDFvyv2+JgW5O:cmj9pAd4M9/xJfAXxus4X215vRfQ
                                  MD5:E87B87AD3A8C03C0B37C7804F83F2DE7
                                  SHA1:4C945CC21B554736DD84AD11512A4F08B9515E94
                                  SHA-256:9272777E54D6776831B5BEA6413F5131B3CEA2E0F99E67C6B401E718E20C4CF8
                                  SHA-512:2D53BBFCF69951754549F7573A9172E936FE194FA8A547B0491D6A12E3C35416717EF721A80FD77EE6760DF5E4BF6625FB5AF231F2944BC3FCA8CABB530A0408
                                  Malicious:false
                                  Preview: ....B.ON...........\..CH..{!.......#$o`14....ZE.._.9861D....vk[D........am..Hbplod....j{....KA....R=..P4BqdNVVLP..\O..M\?$..v|..'..\=LEqh..9i...7{{..%9GL......LW....a5..1i...?...yh.......Nd....rr......fd..WL..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..`.D......$.'..}{.}{439}{00004900005500005200009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\175__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1530
                                  Entropy (8bit):7.525605475897928
                                  Encrypted:false
                                  SSDEEP:24:Xig6+I4mlk0rci+Wz9xPWTRoeZiln84tFoze4ytP6qfHSgC0fNSZBzfteJTQRU8f:XiQDQ/cfuWTI8Ad4M9/xJfAXxuA/RABQ
                                  MD5:187582A413A6623AEB05B4F8E1B8397B
                                  SHA1:EEAB78CA86EBC4EA30FB547588E36A4D7E1B6292
                                  SHA-256:E68E78FA638DE70501E42A269545E9212725E385F355944C69D7D5942955640E
                                  SHA-512:069BAAC21FF4670E7E4A43671F8F5949B905181B7579AEC939FA9438210E20E6BA2093023B75705E787764C798F9019A13AC537E8A45430AB708984D49D986C6
                                  Malicious:false
                                  Preview: .....ep........}..._A13........VI...SI.."(....{#.Q..................i`.....TT....]N......|a.A..................wm..!7;'fa''..W.r{zi...h...I...................u....3$ V..VV........_-gT..//....W\......BY.....]dm..e... DB....+.......so.........N]....?7.................!...1..o(...fv....q=..e`....C.s4........8`..35....gh......HT2~R[.........._.........K....]U........De............)<..oz....mv....n.......vv.\pc..o`|t............8`.........fg..^_+)!$....5 ....0+......MJ..0022.3qb../ u}..=$S~..VT......Y2tR.T......3&t}`8....NI...=...uu..-1L]TK....].zCDB]PF..8"..NL.....M=,./..L.....d`vo..^K.............{0t....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\176__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.790429917964799
                                  Encrypted:false
                                  SSDEEP:24:s2nI1UMqltUUXrsmS184tFoze4ytP6qfHSgC0fNSZBzfteJTQRbhcsUzfXF2tDFA:sUMGJomAd4M9/xJfAXxuChG158B0fF
                                  MD5:85FA34B90083E188D33BDDBAC3257E1D
                                  SHA1:72C3301702BB950E3C9534C0E4F5E6B56213CBC9
                                  SHA-256:CE11333F701B18416C387516E2EED95876B7FF22CBDF5ACDF27C0F16A6BB35C7
                                  SHA-512:84C0E5CAC4C0EB9902A96414E29392E8E6B23019F401713BD258CCC88AC9FD703C8F1B6558F07D6119128589875D349A813D3342DA42960AE76B131C96757ABE
                                  Malicious:false
                                  Preview: X..h..............;$.......A.,>N[...x..hm...............,qSNwh....ur..#/.*.....................Z(..,3..yx....)..577.........IR..RX.xqX.#@...n?..Zp44RR4(..........mj28>j.......I...{*.E....7e..x7..&8..o;.k;..K.)v..^t..!!==!=..jy...n......U....C..=.YY..dw..$3./..#2...'..dh{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.q."U.T.x..j..}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\177__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.716053715521416
                                  Encrypted:false
                                  SSDEEP:24:kCjW1Pcyz7XU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvqyUzfXF2tDFvy8BXCL0:kCjW1PcsBAd4M9/xJfAXxufd158B5ft
                                  MD5:92A91F914BC687B340137B8833B5694C
                                  SHA1:5ED78F4031AD18B7D8699EF32894E69C884E7EBE
                                  SHA-256:26B3A94EE254172EE6357E29B601BB3FFFD4FCC0770C024FE1DB4052DEE6F763
                                  SHA-512:367ACB09448D97C61E4F1A6C21CE98FA967CEB8C7428C2B78C0ECB290FB545E26727DC5FAC93C0CD93B32BBA7B1B326B33562833A090990D0CD48FD838452971
                                  Malicious:false
                                  Preview: K.:...vw.H..MW..'8kt*8.........Y.O(:.. "..WX63......>".........K..ls......'$p|qB!...\Wh{fdCR........8`%J...k..........):............(!u-c.......l_.+``{{......jhfw....bh>j...x......<-....,}Pc..::))@@;'......VG.......W..|$...SE::....@s.0tt........v8..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..f...,=_.A.P.p}{.}{522}{00004900005500005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\178__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.739006977679712
                                  Encrypted:false
                                  SSDEEP:24:t4q+AJL9q84tFoze4ytP6qfHSgC0fNSZBzfteJTQR3bDUzfXF2tDFvyv2+JgW5fs:GKAd4M9/xJfAXxuOC15vRfBs
                                  MD5:09075AB6A8F7D4C3E7C5F84EBA69F500
                                  SHA1:94F3E18142B78242D62CD53453246103313D9BAB
                                  SHA-256:1ABB40FD69A26F3EB8D139E5AC4B533C8606CB22B27F19AF10332D4442A56887
                                  SHA-512:10582CEB0A65B080120E489C0E90967326D73FC3A1C3ACB67C4F391989E6E23C3FB7911AA7710707FA974E911906C5737D5CB25ABDEEC747E9A6E65A3DE60991
                                  Malicious:false
                                  Preview: 'sM.......\K..#"qn..|nL....%......(:......S\......LS......g`..KZ.kv..NT.........3...}vL_..&7VM....m9.........uu..YR....]L..../%.....Ii.PY...|,..aKhh~~..w|$7...hs!&...u|#{|.....Qo........rA.?.........tO\.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.U`V...T..F.].."}{.}{442}{000049000055000056000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\179__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.37386952560141
                                  Encrypted:false
                                  SSDEEP:24:/n2QPHwSsJPnQ4QvvfO84tFoze4ytP6qfHSgC0fNSZBzfteJTQRDm/VBBpFUBQ+6:uoHj2vYjAd4M9/xJfAXxu6mvBpFUBvfS
                                  MD5:139C186DE560A40809AD2C5FE127C8D2
                                  SHA1:67CD710767776EE1B8B766043C323AAC2EB8E3CF
                                  SHA-256:980AE8A27D866E847DDB9512BDD72F638F058CB4DCBD35F86BA53D3E6B8AC118
                                  SHA-512:36D9952202D34F82CAE1DF46511E9F924DD3A2C8CAAFA614FC7E6E178165D2DC69401695FE2DFA8DC96DAEE3AB6B00BBB4023FDD3F715D1D49583BB58D102C92
                                  Malicious:false
                                  Preview: .\_...DW....Y.7$....=6....5<..&'..!;...........YO....Tbk}.D><..........%.........R[........?"W... 5....a}....wzaV...?)=!43SS..............XOB.....72leod........-MB...+?l.L^mr&K,;.........HHr-%,*9.......J..3&HW....at......]TCZ.#...../..........6)7y\PO..AC....@n..`vWtlj`z..s{!#..cz...DY....N.U@.....)x..*-.N..."........'4....F\a|s.eb..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\17__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.398995328659407
                                  Encrypted:false
                                  SSDEEP:24:/r4BsLHq8RY14FFMy684tFoze4ytP6qfHSgC0fNSZBzfteJTQRiR4BBpFUBQ+JgJ:Mx14FFfAd4M9/xJfAXxulRwBpFUBvfo
                                  MD5:4871D5210433920339712F51EB068AE9
                                  SHA1:A9DA859ECB562B7DBA3D4112B09F4C9CF6B9C06C
                                  SHA-256:DCE0C25A9698AA1D678332D4F52E39068ECEE1AD5A95A02B8D1232CBC2B2428C
                                  SHA-512:2D5985C35973E47C444B917865E511EFAC53CA567399BC668BAABB01D6659130B95FBF3EAC085A6DA29F88843EC21CCBD322C5011035FA8A1B63C9C6905AE20B
                                  Malicious:false
                                  Preview: .37....$h....AG.^ar....5>..&+.....~.A.........)(..C...B_..uC...............z'x.......[H.._Hz`......I\<#..9%..b{......gq........L......'=.......VI..D[71"c.......+#..O."33..'*....:...AAWWMQ......[J.....l8...X...&.......jL..OV......uu......d(..I...MRer...!ZS...!!.9cd......1g.........su.O..29..Q`u7".....06af..vy....))<</3$hQX..sdQF.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\180__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.3738011364526574
                                  Encrypted:false
                                  SSDEEP:24:bW8vwmUPA/BGZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAqN5BBpFUBQ+JgW5R:C8vVTAd4M9/xJfAXxujSbBpFUBvfD
                                  MD5:C361A7FF3BBE7A690E83D8EF2638725C
                                  SHA1:9143C9B5F270A62F4668E59802B82520F893AB0B
                                  SHA-256:BB90B34AC5F61ADB03035B1ECF18A6CC0B6DCA09DB5B2A640BC55B158CC2890F
                                  SHA-512:B9D4CC9345BD6FEC64F89A8D74F8C8A9F437C6F3AD7AAC19CA042C046B23372F23CE9B4DCCF64A493426341E240A7D2EE51DFB959A32893051917B6BDBE9D7F3
                                  Malicious:false
                                  Preview: ...$.......UO.........................nijeli....NQ...........z'|a<#..BC....Iz:..._T..y{....61..V.6?..bp..(1....}{...QL.?.**..ZQ*9........4=...nr_]...l......B-...........}....@-....vj..SS..::.......yn....D.......!.......=2iI......}-..nD11....[G...._....<Y....\T.0..m{6.LJ..=.91df..|e..X......G..S.......y(..ni...>..zz...........gp........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\181__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.349163281042703
                                  Encrypted:false
                                  SSDEEP:24:6BiDICoiD8g5ISL7/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP7qBBpFUBQ+JgWp:6BiOg7gAd4M9/xJfAXxu47aBpFUBvfp
                                  MD5:DFA1FFC496EF58D588ACDE4F21C2214C
                                  SHA1:0F753CCE01A37C37D4E418920AA30365A038BFA0
                                  SHA-256:74993B42B04586EE67276F61A8DFB43D2130883BDC593F1F461CE7F985E19A7B
                                  SHA-512:4EC35BDAF29DE77665C792B1BDE51B4C4CC3885AE158EA973ABC90F2C5F610AED3EF3F5C9973D01AD31CC594925D487165CDAE88C0ADD25D60A3DA42575C02A1
                                  Malicious:false
                                  Preview: ;o.|..ON.....QPXG..);.&+sx....^....70BM?:..v}..}a\."#ru..CR.."?..KQ... #....)5........VQ...$-.Y...hNjj6/BQ....dh$u".........l....?....ND...a9;Hm4....?=3;Bw.........))........=O...6..--">......UD....6<..Y.P6..iJ......Ga``............ll...PC..)&..RM/8=<cD....>>.6mj=.7;......]Bwp%4....|~-(..{v..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\182__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1525
                                  Entropy (8bit):7.518791389673053
                                  Encrypted:false
                                  SSDEEP:24:Ygd2B/hKI+cV6ULMScXjwCaBd71BQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRL9F:o5N+RzScTG71/Ad4M9/xJfAXxu4oRIBR
                                  MD5:BE27E773E0A3B0570025C44FEA6B52AC
                                  SHA1:AE1200BDF0B26FFA02264EA454CBE786F8101E2E
                                  SHA-256:163A765D6BC2CAD5C0D0C1DA6FE0039F4BECFE8DD94FEA6053390BC955AF3B19
                                  SHA-512:F8FC24F0D7893ACC7FABD38711BD392D1BABBC543F0999D6543C6916EEC0CFAB535B0B47971FD2F2332597ECFDE532144A575D242C0173DE8465F2A5CC3D6C24
                                  Malicious:false
                                  Preview: |(..i...'qAV..JK.......|q..:= z.GU..........BA@K..C_......KZ..PO........MA.#/.1-....LN......CI...9a..ft....f.....WQ."..?.....FM4'....ybx........P&........)R+:...:.....A7N..............h2.....\\rn..</........dn6bR[.T..2!.$..........f........eeRR..&j..l!ANh`........."$77Uj...:....5c....ha..=q#a..`gt?N[XZ....WZ..MR...............UU..RY............$.....qq............c....Mq'k<j..cs..~m......(!U...35....BMTg....''';!0.....E..... )r5..........w5.pr..ZO............JH......ww....7$..GHFNwh~O..jr..FQ..G...B@.....+>V[............fw' .....:v1".........OM..b@../*7fl:.............KW9;..H..Z~2AI............RW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\183__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.801131684864615
                                  Encrypted:false
                                  SSDEEP:24:fg8PSGdPW7DZn7BusX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKcYfUzfXF2tDFA:fg50W7unAd4M9/xJfAXxu7O158B0fF
                                  MD5:09C9D55EBC2D7A072BBA972B462DA335
                                  SHA1:D38E55F80C15C9ECBE53B752FC4BCFA4A63482E9
                                  SHA-256:473FB8FB329466E05BF172BE97108B3093C8EC605C8998F5B2C46B1EEF05C2C1
                                  SHA-512:A04699D906B60321DA408BB6DC7E73EB48B1AD9770A81519F1AEC0223F3B3D2ED312402194B5F0C4E1C77F665086BAEF51D49A53EF3149D57796B9EE8B0D40D0
                                  Malicious:false
                                  Preview: .h.....QF......PO..o*......s).S..TA..eb..Z_30............"3....yf..XY....nb(.ZpFZ.....*;..AF..E.md3k.......... ......ZQ..caTE)2..U_.+YP9a....:k1...jjXX0,..........,&....c;...]Z^..E.........WVIW....d6.W.....FuYs....""....YJ......QVak........qq....N1..~D(...>#..<`..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....3*.p.....r.}{.}{570}{00004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\184__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.6970231383503345
                                  Encrypted:false
                                  SSDEEP:24:KhAanHuSW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNeUzfXF2tDFvy8BXCL+JgWt:KhAan1Ad4M9/xJfAXxuMJ158B5ft
                                  MD5:3C565A6A18B730CFABC2961ABDCBAF92
                                  SHA1:D061DCA6812F9D2030EB9B920FDBBF638135052E
                                  SHA-256:4F36D789004AE6B7200C13859B7E50FE0A2139ED3A5C6AFF91B0E7D924F149B7
                                  SHA-512:66DCFA8975DD2973DE07161AA9723AFEC2DEC05AAA5112EF90ABEAF88C7640F971086FBA5BBCC4BD9788CA9795958C034A02224F830A9EBEA6893D3C27C6456E
                                  Malicious:false
                                  Preview: d0.x^........+*........fk..MJ..c4..@UOM........enGX..........i4MP....../(OL........EN..b`>/..)...Z.....9V..Q5uF..YY..,'.." ../4BE....+"..e-$..:7T.9.....mmlpdo..~o..UR^T.S...CO=....+..........!........MQ5>WDFD1 .5dc...cj.RTm.nx..0=........ff..``......#m..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{gbl*......u",h..}{.}{522}{00004900005600005200009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\185__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.688584198019909
                                  Encrypted:false
                                  SSDEEP:24:jVCR84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5dUzfXF2tDFvyv2+JgW5fs:jVnAd4M9/xJfAXxugc15vRfBs
                                  MD5:16F099DB897E090E83D51F4F90CD3C23
                                  SHA1:8DDEA00908EB3F1E7407E67DDE1BD9F0C81AA760
                                  SHA-256:B4C847CF6565FDDBA98219A70000FF65DAC101E49F975AD2673FC62A42D300B1
                                  SHA-512:76002596664BC519E2C3717651916761126CDC67B7A49606D29E473647A6B72D30F8D717A09052233EB7A0F438671EC82F9DFD652A1078F2234E4269A1C21F7E
                                  Malicious:false
                                  Preview: ...y.J...%2........UG...K@...........r}......0/ey..wv..:qte..lq!>..no..x{84.>....V]....;**1..[Q.*#.F......).Hb..QM......1 _DebHB.. ).[v...cz1<..&..(..00..fm..EG......9mPYf>F4+<....1 8%>7..5.....MM==.2bi9*..AP.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{"yP.k.....L.y..}{.}{443}{000049000056000053000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\186__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1536
                                  Entropy (8bit):7.533464483115638
                                  Encrypted:false
                                  SSDEEP:24:sExjaFlR9VuZvrd+eSr7XYupayqRv+T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRL:HkjSlrd+v3XjCv+YAd4M9/xJfAXxus62
                                  MD5:6A0D0E683C63BEC234261C0384340280
                                  SHA1:1F70E04843946A109D11C6168B13F456C4C5EEE0
                                  SHA-256:F46CF00A5F7C04C79D0A3D23276FD633D8C6579CFB7F4852615877ADE522DFEB
                                  SHA-512:6C06ED964BA2E6D1CA4CE7D5BFE5E1106C402152F7BBE834BDD2F4522400CB0ED07826C1AC3C50E02E34DDED18330B69A5EF02CE8E571D8A5D111A0A1A80A3E7
                                  Malicious:false
                                  Preview: .pt....-a....tr...2,.......rm.~g,..`3[N....fg......Kx..NX#~><..tn......4?.............]J..PM@.........lp..(1bo..kq..~h......zz......UB.......E....3,d]....W\2U7 ..................,3..........88....xq...........XEHN[...3..sfhb...)..2+..........EE........!o....QS.....!66..(.vpe...6>....7....L....od..7s....5<C...{}..`%...9<.PP..fz....'4GP......&{......IIZ....V{tGO..Ty....^.....LU.C........ -..xg..to.................@......TuIY....7...Y-(#ho................?<}w..tq3&......:=$?..........MM..Z......( ..D]..#6....vo.\.{.*......WB{r.FA.us....'........AP/0w9..[.y.$#? ..(...........1i..`0........^Z.......xy^@z/m?....@D......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\187__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.277236795016775
                                  Encrypted:false
                                  SSDEEP:24:QMZ+A/yi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXz4cgkMJ+JgW5z:Qm/ynAd4M9/xJfAXxuxcgkMUft
                                  MD5:0DC794B40003E79791512120833E96F8
                                  SHA1:336A42158C67722B64A39919610F5F54790702B1
                                  SHA-256:436749CBD86AD5B506FAA47A708EC3443DDAD15D773C27BF21B6B55AF56D07EA
                                  SHA-512:8BF328291B52E77633694695E6866D42A022976D7FFDDE2BEA79F11C5E88DC3CAEFAC1E4C3BC18C9DBC87615E6BC65E32AF993C5C56B69808ADC09ED6BA1BB2A
                                  Malicious:false
                                  Preview: .....i|....-,km..........ZV..!(....q:...}0%.......'E..........{&........AF(!.......t+....>)..ou/2A.$)....Mjx_'8J.+.."..;'...1L./#.L.4;..xy....8!J.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.F-.k=.).n.U...'}{.}{297}{000049000056000055000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\188__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1315
                                  Entropy (8bit):7.415056207230083
                                  Encrypted:false
                                  SSDEEP:24:34dBrTNM7nBsdQIQoi5W64ZbRQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQKBBpR:odBrTCBsuIQok4TBAd4M9/xJfAXxut6F
                                  MD5:DAAF1990EB670E5E146B6BBCF996555A
                                  SHA1:13AC74B898E4F90AD382006900F97271BA9AABAA
                                  SHA-256:16B8F252FC8B981DFCFCB320F7E608AEF19866C77CC22F3308D501A60BE32C4E
                                  SHA-512:FED57F17FCE3E54FE4209410389D7FA068E24B2C824CE90E357AB052D153E2AA5C26C47DEF00132A579EA6D7F43437E179C8F10143B95F08A68335896DB52DF9
                                  Malicious:false
                                  Preview: .pt..........V..........OB............+!.....%~ 6..UfSe..$yy{qh.........."......qyp..{l....a|....a~....4=!8.......QG....rr..;d..........(5..85....(.hg..$GFU.YU..S........."6..$63,......).VV....8g..5&..DS..%8=~..zo`.....TAJ@EJdD....GJ......""99``..RC#<8vR^....20.....'MM............f...e(............sfWZ................ZZ........bq.........../........o~..z4>2..p.TO.....O.]P..xgl.D.......2j...`g2w.....{{..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\189__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1482
                                  Entropy (8bit):7.511610802097327
                                  Encrypted:false
                                  SSDEEP:24:Q5X7Te59Nq/HYZGKX41Sd1nH8I6yl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRM5K:47659NkHYZpX48d1H8zAd4M9/xJfAXx3
                                  MD5:6996EAF0509AE7F07665B336AB2D878C
                                  SHA1:EFFEB94C62B4EBE70AA93E70610013A835CACED1
                                  SHA-256:BD67F472987A9AEEAF432801D359EE92BCD52F73F7D1B2645EDAC3AFD4023323
                                  SHA-512:5542CFE9D3B4CEADDE8D8F0085FCD054EE08B501B47238CA5C64EC7FBCE182D773557BDBF30060F55D9067D09D75D127ED01FC6C9F224F76DDF1E96357D73FA7
                                  Malicious:false
                                  Preview: ........FU.........b`..XTp}7>GX...a{...;............Wd.._I5h{y............b?..............mw.._.....*5..UIi`....NyUONU-;..^Y..........GP..PM{8........5&*e..gs+:....;b........?V..W%..j@.......s`..ap..16FL.RFO...f......................||NN.._...E.......REutEbHA....EE0...+.........'8..<s5 57FC.........&=......UR....MM....BQ..$5HS............^B.......+s...{c..z6..?/.......&3......x~...K..Wd...........\P)q../+pyv1B...QA`...b .......k~..EB ;........$$..++_..........6.11MU..46...H.X....JO{n....\C34.................3~.......tv.........J#uV[..8'x......Kos....t${ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$)
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\18__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.411523355937832
                                  Encrypted:false
                                  SSDEEP:24:go2Ci/x+ST/Zg0lu1eLJKQG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPc1BBpFUt:gUi/xdfK6Ad4M9/xJfAXxuVHBpFUBvfv
                                  MD5:2FD71319A870E8358F9E3C7D2E2BF0B6
                                  SHA1:548756F419AC9CC54A856DF6ACF63340FB104B21
                                  SHA-256:B2F4F0C5EFCF0212CE64A80B340BEFECA6EF8587428D0FDE46CD4739539ABE7E
                                  SHA-512:70C461313FC7215C6DAEF780843CD4FCA84C375BDBD439720C18EC77BC61283A1CD2DDE294701CD5A53839CE0A6553E762963366BA1587B0AA8F3F13B73C7182
                                  Malicious:false
                                  Preview: @..]h/gf%s%2....ju.. 2..2?.....t#dv...ST96mh.....HT..*+cd..&77jF[..wm............QZ..sqHY!:....I....Z{.L^....b{`s....GKB.vE.2WW[G[P....*;TO.........Zc.ha......Gs....SV...+FR.u);...fqQ@)5..<<nnCC....!2..<+#9EX......!>..+.......*.............??.......>p........H@......Lo..RH.P..eg....C..t}Z]..k,BX 7do.D...I\...T............LL......v..K\....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\190__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.377765930473907
                                  Encrypted:false
                                  SSDEEP:24:7+8Zwldpf8G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRk8/ZBBpFUBQ+JgW51:7+ewXYAd4M9/xJfAXxul8zBpFUBvfX
                                  MD5:E64716E78ECC9A9841C65F06C2FD66A6
                                  SHA1:C7CCE8096DA7C49FBD2698F4978811158354D3D2
                                  SHA-256:58CEEAD0F94F42FDC127516ECFE36E553EA08D27ACAFABA91A41E43781CB59BC
                                  SHA-512:4676E0A4CC90A697181F256E24316924820875E3B0C97FAB319A1EA9F1964BBA90F69B02857708434A60C077DD07F1B5AA9D2A5796ACF4529D9D2E342CF0A8EA
                                  Malicious:false
                                  Preview: f2. ..ED>h&1..GF......Y.eh....f<.....~|PW............C.....=v..>c....%?.......... ...k`wd......' .........L^Ga..#:..@k....%......SXtg....d.AF5?....m5..2;.........q......eh.._..........V@.............@S..ap....dnj>....v......JE.. .........FF.......ARi$#,......23......^X..B}af..co...LAN^...........Z0)f|8-5iKXrp72....^Khw<;......n...........+ ..02....16{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\191__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1454
                                  Entropy (8bit):7.5019008129031155
                                  Encrypted:false
                                  SSDEEP:24:WSDRA+99Wae97bIKe84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+z8/KBBpFUBQ+JD:7q+9i9HIKzAd4M9/xJfAXxuf8yBpFUBB
                                  MD5:48519BFAA79C12D575236A3AF35C8FA8
                                  SHA1:A8F4FBE3D588EBB89385D8EB8AD64C13EE4FA484
                                  SHA-256:CA0BF2E332C3A63D696FC6E854BA7DAC2DB54D20EC981BB21073877D869BC60A
                                  SHA-512:E592B15D4AE484A4847395791F021A187B861E8E92507F38F0AE84A663A767E5262AD1EDE692CCBDB870790ED85B5EE23381B188813E82440342801173FED33C
                                  Malicious:false
                                  Preview: ...FEQD`,!2..oi.xk..XZ..........:;.VL.B....\Q./x .k}%8.............qv....(u.....{r`s<+.......di....jd....$=..'...>%..9%be^^xxM.....ZM..siQL6u..SF......$,Xj..[S0=.ZpF]I..'5..........................)4&eTY......?......<.jc.........jj..,,~b..gx._..K.U0..D^....==......: ............?.....^]../uIG.........V[........U\)+#2......NN;(-&QB,...HSur..2...00......[Dr<..i1.......u9V.NC....ve8|PE]H..l4..][.........rr....N_..l"...V=..V_..:l..dtpo...D.ZXhm......po_XazDM..%4..............DL..>.IKso2.7*..A......8'....()..dxvt..5eb9.CKoz..C..V.....E'%jo{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;.......
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\192__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1513
                                  Entropy (8bit):7.518544362778835
                                  Encrypted:false
                                  SSDEEP:24:UAjksKXDcT8qQ5TP58urbRxuk+qzmiL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRo:hZSDctQ5TP58quk+yPQAd4M9/xJfAXx0
                                  MD5:D1627C23033642580A2E24DC6CA5854E
                                  SHA1:C786C9EF2F15E4CE0F71AB037FD7E46356CCCE9B
                                  SHA-256:587F2365360519116B6C447D4EAB31097D147403290783C19C7568FB659F1EF8
                                  SHA-512:0BF2EC31D038FD0ECCF9B7FD95957E9D37901346E2FAABB09C0857415F7D75B83D945D1249BEF64633CAE6E56F8FA7AADFE5E73D4688A5A41291FED8EAF39C45
                                  Malicious:false
                                  Preview: . ....%s^I..........D...#(....t#N\DQhjru....ji..FY...WVPW.B.....rmrhyx........Oe.......vg......)}..F..btf........Neoidh.F{H3.....v}..........,&?k4=.......H@Oh~t..[I#Uk2....d.:7Y03%......rrff......+);*IRAFlfq%..a9X>....MK......iiNW4'.....{{DD..p<....87W_....SR....Ge.........&<0..X.......c`8w........1<oz...........st..................x.rx3...ee......gxA...?g...$<b^#o.......YJ'c....CJo7....N.uzN}nD....."34+...Bh...BKW.%s....9&3*k)..........u`.........rcin..ll...7$W.&)'/<#....qi..Y[TC...U.<U@ZX....gj......?$....sb..EE..ss.......u}........../*.C.HP]^N_@....@Ac5....RH......XP................FC..ux....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\193__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1453
                                  Entropy (8bit):7.50518938497132
                                  Encrypted:false
                                  SSDEEP:24:cf0Xm4lJdXeewzDcQbIHOAK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxT8//BBpn:cjPFN8H/vAd4M9/xJfAXxu68RBpFUBvE
                                  MD5:5AF9D5A4628C46F2953AAD64E65961BF
                                  SHA1:BC9A59DFCE8AC3029C7AD7E36F031FBA92E57CB7
                                  SHA-256:61691C08CDC5574090C1F2DB653D729771AF14D5084A732467151BD289788A71
                                  SHA-512:E23325DB97F555AC61F20E28ECA61FE42FE0075CC5F1B9E73A6322B7C6E380C26E4AFB8BFE98B14D1461764F1626D146DCD710F7632961D1FCEB8961ADDD814B
                                  Malicious:false
                                  Preview: 7c..e"...X....*+....guk.NC',lkM.j=,>.;..+,..........#?.G....M....<!yf..! WP.....3hB..........LW..+!B.!('..pI[+.__.................zf..O\....7,..ICw#2;E.j.LBe.`.76gvUF+q..R%..xg.s%2o~..|{....nn3l..</]J....JW.B...._@Lm..vcka....(!.....Ve.....66......H....6S31......nn..Uv..e.hG..EG*=..........p*..M...@BFC........."9..yh..\\vv....lg..=?..WL/(&,aR_uoo....n.|c.....Z9..8 .<.b4......m~.D.......HF.ioUR.....\vCC..ZF7&..%k....u...YPN.).;65%UJkr..K.LN..MX.......................!m..G......Gb......-041.CA...AQ...VV....zf/-....z67?yljj....VRJ.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;........
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\194__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.335306840251497
                                  Encrypted:false
                                  SSDEEP:24:8Yni4pbsmVzcYDr84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFk8/+BBpFUBQ+JgW+:dsmVzKAd4M9/xJfAXxun8mBpFUBvf+
                                  MD5:C5F65002DD0E5F3BC3D0201CEC4F7236
                                  SHA1:AB6C20D19304813F35B8765C763F58095C4A03D3
                                  SHA-256:AEB2D1F27C48F6471F980E38D1895373B187AFE5D0E6E3501EBACEF3DDC2556A
                                  SHA-512:9D4C8D05465B115D646F9FDD81FC8332042A0F4AB5580D28220E464776FED1A73A503AF4C2EBA01FDC80575D4C39360AC2FD18701726017250780A7FA8007902
                                  Malicious:false
                                  Preview: .....I\]...gf...........NB..CJ../..Bbxz)..t~..................@Y....ur...tx%..NN....%6..2%G]..$g..-8......QX}d..fQ#9<'..nr....VV@.4=..<+pg..WJ.......DT......\.z^......\*m4GK..\G...|9/...7.bb........FD/>..FA...EL.7Q}n...mbSY...._L..~y//AAss......DK..$;....|[......>>....}GP\d#C............\.>+..{r.......^{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\195__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2628
                                  Entropy (8bit):7.763032777022938
                                  Encrypted:false
                                  SSDEEP:48:GYarazHXglOV/2tfiY9BeMaev7log9f2ksv4IAd4M9/xJfAXxuD8nBpFUBvfn:GLraDwCetft9LR9+mpBAXQDmy
                                  MD5:5EED8CBD89BC8AB2E4D4A7CF61B256F8
                                  SHA1:7314F5EFC8C8B8A568EAB6712F9BFCDEDC9E592E
                                  SHA-256:18D289721AA1CBFF96F746E688FACFFC0D9DBF8BE49514B205011B2A2D7B279E
                                  SHA-512:C2DBBFF9C59552AB95A8F2954EB8F18D3201F143790D052EE59A07C61F0D3C8A6DFDDDC3BBCC70D4258D8BFF33A30CB63DEC7CE512D8CE4206D51571A7752CEE
                                  Malicious:false
                                  Preview: .....4!.Y........xk,2$&..GK..+".....HPJ.........v......... ..s.......X^.........ZZ.."+7$..gp..YD......xg..(4....=0;.jp..@VB^....]]S.R[..NY..%?..|?..QD...........^-^Ms.A.:6ss....!H....(...??ss..;0........hoQ[!u....!2..24....=.eef........//..qq"n...69.............8..**yFy~.,JF.....NQ)0.X_C{l.....IJ......,!BW..WP.....SB~y..hh........rc..FA...,......dxyhSL8v..b:.@[....I.Q.....FY...D-8............'Nd...............A'awF..O....WH....Y=...RM...;.{rc;..PV.."g..oEHH.......r~.......y>..bo..PO..G........:7..LS9>........UR..~~DD&j..K.....ls..+)..@b..Y\.X......RM.SSfgN...@BSI........))..u wu.....72zo......}zsh..64......xx$7XSm~..3"......U.......XK..............U.........Y2......e...8-.\N'8.....BE11$$..[.......xo....O.....3.....xr....W^....{+...#QQ..zz....="1.ei..E ..: ..r\...._|............wn...BQW...'}..ff_...t2....;pe}t..E......=2Gt...............~i....Q.ts..))..?s....4;....#fp}w..EG.....?,[Y..XM..........9;.....YY..5y..n#....gx....mogphq..ET.."
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\196__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.390681891216894
                                  Encrypted:false
                                  SSDEEP:24:ENQOQ2FrfeTSWA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR228/acsBBpFUBQ+Jgc:0Q2lWxAd4M9/xJfAXxut28ChBpFUBvfF
                                  MD5:E4A54EB4942CB9D19CA1C2A1332FE69B
                                  SHA1:C38923EF02473225832FF1C8FEF7C119B8177345
                                  SHA-256:70AE2E37004C10C7837E5FFCF099C15B935E2C4E0365163DF3E249556D90154C
                                  SHA-512:6B726387ACF6D782AC5BE2100D18ACE7E04E50712C016D200FE9B20F11E02ECCF16E54DAD97632192C584CBE91FBE0F3CCF756D1038CB8006C404A0F1BD1DEDC
                                  Malicious:false
                                  Preview: .TE.M....RE..bc..#<ft)l..BIkl....DQ..ts...........utts...T.[F..YCML..!"... ..!=..,?.."3mvinW]...v.B#....gg......,*.....4....CH....+:.... *.bk.'K*#&...^_..uQzs..................u.l_......qm.%..}.`q`{..ZPs'....u.._|$".p...(55.....16ll......B....2....j}........"$...............eu%:....rp..gr....RM..zaQX..PApw//KK...........ru../.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\197__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.365209324508853
                                  Encrypted:false
                                  SSDEEP:24:rkWTeDd2SEd4IFQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0lD78/7BBpFUBQ+JS:gWY2tOIFBAd4M9/xJfAXxuJD78tBpFUe
                                  MD5:4307F52AF27BCA99F1E7BF0033806919
                                  SHA1:F44668B92A448BA5CC6D0E4D9765BD00CE66F646
                                  SHA-256:C9265919AA2925FF37F3A9455267591C503A8773575A3BECCD7DA71BE9715E55
                                  SHA-512:D7073898694F000CF2C80F3D0F266B6DB6CF7303BEE257BC96721DAF9A02A74E76748F9211873D472E3FF286E30F7F3E6BBCD95003079216FE65A73D9684044B
                                  Malicious:false
                                  Preview: .ok..dq.......ev....IB..GJ....:;n%!;({?*pz..qp<d.........`v......0*....3:NE>c....P...&5........ c..3&..97.........................._L.......O.....gt.... .{r..^_.Q(:......f..|c4YRE....07MM..##..5<..oxav.....ZO.`.. ...\V....vo..>n..zP==......?....co.v5P..RH#+#...>(..VP..!...xz......nn</N[.,h..!4PY........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\198__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.334186253019113
                                  Encrypted:false
                                  SSDEEP:24:nI8MWRHYtT4DDw7Z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCB8/43BBpFUBQ+Jo:I01caw+Ad4M9/xJfAXxuJB8CBpFUBvf+
                                  MD5:269CAF17098050D7EE5CACC3181622D7
                                  SHA1:3C52B87135CDB300383949BEC7E9052A50F71EC6
                                  SHA-256:002B589C31C8A4B51C48459A89EDC364ECBD39677469C9DF2425F2256381D2B6
                                  SHA-512:6040271CCC5C33DB03039E70365BCCBD63737688752D71E90253D2ABE73A8D12C429E231FA770D246262CF5A673CBAC70C781119C5E4FB0FFE5B3AAA7DC4B1A3
                                  Malicious:false
                                  Preview: .YZ.;Y...()....#0......YU..;2............hbid..?g!z.....Zl_I.Q/-:#..06....ENT...33`?...h..........TA8'bl.........3{a..V@.....IIc<..]N........k(EH..........(...@+........8...dv..b.......5255..xx...|o@W......e&ZWU@VI....$1..@O.<....V[..........#?..\.txL.$A ".....(.....;24IS............P.....2v.........53...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\199__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.39894374876669
                                  Encrypted:false
                                  SSDEEP:24:MOTvKDMgEuHD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRy78/L/VBBpFUBQ+JgW5Q:M0vK4gEeIAd4M9/xJfAXxuf78DvBpFUQ
                                  MD5:E0C492AF31F6173E69C88070A76CBA77
                                  SHA1:4DB5A5D7B4E13DCC1F3303684B865E59C7177249
                                  SHA-256:7FB7FADFD785288150590E60DEA78B6DE7B9947EAB2A85235E91A5C4ACF9C6EE
                                  SHA-512:D03655D687C1118B0589C56CEA222F69CC448933F3B70FBC8BBFABC1899F0F4834B7E86680BED46F0BCD61E2995F0DFCBBA357C78DACA9A7F8C53071BA85712F
                                  Malicious:false
                                  Preview: .@D....,`..yx.....IWy{MF.......E.HR.[N....yx.!z..l_..xn.L....G]....ha.....jjw(SZ..6!_H.....*'.. ?ek.............SE..........ZI....]G..S........1......%^GL{|....K+%$1v.(i`...9O................9%...66..{pTG.....5..W]..............oe/.QQ..CP.2......VV....\.......2%....gn..........., $c3e..QA<#........*(........poni.........vv..vv..fmuf......25U_{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\19__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.389204656133133
                                  Encrypted:false
                                  SSDEEP:24:LXwcPsD1c/rzEMfXiJf84tFoze4ytP6qfHSgC0fNSZBzfteJTQRs8/VBBpFUBQ+p:LXdPec/rzJfAd4M9/xJfAXxuZ8vBpFUj
                                  MD5:06543169B65FD7025136FBA20743B95C
                                  SHA1:F3F56EEE6DA533BE479F7BDE16F5C0DA510F9BAA
                                  SHA-256:057139E8C8306EF1E225FF75CE2A07528E0C408707C8FA2FE8805A6193561CD6
                                  SHA-512:269FA22BF7C5641321D546C85BE332D9E6DDE06770ED8D6F23497AFF7197B069D1E8C0E0759A233E67BF2253BC993AE58B571E7000ED9D26D8323C2E8DD4F173
                                  Malicious:false
                                  Preview: J.B....]...VL....UJ..+n..CH]Z......@B....SV.......K....U...d9..............Ak...m~..TE......)}.'...a..&...RK..}V....x)M~..!!QM]V..57...........;cM;I@AF......#$.....H*.EQk...9&+FL[..:&@GllTT%%M.qx......uowj.laRG<#Ed...u.p.aAEL0)..4d.,u_ZZ..~~....)6P.IE.....pj....]]AW,...?%..w.......H$r81........ER...h,..........CE.....$.Q{......M............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0975
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\1__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.415587756421061
                                  Encrypted:false
                                  SSDEEP:24:G3jMqxRXmDtW+cz9UtuR84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSTeBBpFUBQ+t:GTH/5zOtBAd4M9/xJfAXxujeBpFUBvfV
                                  MD5:1D2D6A655C0413529547C88FE56E6A53
                                  SHA1:3EC1FA1B8592023FBE229F3E323A21887D56443A
                                  SHA-256:6075C4CF59B0BE96BBC997A3079C00B3053FDB962AD0A57EBA47A68B7B5904DF
                                  SHA-512:B52ADD0ADA6A29554B3ED0798DAAD71DE55747AA9CE81627484B9D935901D90BFA30E59A81E38B8BF64A738BF544090852677CFBB28DA1C89FF8B5BDF5E431D9
                                  Malicious:false
                                  Preview: })Y..R.....^DUT.......C..]V...L._MTA..34~q..VU..LS< .TU<;.E-<.........be..tx........!2..........:n....~....7....BQ.6TR....yJ..&&5)5>QB....xc&!.......[.=3JE..`.Zx..yp....JM..DY..K........d.d=..""TO......../.$!!......?,.......fl....E......-+..>4x^.....~b..ccAA~~..g+..._......\K......rP....Uj`g.....^...HX&9mJ....rc..IL........%"..ha..........uu......20..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\200__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.334154874981252
                                  Encrypted:false
                                  SSDEEP:24:V4Flf5c5c4R9FiPN8VR9G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdABBpFUBQ+s:V4FUR9FiPqR97Ad4M9/xJfAXxucoBpFR
                                  MD5:B9D275B736C909912A20D3E262741E2E
                                  SHA1:F03C7F11DCB5F465BC6436DE1B82ECAE74BC5AB9
                                  SHA-256:0F1CE3F0ACE6134AF4EA04833F7DCFBD06A7880B881C63092F7422722353B454
                                  SHA-512:7F62F3B02D8CEB4FB95D2D05B0FC2FDDECF4EB45ADB7E71D8D70446115FEC3C4983FF0CF820B86B02F5081FF3B38120EF3BBC0B37E681CE5CCDFCB83D9F23E17
                                  Malicious:false
                                  Preview: .SW-..........|/bqgy....1=...vB].....K...:0p}...w,YO_BArM{..m0........oh@IGL.............`w.....I....nq..%9....R_..OU......ni.....Hcj..av]J.......:%Rc..^_...<t}....c........R...BB..../F|j....+.UU>>..........5......`i.A'bq7..(p.bh......=...RU..??!!...Ch{..'(......HIHoha..24......#.uy....ZWTD,3.!....N[.....i8..kl{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\201__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.391261511655141
                                  Encrypted:false
                                  SSDEEP:24:Dgy3pkFRbrDZ4+z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRm7BBpFUBQ+JgW5G:6Zz4Ad4M9/xJfAXxu/FBpFUBvfs
                                  MD5:AA0352789B1CC04FC4BEACB135F5B222
                                  SHA1:08FAC207B00CA4A4C0F40B55947E5F3DCB9ADB07
                                  SHA-256:6FDEE7C7D12C147761BCD82B41529BF7A52D6B35378CE3E22CC64187E68AC11B
                                  SHA-512:8DB3BB35B408AB4EA6AD880BF2E709ADB126B58297FA0B70AA94E9FDCDE8231B93FECF59A53A9800030E84D4299878A8632452BE014AC50FE7A838CB466E30F5
                                  Malicious:false
                                  Preview: .!%..0%p<....{}b1cp7)....ei..ZS%:tu..V.......109a.N......Qg..S......./)wp.....X..)v........Z@.......b}....YP...............bbjj_...WD\KH_yc...............a..hf.....%....o?.4...x.........9>........3 ....PJro.TY..<#|]......JEhH..0)7:.U.............."=x6dhK.....mw........7...WM+.~v....9 .y2.......gvpy..:uj.fs{n..._.f`..l)ZU....``--.......,;7 ...b{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\202__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.786531990347121
                                  Encrypted:false
                                  SSDEEP:24:EhB2BFuGvciuP84tFoze4ytP6qfHSgC0fNSZBzfteJTQROUzfXF2tDFvy8Bp+Jgc:cBgIGyEAd4M9/xJfAXxu2158B0fF
                                  MD5:F02CD2F95A13A6FE2EB962AC95D72CB2
                                  SHA1:32B375A9DDFE6892CC431E7CE189BB0251E1A5C4
                                  SHA-256:BA77D8C94AF1CA9E1087533217259B7F83D09161D354B8F4E0A920AD4384BE05
                                  SHA-512:7294E64923251AE11A1E41FDEE24DF07B12E823663ACC9F1989D2130F9F0BF2A57F1E1886834630467072D4D80AA7375B70BA36A17F6F9F942D49AF73CBEBE5B
                                  Malicious:false
                                  Preview: J.v..kj..ds'=`a..QN.............>,....<;69X]dg....DX......../>.[F........47AM...;.....46..D_@G......#{..TI..E_.....aR%.....zi..pamvpw?5n:FO5mL/``XI,}.>.(jj............$?....M.........w%+/M.W...0%.........U.q#i9fh...1......44......AP....|v>j......"..IP`s...}G;...;&......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{_...LK3.et.).. }{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\203__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.674190284940008
                                  Encrypted:false
                                  SSDEEP:24:7FjEDEb8iRwr09eTiZfkG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMpUzfXF2tDj:hrbLarTigAd4M9/xJfAXxudI158B5ft
                                  MD5:10650F7CB7CE7ED36044C30468891406
                                  SHA1:9D2DD5AB0AC0900AAE7F41ED9FBC1F5C3B51B0E1
                                  SHA-256:EB4FE233AB9B881ABFC04062621ACF85A2460865C538DAC28F496D4EEBAEB765
                                  SHA-512:EF376C7DB4DF3658E9BE76C7B9FBF7D81D929133CC5C97EE6DE9AC1DD5BA00DAFE50E356CBA6C103C0A6536FFF67412FFF882BF3A15745163762624CD185B7B6
                                  Malicious:false
                                  Preview: .MI.......67d{hw..x=6;7<......oz..MJ_P........3b.~MJ.KAP.PRO2-*06707..MA./(.=!......BS.5/(5?..............ZF....}.duby-*..<h{r7oj..........7:...++....):..^O....ci.......................mm................vqQ[..o7..6A....alYR..........<<:&....S.]Q{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..9IUF.....Q..K.}{.}{522}{00005000004800005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\204__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.6993258917863105
                                  Encrypted:false
                                  SSDEEP:24:IU9WHnR12E84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSeUzfXF2tDFvyv2+JgW5O:RWxUAd4M9/xJfAXxuhJ15vRfQ
                                  MD5:4CD609DDC0775C72AA5BEB93DA2F1EF7
                                  SHA1:1A6BD63FA1A9E6E3276E16AE97DFA0365BEC19C3
                                  SHA-256:8B7E416E388CED3934780C748957979BCF6717015CF2D212CD2351CEE6808548
                                  SHA-512:8234B116CAD55F3ABF5C57ECC2B66BEEB9C418EA3FFB79A474B64605047E138BA87BF8119BEED51C4F19B0C72CF4449932C4651C6D5E4C868D0D32280DEBFB08
                                  Malicious:false
                                  Preview: ...G....D...MW......"0N.?2.....l;^L..df..?0..`c..YF8$......e.....JUou....30..l_....v}[H..............[.YI..}N.)................\V.hao7M,of>'..X.kX....ss..............OE....H....-Gy......k:....vv++..< .%..:8..!:..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{\.Q.8^.....*....}{.}{439}{00005000004800005200009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\205__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1539
                                  Entropy (8bit):7.550688745533921
                                  Encrypted:false
                                  SSDEEP:48:yUvFJNNN+c6Ad4M9/xJfAXxu4m9BpFUBvf+:yUbPlpBAXQHnj
                                  MD5:37C34E39962FE16C29A37E2263DF7D23
                                  SHA1:020F88936F8A138898B58BFA9B2AA1F5D27B6BF4
                                  SHA-256:4DAAFE025AF4034A5972423B420C9A8033FEF74EC5555DB7DBBE111811F13205
                                  SHA-512:E227E3570FC98A48AB06886C3C1D8DC68A0C39BBA4A883705217FBC032EA45EE299FB8F6665C17E2F447AE079C69CC9FC44FBA058F22B1EF212FADF58338E769
                                  Malicious:false
                                  Preview: l8.^].67,z~ihr........_.m`)"/(........WUdc....QR.....bcFAw<..(u.... :.........++77<..........hb!u+".......UU........ocu$...;....IB........JM....R....16............B.k]FR^)..C\"O&1xi..pw]]..??E.....RE......I.....vidE.>..%/}r.........@\oQ{,,;;;;.......f>d.............dG....s\....8`i"%?..k`...72.......oj.j -..............................PA......iZ.-........vi$j1=.F.xUN~f.....JG.......TA/:7>^.U........[hoE..NN.c/>YF.A...W..)?j+).....LS'...bk...ri......\Y..............ge....%%kk......EJ..QNF_.............lJ....T.;..&/......M....(bH....b~..........UR..................:+.........sw`y{|?*....3-..N......5q.@..k~..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\206__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.272497728829589
                                  Encrypted:false
                                  SSDEEP:24:6P+TGo6JJ/idYx8484tFoze4ytP6qfHSgC0fNSZBzfteJTQRtctgkMJ+JgW5z:nTGoi/S+QAd4M9/xJfAXxuuggkMUft
                                  MD5:70F34B8B11FDA399FB571C6ADFE8C80F
                                  SHA1:5CAC43DCABB56B4114831BDC3E1981F39CF675BB
                                  SHA-256:11519F701B7D7BF3FF8B8C7C9380B82B430C76F6AB52B5223C96D310FBE3F0B5
                                  SHA-512:1B4806E3D7919FB1CDC4157FACC4E9C808AC68DE9842D30D71079AA73139D32D65E6E10157450ED08FA7E19B4815AC912F4429E6C33AA18015A4294EE1FE2A89
                                  Malicious:false
                                  Preview: .WS.....]........dw..9;)"......9&..-f......V\WZ..#{P.BTa|..Nx...@....6,9?..JCsx.KL..^...........A.la3&*5..Y~..........rc...M)%.y..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{X..1...t.Q.'9!1.}{.}{297}{000050000048000054000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\207__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.338728107195715
                                  Encrypted:false
                                  SSDEEP:24:wKjqeM5o9Xzl0984tFoze4ytP6qfHSgC0fNSZBzfteJTQRYugBBpFUBQ+JgW57:pKkXzCuAd4M9/xJfAXxuJBpFUBvfp
                                  MD5:EEB2913CD7BA36CE3AF5216BAB7AABFE
                                  SHA1:30F9F4989453BCEFDBAB4FD951DB1F9509D99A50
                                  SHA-256:962D348AB73F31E48CFF77BC7E97ABC49D67A55A4480A15906C01788E05A18A3
                                  SHA-512:00843BDB555F0D708EB304C9A88A326E45FD29A24E53E916C5652DC4BF9252DD0AFAB588D103FDD3E7D148606266171B9353E50966E843610E7C1CE5BC5E6295
                                  Malicious:false
                                  Preview: .....SFG.XVA@Z\]sl="<.,i.......W.G..OZ@Bfa......@K;$.cu$BC....&{......A@.........==!~u..PRETCX.......~& AO]Ag......6...XTB..<.#..............43..W...c;.........pZ.......;L-?C\.p..SB`|..EE..0oELziZM.........qd.......q{<3[{.. 9..@....)..qqvv..<-...FGK..&C=?CY..Mc.... $"MW.......";.8s..-:.....wb....F......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\208__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.806785396758903
                                  Encrypted:false
                                  SSDEEP:24:Vdt3FdCkIJDaQge84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkuUzfXF2tDFvy8BpM:Vdtyk6aQgzAd4M9/xJfAXxuHZ158B0fF
                                  MD5:22CCC0E144E2FA4B4CD9B96EA870F3C2
                                  SHA1:D8128776198031D697FC670C09CEFC9BE045E77E
                                  SHA-256:4376E1A6E41C487E9D3E47D28BB99D1E0CB1F992A17B30559B8CFF4E31C6DC43
                                  SHA-512:6D3AEF9A53A9DB52FDEEE6669569F8679A53086EED0CCD9597571B727FABDE91ED2A335C2E8FBE9B2B6A84C66338F95D02C7FE05A9AFADEADCB1D7ACCC68998D
                                  Malicious:false
                                  Preview: ..0...QPP.....fg....CQ..]P&-.........DF.......A^............yd....no..psco..,..........|g>982....W..jw....98vq...8..........XZ$5.........B.,O......).lF.............`{.....L.....u'...k ....ObgE...6(..E..........>dN..ii..:&............n:..O..........7H....[e.......dh{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{ ...-.Qq...3~3..}{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\209__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7189409028064615
                                  Encrypted:false
                                  SSDEEP:24:QI6aLpaxuYYWgJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRg/VUzfXF2tDFvy8BXf:qawxuYYW3Ad4M9/xJfAXxuhs158B5ft
                                  MD5:B55FBA8DD12CEE4DF0B5F909D37E79DA
                                  SHA1:EDE20150D5B5BDF14E798A1BB5159655622689DE
                                  SHA-256:6F33A58616A87BC78622EF2FDB4D5983E38494F7BB3DE08F782DA87C1008CA01
                                  SHA-512:C7E5BB37ACCB4242ADF50B595775C4DDA129F00314CBF2814789D87533774E24A87EE1BA26FC87A3933CDEBB8492AA75985BFED1F712609D663535136F0AFFC7
                                  Malicious:false
                                  Preview: ....q6......'&......@.S^......?-..SQ............b3.........V..,3....WP..EI....fzne......`{}z...5<.Q-B..h.).......6=..Y[>/........../w...;".."r......>"..................m!6..!.L]....C..4.:##......K@ve......URgm.816n..c...ss.....>.....NN..!=.. ?.B..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.En. ;....'.?.J=}{.}{522}{00005000004800005700009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\20__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.418467803135237
                                  Encrypted:false
                                  SSDEEP:24:3gphMYY8S84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwQBBpFUBQ+JgW5Cp:Qph1XAd4M9/xJfAXxu34BpFUBvfo
                                  MD5:71DE109EB787E8089765D2F69DF667E5
                                  SHA1:E6E4177FC58BD1A2F08E90076BB671945ED7F585
                                  SHA-256:60924083F41768CD5FD441CCBCCA2544422811C0D017777319E7468F541691DD
                                  SHA-512:3E5DE961BCF1B626A7213D12BF301C806082842FCE92505A2B80C09066B2A2AFAB4DC9D5ED72EF35A93525337D68AA6398D7114991EA72502E1BC7B8A3F01285
                                  Malicious:false
                                  Preview: .......N.BQ..Z\...JT..DH..\UKT)(.#9..rx...~#{....\o#.....PRRK......) hc.`g....le.........B.wzh}......LE..........B^..LL..b=xq..W@@W*0RO.. -........DB`!q.ce......F0.ma.... -.........UZZ..';v}..df...........N./Iuf....EO..##.......::....{{.`s..'(..........;2.9subb...`Z..'`...4$WH.........J..TV......................zz..EE..ra$&xi.._X......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\210__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.713987177114314
                                  Encrypted:false
                                  SSDEEP:24:hwdwaLc84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcWVPUzfXF2tDFvyv2+JgW5BT:hgwaLdAd4M9/xJfAXxuA+15vRf3
                                  MD5:E4EE23466C53A8F19D1E2B0FA05C991B
                                  SHA1:99DA98886733C3AC5CCF754925D981B9B473A71F
                                  SHA-256:BE88FAD0335DDC3A34676B940AE441BCE588F6C0E99AA3A6605E48AB27E6D0C4
                                  SHA-512:DF097579FF516B932B99F501AE1F090A2D543B28CB9B83BDC9652C1161D5C4C44FC324ABF629D615DA81BF8BD38F96E0BE20BD509F6FB8D622E7DE76D5F44438
                                  Malicious:false
                                  Preview: ."&.....@......e6..........}p..b}NO...{n......l4..}`jY..gqz'..KQMK..) ..y$.......\OXOPG.......K^........IN.......IZ......LQ^.eh....]{..........99....DM+8....Z@...>3........JN.>ww.........{{......O\;,4#....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{8..../Es..5G..Ls}{.}{444}{00005000004900004800009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\211__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.346073904355167
                                  Encrypted:false
                                  SSDEEP:24:/ZzCKRNWc75Ow84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5bQ3BBpFUBQ+JgW5G:/AUP75SAd4M9/xJfAXxuJRBpFUBvfs
                                  MD5:7495E7AB58D86E03BA129EFA8D59027B
                                  SHA1:0189328D7B4F6670C9347E345C8803F8383B565E
                                  SHA-256:177E80067F126B09986A8F031ABE796BB99053C9FF609AAF5394A3EE06229A5F
                                  SHA-512:054474206A72429249A48F44A628AEA284D0FE42BAF9D3FF1453B5C9982F24CB333505689CFE886DE5944B5620E8E4DC2AA136B7B38A4C5BB7DC4E9AB5ED830F
                                  Malicious:false
                                  Preview: Qtp....D...BClj.^pcyg............ih...!r......hi..._B.+/.0&L.]_4-pj..WP..........EL..)>..[Awj%f......EK..#*B[................00..bk..tc.......R0=....!.wr..#(.qw85_UXP]wPY>1.Es.... ?A,qf....OO........]N........R.......nO.+.......:....gj.........pp[GL]..!o.......]G19.*..tb"......`h..)>...V..........4......@M..-2......$&O^#$WW..66..RY 3.. 1$?..ys..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\212__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.382625509362137
                                  Encrypted:false
                                  SSDEEP:24:iz79pG1JOgli/0WeW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPCuBBpFUBQ+JgWe:VwYjLAd4M9/xJfAXxuSCuBpFUBvfe
                                  MD5:CBC82F5FDC6F1A1A767FE5E2989F7CD1
                                  SHA1:EEE01EB8862A2BF72909A58279DC4C7D5DB2A049
                                  SHA-256:4345F9530386431DC823B4B828F164B5C74CE2755A7663A5C94DE7368EDEE631
                                  SHA-512:1DF3B9FA63DB94ECCD2772DAC0ECC7984F903B49C095364053E2B4A519E3DD157DEC199BDE6147F8EE0B2FD83D8CBDA0A3EDE44202BA369C509BAA538959E663
                                  Malicious:false
                                  Preview: '.. #...evcb......nl......t}.....D.............*q.....Yo`v.Q..e|......ah...dc..G...s`#4gp(2(5n-..oz;$...........D^shOYHT....&&8g81..}jYN.....wb............&+b*5...\+......bu..B^....FFXXI.JCFU............WB..5..:........QX^G......%..PP.............{SQJP|t.....\..Z@.*t|..}j..f>F.4/......YNIBj<J.......h0.........cI..<<.c...,;...>#..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\213__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.7791067818523905
                                  Encrypted:false
                                  SSDEEP:24:cnNDuPGs10mG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkX/UzfXF2tDFvy8Bp+JB:8DwGLEAd4M9/xJfAXxujXu158B0fH
                                  MD5:E8CEB352BC1191F7CA9F1306E9CB13A3
                                  SHA1:028E9A30B445357D12AEEFB9223A768478B351E6
                                  SHA-256:BF6C6CAB33E167B9DE9D045A54DEE9F3255B4B5D8118EE19312020B34BF81C7B
                                  SHA-512:B66C03064C9C992709923702B6503E108B674002F016BD73E31F6A0DB7243344A811F6C831BAE3946FD6E04F0D50563A31743E4EDB557531741BADEEC36E9CE8
                                  Malicious:false
                                  Preview: ...........3)........,i}p......*}"08-..(/!...SP....7+....HO...s.`}..qkNO.......Xrg{P[..,.....z}....le&~|./2.......h-.*#.......5&............py............TT..LPK@../-..G\HOmg.[..%}.K'|n<..i8...9,.Y..4{45....G...,|...D...Eo..33^^..u~jy.........`4=4......;;..fu.......py.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{w.-5.P...m...~}{.}{566}{0000500000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\214__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.724461862319373
                                  Encrypted:false
                                  SSDEEP:24:1g+1atG8+I1+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMRuUzfXF2tDFvy8BXCLr:1v1atHZ1TAd4M9/xJfAXxu5X158B5fy
                                  MD5:7999B45A228F88997CF5F2915FA3D4B9
                                  SHA1:50886D70D9BACFC214F900D4E7572948D35757F1
                                  SHA-256:90FC7A59B83768351AF570A2A56A7BBC72E0E73B9E0180923946B6C38AE31F8A
                                  SHA-512:AAD792383A204D640CF1F1C9DEB7E99FCACC304E07AE297D28EB35B6800C20265C2850A7FD6D6BEED500E0B6F377297A8F6905E6FE4A29FA918F270DF75238B2
                                  Malicious:false
                                  Preview: V......s?XK]\.......ge..JF...ls...Qxb.\...gj..........7.........[A..pwpyOD.43..M........a{..*i..@U...._J......K...!2av...........SL..tty`evNR.............}j..MW{f:y..2'..7...QU..&&..j~EY.....++MM].....va..............48..../% M............MM.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{u...S.p.e.. ..&}{.}{520}{000050000049000052000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\215__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.699215188359087
                                  Encrypted:false
                                  SSDEEP:24:8qFzFR84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuUzfXF2tDFvyv2+JgW59:8UiAd4M9/xJfAXxuy15vRfj
                                  MD5:B93BA26FF3E8D857A15934666C7FC1D3
                                  SHA1:2E87C6B4E3FA55266BEE813009D55ADD9D985E84
                                  SHA-256:EFA64289D3E8715FB88B8FBB1408FEC125748A70E9C9A7AA17F27B2C4780A1BC
                                  SHA-512:0B13A05E867A43B46F52A522D49F461E8D4212170D7D12B239B05E9A802E9BE2DC41A46B7AE6579BBB85E87867F23861D4CF73660891418662D5AF980299DCE5
                                  Malicious:false
                                  Preview: .....4!..EV45......QO.......R[!>......./:..la...@.......'....Z.><.......,%V]......SCJ'4.._HF\........vi4:2'....................2q85..$;..NN......9>.........9.........'*....Zo..KO................ff88.YJC:){lsdCY{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.P..v....+v.u..}{.}{437}{000050000049000053000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\216__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.317773740310821
                                  Encrypted:false
                                  SSDEEP:24:EUdLW1StXHX84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4csBBpFUBQ+JgW5P:HpW10XsAd4M9/xJfAXxu3hBpFUBvfN
                                  MD5:64AE3A1955CAEF236A8453963AD6C01A
                                  SHA1:862AB6E443D576E8F0085C10DE5F47E4D1031DA6
                                  SHA-256:66E9BFEC22BC5B06A73CDA7A07AC987033448CD5EAF1D8640F707B6FE6E7CEB0
                                  SHA-512:4876D2D0EDC4F8F1678D42F92AAF12E98335037777C1CFE14A677D378765766E1F774E1FB5201537D616E687E3F4D85926B7DE3CE9B9C628D9A9B2FF840C2E75
                                  Malicious:false
                                  Preview: .SW.........67d{hwi{........t.1fgu>+rp#$1>41.............kz'zxe|c.....................................Hngg~gjy........QbeOOOOSSXQBQSDU.......09,tk. ;............................`````|#(..............<d{.</..rt~q~tQw......EY............WD../ ,$,3.......\~...........M.Y.rk{ze..35$-..76.P\^..DAcvcn.;..524/GN........RRsso|EN=.....2).......U++{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\217__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1450
                                  Entropy (8bit):7.4872930357868865
                                  Encrypted:false
                                  SSDEEP:24:kt4NH2umr8q4jZj2gBKB2LDA0lHF84tFoze4ytP6qfHSgC0fNSZBzfteJTQR77Ba:keNH2fK92kA0IAd4M9/xJfAXxuyFBpFw
                                  MD5:9BD30A4C9AB38D4E5536FC96DE22C2DE
                                  SHA1:4B6B0F1E59664385E247C855F51C56FA7E0B2534
                                  SHA-256:CC69A723CD1A1677CAAC13B90B77019AE488EFBC2C9CFF03F103917123F29DAF
                                  SHA-512:A945628D63C9929F02DDC305627CC810FFF3C9BB58EA6B075583E7A13EE2D9AA074F187B809AB7665B6889A63212142DC307F4886420202F414B2A33649B05D9
                                  Malicious:false
                                  Preview: .vr....6z..on..|/......ODkg..=4....PF\.K....<1_^..f=......,:......f|..........dc++D. )0#....?%.....r......................,0......Y.....j}....>#=~~sGRpo......-yI(39&'+=H@U#`9..xxaz.....u.2.{Q........s`...d..:0.I.. x..o|....YV........>-LPkl!!kk...._...1|EJ|t......5;2....vI...$}q..J...rb.....FT..V..Rfs......P..X_...................hu%xin....tt.~mq<../'..+.^Hv|......7..4'\^..PE..(=ez=:...._]l}..{{.......'j:5t|......... 7....}....l..!e....R.!p........./.##..3/..b}..l`.........0...........wf.Z[...HH..:#8?................Z..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\218__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1523
                                  Entropy (8bit):7.5100623182275905
                                  Encrypted:false
                                  SSDEEP:24:TKT4xTdPCl88sQ30NH5JxDOG+QPn84tFoze4ytP6qfHSgC0fNSZBzfteJTQROYBB:64xTUl8I30N5TffUAd4M9/xJfAXxuGBj
                                  MD5:F57F0C8A293502BFBF273E67527201F4
                                  SHA1:6BBEACA31334C92E0EC151CFB379716AACCDF967
                                  SHA-256:392D041C3A7C3EBACE8A70E13D56B7C4A46F3495ADB16BD59CCBB8493C190510
                                  SHA-512:34AD8C602E9B9585773D52B9116D31EF97C54EDAC27169F7C1545CE1A0EA94720B6FC773050EB8DB783C7276348CA602C75FCF004880B25E74FFAB8AB108F7E2
                                  Malicious:false
                                  Preview: ..1..{z.....qp.....y<..XS...P8o....xz..^Q....")OP4(e4..cdE.Q@F...........ei............'6d.....L.i`..y.........{P..S_...ySTT......LN......RX..AH...DM....sz...=......O.Drsg................55E...=.....PJuh.[NC......|Y-8.....................xx.. 1........9;-7......{m..17..O`7?..xo...J...ds....Lsf..R[*r......^.....8..44$8q=......7-..........PP..kxZ...........<6Ed\^............EP6;....34............ii.....C......... 0RP..sj.......?!............20...............*(..PWii....Q._L....jb......ta..erg~.Q:..f$5!..3&...}%u$9?...S....q[WW.......N.uy..E7.............j}MT........##..st..n>..*4*...{xVT...j|8{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\219__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.387057666070848
                                  Encrypted:false
                                  SSDEEP:24:2WLDz7O1CTFJ1NzA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRv/VBBpFUBQ+JgW5P:5Dz1TjzxAd4M9/xJfAXxuevBpFUBvfN
                                  MD5:C53A4595E44EBF880FDAE995CBC6713C
                                  SHA1:847A6C405BAFE21BA71EDFF9EC602A34E0A0F9FE
                                  SHA-256:E24E9ADDB71846D5FD2419A595B08267B1452C70DA21964BEDCC1F1B02FACDB4
                                  SHA-512:8AF5B8BF4F096711E1160DB7158AA9BB16214955718451D3B0D8C335CCE878A9DEFE5F787E794F9B8542C81D8D384ACEF0DDF726517D873C3CD788F343EC4D15
                                  Malicious:false
                                  Preview: ...C....M..\F !..8'\N...YRKLI..@..QD......................U...:g..[A............=!',`s..sb..Y^+!.P....m-?..................%%....):..kz..!&DN.;2t,.=6..BCq4r.....>(7?.w].fj..&=>3a...l..#.*....]A`k....}l.......L.......:....mg..ff...........--l ....gh.................6......-jx.R_IYOP...P......W.l}.......?*.........8)..22\\uu..........ZA....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\21__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1378
                                  Entropy (8bit):6.607360332627359
                                  Encrypted:false
                                  SSDEEP:24:CxhgdSAG5wN84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcJUzfXF2tA63yrb+JgW5s:GgdSAWw+Ad4M9/xJfAXxuw1EY6fi
                                  MD5:1F559BA417410BB1821735A22B5FEDD1
                                  SHA1:BE5870FC8F8C405C21C9B2D23EFF7A715D89BAF6
                                  SHA-256:1852A0A748F18B98C079F2719161297384CA398F5D6B9456B9744A818C6A72CA
                                  SHA-512:9603FCD603E8A2FF565F5CBD262414390FFDB34AF3B9AE2749498B3E074FA7D573D09530FF7C8A5362E64A57C69822CB82887437AD26F6D9D05BE2BB1CB560A4
                                  Malicious:false
                                  Preview: .Q......[........PBf#....URI..y....><vqJEUPTW..@_...54.."i"3.....]G....56..l_...FM!2......_Xeo.....y...P4.......922!`b......]W....VP17>.....S`.......................BK:b.o.............M......aaee..\W;(..ix....MG..bk...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{0M..)PG..Z..".ja}{.}{459}{0000500000490000950000950000670001010001080001080001170001080000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\220__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1130
                                  Entropy (8bit):7.288354184713565
                                  Encrypted:false
                                  SSDEEP:24:c6rdBvXWrq8c84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZnMzBBpFUBQ+JgW5q:pBUAd4M9/xJfAXxu2MNBpFUBvfE
                                  MD5:701516900C3979F5FF89BAB70F573D96
                                  SHA1:A152DEBD0C807E8ACC4CC341ECBD44D246ADC86B
                                  SHA-256:869E65EFA4C0EF33A368A15D9FEB8EF460955487390212DFE05E0728C09FA17E
                                  SHA-512:6C9AD74E0C27ABE9ADCE7532C7149EFA543A00A651F355634C11B82AA7B9477A2BCBD834B2FFBE7ED97777BEE664AF8E2CF614A884ADB07FED9428BF75ACC021
                                  Malicious:false
                                  Preview: F..q...*|..kqCB........>3.......}o..HJ...........RNE...' .]^O^.......mlru....M~:...japc....!&...\.........?........0<I....>..fz....}.........\zs...9#qS..\.......9dp.5'......xiXD-*..ff......n#.......R....1...../6.....BG...\Ia~..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{X.p.../..B.l....}{.}{479}{000050000050000048000095000095000067000111000110000110
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\221__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1278
                                  Entropy (8bit):7.37943992492792
                                  Encrypted:false
                                  SSDEEP:24:LahKIpyv+NFdhlOU+W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCr9BBpFUBQ+Jg+:uh/pyyNl1eAd4M9/xJfAXxuPr/BpFUBP
                                  MD5:852E4AFB256C0AF7A419F79AF056361C
                                  SHA1:5248965EB50D7368A1860185064D88F92CDEEB44
                                  SHA-256:3A8772FAF87DC309D4CBBECB469A749336815B9AFCACFBC1648388630E76AD15
                                  SHA-512:54160DDF3EA794CD0A9B71898888FED0A6283E0D73C57E3135F24EF32D262AF3E6D21958E6C8F95F82C86A2141555C95652679351EE67C4B1CFA2395696BC0B8
                                  Malicious:false
                                  Preview: t ,...<=:l....TU....................UR]R>;qr..../3.Pbc...=,....rh....?<..QbmG0,`k................S.J+....@@....lG..Q]......ui +....$55.<;0:......ex............=...+...I>......WF..JM..cc...L...... 7?%...YT..A^..*?........ 9...'...CChhJVapSL.nb.P.u31,6IA................EG.......P..?z8%..I...qs;>..jg...]Z..$-.."3<;.....H[LG..[Y.........=..ee`|"3..y7ie.......$....G{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\222__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1128
                                  Entropy (8bit):7.254034943743814
                                  Encrypted:false
                                  SSDEEP:24:fe7UfH884tFoze4ytP6qfHSgC0fNSZBzfteJTQR4yBBpFUBQ+JgW5vjg:WsH9Ad4M9/xJfAXxuuBpFUBvfxs
                                  MD5:0EFF34794C0246008D83D3DE564D6403
                                  SHA1:65ABEFE3774BE4D278C5AFCD5A2B9C7D1CD00783
                                  SHA-256:9E7865B94D15DE29171CAECFD178F46356CC66551F18B85657EA104DD8589784
                                  SHA-512:EDA74A56772AE2EC5AFFF9D3BF12369ABB1CDC0BD120D2C3CFB9E6303F4C0554699D7BAA8A2D3234BFBF6EB69F6D19C78C44CBFE053B4006DF0B4573BCBE4B63
                                  Malicious:false
                                  Preview: ._h.H........=<.......KF..\[...;)..{y9>96.....<#YE..`a..b)..!|........yz..Ve....ZQ........NDM.!(.F...<.*LL~g..?.....5d...@@jv")bq..7&sh....B.$-/wy.....fu>f....-Z..nqF+i~%4........77B.RA..96....>.se.uQp=?..4-....9;..ep....<#..MV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{-Z!../NeL.j.e@.l}{.}{475}{00005000005000005000009500009500006700011100011000011000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\223__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.6008658362846715
                                  Encrypted:false
                                  SSDEEP:24:Uxv1Am/Jz8Z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRl+QUzfXF2tA63yrb+JgW/:UtlAd4M9/xJfAXxu0+r1EY6fTT
                                  MD5:8F1D99AB1B0C1F018B3A6B378285C5B2
                                  SHA1:9F9F52AEF24028D604DE3E21B1D6A3E5A0523777
                                  SHA-256:459A7CE7357925C4C7E73040289E4219CBAA77D335B602CB5C1BC49ABF3F97D8
                                  SHA-512:7745B031BA690657FA06A6C18D7B0496429EB7E577FAEB439945F8A85E838D527AD5684D64A061DBCBBC0D19FB1DBB0129FAF31B63B7BD607E8CF57A24408F0E
                                  Malicious:false
                                  Preview: o......v:..PQ........(*xs....py......cy....w}..GF..[.[M....Gq.....lu: suMJ..ne....cc....TG"5SD$>..5vBORG-2yw......33..D.......VA.....nc....y_..|eDW.....}}.......UBZM...........&...40....61............IIM.<5......VL.......ei{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{]~..E..{A..5..}{.}{460}{000050000050000051000095000095000067000101000108000108000117000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\224__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.366128960660447
                                  Encrypted:false
                                  SSDEEP:24:Eu/AILxqaQXam84tFoze4ytP6qfHSgC0fNSZBzfteJTQRd7BBpFUBQ+JgW5xs:EbMxqaQXgAd4M9/xJfAXxuYBpFUBvfTs
                                  MD5:509D25DA45E0C4D24A67949B1523E576
                                  SHA1:5E4725F4B6A86F9D74447AC6F140221037AF20AA
                                  SHA-256:5DBEF3B69188931F12EC69E6089921F47BB46A13DA86527C1738E17AB9C3C6DB
                                  SHA-512:9EC26FB61292ED5C1C62C85AD01D3D4B188DF224AE141C2A0EA2BB9AB5462396506BEA05A35560E0EACF07826C4730F4E875283808AD052FBAE5AA1243E846DA
                                  Malicious:false
                                  Preview: V..uv..C.=.|}oi..&5dz...xt..KB..YX...e.X..FL..ut(p...}`..H~i.=`wuSJ..X^...'hc..TS...............$g..?*UJ..UI..WN....pj............@...pcva....|a.m_R........j}..&,.!xAM..=&...a...wD..MM..KW..O\....]FBE../{...Z>X..!.su..............RR..//FF........|t..UB\]).....==...., >yb4~s..iv.....^U.u1I\.......E...3vYV...U....}a...n}....;!#>......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\225__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.363802862399053
                                  Encrypted:false
                                  SSDEEP:24:EYtsiq4/86zxA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrxBBpFUBQ+JgW5E:bs7cxzLAd4M9/xJfAXxukBpFUBvf+
                                  MD5:875BE7CE54BD4B4ED732470254418722
                                  SHA1:C0C9E2003D5C796BCDABAF12C3E32895DA7D8B43
                                  SHA-256:953F665ED57EBFEBDF8115A361F6679E9425FFA8BFE72B43E8F9398F45388188
                                  SHA-512:D93525D7FE687F8CB4380C752AF837EF9185C6DD85935A3AE2B927F4805919EA9247C0781DB47A529CF980A4AD450F2691A5033B847704F87969EE17B5C85992
                                  Malicious:false
                                  Preview: .....3&7{....vp.$7...._T...qx!>......E.(=..2?...D......vE......=?......:=.........A..ZIAV..0-..zw....OA....b{..W`.............KZS..MZ.....v5....nq..RZ*...uz..Uc....gu....-:et\@/(....kk..FO........h+M@9,.../.<..........ul`m.@......SS................^V[u........UO..QYca......G..N.........uw......:/opST....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\226__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.778090440526776
                                  Encrypted:false
                                  SSDEEP:24:D6Spc/4yINVvmL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZXcsUzfXF2tDFvy8BC:D6SrysVvLAd4M9/xJfAXxumG158B0fF
                                  MD5:72ED4E6207D252665C4EE7CC1982D5C9
                                  SHA1:DB279B7DB4A2BE389C205DDD3E61B1C414C48602
                                  SHA-256:70A72081ED129B47134C69627310A2D36609E7DDFDD9A9B09E90361D8E614841
                                  SHA-512:2C72C8A08A02212FB157E2C1ABA4142289BE6FF908EDEDE72061B076D216D60D7A7CB44779376574AC99F4C7F4ADAE23CF68C54B76C3F0DC1DBEC312E5FE8DB1
                                  Malicious:false
                                  Preview: \../..'&..`zFG....EW..... 'T.....VC....."'....FY..O.$%.....Y..="..{z52..uyZiAk9%......3"..JMYS.HA...............gM.................U...y!...ZK..-....g{-&9*-/..,7_X...KFO...Ak06d>:.F..hl......YX.........Oek...B.....@@......*9..RC...........CN'.@@TM........Qo1 ....2n6:{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....,...f..8~..}{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\227__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.68963953555849
                                  Encrypted:false
                                  SSDEEP:24:P+6O4+txEL5rKHMig84tFoze4ytP6qfHSgC0fNSZBzfteJTQROkZUzfXF2tDFvye:Ge2iUdRAd4M9/xJfAXxuPr158B5ft
                                  MD5:F3448AF75EB8246CD2C5B7490FD51C1B
                                  SHA1:5DCDD472A387B22E970A948F8441EA5410CA5638
                                  SHA-256:CDD25AAB7843E4CE74DBA7824181CB94A289D611E717D625A6136239F654F3BC
                                  SHA-512:0CBB475E2AE47E3A03DAE88AC88CA4FEFBDE5A819EE091B374DCD08A93D30F8ACDF1BEE6701E0913F4F60A559C6D5FD2CFC58985BFEAE76F575A7B22AADA1D5A
                                  Malicious:false
                                  Preview: .)..,-.ub.......cq.k..38...,{5'..GE....JO..[P......WV&!.....orRM..(/......).....=...N_QJcd...A..%}!N'7v.Uf......k`GTom..(/..})......UL..U....;..OO....2!57....:=...4=l4....pJ.8..4)...........vv..~u....]LXC...u..<5....z..........Ci((bb.....ud..b,..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.........Q9Wa.+T}{.}{522}{00005000005000005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\228__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.704088028124697
                                  Encrypted:false
                                  SSDEEP:24:BURxPtLUdV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpFVCUzfXF2tDFvyv2+JgW3:BUfPmAAd4M9/xJfAXxuUvt15vRf3
                                  MD5:69863230E0D8C854E3BE488A04B3A9F0
                                  SHA1:5907E731412A849CCB3833532D2A9C56FC341021
                                  SHA-256:D55E21BF87A6B31A01A47B2F2B38C68CE3DCA1DC18E6E453632BF7C45217D4BA
                                  SHA-512:FFADEA1BB4BFF1549FAF9122967FB99B198ABEBD698EC716698E7C77B72873F3200EBE0225F40D4AEB5CC2BA7A8DFD9159F5336FBDD9E2B6A26F167AA30A9B7F
                                  Malicious:false
                                  Preview: .tpsp../c........):........KB....=v....!4kaFKHI....i................Z\........wp11C...h{......(5T...RG7(3=sf..........wdqf7 (2....LAYLTK.)ss..........<<......,?NY3$bx..\....."=.(....==..sga}x.aa[[jj..e:......(?z`...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.1pN..(%....a...}{.}{444}{00005000005000005600009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\229__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1321
                                  Entropy (8bit):7.4142879293341535
                                  Encrypted:false
                                  SSDEEP:24:c2ctFAFhSjrj9gci84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuq/VBBpFUBQ+JgWw:c2cBvm6Ad4M9/xJfAXxuxqvBpFUBvfw
                                  MD5:CE0B5DD10619863E5276BE1ABD7CA52E
                                  SHA1:71D832449D84801534EB23CA6D7FD96E8CE13F62
                                  SHA-256:E8E947D0BEFF08AE3444E1739CEFD80F178C14980568172767292948C0F7C7B7
                                  SHA-512:36AD5C0E95530B37ADC72BA8E2D6F4B20AA53C1E65597BA3FED2A3C2A458F4EEE7304D66E3DEE473FA36321660C51175B4954E2C96D56C454B5753DE4495E575
                                  Malicious:false
                                  Preview: .........XYagV.......q}>3..qn$%..d~..4!..ty:;..:a.....7...id9..4-/5......!*..>9.......ds..a{...S......5;LP..+2...^D=&CU..lk..--.KB...bu..\A/l...."=..OJ:3..2[......OG:... /A.fP.k.b....X5..Q@....11YY55B.................-2..;.EP....oO?6.._Rd4........... 1......H.=X../5ck{U........................ULjo......$c......?6.6g........8U........J............._}z....!!..vey4dkKC........DeHJ5"_F...VT......oz.....gn..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\22__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1276
                                  Entropy (8bit):7.392330633246139
                                  Encrypted:false
                                  SSDEEP:24:3TeDT3fqRDKVONqP884tFoze4ytP6qfHSgC0fNSZBzfteJTQRWBBpFUBQ+JgW5x:3Te33fqRDMP9Ad4M9/xJfAXxutBpFUBj
                                  MD5:1D9FB8E1D31AB2627B6BAA84A97AD98C
                                  SHA1:099F8968D78770AED6B69B9210561E3BC88244F9
                                  SHA-256:C8A7456A5EFD03A321517A1E72AB19DECBC6B1F8A6E6F137B7153E32E7E13A7C
                                  SHA-512:5C471CC851C33775E5F921F278FB3F19B12EE2B9076B56D1372E1D8C18328F40811BF249ED3DD28A5B79627350535E0B9FD27EC9783A301C8247A63C7CF57A38
                                  Malicious:false
                                  Preview: ...}3ta`...RHNOrm~a..............k~dfWPEJy|qrhc;$fzl=....a*<-{&$9EZ@Z/.)........................................ce~r=lpCbHHH......|mzaUROE.........+*!d.......%-e..............ts@GmTTTTb~!*?,?=yh.d.......\..}0#.%....eo..22.7..kw..MM................ctBC................%b.....HW........-`....HM....at"=eb.."+....VQ...........|~......#)l_..44..+7.......v.*I..RJ:....cn..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\230__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.283707176466883
                                  Encrypted:false
                                  SSDEEP:24:mG5NZ384tFoze4ytP6qfHSgC0fNSZBzfteJTQRL1gkMJ+JgW5z:jNZMAd4M9/xJfAXxuI1gkMUft
                                  MD5:917AACB25A046B0531365C708A609259
                                  SHA1:C5F2233AFB68AB34E6D6727DD8208E668337FA4F
                                  SHA-256:4672FCE5EE2DA91A86DE31DDFC07B3F6C2ACBD148532F9C0A39D51FEB105C042
                                  SHA-512:2710AB80D4D538E03A03BFD0F774FF2D3D21B0A7258C08A0FEA963739A78B67C7ADB2783DDF9F5CDC201853B6DD1F12B0BE7026FBAFCD5DCE3EBE942CA8BAA88
                                  Malicious:false
                                  Preview: .mi.....uf..f`>mn}0.13.......rm...JP-~..%/..KJ..+pcu..]n.9.......pj..y~..7<...%%)vcjEV......B_<...*?...".......+|V}}3/.....W.................[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{4...]X.......Muj}{.}{297}{000050000051000048000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\231__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.3621205587780185
                                  Encrypted:false
                                  SSDEEP:24:bmpd/RWJqBQu2JS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwBBpFUBQ+JgW5I:bmpvWJqbQAd4M9/xJfAXxurBpFUBvfS
                                  MD5:3EB75B2042622BED136B95A3DF3D0233
                                  SHA1:391A4959DA0F157833EBD455513729C5FB05D04B
                                  SHA-256:37D7187974540EAE3A978E2547FC79F382C5B60DD2255A73AAC753D89FB63720
                                  SHA-512:1F6DACAF3D5722CFCFEC4F3EEE0DA06218D5888B7B926B42D2F3CEF578F0FD16659D70D7FF3C0366A77176A26B8DBF138846244365472ADBD5E556AE1E391ABA
                                  Malicious:false
                                  Preview: ...\_.................SX..R_....tu...........+s......^m6...U...JS........0;._70AA..of..dsdsHR\AB._RFS..u{..........z`..qgmq......._V..TC..`zWJj)..,9iv.9,,..S.X9..?;y<.7H\..4&.....sbMQ`g...........[L...4*7..._J..8..<..rx....V_....f6zI....zz..zk......d<.j.....Hf.....y..uZ..qsFQax...I^..h{ac..........TS..7>......((....\O......et.d....Fu......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\232__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.346128065994036
                                  Encrypted:false
                                  SSDEEP:24:Nucr36rQs37z964obaxkP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxBCBBBpFUBv:MAiQs3A4oYDAd4M9/xJfAXxuhzBpFUBv
                                  MD5:5FC4DE28A026C9E383D0C1527FB366AE
                                  SHA1:76D0CA04934CF653DE27423031EAE40CDC2D2B5A
                                  SHA-256:853379E28CA32EE15472495BCA4BF8B7B61ACADC33BC3DF4D6E44EA1CC904B74
                                  SHA-512:7F4ABBFA8394782F145178330AF5F4CC623DB9337F4EDFE3954741912755C811C08358F26216274E66ADA77A9FE2E68EEF406C336EE5E48CBFC2847CDBCAB7BE
                                  Malicious:false
                                  Preview: N.+....x.i~: ...6)....OBDO#$.Hu".<(=..(/..+.SPxs..`|.....R...a<......~yMN..Bq2.....$7~|......;1W...{#.dXJ........Sxz|txw&..Ka....5>..hj.?..NI..c7~w-u..m~..3v............HW..]Jj{>"..RR..........mz..wm....al..;${Z&.fslf....MD........::......9(nqc-=1.C...nt-%.0UUXNKh..MW....mo{l)0W.|+..xi..fw..............AZmdom......FF..........ix..9>..pC|Vss..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\233__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.581515411374413
                                  Encrypted:false
                                  SSDEEP:24:z2W3zUxe8U284tFoze4ytP6qfHSgC0fNSZBzfteJTQRT/cUzfXF2tA63yrb+JgW8:z2azUsPrAd4M9/xJfAXxu+/X1EY6f8
                                  MD5:E83FF0BD9913F845E87C894E65D48A25
                                  SHA1:46CC7C35579C91D48976A208EA61AB3BE974A1D4
                                  SHA-256:9620BDCAC319FD8AE24147961760FF9478331872D1A3F773FA647D32C7B3AE75
                                  SHA-512:A27DDAD06814AC474CD6A677775F691A98C9E8AF8B9D2714CBF569685E4566AC8913A8E3F30AE44D70ED423084481192E047AA3C8E04DBF464D39026CAD48C2A
                                  Malicious:false
                                  Preview: .'.K....UB.......&c.......0g..@U..ni....x{..9&.....OH..xi*w..;$[A..WPWT=1......v}..vtTE..^T........0..<<....?,/-...........F...FO9 ...Tg5...........DUby...."v.. x.}RE..zDET"?I@v'0..;....$$#?..s`.....70* ...,t~x..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.j.s..<.....e..T}{.}{462}{00005000005100005100009500009500006700010100010800010800011700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\234__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1316
                                  Entropy (8bit):7.430961916676345
                                  Encrypted:false
                                  SSDEEP:24:ZfOzct28pi3OLZyNi01/7A84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7pZBBpFUBx:9Ozcvpki01jxAd4M9/xJfAXxuQ7BpFUj
                                  MD5:6C8B770BE77BBE4F1D11CB54B55FB3BC
                                  SHA1:6422E810340B0BDB70364075B5FFE81993B0B3C1
                                  SHA-256:7388E60E91B248FEB2840513E9050D8E57FD6D7D2890CEAD04A860CA1F474DB8
                                  SHA-512:E292425B23733863FA500F2D1C7DEE84D229E0AFE2A230943308A6941581241926C153DB9D62F4FD3E612B24FB13DE25387C8B3DC4DD50B587EC7747128B1245
                                  Malicious:false
                                  Preview: .b.$cSR..avkqFG....5'A.....lkc9....ep.."%69..ji..jumq.'&G@......IT....Z[....p|-.......fu'%9(..16...md.+J...bbCZ.........V......zf}vn}..:+..;<......o....*-~uOG......d.^.............3A....55..os.t.............u|.Rm...zY.......<[[zc..=!................H@NQ....~w.%35...........E[...hx....zk....)wW^..kl..U...*m..:~+>:/PY..[.....T...2.....jj...........Q.........%is`...]U......?5.;pr......N]EG....XM+4..7,....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\235__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.788600875388705
                                  Encrypted:false
                                  SSDEEP:24:s2OzxDAIyFRvdFwVu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRY3YUzfXF2tDFvy4:sbxcHFyAd4M9/xJfAXxufD158B0fW
                                  MD5:9B8614F6EF76AFFD807C046972240F02
                                  SHA1:324617C36C5A11F5F03D75B440DE3812F9AF019D
                                  SHA-256:31793A1E407A61DE2676AF73C2D7E076D825621C1B9AD88361A014B89E2F0926
                                  SHA-512:F6BFEF95200DCBB588342DA2227EF2AB8EA6E3A582CD72AD3168DE25A0A44DE5EF62557F13D26CC169D9D88C1B2CEB732A687E8F978B2436774DE920417B9443
                                  Malicious:false
                                  Preview: ...EF...H..:;..x+..DZ]_k`..'*....54.....OE>3mlW.......v@LZG...=$..KM.........//y&.."1/8....lq...yl!>..cz......'.......$$X...../8BU4...o,....................A...^M...IS.....|i....z#ih.....#*pi wpiX.61H\.........WKhoGGuu.......kx...........tagx{.LE...._........33|{{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{[....[J.(~..D.B}{.}{560}{0000500000510
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\236__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.703650340081684
                                  Encrypted:false
                                  SSDEEP:24:0zkfEeSvczgsS884tFoze4ytP6qfHSgC0fNSZBzfteJTQR7scsUzfXF2tDFvy8Be:hfEeGW0Ad4M9/xJfAXxu2sG158B5fk
                                  MD5:388AC957D0BD896E395886A010072FDE
                                  SHA1:59EC981A1A8E53A89B6F422B2B77EDC77B8D3AB9
                                  SHA-256:545AEC926AA1C07133018504F1BE1B7D70CB39735BF7994E1363A79D05820B1C
                                  SHA-512:AE8CBDE45E4BD7D676863453FA286C55503A726440CAB5C9707EFFA478D57F8258B363FCBAD1DC7216F6EB9B910FFA2DC9C4FFBA5633F4FF3314018C84BEE143
                                  Malicious:false
                                  Preview: [....CV......US.O:)VH.............ISj9......pq.[...&;eVwA.........oi..&/........._....sdub.....^...}b....`|......E.7>....+<XBKV..HE.....(............OO...md..bu..........d{..z~....<;..0,:=FFYY....O.+".l+<....*7'd_R........ak..........''..;;))..J.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..2..I....?..)}{.}{517}{00005000005100005400009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\237__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.712736744380461
                                  Encrypted:false
                                  SSDEEP:24:PoORM+IM+XthuvM84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJUzfXF2tDFvyv2+JX:PYMK3ulAd4M9/xJfAXxu/15vRf1
                                  MD5:BE674A8232104615B1468FC6561C72D1
                                  SHA1:F92F1ECDCE4FE7D669872BE373F1B023803E6E1E
                                  SHA-256:2EA6F9D3BB56F9C3CA3AA555A374331E6A78100F3A1596BCEBC9EAE076118622
                                  SHA-512:CAA7D5863872E3A93101AE907C4362ED0D49EB42C4A27B8BC9735D25140D7FB5C833A0DAB68AE083679512C9D2FFE6AEBECCBC735961DF96B924DFAB1016223D
                                  Malicious:false
                                  Preview: .uq.. 5..%6IH.._...........MD..UT.QBX..FS..s~...g<]K,1!...xn...........MD1:...//.Kt}}n....&<..._..wb..GI..@\-*##.......va]J....8{......6.....fu..LK......>a........mw..v5..EP..\i..hl........[G..^^...!!@.....,;....QL{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{z$U..Ji{......-E}{.}{440}{0000500000510000550000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\238__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.3755860063804075
                                  Encrypted:false
                                  SSDEEP:24:jSCYzhKgmynyWMneXftl7ro84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSBBpFUBQR:8VKgmynyEXfjJAd4M9/xJfAXxu5BpFUq
                                  MD5:803E78C66795A647F7F7537BC34938FA
                                  SHA1:F6CD96D85E1DFE037998481AF231CD64B88906D9
                                  SHA-256:7A00F7CEEDB4201154ECCD35FF41719C5EDC119B16F9D3CCE078D643ED9C5ED0
                                  SHA-512:FF59576A42FCD590CF66481F3E5A87299706056B97EC8B6B51CBBCA96011BD106DAF48A853019F9799E9D248F3019FBF26767C0C18D779B625A76164713104EF
                                  Malicious:false
                                  Preview: ................tj......eh"+LS..j!..`34!..- ....o4.i...........nw..........w*.....E........(25(.?2=(po1?..........VLJQK]........2m..................|aF+v.*?......ooLW...bLZ..gT..<<--................}).......aBz|...................OOiiG.KXv;`o..........2;?.....+.....95y>.V....8'..7 .TRVw0...B......J.Q..07.^Q..~T.....!m..........$9.mj..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\239__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7615404214718575
                                  Encrypted:false
                                  SSDEEP:24:by5C+DPu96x9udgH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkZeY/VUzfXF2tDFA:by5CVo9SgcAd4M9/xJfAXxu9Vs158B0d
                                  MD5:CB8BCC5B2E8F9385831B033A34F3B758
                                  SHA1:70E1993DE09567C6840D386759BFBB4B48DBB5A5
                                  SHA-256:4025FD48E1880044FC6A19B8F9860EC21A4A570C40343371772A268D019CB82D
                                  SHA-512:DD9DF53C3B50B46186071A7EF3DB188DA223A5CF971FC2C297155AB47B24AB4056A561E1E60EA05C14E1DE961524010076A7F1C097A7B09F8643D46F728BB311
                                  Malicious:false
                                  Preview: .|.,k! O...................k1f1..1$UW............,0......7|..e8(5}b`z........)#.... 3..|m..>9...EEL.......NT.........YY< ..........pz..I.M...#2...7'.dd......qs..BY"%...X..W.K...I...B...`d..[...7xyx.....a3d4...e:............|w......nu-*...Bw~$|...%%";#0s.mz{AWiHY..le!}..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{fC.e....~......}{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\23__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1382
                                  Entropy (8bit):6.617774199666037
                                  Encrypted:false
                                  SSDEEP:24:G/mhoez30d84tFoze4ytP6qfHSgC0fNSZBzfteJTQREYXUzfXF2tA63yrb+JgW5o:0kkOAd4M9/xJfAXxuTYW1EY6f2
                                  MD5:C659D1D7219FBFE389B82BA38C28D00C
                                  SHA1:D9DD5672B84480A898EFEE7369004198F1EBBA04
                                  SHA-256:3A031B7D85F0E185A475A5C4578A8199C8D21EEA1BC5728ECC92823246AED5F1
                                  SHA-512:09A3A5FEF24B00259E30DBB2A437903E98412C1874076401B79A71FD2C3970A188B0ECE21EE72DC9DC292E3695A5E4C10C0867023522C0E65051E8615BEAE2C9
                                  Malicious:false
                                  Preview: %qu.o($%....QK..qn..1#R.......<fF...at.......SPod..qm..^_......../0......l`....eyP[..Y[...jm..N...d<.....>zP......CP..|m+070..})...#B....&+"r.3..HH..SO..dw..............:b.....,..xif{..|-....SS..]V...............-u..e...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..B.o..7.a^T.;.}{.}{467}{000050000051000095000095000067000101000108000108000117000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\240__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.669902802542767
                                  Encrypted:false
                                  SSDEEP:24:GiNzAIG+jIStCQLIGRmc84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRUzfXF2tDFvl:1VAIGwIA/MG2Ad4M9/xJfAXxu/158B5V
                                  MD5:7249C53C05E0A51AA6040912DB56F06B
                                  SHA1:A67E78E6951B6724B9DC11F39A0DE0EFC8C0BEB0
                                  SHA-256:E4A9A25C09781B5328E0EAD12AC3CDD1F75B7AE68D86ACB18526DDAF78A3E3BB
                                  SHA-512:EC17FF1E3DA4D9B6B1F51E41F06582A079B542A13D6B509E6A7214CCAF5C336D125AD855B341638D2573410FD6A3E992741A3C4E88EC0132CFAC6BEE508B69A1
                                  Malicious:false
                                  Preview: ......-,7a....z{..........}v{|..E........:5?:..HC(7lp....hoY....B....='..Y^WT=1...<< .. 3ZXO^.....fo.M....7S.4xRRR0,..3 31..:!.....Mr{W..qT].f...I.6iC....5)..ZIZX..]F....b6EL.................1...@@VV..!*|o57......%/....p(..#T..]]......&..jjGG..|`.....ZV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{2>.#.0....@V.W.~}{.}{522}{00005000005200004800009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\241__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.701300735592131
                                  Encrypted:false
                                  SSDEEP:24:4ngxwd0VBdAc484tFoze4ytP6qfHSgC0fNSZBzfteJTQRQgQUzfXF2tDFvyv2+Ja:k07u2Ad4M9/xJfAXxus15vRfQ
                                  MD5:CD4C53B1682B36A04CF80CCBF4B72329
                                  SHA1:80E56F5732AFADE41934076DD534BC70C49F6468
                                  SHA-256:BF69BF72B428C5E40BDC6BD07A33FBA9E5AF1C626F7781AE1918B64210762B72
                                  SHA-512:5E3D068B3E7525C239B39AB040755109D89D398BEE816B954653BEDE17BA68DC35192A3B8516208144C9909B09378CB585A98FD9B76CFAE2A9FCD44DCE20B815
                                  Malicious:false
                                  Preview: ,x.{|;.............bp....yr....\...,931..('.+/,NE...........kz(u........tsMN..aR..ZF..ve..N_........XQ.......0..2....5>XK..*;.....*~..v..j.vg~(%...Akuu.....t...]L%>.........K.z...pN..HU2;^.^m..~~....th;0..b`.?yb..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....E?s....^.}{.}{439}{00005000005200004900009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\242__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:Encore unsupported executable not stripped
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.3475803185077035
                                  Encrypted:false
                                  SSDEEP:24:8muaURX6+uPL7cOaBs7P84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIk3BBpFUBQ+1:3uaDLPcLhAd4M9/xJfAXxuSBpFUBvfN
                                  MD5:E3F1445D62A86205EB65DCACB32FDD5A
                                  SHA1:6975C59A992B80C76222E8A5F8AE5C2F4DD134FF
                                  SHA-256:B0349DC030F111DDF0C0E83A7A6700C4D852E1EC2169B9063567A57F617F6D7D
                                  SHA-512:6263E3E7AACCE29E29753B84D24DCCA689DBA0164CB792ACABA72AA950C87887F515FB1B5F0870CE4541D8F123A2DB719C103094DB132FF584938B24FCF3C896
                                  Malicious:false
                                  Preview: U.b........*+xg="ug.............m.....FI................$5h5..3,....>9...........................a... ))..$7............99................Y.{rg?.jmf{|ut..SNnf.:..7g.5lx...........#?....!!'';d..uf}j{l..jwL.[Vyl..jKX}1$MGt{qQ,%~g........vv..vj..!>..2>)q)L..XB........Dg..............y,TS..(+....P....^K..u-v'z|....~q." .NN((...ah..<+I^....s.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\243__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1449
                                  Entropy (8bit):7.468926106899115
                                  Encrypted:false
                                  SSDEEP:24:vZPuLtE7+ZhOCeiz4TUZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIerBBpFUBQ+A:v5uI+ZECJ4NAd4M9/xJfAXxudkBpFUBo
                                  MD5:231B24FAF10CC49A5EA6999FD1694564
                                  SHA1:EA47DC9400BEA260118DD243CA0EB16C8DD3505B
                                  SHA-256:CC4BFBF187CFD04415327D6F92B90F512BE8ABF773642200EE51205C92B9821D
                                  SHA-512:1FA454B65A484B13E5A9EE8E8C449ADA51A9A99DEC1C067F68B2997E63F0B09AA1181C35D600516D59DE9FF12DBFF530C1672648D51F96FDDE02E00F9C2B178F
                                  Malicious:false
                                  Preview: ..W.4s..,z......a~EZ..6s..FM..q+'pYK.........RQ....1-./.WP...lq..TNIH..WT.......RYIZ.........`4....|n....3*tg4...1=........lg..y{!0.....$I.R[..A4^Y......;?I,u.....<1.Guc...Oe||^^....AR..fw.........@SMn(.../%..KK....ye....ww....h$..l!.....1..fg......CC3.....!-...V[vf$;....UI..Z.....,hVCJ_.........]R..@j......t8`i..I^..[A..P.25ff>>dd...;v..px.........>.....X...........lsni..HA..:+70..^^....&5d)...........FD..";|$....wcy=U@..CJ.I...Z]....!.Ic..**g{m|B]X....v.}...........;9pg....4d.....<<......1$...=#.4f%&20........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\244__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1579
                                  Entropy (8bit):7.5597228897365785
                                  Encrypted:false
                                  SSDEEP:48:fi82vmfrKmJYg7Ad4M9/xJfAXxucBpFUBvf1s:PGKPipBAXQoL
                                  MD5:E31D7448412E26388202296E149DBFC8
                                  SHA1:EFCA62D9E33ADC5ED677B35C3A2836E241763690
                                  SHA-256:12075553C959FFC49833CD37DDA3306B6F948D7A8D1B704533923BC2843CE4D3
                                  SHA-512:137EDD756114B817D6202A013C6860A1756594736154CCE96CA85782AC12BA2C83425A3784D62552796AE099292FF498BCB7271FDDECD90DE2F1277EDEEF69B4
                                  Malicious:false
                                  Preview: ..0..Akj....jp98..>!...PHE0;...X....TVts..hm..&-{d....z{.....`=........LK..R^............d...EO.MD.T.._M........rY;=..A..5........~m........w}.....T5......+nb..{3..........v..(9....WWll..Y.v.8+......,1/lWZXM.....#bw..............t^........-<...L..r*.q........AA...6..4...ai......8`.A....].<1*.......(e..0t.......%,|$S.Y_:=.....:,.........5<..........'z......GGd(iz......PO6.pf....}..-4.JGT57....$)..PO......VT..JM....77~2......5=fy...$4!VT%2.........^J.h}-8EL.......U...$...nn.............[)....HU....k{..dk.....j...R[.Q.E........NdCC''............c|......KHXZub...PA}-23...>>?;..?8sf..on...@.psUW...:~........X.MK....... .....A]..>!7y..Q.........K..[K{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\245__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1137
                                  Entropy (8bit):7.265613275352228
                                  Encrypted:false
                                  SSDEEP:24:SuDyPKN84tFoze4ytP6qfHSgC0fNSZBzfteJTQREcZBBpFUBQ+JgW55T:Z0Ad4M9/xJfAXxuzyBpFUBvfDT
                                  MD5:1F9E315A1AACA8F80A4D711AD22E7A5B
                                  SHA1:3A02A9981320EC9740EB5CD20F47E6A64ED1962A
                                  SHA-256:AC6E530ECACA4AFFFEADFFA71D98A24668B75901820442DF5791FE6EE194CE0E
                                  SHA-512:C854F3D7A9ECC63AF1834BEB2219390C496A3E9978E202F2393F3578FC051DF40587E5A13C5D076A4B2789493A643D8417E9BA556FBBF8CC63DD61341268401E
                                  Malicious:false
                                  Preview: C..56..z6..NO!'.V..RL..92."....XYy2f|....:0..ONH........+.AWr/@B(1G].............................Q\...`:4..=4zcYT'..................NY.......@M`usl....P_p4Iw....ppH@.........0...L^....ds.....NN....j&DW...%-......DNa@..l{../w..sq......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{hA@.u..A.!...}{.}{492}{00005000005200005300009500009500006700011100011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\246__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1283
                                  Entropy (8bit):7.385850298169323
                                  Encrypted:false
                                  SSDEEP:24:TBCgS3Z/eh5S+MmbwMi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvycsBBpFUBQ+e:gLpQ5S+MmbwMnAd4M9/xJfAXxuYyhBpx
                                  MD5:369A5F50D208AEF777CDF04FF559419D
                                  SHA1:295A165049950E3283E532C6FAA04F669B9B7B97
                                  SHA-256:73A72EFBC6FBEBC0C186B6D997922D33A406F43A5967FA07B1AD7612501622CB
                                  SHA-512:5703BF0D68D796A26D89084C94D94A7C881ADE2ECD948B1F3F0820DD9F516FA95760235E284B2BD510C8D60A77075D1191E055EBB6942C21629652D221029EB8
                                  Malicious:false
                                  Preview: ujnPS...=..........................M............5#....).#5..TV....MK....5>...__l3'...QF..........EP..........;6.....d...."%((44...............\Q~k............RP.rN.:6..az..:S<*2@!.dNjj..RN`k....l}{`[\oe..ahj2{.GT.4~x('28lJ..................L.........SD_^........>>C|.......%s(%eu.....O........<0..'%/b8:......BW-2^Y....ln..+,yy..............g|....Uf,.FF44>"..D[.....2Q..]EA}.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\247__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1802
                                  Entropy (8bit):7.6247103592564685
                                  Encrypted:false
                                  SSDEEP:48:J3BNqkLSeCMehv9R4FKnTAd4M9/xJfAXxuvBpFUBvfu:JzLLX6hxqpBAXQhH
                                  MD5:FE38BC68351C55304C0D1627EB866910
                                  SHA1:31B8A59FDDBD9023895ABE9441EA5724C465F68C
                                  SHA-256:CC1E706D278283E42D27F238815CFEF1B7E035BD3BA3A2DEA9C6E1B04DCEDC16
                                  SHA-512:74F26FCB9C3F5371191066D41845FFAE1A1CE2EFDF40A02121E1C9AF8FA3CFC0294AC36EF23E3B37EC891A9036253A5FF2DD2D5931DB6DBABCD8C919699A8C83
                                  Malicious:false
                                  Preview: .|xmn@U.R..once..VE......"...AH..sr....}hw}HEPQ$|Y.oy..cP'.$2...cz..OI....%...8?22U.bk/<..<+....+h....(7/!..[Re|..qk!:......==..s,qx..=*..6,.._...N[.......9%-jA..a&..#7..-?....+<gv';......--..r{....CTd~...%(..HW....+>.............MxK...((........O...x .wRP...................+)............%.....j..p(.K....f#..h[....}}....%,.....+6..............E..2::%Yt....\}...d}......!$.....................VV..5y.......#.....VA....."=......]...m"........9,..,+..@I....G@..++........ld&9....WBhj..f...X3...zn........v.,}..;<.....(......`q..r<6:...........is....ds..o7..T...|-fy..AE1(....t$.....C...KI..K........!y^.......fUOeAA..v:jcUF@WJ]..ql.P..II..5j......UBWM...gj.......%....V}0!......GU{d:Wub....-*..!!~~.....i~%2.....YT.....%CffsXR.....Y@.......33......{d.zvN....,]G..^p.._I..SU....|tpr..'>.Q,c..;,.0....D....?4...K^..OF..s"60..6s......mm....I.FO..fq........RUdd77XX.H{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\248__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1307
                                  Entropy (8bit):7.439622879890041
                                  Encrypted:false
                                  SSDEEP:24:qIS5x2uva8RftLsS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvBBpFUBQ+JgW5k:q9588R2XAd4M9/xJfAXxuCBpFUBvfe
                                  MD5:3F16262A0A2AFC5F790104987DD12E5A
                                  SHA1:E41B48B844F27ED6C861F577630CC6C324AEE989
                                  SHA-256:7365EA7D77350943C9F5E10950D530464C3ABE2947F0C7B497EA565EE0C36BB3
                                  SHA-512:82ACA9EEC10835ED67D8FD4E64F5461F985E4715CAA91566265A6BD32B1036813A70F348E546ED55D8214628FDC7E1E380B20A6A6892C0661ADF477B64F6AE8E
                                  Malicious:false
                                  Preview: 7+/....s?....................yfQP.J......=7,!......*7...?..*wom..'=_Y......v+25....%,6%.h...............tm....SIir..DX......E...........)4^....fytI.....bG..Q^..V............r....!....kw....VT..!:g`j`.....K..(;......Io....................WBM..>!....{r6...77....!..X...1<3#KT...Q..YV...Gg*.h}..ha.....NI...........WK.G..N]....9#..\.UR..NN............4..............7$..+.}hidFS....az.....34..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\249__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1208
                                  Entropy (8bit):7.344551943663341
                                  Encrypted:false
                                  SSDEEP:24:93hAsVG7AhxmM9u984tFoze4ytP6qfHSgC0fNSZBzfteJTQRsB/VBBpFUBQ+JgWl:93h7UigOuuAd4M9/xJfAXxutBvBpFUBl
                                  MD5:29721F015A1D1D9CCB896DBDD3D1BBAE
                                  SHA1:ED72C8B2D33F8117C4A7B8FD2069ED8A304B126F
                                  SHA-256:F7FE63F5B2D3B5056EBB5CE3756742EE78013B025DACFEDB9A5C731F1C1B1D80
                                  SHA-512:49B610CE943ECC817CB1E043774A311A60748E965BB9FE0A5295B08290FF908E4BA442AA8C3DB634E3181656566E565D8BC1608FF2772C17A53CAA7FBEF0BAA7
                                  Malicious:false
                                  Preview: ..]..WV.C.........6$p5....DCQ.^...`b<;@O......&9;'....ru.@m|....%:..$%........."..odo|..0!..;<ND..?g.`rlJ........"..B[h?..... +....{`BEt~..T]..}&%...*Hvk..~9\j..r.DV..U8....MJ..yyyy....?,.9sd....>}DI....?.]H....5.......*zxK............$;`...0h.............(...XB....*(I^.......=?........_@43.....ap{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{\;
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\24__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.828184048458081
                                  Encrypted:false
                                  SSDEEP:24:okJsAUoe0G+fGi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRoywUzfXF2tDFvy8Bpj:okaoep+OnAd4M9/xJfAXxuTyL158B0fK
                                  MD5:54B6055DB249910A6C6BB9E00163CE59
                                  SHA1:2AEDC5E4E775F15207164290291EF9A96D9D4C10
                                  SHA-256:B19001951B34DF0B1CA97E92DD38D993250D6C26F06364391DF66F9178D047F4
                                  SHA-512:F5D06DD80F1CE263FB13E9AC6D1CAE9D4CDF8322E5DB69BAD5C5B1574763C37DEA948EEF4E39C5F062372747BD5776F0126257C506BA2FF66E4E4D8DFAA8A842
                                  Malicious:false
                                  Preview: ...(+.......ga=nn}iw....hd..el..BC....^...}wob...UI.k}HU..............18..{&..oo.D............kf......xa.......OSy~.....S......j}..&;"a..AT/0:.............LL.3:..tc....vk.LA....../T....U\LUK.../x......................NN...O....fq..3)}`.wz....S?..+2..j7Rg.....+........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{QvZ=........H..$}{.}{569}{000050000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\250__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1544
                                  Entropy (8bit):7.526055139026121
                                  Encrypted:false
                                  SSDEEP:48:4+njTlq028x+Wr6M71f+KJAd4M9/xJfAXxuH/BpFUBvfP:4212fsIpBAXQHx6
                                  MD5:8CA77F6F6051985FBB45B3C298D751FB
                                  SHA1:872C10BFD3C00517985D662C86AB293382FFE876
                                  SHA-256:EA00B34BDB4B3342DC3D8764D5D28A714304C7DD22653B1ED98D4279652861EF
                                  SHA-512:72440AA64F6A4B4FB20FC787832D0E1879B873F85B06C4EE89CF3E49ADCCAC130F371D578D8EF22A1900B391029F63F354C7A423A9C8980EDDD22F4544BE93FC
                                  Malicious:false
                                  Preview: .PT..3&T.s`....1b.......48....op...0*t'...............vETb.....rk@Z........m0......el.......f%P]3&9&..so.v........cx(>....@@......<+................7?nKFP /`...oc..G\NC.l...8.....IIwk_TpcCA..KP......le.......42Q^....,,......wp..rr..ee.......ld...........LJ..{Deb.?BN..D.`m..%:..udos....\YBW........./&..............sx%6~|paza..LF........-1......y!.t..um%.~2h>$)..SL...[NGR.......9>.T3<..=.oo[[.....1.l`*r......N.._...o|c..s1+k..|y1$....%:..6-.............4xgt.5:.......MQ..ORe`.#u..........tu..SOvtkq2b$........._.....2a!#......#6..WP............ss.~m............CK.......3v........(.....\I6?.......1t..Dw.(....!mu|{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\251__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1306
                                  Entropy (8bit):7.393148601240607
                                  Encrypted:false
                                  SSDEEP:24:oJWLH6eJFhK0Kzqu7KG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRReieeBBpFUBQi:B1JFhK0C7K7Ad4M9/xJfAXxumNBpFUB7
                                  MD5:E70E9A8DCD9CD1A2B04DC7CEE8A6D427
                                  SHA1:72662920F916C246B59D0AC46AF3BB2EA1311F03
                                  SHA-256:B9BA3DD54C22F3908031A9C1A02AF98E92E7BAB8964DF8D300CC3ACA697122CD
                                  SHA-512:84BD42CAAF16FBDB8F84022D3813F1DD431A04514BB8EAE6A95E771720AEB6FF5E899DFE0180E5108301D15C8833663C476D53033A7D8C9901B288F954A4AE35
                                  Malicious:false
                                  Preview: ...W...<j..ousr..-2...........D...K^DFpw..gbol..5*....%$|{&m{j..&;....+*..# +'............@G...GJC.............. .z|GK},0..!NN!=bi........G@...@MDV.O>RURA("..ai.$...............tcUD..9>......<5..7 1&.......-8...8+.n{:0xw}]..........J`....yy*6)8+4...........................sd$=`8'v|{jyt~rp..72...................**..66AR{p....:+..............SB......V5....!...K... 0.........CJs+...st.H|s..DnWW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{64
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\252__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1225
                                  Entropy (8bit):7.336015199654559
                                  Encrypted:false
                                  SSDEEP:24:aIU1HlhaRDuK7WHedU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCyBBpFUBQ+JgWQ:zuxGWHed1Ad4M9/xJfAXxu7yBpFUBvfQ
                                  MD5:8BD11AD897D32B4DD16EC7A943C1FBFE
                                  SHA1:DC201AE4BB1ADF49EB3A51ECF23EFF2D971C008E
                                  SHA-256:A3E71053ED7CA7C7777E463D1231A3527DDD669BE9F1406C62E03EAFE4C2DB96
                                  SHA-512:00321F670D657DFEAFC1C570C21512FB7651BA78649571B7337812CBB49387BE8FFCB47301EC64941914A668D8844635C7F98D78B6D6CB6B6A93ACABC4B7C711
                                  Malicious:false
                                  Preview: q..FE..1}....DB...ZD........fo.....W....U_.......4"RO.)#...T...|e..[]......d9CD<<.V......[L.........poXV........}J"8..I_....||....,%..6!.......\6;6#*5..z.e~..j.....EYteKC>...........5*.er...............`wh.....2q....lsVw]x......3....>3.h[.$SS~~yy\@RC;$M.hd"z..LNHR......K].......xpuw....d<....$5......ZQ.....OH..;tl(..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\253__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1217
                                  Entropy (8bit):7.342718931075489
                                  Encrypted:false
                                  SSDEEP:24:OIzgaFu7IWBuVw4wx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRavBBpFUBQ+JgW5S:XzXgvSJAd4M9/xJfAXxubBpFUBvfI
                                  MD5:155EA4B1C48D9F91E6D299272308E28F
                                  SHA1:176C960F124CF8995AB62E96F5168BD54872C135
                                  SHA-256:44A941F4C4F63641A1175BEA72366F6E875EA5FCA5AC1288BD15B7857E9A5F51
                                  SHA-512:DF5764334043AC88B16B01855AAA3C3EFFACE79059C1865DB0E4F2134BAE3560699FD556EA0C6E26EBB30F3162E3FC785294317AB00656937C8ECCC4187B641A
                                  Malicious:false
                                  Preview: ......&5XY/)..YJ..GE......ha....7|YC......IDUT...!7XE....gq..;9..&<_Y..t}..5h......dm0#OX5".....94..mr1?g{........LVOTTB^B34vv....BK 3}j<+.............[N:=.........Q'x!.........h..D6/.'...............$?......../w.........28......=!st..!!...^......V^......~Y...QW..Qn..Xb=1s4..ZW............"7....>q..y6....`u....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\254__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.348377099362531
                                  Encrypted:false
                                  SSDEEP:24:UGybKzegrYnymN84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNGYZBBpFUBQ+JgW5n:iuzegrYy1Ad4M9/xJfAXxuJgBpFUBvfF
                                  MD5:E6F8C26A45ED7502E1D16AF8B291ECAF
                                  SHA1:26E2BA5D2516BEEB6C212312FE656E61A537D89F
                                  SHA-256:65CD72CCD9AE39439CC39E0912B842A2E1BE4E45B8220410FEB11495768EEB98
                                  SHA-512:10C2D7EDF3E7810BCCB9415FAD0F561EE507213A78B951F79D500E563DC2BF637300E02CA92E858624C8F95D4824E56B19E0DD50BA302C1111189FF085515E7F
                                  Malicious:false
                                  Preview: ..]......5"(2........|92?29......!4]_............th.....!j.....a~: &'......Mg..YR[H....$?%"..t ZSF...........Ne.y...G....WW........+:IRHO_U.........p>.h..rz.............HY..43..FF......}j....IT.../:,3Ed^{AT.......!,G.....hhHH..8$....%k....a.."82:......yZ17...%......y`..}.,/../-..`uBO......jq^W......aa,,..wdYR.....(3..BH..Oe....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\255__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.803017595631716
                                  Encrypted:false
                                  SSDEEP:24:Ujy/Qx4HRzdqA6GmcNsQW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNNdUzfXF2tr:UOAERp76GmcNLAd4M9/xJfAXxuuc1581
                                  MD5:63A4657B5AE01B0E30928E0727CB5A0A
                                  SHA1:0C02E6F91AEED94F2DAC3477A0562050E09577B5
                                  SHA-256:6BEEE30F5A3D3FB0FE4414782E406C88BB55DB84138532D0B33631A61749ED1A
                                  SHA-512:04A83843F05513CD4CF3217E1EDDF9F0CFF854D47AE822C171F995DC0B5EB043AE75511956B78E02DA3330C9B480B5786C5A1B042147E4477B94E60E4D2887E7
                                  Malicious:false
                                  Preview: v.......F..utHN..4'jt|~}v~r....fy..<w..f51$..:7..b:-v....Uf....5h........QV..lg<a..vv4k....<+.................%?@F.......cc...W....re..%?..x;..WB..%.........$$))KK&y......2%...P..........23.%<../&...R..&q=:..z,.....13....DC||.........dw.....6+.V..*?..]1....al.[..GfIM......?+{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{+..W..Q[..p....}{.}{564}{00005000005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\256__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.716158820822389
                                  Encrypted:false
                                  SSDEEP:24:SbiXFjTdxf984tFoze4ytP6qfHSgC0fNSZBzfteJTQRkkYcsUzfXF2tDFvy8BXCq:AiVxxfuAd4M9/xJfAXxuYYG158B5fP
                                  MD5:182EA9ECDE6071348E8BFFCC7062DB99
                                  SHA1:9A3126923EE8CA871F9CFFB6180EA6B1D466E7B7
                                  SHA-256:9487B9E9F336496BDF70BA91AF91CBA929583BB682B9E783E30C91B942AC1ECC
                                  SHA-512:1C1C0C8BBD88C9856F32E9ED2AFCC6F0C13DD8B6D638CF02650216E60BB3592A3256DF6BA02FA6E652EF19F4B2F197216D7C359C76FF07477F9F22FD57C05D7F
                                  Malicious:false
                                  Preview: .]..>?T.J]..BCjupo..F........%.[...............SO..#"vq......%:...........,.........^O..QV82...*rY6p`G#..Akpp%9..O\+)..&=.......(p..of..eh.Kx'.......RYO\..HS.._UO...u-..ds^d.................=6ra(*.........S$-.#%_(.......'.;==PPDD..0,....r<{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.i.b...........}{.}{519}{0000500000530000540000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\257__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.686323680275561
                                  Encrypted:false
                                  SSDEEP:24:mbfBUZiW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfeUzfXF2tDFvyv2+JgW5r:mSZuAd4M9/xJfAXxuSJ15vRf1
                                  MD5:CEA8654F7EFBB590168842745301F1C4
                                  SHA1:A9FA08A6EF6EDED834B16E21CB5C8CF44B65EF70
                                  SHA-256:961AD801077C26130491C5A8BE0846DE6D2EA675327923308587A5470192A6B0
                                  SHA-512:28FD3D5E49EF900970383119ADCC312C118BBB02A364B72E7218FE58C1A501DA6BABA199789B388A123DF6DE8704D0C15D2A98B6738EFA552CE7FDA31D1EE167
                                  Malicious:false
                                  Preview: #15EF..e)....MK.....+)..TX..........9j;...`m..R.......xK....7jtvOVHR..CDt}...@..rrQ.......gp....I......>0PE^B|{........KX..'0xb..W.2?.....<gg........$$.....cj..2%K\....?|........~_UQ.0..LKFR....jjSS..ss......<+..3)..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{"Z.t{.xS.....U.<}{.}{440}{0000500000530000550000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\258__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.376517546456488
                                  Encrypted:false
                                  SSDEEP:24:Fo9EOkInvBS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzVBBpFUBQ+JgW5I:FolXAd4M9/xJfAXxuQBpFUBvfS
                                  MD5:D6A766293877F25742EB570180CA9B3A
                                  SHA1:6F926FD641D3AD108825DC97D2909B44AFF4A59E
                                  SHA-256:F1BA2DCFBAEFBE3369A3F83B9C24396CC85FF8A278A9CCCF4DE0D2921F067111
                                  SHA-512:55EB35E7FCA6DCC39FDDC89A29651C8B9F2A902DD8F91F785D8027C74530AEC7CC79DB2793E6C757F86A7665E17CB55355E05C4009502FBC137038BDACE2EF70
                                  Malicious:false
                                  Preview: ...56oz.V..TUWQ.H,?ku`b..........23O...8k........h0!zk}...,.?......D]f|..DC......be__,sV_.."5..IS..'d......AO.c]T....@w........=:==...GN=.5"..UO..'d>3....t_TEd.....IB...)><ldg........nc.*<...2bH..77..zq...... ;.. *K.......XK.7..('.....d}......vvjjff......3~87..uj1&..xq....AA)....6_SA.#u`m`p...O^..................V_..EB.......W\S@..AP(3Z].....4{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\259__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1308
                                  Entropy (8bit):7.427711023373436
                                  Encrypted:false
                                  SSDEEP:24:wFF8Bhped1kbvum284tFoze4ytP6qfHSgC0fNSZBzfteJTQRk4g/VBBpFUBQ+Jgo:MFfd1kbvumrAd4M9/xJfAXxuRvBpFUBJ
                                  MD5:DC82BFB9A8E66E5A165F5707F7C4AE9A
                                  SHA1:33C5D00376EDE8FEB60878B9A71D1732EF23B105
                                  SHA-256:068141FFB3D2FD42907C1543A99A2214704179002993FF6DC3467479B7FE82B6
                                  SHA-512:AD0D5CFCE01C022A815EE143884DE4339E912BEC0CEA182E1D511DD80015D4D75876A67C7B650892302F7ADCBDBBA1EE3CC4B72C0FEA192548971675C9B5FCBD
                                  Malicious:false
                                  Preview: .L.{M.$%....z`...........;0..S........|{ /pu.........rs#$.E..o2......ml...., ."..JV..........KL.....]...YK......dw9.su....cP........L_.......);1.....W9....CnQS..&P......=&ALS:..>LbQ..........M^....qjX_...bkL.K-....dbQ^%/..**..^Mmq..rr........./br}........vQFORp..ww(.......]....>.............$=2p.....fs......}z.@....\v##..7+............V..,,..!!8t..c.....gxv[...Pq`b.....X..%'.....#..<#........2#_X..=={ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\25__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.719184792856871
                                  Encrypted:false
                                  SSDEEP:24:9QUfBMVQhzd9d84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+UzfXF2tDFvy8BXCL+V:9QE+6hx9OAd4M9/xJfAXxuq158B5ft
                                  MD5:E81B46AE38898094EB3910A1A3BEFCE8
                                  SHA1:281F4C3E3ED1FD8DCB290CCBF6FADD36FA0E82FF
                                  SHA-256:E735B07598291A146E725F9721F16DCEF6AA2BB967AEDE046D6A61C0A25B963A
                                  SHA-512:49CB7EF9F2EE8C66D433511871141DB411281B4DB63B4FF2097947BC8B70DC6D8DC748842549619EFF244980F1D11E725A2E0B93A1E326045A4F85E9E7386FAB
                                  Malicious:false
                                  Preview: .x.....J 7BX...... 2....CH25j0...YL..61wx.........._.\]...[yhX...nqmw........|O.%............~y.....w/..*N1...&&......|mSH..?5..sz.&G......U.......::]Aw|o|......07......XB0..F|Lr~o..KBH....)LL++....fm............X.........8..}paj.$@j......pp&:........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{D,..|.u x...?.}{.}{522}{00005000005300009500009500006700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\260__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1282
                                  Entropy (8bit):7.362824817755983
                                  Encrypted:false
                                  SSDEEP:24:5mchA0OLOq2OnV7LJMP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFjpX7BBpFUBQK:5mc7OLCOnJLJMEAd4M9/xJfAXxuaj5FA
                                  MD5:EC5874667847C31949FC376119505589
                                  SHA1:87EC4F0080710B8E20186DF76AEBA273028CFD0D
                                  SHA-256:41CB082A1A656B3836D9747D0CB54BDB1FA0B0F43505A63D244B08A6607BA224
                                  SHA-512:BC647EBCF4F07512A8500C31F4DDACE8C358CDE9AB87E8B7BFC35C3090583CD00ABDD12AE15C62FF076FE627E22C406B242E6280D7FFE049E350190910160011
                                  Malicious:false
                                  Preview: ?k.'.....................70.....qd.......+.........kj..|7..e8..QN.4RS..`c.. .......!2KI....niU_.B(!E....,..........p|.Fu..88...O\LN....oh..+.EL....................88..FK....-.!...55..&-;(...?sh..ys.../wa.#0.!db..j`.>..RK~m,0....<<.....VE?r....0/..hi..W^....||....(.jf..d2LAbr"=..DO....yh........I..e1.........HN....('....__....09TG......EX.^....bbLL..$7p=..*"TK.29/....IK{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\261__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1278
                                  Entropy (8bit):7.371273546898959
                                  Encrypted:false
                                  SSDEEP:24:mGNLioojdTvQzTtfj5bm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsXcBBpFUBQ+X:m+io+RyVbbAd4M9/xJfAXxun0BpFUBvX
                                  MD5:E9CD1916B1DDCC534EEC4F17695B71EB
                                  SHA1:05B302888473569DA4256C93313BDB3BBC536546
                                  SHA-256:A8FAFD20E237DB12D103E15A097CAAC2C4B1F068D4E4C5D93A5AC145E63ADD75
                                  SHA-512:D05BAF6D802AD3F593CEED587E0299D6E0795A6ED7350E6825AE7A3FCC94331DA8A8B6CCD0918222EA582CD6AE4E83B73DB439CBC54F78E61BAA825A7D68AB71
                                  Malicious:false
                                  Preview: . .N...Q.................sxjmd>!v......IN..DALONEFY9%3b.~..?tbs.s..juousr...............5$3(25..n:7>+s.n\NRt}}........BN{*6..(66~b=6?,20.........S...;M=4$sai+...u}5CZ.($......V?ESX*kX......nr..5&tv....!&.......T.f..........8.oo...........uu##.O\.J.... ?.........)=;__....4.P\.....DT{d......CJ(..U......(=...?n71..]..../<.....a}8t;2....MZ(2YD.J}z))66...X</.\&)......ZL... QS....2j{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\262__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.356018646508841
                                  Encrypted:false
                                  SSDEEP:24:D1nipY/Fp1c6RrK7HQ26tskHm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRoXiBBpb:D1EYdjcoep6tskHbAd4M9/xJfAXxuHif
                                  MD5:FB85B586FD6A0E014408052DEF5BA2A9
                                  SHA1:A0718D570E39DE7FEDFCA60D7EF6DA6EF54C6927
                                  SHA-256:2074AE31325AE9835360DE25CABCFD9C5A388A98740C23676BE4888BAB275666
                                  SHA-512:94857E1562727B9D98BCBE0ACC27A36AC44562CE23E9BFC1F1D483A115EEB0D546ED96405FC794DAA45948F5A9A01EF5E6F6E14444C9591F04E210D747C232D6
                                  Malicious:false
                                  Preview: ......i%s`..............Q\YP..HI.]OU].......=<7o2i..........>c><..5/..../&..j7...........XO....3p........ey......................\.mdwd=*......*i......61..........wc..................<<...1"L[..kq...\Q..2-.......2=..JCWN..._.L..SS//..............@B..s{............;s{..........^O.I....ei.\R\^\..EPyt........JC~|........%6....<>..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\263__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1281
                                  Entropy (8bit):7.371617675938242
                                  Encrypted:false
                                  SSDEEP:24:pQNhugi1opbMn/d84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxXxBBpFUBQ+JgW5ps:pGIg+UbM/OAd4M9/xJfAXxuGjBpFUBvw
                                  MD5:CEF497C58250C01A086474C235C2E377
                                  SHA1:F5FD7FA0A151B413FAD1431C5C1D23661BEA9168
                                  SHA-256:05E1BD76542325BD99F93A7197B6219F0C8366CA26701A544BD94CD085E2093D
                                  SHA-512:AFDDC9EB102328EF3C72D3FE1DE6416AB27B6929AAD13D013571978E2F029798DD25268291676FB790C629D14BEAEE042B3E83F445EFE224964B0F88CB5A2ABD
                                  Malicious:false
                                  Preview: .GC..?*.TG....S.BQ..QS..../"!(.......6e=(hbZW-,.....xe ..=..Y....7..:<...........q&/AR_H....SNq2....!>....&/KR..Yn$>...... '..XX.\Um~..reA[..W.=0....]Dn..,2$C.......jkO9(q....:!..9P... .U...ff.....CA"3..vq-'..QXz"M+1"Yzag /T^Y.^^ovCP............ l...hg..]Bqf..1.?6....RRA~..g]...;mUX....qfJK......,:X...."f....$-..)x....[.....J`..hh...ENG....QF]GF[.TS....RR+g.........1yT........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\264__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.790327845005537
                                  Encrypted:false
                                  SSDEEP:24:fkFH+DeNIU384tFoze4ytP6qfHSgC0fNSZBzfteJTQRSxX0UzfXF2tDFvy8Bp+JT:fEH+dNAd4M9/xJfAXxufB/158B0fF
                                  MD5:E3D84DC33D0EB839C1F70FF551AFDA82
                                  SHA1:42F028FEF7ED4D3BF6FCCA4B9C3A58263BD04EEC
                                  SHA-256:3086534525BDA5DE001C09899C90B786E2DFB3E4944E635432BA2EAB8E69DF1E
                                  SHA-512:9AD26FC31CA1FCD024A3525F3DB2C9C2971F869FC23B55C393AC11AEF3AB2CDD34A8E4BB02BBD91D5BF347E0C5855CCD1EF7189932B70A7A038BB77E9E79315F
                                  Malicious:false
                                  Preview: %q.#................R@..Q\ib...G.6$!4........8;.......{z......l1........IN..YU......KXlnap....x,81w/.dyA^..pq...KdW..cc1-..gt...........QkbH..++l}]....??QQ..`kve..l}{`........M.Q.....D............>?..P^c7.2b.....+..;..HH....~u........xrk?3:L...Y..................CJ..6:{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{)....(..G.....q.}{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\265__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.6730901274206085
                                  Encrypted:false
                                  SSDEEP:24:9rQSEHoP4B6Vh/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAxv/XzUzfXF2tDFvye:9rQ3SeU0Ad4M9/xJfAXxuPvvy158B5ft
                                  MD5:71D75C80A5F9C541F0793CC0EB914323
                                  SHA1:E00BF7F0CF5E9D1D66D78A4158F23D862C72B0E1
                                  SHA-256:55AE793F39491BB410375A74254F81F4BA2E39158AA117B2A1B2050B25A470CE
                                  SHA-512:8701C5EE0C8340BDC03ECC82D66AAF9CA55A0C3936B7DFA1DB2F32BE68CA158484410FDECD2786A2274C6E3C324401F7EA2A5D8760E1A274BAA1DD24182F9739
                                  Malicious:false
                                  Preview: <hY.c$..r$....rsVI..-?.<1....;a...qd..!&|s..qr....dx..ml...=,..kv*5..=<....r~Uf<.=!..3 |~...5....|(..7o....[?Uf..==..1:....(9....5?.+"x .xq....o?..Xr....|`..xk=?........X.....{2%?...ET&;..{*....ss........ge...):0.B..$|..*]TB.......0.!!!..!!.........;7{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.St.o.....P.....}{.}{522}{00005000005400005300009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\266__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.718499369314034
                                  Encrypted:false
                                  SSDEEP:24:zZOo2dtn84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpbXEcsUzfXF2tDFvyv2+JgW6:zcrv8Ad4M9/xJfAXxueEG15vRfBs
                                  MD5:3593A61E4031948FB18A0B16F80B3133
                                  SHA1:BB4037EFA671F11F0D8455EEC0F232EA519DB63A
                                  SHA-256:1FF41DA99957A4F03B4C669434B70AC3E03ABC38310DA2D242714BC3A866BCD5
                                  SHA-512:E7967211575361C56E9A3700D98C7F16E3215FB431250608050CEDDDAAA5317A97D7A984A874381726FFF386AD31406A4C69B977EF747A60CE350F6BEC73E81C
                                  Malicious:false
                                  Preview: g3..9~HIx........ ?..k.................+$......0/...._^......<a.............._lmG......UW........&/...WG...."...}a......L]....5?.X....%DCJ<%....=.....~~5)..jy........K.MD..ZM^d.............44vv..5)....rp....}z..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.vi.."..}\.....}{.}{443}{000050000054000054000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\267__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.364517699675561
                                  Encrypted:false
                                  SSDEEP:24:Sx4qHR9dLtK4fzLIQG75F9A03KuP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjoXA:SxtHRbL4GL585KuEAd4M9/xJfAXxu/Hg
                                  MD5:87ED68DD69FB5E32452B3BA5056B76C7
                                  SHA1:637349CA6B795D39BA09A884D221B0C3F563C3B5
                                  SHA-256:C29E56DE7F98923C5E4567B784DF973DC86FD79EB1D3CA40597BE8D0745052D2
                                  SHA-512:71B93EF3FF4B79377E49586857DB3095BCAE79F993073F12505227BEE9C821E60E89CC807869F375B51562CC645C779DEC7D1544F643371F28D1D5B534599411
                                  Malicious:false
                                  Preview: _.&.....x......7(..JXZ.jg........FSIKTS.............10mj....'z......kj..........KW..FU.............k3B#....ff....?.pv..........KW..FU.............k3B6....eg.....lk.......4.[O.x.............ll....bkgt....mw\A*i.........8WB............i90.......**....:%$joc.Nn.....;3u[DDUC......Gh............!*...X..[N..w/5d.y' s6p.Ve..AA..fz.........1+SN.CLK{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\268__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.378009212702091
                                  Encrypted:false
                                  SSDEEP:24:68tgT63IySK1y36COp+b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP8X4BBpFUBQM:Fd7yqYgAd4M9/xJfAXxuQ8wBpFUBvfF
                                  MD5:BF5C782F905AC0BD4AA08346BB43E50E
                                  SHA1:4C33D0F94BD1E6BB36A89EF0089BFAE1CC1B44E9
                                  SHA-256:8E9D180125C57C60D7FAC141228808CD549B0ACFB4B0206ED9A16B7723B6D821
                                  SHA-512:AA1180C7634C0FDF74B62C6B7310D58CD9189F9075E78CC724A0211198FE2C0C3AE163FBF0D5709B5ACD8572C0DCE506498BB004E9AEA787604A9A60C4CCEE86
                                  Malicious:false
                                  Preview: r&......t"..cy*+....l~.$)")...9n......jm..UP.-..wh..C...z}.J..k6..:%..yx.......Zp..92..|~hysh...f2..^...qc..tt(1..Od..48f7.<@j..@\....AC..-6PW...]......f~ZU{s.+...KoY..[,..;$Q<)>...........4k........BX..............@U..........58.....:&&,,..]A......]Qr*....ntjb...!7/..........,;..p(#v..:8....XU{n..eb.5YP........||TT...m~EG.....mgvE..hhmm{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\269__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.3743094309831205
                                  Encrypted:false
                                  SSDEEP:24:zvaDLFT4KNlz/YB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCX1/VBBpFUBQ+JgWm:zSDRT4KlTLAd4M9/xJfAXxut1vBpFUBm
                                  MD5:FA6648F205618BA94D13BEEE294A16E5
                                  SHA1:FA9592F1F03556DF9F077DA863E05B3AAA36B7FE
                                  SHA-256:4911534793F3EC93CEFED4308D08E95BDEB39FF09BB7C7023DD010019797F01E
                                  SHA-512:1F5FEA00A748F19F99479F8B96606E1B818B02858D6BA13B79AC82D762762707996DEC8E72E3C0A3A08F122AF2824F2F496FB890725C78156B892AD18D86D3CB
                                  Malicious:false
                                  Preview: ...uv_J_... !..)zH[..KI........-2..z1{a..)<.u..vw.....6+..,...0m..-4Z@[] 'dm]V{&..449f..%22%..6+............B[....7-..pldc..VV........<&ROX.......w...{~jn.........PM.......s.........j|.,......fz..TG9;1 $?....o;.....b..qR.....rT||...KW......&&......s|s{#<..^_Pw.v.0.....;..bXZVA...m`..RMB@+ .....(c...;&/...~x...F@O..Xr.......[...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\26__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1320
                                  Entropy (8bit):6.7331507320556225
                                  Encrypted:false
                                  SSDEEP:24:qwn9wPw8M1A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsXcsUzfXF2tDFvyv2+JgN:qMZ8M1xAd4M9/xJfAXxufG15vRfQ
                                  MD5:73A34964B0F33F36A1F99C7896BDFEC2
                                  SHA1:F6351F6723FC6926D18714307019501C0599E9BE
                                  SHA-256:DC6F92735A655CE42317A800941A97BEEABB0557211DC9D6B4E9CD7E76D3AE91
                                  SHA-512:697C198F5A1A8B48C221EE23240CB77C4AAFFFA37F908CFC2AA3C63D90D7453DA1A59E7100715A860F4B671C0C54FC9498B44B3E98E3FF677510D3CB8237F378
                                  Malicious:false
                                  Preview: .B.Z&a[Z..|k+1rs}biv`r....?4...U/x......UR....ji..../3.P..[\O...............rq.....5|`....=?..NU........@.......==`|..|o....xc.....^%,......m`#s....&&..FZ...._]YH..jm...D..I.....?.{E...\U....Q{..88.........ET'<..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{../.......f}...}{.}{439}{00005000005400009500009500006700010100010800010800011700010800009700011400
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\270__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.77217161944674
                                  Encrypted:false
                                  SSDEEP:24:qjN+lRieCv+a84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+KgUzfXF2tDFvy8Bp+Jn:qZaRixvoAd4M9/xJfAXxura158B0fh
                                  MD5:5FF256502F9F99FFFA38E778182DA313
                                  SHA1:C10E119A733ABF436A1AC9F915D22D1EA67F2E9B
                                  SHA-256:C394F38900E8894A153A88F36409BDCE8678884C32EA44738C65A892A11D4069
                                  SHA-512:9C0227BA0C71EB32891F6630A626673E5B89B826E847385D65A3B803F0B66A249DAAE7423C2237501643F4D5A2121AC4A1D97C9AB3AA87BE169480413FAD008B
                                  Malicious:false
                                  Preview: ...V......g}.............#yC.TF..........;883..}ae4..RU.}lW...2-..?>..QR...9..$8......ud......8l/&..a.........16....ff............>4.G...z......... .99!!ye...................U.......<8....$!...e{...^.M......].....MM..!!........]L..........P..eCCCvo.....jP....}`ah{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{B....;.t.......M}{.}{562}{000050000055
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\271__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.682741557907906
                                  Encrypted:false
                                  SSDEEP:24:4KbbfPcnjZmbkW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRUzfXF2tDFvy8BXCLO:4MfPK9LAd4M9/xJfAXxur158B5fP
                                  MD5:F3F176D095D1C631BBCE7B0A5072337E
                                  SHA1:22BD46FA9AB2A04A5ABA4CC45C22209C0A8FB935
                                  SHA-256:A21A3DA34C00CDAF52F3AAD7F6819E81833F69445DCB1956519CC634B2D01496
                                  SHA-512:2FEE05D0CE80A1DA924DACA6E7FD2CF7199944A9E754B3A1C93ACC3CD2783AAEE46B654394047956BE64696F7567192B1B5622057702ABA3ED56684117C7BC45
                                  Malicious:false
                                  Preview: ...L...-{..3)..)6....y<...............lc....RY....M...FA^........='..;<rq...?eO......`b..AZkl.......}my..'>...pl....QS0!..FA39../&b:......OB;k..{Q........RA|~...be....T]........"3..'.....Ys........;07$..*;:!INzpx,7>8`..P'......mfZi.5XX..mm....DU..:t{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{&...j.3..g.-....}{.}{518}{0000500000550000490000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\272__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.71214781765136
                                  Encrypted:false
                                  SSDEEP:24:vcwfw5W2Zoh84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/AUzfXF2tDFvyv2+JgW5r:vcMw5LZoyAd4M9/xJfAXxuub15vRf1
                                  MD5:8023D0A6AF66E5F3D8004656BBBEDE6F
                                  SHA1:4E1A28960FFE06B2D4D462F08B2474C4D2F6AB45
                                  SHA-256:4C24C1EFB9E41822F11B1714B702B5BFC1EC786EF7A5B898EE65664606E64B12
                                  SHA-512:D14EDF65BECCEEC28B82E838E3E53103B16C93C16FB92CB06D57921B1F76A732FED8749713AC7F1BF78819771F5C1789F4D50BD8CE8C084343920EF9AAC79785
                                  Malicious:false
                                  Preview: .'#HKmx....gf....l....do...:3..VW2y.....;......D.W.-;..;.Bt$2.%'RK..........C......\......gp..3..A..qd..1?ZONR..FFss%zR[DW..VA.. =.S^..<#.*....veB^`g.........@S....d~..:yux....]h.*!%........Z]...........2%......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{3..B.O......<.6}{.}{441}{0000500000550000500000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\273__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.371372485978636
                                  Encrypted:false
                                  SSDEEP:24:5GpttbWeDLQeZaQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRonBBpFUBQ+JgW5Cp:5GJbWe56Ad4M9/xJfAXxuJBpFUBvfo
                                  MD5:3A6339B4E7B686BE0407E8B85B79F6A1
                                  SHA1:B61537854565C5D955419B81AE9BA88F90DA5428
                                  SHA-256:A1E9AD3383A4A0592B0EFFAA975AB6A4F2518437656C42A9C7257EC12049F91B
                                  SHA-512:48B821F07F771F4C9C48279AF74582D769F1E9F94296FA0F4C47D23E17ABD6830FF77924F073253EBFD4E032F0243F05AFBD2A72F18FAE0A6693D60FA025FA32
                                  Malicious:false
                                  Preview: .....k~i%..EDHN......OM&-.......S.VL..0%..s~...;`......%..8]...-4....' .....FAuu+t..o|k|..='.......KT .........Xo.............w~......^DOR.V[.....\.|..~o../n..................a...nD!!..2...):..et...........^.....!..]R"(....6/....fa.....TTi%..\........Z[....0.AG..........y>......0/.....+:..............ZA"+..zk..??{{ll.....31~o+0..DNdW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\274__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1275
                                  Entropy (8bit):7.3578344749959665
                                  Encrypted:false
                                  SSDEEP:24:IttipRG4ZBxi8mqbiZ/584tFoze4ytP6qfHSgC0fNSZBzfteJTQRZ3BBpFUBQ+Jo:ItQjHcqmZ/qAd4M9/xJfAXxu+RBpFUB+
                                  MD5:D19BA6AFE07E0F29B12BBC31A40F49F1
                                  SHA1:451EBEA7A6E9BB595459171BE4DEB9C85A654EE4
                                  SHA-256:140242FFB4B76022DF09115B256F2F704414AF032CF394F7428F0CB9C6B68C9C
                                  SHA-512:C820A3688BA9E1AEF1D48C4EE9FF16AE7CD2B01735C1785F86D5B6387A183E82653545B77BF5F7A30C0C557333539DCA14C1D8B59DD82381C82A26552F0E2407
                                  Malicious:false
                                  Preview: .AE..i|Z.=........tj....^R.. )..ed...6e..`jgjYXN..B....)..:......7.F\..Y^....R...ff...PC....jp..{8..rg-2....ah*3P]@wMW....TH....xx.qx....i~....p3........ur~o.U1../2.!....\95...p},EM[......~~..)"1"WUUD....DN.....!G....^Xxw&,...................r>..}0........Oh18..;=.......:.....Z_RZJ..RP....C......zs.._.............kw_..._L..#4;!@]#~..gg........if..op..........6!..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A13
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\275__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1519
                                  Entropy (8bit):7.5138900320100825
                                  Encrypted:false
                                  SSDEEP:24:UwWifGj2YCXLE6+WZtTFmg84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2PBBpFUBQz:IiE21tTFCAd4M9/xJfAXxuN5BpFUBvfq
                                  MD5:3164AF9F3C911AC7FC8D041484491366
                                  SHA1:AD075DC7D19CA5FCFC0F5A649BA7E27476E22BDB
                                  SHA-256:95D2A81401FCFC1AC157E05F5A3E1E4FE640EB53AD6203E2404C22D94CF247F6
                                  SHA-512:9A8433842E3162E86EFA113039E5F6F3F6A3C0AAFCE363D602EF932C6614DCC76C32378B4B45106653A0C8297C41FA699743CF4C19960EF28F5B50136F8983C3
                                  Malicious:false
                                  Preview: .....PQ..is98....$6.p}..8?.9n..RG?=..|sqt......2...kj...xi(u..XG..vw...., ......bi....HY../(hbr&.......6...ovpc....{w..!.11lp......8)....rx.L..8`.uNGd3... %9..%"..Nx......ZE....RC~b..FF??....w~s`............op....ZO..vy../&......9.4''..CCjv-<......JJ/..UO..U{....~]..LV[t......\Eq).........;,}v....}t..iq(*.....taop......LNDU..................f}AFHB..t^......xi...K..d<G$....4.Z......_@..<x......9a.bd.x$aJETg..jj.......AMN.f...&/D.x.........y;7w......{v..........qs...HHKK.....&k)&..TK:.YYQI..:8bu..+sV.......i|....b}......QS.."%aa......wd\.........GETHKi.....T........B...........^.<g..QY..cc.o:VT....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\276__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.77697064847808
                                  Encrypted:false
                                  SSDEEP:24:jmuYlt84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1EsgcsUzfXF2tDFvy8Bp+JgW52:ccAd4M9/xJfAXxukgG158B0fc
                                  MD5:73BCF09B7E7832ADEB2B62742811780D
                                  SHA1:9FC67EED7FAF0F09EAEE9C2B5D2B039D6C913EAD
                                  SHA-256:7A7001C8AA1E5CAD27B57F1A94E0879CE83093F330262F31FAE44F93C35C7CF3
                                  SHA-512:AB9B0674668BBCECF8708F533ACF8B215FACDA80DB6B8E0B847AB214D65584D35242728A27331F3F98966A7010131BCDC244E1B1E1B54979F6F2B43EE9FD58ED
                                  Malicious:false
                                  Preview: ......K.........*9......2>....ls.......J..NDAL...b9%3..Qb...........>8.........88${KB........EXC.TY.....3.7..........1111^.......$3..4)#`....7(Ky..........--...MD....|k.e?".....5*....@AA.IP....... 9M.+,.:._..5a.......xuu.......E*#..../8....^.r.......B[nc...'....H~..EB..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x...)TOK.E..W..8}{.}{564}{00005000005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\277__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.687283484431629
                                  Encrypted:false
                                  SSDEEP:24:iDNmTi86W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuUzfXF2tDFvy8BXCL+JgW5N:MNm6Ad4M9/xJfAXxuG158B5fP
                                  MD5:08F8A6F65AF414C4BEA53892BABE9020
                                  SHA1:DA7EE70B50E3BAA9B10B67C0A30507810EA86F3E
                                  SHA-256:8F5E101B5F404DC61A80FF94D65FAA9AAC89F83E3091A7A09DEDA8FE9F9E3742
                                  SHA-512:82A75DF214E6A0BF7B8A32DD225CD5DC2CD5ECA87A44C34935BCE09DFF9F4254BF8D160B2E356E756A073A3932768E48D6B6881EA292E3919D57D0714C2B50A4
                                  Malicious:false
                                  Preview: ....E......G].. ?..SA.N....43.B......25......hc..^B_.%$....j{._ex'8uo...sp................_X82(|..8`.....e....GG|`....?=.........XOF>f....9 ........//..< ..XK..'6.....-y....F41&.......3:..JyIcVVww..uiV]....xi..16.......agI>....nc....rXiigg..``2.AP..y7{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.D..9..;.x....[.}{.}{519}{0000500000550000550000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\278__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.683589906556582
                                  Encrypted:false
                                  SSDEEP:24:IEeSeNrB5wWCjAWnP84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8UzfXF2tDFvyv20:I7/j3ChnEAd4M9/xJfAXxuY15vRfR
                                  MD5:9C33EABC1A5453B16E77D8077DD01170
                                  SHA1:FAA46C7CC47C4BBE77B0E0DBBAE5A7F492413639
                                  SHA-256:FC4B8C8617769F166E4F911D6B3EC1A85414269D2BDC12CEF5BBE9169D6B4B93
                                  SHA-512:71E8BEB51545C479B4D759E3BD7F139D0993828A132F94F1B4C79573920074416D5ABA833FE16899BFF9E727BBC847D564713AC600ACC2FBCD81F0F530F7854C
                                  Malicious:false
                                  Preview: (EA.............FUJTFD........KT...FSIK...............GtsE...T*(5,3)35QVQX[P\........,?=*..7-....%(......DQ................../2.s~...1@f..@Y......rr.....BK_Ler)>....T..........%............X_......s,.'ve..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.9.....&4.2...}{.}{433}{00005000005500005600009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\279__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1306
                                  Entropy (8bit):7.408238780058009
                                  Encrypted:false
                                  SSDEEP:24:uVdh3wxuR+aM6MaeOx84tFoze4ytP6qfHSgC0fNSZBzfteJTQR//VBBpFUBQ+JgS:f4Ry3RAd4M9/xJfAXxuSvBpFUBvf7
                                  MD5:AD713E660FB0EC79C95D10E54BA8F9C5
                                  SHA1:E48072B95D3B07069253E05F1DF3DB07520D09C0
                                  SHA-256:2ED291E04151B7FD0233B6196B31D117AEE322AEB55BEFFA6F16B98D1C335008
                                  SHA-512:419E3619DB8E34FE866436BDC0217C1E6E856B42BC7386AA6AF6AFBEF0E64270A7CC9AC9419CC61A7AFFA0AADCAAC9CC62558B3E6B223FCF2BCDB80BD05309B0
                                  Malicious:false
                                  Preview: ^.......k=.98"$%.......B............................tuFAw<*;.WUHQNTN.............................................}{`lz+7.Ysssso0;......................^V2.....rhoz4Bt-;7@@RI..6_H^O=.......HTp{.....!:....R...@.<Z..C`qw..RX....g~JY.......rrhhy5...('7?.......0......ZZ..oh&....C......)6..bsDXgvcaoj`u0=@Uju..+0..,........;;h{....$&..by......rr..."3ju7y..l4\?OT...5u9.X....vi..I........Z....RU.@....9..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{64
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\27__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.403527266877772
                                  Encrypted:false
                                  SSDEEP:24:VyCxi/jo/7eDA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRBBpFUBQ+JgW5P:VylojmxAd4M9/xJfAXxuIBpFUBvfN
                                  MD5:A416C6C95DD94B32F5C206C6E7A68870
                                  SHA1:1699D6D4A0217E28C568D56CC3B2D2FD3AA3E956
                                  SHA-256:ADAAF51B67C52453DCA01D7172DB1759874B8DD974F62606ED7013F6B12D8D0F
                                  SHA-512:E41938288A0D6DE7EF767CFCBC6CA47EA167A0BE5D01F208A1D5EAC922EE941B9A3C5D7CA078CC7218024D954BDB2E5110CB3EE345A419D83FC45C0E197D59D1
                                  Malicious:false
                                  Preview: ..X.7p..6`QF..@AujLShz..\Q..vq.(.KY..FD....NKvu4?sl:&.Wfg......z'.................vj...fd|m....KA+......zh......t_y....J...DD..BI....vg&=..\V..JC....lkJK.Q...............+..h...|c....te..~yrr........-:9...UH.N........pU'2zp........OB..;..#{{.........'i....'B..vl..+.......8>OU........xa..Z.vi"i..GB....4y....bg.............,..EB++..44....5&=?bs{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\280__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.404270770140488
                                  Encrypted:false
                                  SSDEEP:24:3YrVihM903P4zT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaBBpFUBQ+JgW5P:IrohMBkAd4M9/xJfAXxulBpFUBvfN
                                  MD5:85085938CE3CC61656971E58BA117E2B
                                  SHA1:41FC1DF7394D3F916311D106B5B228C801DA5E47
                                  SHA-256:E954F8465E31F8DD0C134CC5F72AD632965DC93A47C443CEC78BB0B96B4E04DF
                                  SHA-512:D8206C33C66B598F3A4F75805BDBEA03E9606CFF74D49BB30741436E54205FEB04BF06B30E36A6453929EB221C468D48F64BAF6453249C06A8B103DA53CFB69F
                                  Malicious:false
                                  Preview: ..$.E...V..........-h.......Z.....ge....~{..@K..%9.&'ni...$y..KTG]........os......#2........>,....rk@S............ee.............xr.z..f>....el.F.nFK/':7...KK}.....D[...h........cc==....../8..;!.....MXC\.5....oe5:.;w~tm........ZZ..dx.....^R5m.........%EE%3.>........NL..tmf>[..........yl..........v.MO...)....[[.....IK..$?..gm.<..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\281__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.3811470474175485
                                  Encrypted:false
                                  SSDEEP:24:7mJ2DrxalA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwLWBBpFUBQ+JgW5b:a4rxalxAd4M9/xJfAXxuLGBpFUBvfJ
                                  MD5:97A9D62F48AA6DFAEEB43A80940F5A5D
                                  SHA1:8633F1099422509F1A253F4D883C22E84E3D1A35
                                  SHA-256:D392240B7FC81F0E4D0B654F4C4DE5863FDAF5F8EF6D2633463D2F24FF7F4816
                                  SHA-512:4F366600F2ECDE195F1D7ED08431BE5CE7EFD4A62FF06344BC7829DA2A0AA7E47165F25BA625BA075C2BB181ADBB784F0DD927CEE34F8E67E70F0009620BB503
                                  Malicious:false
                                  Preview: ...B......3))(..iv..L.%(!*dc..@EW}h..|{....`c..slXDG.|}...|m=`....@ZQP..)*.._l..|`XS....xi!:.....Gr{..s...%.......yR..FJo>.#<.LL......zx.........C....}.....6..l#...8.+?./=....ny.......>>$$r-..\O........................Qqt}ov2?.T.......tt....v8...k...8".........][vl........QH..Pl`..[L..><....DI..NQ@GIR....)8....gg....RY..nl...........0WW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\282__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.3417435506944395
                                  Encrypted:false
                                  SSDEEP:24:mJwAEDRuxjtJJPIhOA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRR1BBpFUBQ+JgW+:mvEDR2tJJPDAd4M9/xJfAXxuCBpFUBvm
                                  MD5:940886D594811B005175EDB99D42D022
                                  SHA1:FCBADACB1536E6A0E17DBAD28453E0732326E4D4
                                  SHA-256:F956E6AD7C9C30FE0B372C445831D6438DE7311E05C1577AF13424398ABF8578
                                  SHA-512:1AF07B8C3F7E35E267038FEE3E9DC974663AAB64801B8CA8ED2D0B8825921E758CE488E62A5B2751F1E5D8304856E6AC96C18F030EC81106AD5CBB0ED3D14BD8
                                  Malicious:false
                                  Preview: "....PE....:;!'h;........<0........y2'=.u`T^[V..s+5nrd.....$oy........~x..............(;ubsd..zg.....j......TM........RD....ccnnr-....ERCT..or....vi...ye.....A2EV........f}:7Z3..[)...0..!!....pcpr5$3(|{\V.......~mHkEC........ipWD..QV....''..XKT.....ls..de..../.'!FF........R..A......Z.........`efs..}h........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\283__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.354826585695174
                                  Encrypted:false
                                  SSDEEP:24:jaGFBAVshKNyYcT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRB7BBBpFUBQ+JgW5R:j5FBAy0ZcYAd4M9/xJfAXxuqvBpFUBvb
                                  MD5:8735B33E3458B2F901D3953C2BA5F7B8
                                  SHA1:98F404E404F5F383A5A8F2652F65934A6380A771
                                  SHA-256:CC7142D1083A2397418F6FCD90E2600C518740C78AF8F885EC21B816AC4E22B3
                                  SHA-512:D9B24919544CB36F81B3AFF8D104315AC389CFB33E6AA12930326B5D3219910A9A592F80DA9AA273C1E09D05F931B241EAB75E9EC94089809DE151B05C201F7E
                                  Malicious:false
                                  Preview: f2.....]J....>!..\N..r...`g-w......nl..........NRq ()..q:...DY;$;!..hoX[NB.%...&-............S........%||SJ..Ne....HIz..66EYja......WL...............^_..>-....OM.^.......w.O]WHJ'../>mq{|jj<<.............................%.........".Ak..||..\@J[uj....4l....F\..Vx..\J..........]_.....@N.(;...PP6{......V.zo...7o..CEho...0.bHNN>>..3...WD..gp{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\284__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.364265785859814
                                  Encrypted:false
                                  SSDEEP:24:5TPp5BuPW7vulsb4P84tFoze4ytP6qfHSgC0fNSZBzfteJTQRbBBpFUBQ+JgW5+:JpyPmvul2Ad4M9/xJfAXxuaBpFUBvfE
                                  MD5:25F80E24E06532B8833B79268FC6057D
                                  SHA1:F81FB48D6C2C706A9D547DFCF2F871C6AAA714DF
                                  SHA-256:E8B73DD500B8E7C7AA2BF51B1D5A8AD894D67D720D8BC42B5A086691A8BD2FFB
                                  SHA-512:92E263A84416AC6D8F716C56CB071CDDC445D0F3B3999CCC33113F92F11A597D6B326EB4A7E9FB2187079CDA6142ABB8785A8D534236A4934E32C7CD5200F24A
                                  Malicious:false
                                  Preview: ........mlPV....rl......DI-$..<=..4...6#....NO..D..MP..TbQGn3(*G^..........|!..;;..4=[H....IS..A.....<#*$^B........SI..1'g{ST....b=@Ih{..,;..gz..85k~.......92ld.-AC o....6...D3..c...wfvj..II....:e....0'[L.....G.........ylBH..Ww....id0`Zi7.ss00..............rp..iaZt..bt4.....}uLN..../wt%........*n...._V^....ho..'(qB[q...fz..i`....k|.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\285__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):7.43868171199606
                                  Encrypted:false
                                  SSDEEP:24:ihU1dFgjdDvRAkpemcZMxYXniEq84tFoze4ytP6qfHSgC0fNSZBzfteJTQR3cJBI:51d+jtRAPvZ7iwAd4M9/xJfAXxuIcrBG
                                  MD5:E862BFCC3398D7C4B6AA93E6B3C5CE25
                                  SHA1:3FB7E82825BE91255FFA147A69C24A3381D08217
                                  SHA-256:B722D85AD9A63D38F08898E2AA7755D2F695E78D63F01B436FEFB7A3E378DDAC
                                  SHA-512:1AB5FFFFE2A314DE33D64A719C9FC2EFAD4088F6BCEE21D29B9ADBE982B215CDD00EC5F6A139C4851CF9583F7AC4E2672AC10557547D232AF5B75F255C507CDF
                                  Malicious:false
                                  Preview: ..."epq......................Ze2..j.eg...............@..mj.....?"...........`Su_~b=6..$&............P...xjvPss*3~mZqHN..O..1......................"z.j.(%.......{pvq~?7R...............?3......l.....-.Mg3333a}]V 3 "...5...........@S..@FLC.........l....>>CCMMCC_................rP..........P.....ZJ....8).........GJ..TK..qj...........YYRA6=....UD<'..7=Pc......WK..d{....V...ot..Lp..+;..4'P.qd.."+.{*....*o78.'4.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\286__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.808007024765284
                                  Encrypted:false
                                  SSDEEP:24:IxZdOdCWTVRf3W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWRYTXOcsUzfXF2tDFq:IxCdB7Ad4M9/xJfAXxucXOG158B0fH
                                  MD5:982B070F9A60669FCAF46D076B47A3B7
                                  SHA1:C79D1636C0B34EB9FC3DE8C31B3F8693992C0488
                                  SHA-256:E6CD7BBD8DD5C563C32179EF5268FD246718E6828B66E19175A44B86AFD6721F
                                  SHA-512:E561B9619272430ED73084AC119C77197995413A1323D63E09BCE7537DAD36CA426A282574DC789194AFA02B73D0E7D533556B796B10EE8A323C6D3C1B07DA36
                                  Malicious:false
                                  Preview: ...T.....zm..JKop.......EN......vd........qt8;....{g.S..HO.\..G...? ......zy...,.>c.QZ@SOM6'\G~y..N....D......TNVW..\.......ZQ............E.....te...W}..........>/.........k0F....... 5....V...B\ke.Q..C..4d..4.aKMM33..]ABI................`F..%<qb....Rh..pady../s{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..>.=..O..$..r..}{.}{566}{0000500000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\287__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.723196788681042
                                  Encrypted:false
                                  SSDEEP:24:ZRzWtvW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxUfUzfXF2tDFvy8BXCL+JgW5o:Ti9Ad4M9/xJfAXxug158B5fy
                                  MD5:3E6E33E8402B713C717413C4C7D1CF1A
                                  SHA1:A0C394902DEA62F88EC5BA5680C087ED65F80B4D
                                  SHA-256:F6A69172ACEA635D6D0D8FAC459DB91C2F4C7A276A0A1735C3507185D35F48FD
                                  SHA-512:4ED18CCCDBC2A1F96E59C5EAD70DCF0DB0C19558862B0EC4160A4CA14B44126EE124728CA912F28A36E11BDF8B14920BFE7375649A430700260F749EAF236305
                                  Malicious:false
                                  Preview: 0LHps.....Z[......~`........) nq..........%(+*.C........UC..{y..............mj..6i/&..........g$......LB.....)..ll~!..o|.......b..EHn{qnLj..pizirn..uu..........3$..?"`#.......!yXCG..~yfruiNI//.........*9..j}..........B]..MM....g.fz......^^..PP(dDWk&&){ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{C+.f.."d=....}{.}{520}{000050000056000055000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\288__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.707777377797827
                                  Encrypted:false
                                  SSDEEP:24:qp65q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXUzfXF2tDFvyv2+JgW5r:K6lAd4M9/xJfAXxuV15vRf1
                                  MD5:54F48D89F308C972C7F392A07622BF08
                                  SHA1:B4B33F2980AA10001C86785FAC6042889029932F
                                  SHA-256:C5084984D4084A200C7E6D2CE8FA5276D13C20C4DF36EA3340E4E4386690BFDD
                                  SHA-512:1401B293EFC1B63905D6D1232C5CE67B9F85E717195E1C661B9153AAE2D3E647799BC6AF6D10AD6D812E7C6B06B441494B97A88781254F7671F2E0DAE5D8469F
                                  Malicious:false
                                  Preview: z............"qVE.........]T ?..U...$w...........;-..+.Tb...Q...........+ L...oo.WSZ4'W@..: .....7"..........dd..;d....*=GPYC= o,..0%1.....9 ...VQ.......F....UB......u6..5 ..Ta..WSgQ..OH..............R.&/ 3........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...{j.n..V......}{.}{440}{0000500000560000560000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\289__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):7.41935104723836
                                  Encrypted:false
                                  SSDEEP:24:w0dFgaQzlqRzq60+Q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRMz/VBBpFUBQ+J5:w0gaQzolq60kAd4M9/xJfAXxuxzvBpFq
                                  MD5:5A2807B8590BF7D7BD4C4725937F9885
                                  SHA1:B70438D95EFD03849C45D48C518C4EAF2B99533A
                                  SHA-256:048C883AF2E873D1B181024E6C2B81CFC60EC32F177B96687B6979A19BA47921
                                  SHA-512:957262B0138F12F4E387BE1E5760970A727AFE0ECECD51EA883BC39038ACE22B0CE3C4C84585ABB03FFEC045A302C6AACDFB0F3CBDE694EAD709937776974C9D
                                  Malicious:false
                                  Preview: ..,....]av..@A....SA....mfebR.`7..........LI..%............fw<a....XB....c`OC..eO......#!M\............@R.......Sx{}uy.....%%................^"+...<%.WBs`......:/..PU.qx.|......%-#U.W}q......=T\J5G..|V........->..2#az....y-..:b:\pc". &@O.........c.lk~~..ffxx.V....q~w.D[..hO-$fD...."...;......1<....^A............gr.....E......Y...5.V|..AA..R.+"..........x%%"dd{{..R....96........+!#........#0......al......OF....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\28__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1297
                                  Entropy (8bit):7.440643995277868
                                  Encrypted:false
                                  SSDEEP:24:TgV2do00pWUXFG84tFoze4ytP6qfHSgC0fNSZBzfteJTQR90BBpFUBQ+JgW5yT:Tg8S0AJF7Ad4M9/xJfAXxuRBpFUBvf4T
                                  MD5:15B064963CD9C3D213C07567DB4F78AB
                                  SHA1:BB6E2B101EF53E12BB992126E706B525609443CC
                                  SHA-256:1C28B1661A65B9555A220086745BBB3787B249F5CF10B3CAB7C7775016C412E5
                                  SHA-512:C3C5C23196366E95EE522B6BD0765AC7FE1778FC9120750F6D83B8A8E7E05B6469C8BFB0B9844F997262EB53D4F7D82BB8DED8AD9A1E02E6257C545054D35CD8
                                  Malicious:false
                                  Preview: .-)?<...E...."q@S..QS......'8tu..>$.}wb....'&..I...YD..&.}k.......hnbe...9d..{{....&5......<!....OZfy)'..OF?&{vqF........Z]....,sle......cy =.fk.........klazV.H~....guXGk...\Mrn>9..^^tt*uDM\Osd....,1...k~.........Q^Hh......n>Jy..OO.........]...^;............"$..uZ..|~.....I.h....^......`i.K},......Ra/.II..IU.....OX.......%"....kk.o|.....:%......z[KI`w....TGegNK....WB.....................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492B
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\290__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.356253870498982
                                  Encrypted:false
                                  SSDEEP:24:+xVPM6Q1IcXiP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRID7/ZBBpFUBQ+JgW5M:+zPfQ1Ii9Ad4M9/xJfAXxuD7zBpFUBv+
                                  MD5:00402ABB3DFFFBF0BEDA2D96BB26A343
                                  SHA1:FBA264D2C94C1090FFE0D255F1666AAF3E0A62A1
                                  SHA-256:87E7B935045CC29EE035983FC5033AF4137ACBF5BA6C6A0B0DDA07029DBF4896
                                  SHA-512:2A2731B5321C0C212E02ECAB4449E2076AE8DB6245E5EAB04CBF365823A29D229610309525E4642C8034FC90FDBD228B355B1401128D548528EC2D7756413DFC
                                  Malicious:false
                                  Preview: ..ol...b):.....Q..=#;9......7>!>..W...p#..!+......x#..wj#.>....E..^G......#*qz....uu....EV....YC..+h|q..OA..=4..?2w@CY....C_' ..SS.........JPSN0s..2'.........r.x`..n/.85}eYCP...`t.....(E......X_....\\T...CP......9$v5..|ihw...8......Ss..$=di.....,..xx..soud_@~0.....m:8+1....KK..,.SU[A..?7~|..xa.........W...;U@....?g2c....s6..JyEo..@@+7.b...."5..mw..0mfa{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\291__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1444
                                  Entropy (8bit):7.488808613826359
                                  Encrypted:false
                                  SSDEEP:24:Sg6TWHRxfZo0VIIVh3H7Az5x84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTMM/KBBW:R66HuKIIVh3bAYAd4M9/xJfAXxu9MyBW
                                  MD5:4AA3743898AD86EE756DECAACF21DE1D
                                  SHA1:1EE334B83AF80E99FB4AFC1A6A4E986E043CE843
                                  SHA-256:C8BD29A2CCCDE75B520722C1DEF6680E4C775741049A20544BD89A620099F2EA
                                  SHA-512:6880E0971AC7992DFD73279428364FFBD757215130E72F85DCBC2CCE676B6120005DF01FD1E6B611906A8E190BF5AA36BFC946EDF024996DE5840E73CBACB15B
                                  Malicious:false
                                  Preview: hEAEFRGX........\........nbr.90............$49...J...vk`S..]K.KMOxaMWDBHO.......)vI@....ct.........MR............IS..*<....WW...LE..MZ......q2..9,........w[..syldw...........zlF4.=......\@W\JY]_..ir.......H..........x^..............!!.X..[.........DE......TR..d[st.=...Nx.....9&........5qI\xm>7.'........5:..gMGGPPWK........YCgz[...UUGG..f*...@................2+..+8....ep..../((318.............r?;4:2....wZ<)`b.....%N.5.1%../:........<;....2YsUU....>/...G....H:....=+.3.....XO...P..<l....yf....$=lk...R{z$:...P..ge.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\292__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PARIX T9000 executable
                                  Category:dropped
                                  Size (bytes):1802
                                  Entropy (8bit):7.632115810549791
                                  Encrypted:false
                                  SSDEEP:48:9SS1AUXnhUV6ylAd4M9/xJfAXxu/xLjQBpFUBvfu:9pJhwcpBAXQZMH
                                  MD5:0BB7E59C59A7A549E2E9839A7B6EBD8A
                                  SHA1:84551F0354327A164038E33C8B3DD1BE92361738
                                  SHA-256:C3BF6EFE747E0220C4C2362A16EBA97957758D6BF60DDE9FFC4453DFCB317266
                                  SHA-512:9CB87AD7DCD395B93B58BD79206E82E52A6D76E02B425C0D01300195C172A16AA95D9C26157D2B1E5814B45247F8E703F237441262D33EA7FF5B36860EE42609
                                  Malicious:false
                                  Preview: .............u&9*..UW....94...........ys...... {.......>........|z{|.........E....}jBU....k([V....@N..`iipjg........?8....4kCJYJ........:yhe........6em.....JPX...eq......Z7...............^WDW;,..........FS....5.TAGMejzZ....g7........^^^B.....[TX.l.....91......Mn........VT....Q.........zobk..U.....:...............v......kq....."".........R{txp................{#......|i[V....pw>%kb'%)8......CC..S@_...em..b{%.....5,y!......e!$1....\..J..<;......>ffff...........fWE+/...........AW..c'EPEPzs|$....r7........^^^B.....[TX.l.!&$;$2.................A@A@...........z*"#..D....jh.............5d......"-......">.........TNIT...####-rxq................\C,.....G"/"2*..A.....Z-..C\.....NRY^ff.....B......[L......s~......`E.......|u....0`...vv..............P.....]Us]............#+.....................[N'8.._D<513sb................ap......n]hBQQ,,=!bs.....%}&E.......L.H)$......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\293__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.364615588009344
                                  Encrypted:false
                                  SSDEEP:24:cn5mkrYVpAzi2HP84tFoze4ytP6qfHSgC0fNSZBzfteJTQR25//BBpFUBQ+JgW5o:enY8G2kAd4M9/xJfAXxuL5RBpFUBvfy
                                  MD5:FC8CB59215EBDD7FE556355882C22FC1
                                  SHA1:9BE8DE8943F25D88C7F240D3E8B9016B3B7DCED6
                                  SHA-256:139B2B6079451A4A318EBB828FC9265DCFA9820ECDDFA9BDF3B8ABD05271F7BD
                                  SHA-512:FE17F08814EFAAEACEF61FC7DD3FF5EC5CBCE469D0B2AC2F55D58FB8DC84212BBCBDAACB142F486ED70E4EC8D74A9B7EA53A9434CD28DE80D919AF630CD7BE2E
                                  Malicious:false
                                  Preview: .....ep..IZ..'!J.....?=.........IH.C..*y4!`j..a`O.......7......FD[B$>..QV..t......g8..........TI...........le....mZ....?)EY....u*...*=..7-B_......]B..........}ea{.O...N9.....c......FApp""..3l..\O6!....<!.H......%...?*..>1....9 ............@\SB...jf.................nh...'iaUW......X......8ukih+.u1..VC&/w/L...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\294__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.380934909446561
                                  Encrypted:false
                                  SSDEEP:24:TaxAJZswePg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP4/+BBpFUBQ+JgW5b:RswePRAd4M9/xJfAXxuE4mBpFUBvfJ
                                  MD5:495A454134CBE9D787FDBBCDB67A6C53
                                  SHA1:476D6ECAF31DF06B550CDE891A4F17ADF7B1D5B0
                                  SHA-256:F70B8B09937722CFAE31F76EE6BC6E328F77FAD171E2536E4AE9B0769EF5D2DF
                                  SHA-512:9FD731BE14A3AA525FF5C3C4DD28DDEA6BFB37DE2A5EBC5C5419F90CE94442980239D4DAF34BD06E769169E6E6D1055A1E6B1D23D0C4446DFBAD71506E3A2130
                                  Malicious:false
                                  Preview: 9mX.......rh..<#....d!IDlg.....I[DQ....../*..%.......HO.4..n3........).los.5..........M\..JM;1v"..3k.q....**.......~r............Q@..VQ....T].........V..AL...........6)..UB..&:..............-:.....T...H]..pQZ...u.....*#.....F..$.XX..}}..~o...=1........6kk..c@`f...;..jhre<%.I.(b..;*?....R..Q....{>VY?.w]QQVV...^.........._B.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\295__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1448
                                  Entropy (8bit):7.503936777783513
                                  Encrypted:false
                                  SSDEEP:24:9QzI2EaPKVFXLt0oMd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQu/9BBpFUBQ+Jd:9+rEaIFbt0CAd4M9/xJfAXxuInBpFUBv
                                  MD5:217BED76C6889704B7EE2216BCC3C484
                                  SHA1:C6B6688D2D707449AF26C2D5B0493168A47266E6
                                  SHA-256:D31E6BC95B36ADCB1A67142A24308FAC72EF075F689EB8CA11A29C13EEA2EFA9
                                  SHA-512:7AC148A048C41082887AB5D3B2019552078C2732635C369B30962E6D01F28A9192CD06E49F794FC9147A01F066860D426623F29E330D0E1CC71A7B88C108F274
                                  Malicious:false
                                  Preview: "........]Ncb... 39'........NG^Agf3x...SF%/ID89-u...a|..Oy=+......@Z+-..DM..............UO.........86.........#..XC..6*....((.I@....+<xb..4w..>!..:W....N......#U!x.....R_.....s@#...lp....ik..........@.............#.........`g~~>>``wwg+BQQ.cl..../8..lK..vTOISS....F|.."e"tV[..9&....FA..zs..........#$....:8....33....1"......AZ<;....cI..VV....=".......NV...K@...........\I<)........AF...]n..ll........n YU.O{.RV.......wgD[..;y/oEGqt..cn.;..........9(.................._][G..TI...A.$)....o9yytu.......s(L.nfbw..<k..}KO...OJ{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\296__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.802555731212385
                                  Encrypted:false
                                  SSDEEP:24:OU8Gr1ohV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRny/acsUzfXF2tDFvy8Bp+JT:VZohmAd4M9/xJfAXxuAyCG158B0fF
                                  MD5:9C5EB31867082F2BBE00CE47A3301854
                                  SHA1:675F3A042F6EE5F58A704150D85E433B2E0E4D3A
                                  SHA-256:46E0448735593976028179CF46594A91C12EC7E4DB3BE881F33CC1422B1AA6DA
                                  SHA-512:B2A02ACEA548E149BD2E7A1F8C1BAAE6FA9E4528BBCB5DE957A2A83EF72086A51CA928DC225207F962E18977E61D837AD03DD8CABD995F8C653C275F140614F3
                                  Malicious:false
                                  Preview: ..0...&'....lv..........^S.................!"..NQ...\$%..h#...<#JP........kX..RN....y{..kp..[Q0d..M...(7....kl......ff......../>..KLPZ................:&..ev......]Z../{.....G..Ufb.G.L-)..p"...aQP.....C......^U...*.OO..22)5...........AK:nNG..>3/.??..............MP-$...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{"..r.....O..{...}{.}{570}{00005000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\297__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.693556065589963
                                  Encrypted:false
                                  SSDEEP:24:yKPwqEEqTibiY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRO/7UzfXF2tDFvy8BXCA:NLqTibGAd4M9/xJfAXxuDS158B5ft
                                  MD5:9D455530581A971B8E188DE7E55020B4
                                  SHA1:FFDDF819C0CE8710809B47BD113E46A9261A53F5
                                  SHA-256:580D39EFBF3340D0A6B55CC91603F531F65D637187E1C271B1CC9992B163BC04
                                  SHA-512:B86AEEAA404C3E94E4D283C524246B930C462339FA80E8B6099780390CD6E0A49F13DEF2CFEA6DE9859FE4ACED9F6DB33F6381D57719D7CF8EAB7E4EE21D317F
                                  Malicious:false
                                  Preview: H...............5*^A...W..sxST.N..<...[Yvq..bg.........E.....[}l.....4]\Y^NM...2..=!....rp......5?..=4...EU..."....TH[P..om....vqnd...)q.},%.....-.......vj......XI.......]...v.......&..........*.....qm....13.. ;WPBH*~QX.NMK......Xk>.HHKKPP....KZYFo!..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.]..6..0.....3z.}{.}{522}{00005000005700005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\298__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.7152590924042785
                                  Encrypted:false
                                  SSDEEP:24:o8y4lsSSF84tFoze4ytP6qfHSgC0fNSZBzfteJTQR01AOQ/43UzfXF2tDFvyv2+S:k4nSWAd4M9/xJfAXxupQt15vRfBs
                                  MD5:CF779B99E2D3D2110B83F6B452812B87
                                  SHA1:6675B91A73DC233AD9F65599084337326449065D
                                  SHA-256:28A8CAF173A26494B3F8F32B4BF890F4C84B8BB82FE375C464B56895A58A8575
                                  SHA-512:088370203C32CBA868FDC8D6EC5E6F7CDF8CCCFDB1D4ED4629419E779ECA87DF79B14C5DABFE4CA4465689825C6751822933390F4DE20A439E00B213E86D2D9A
                                  Malicious:false
                                  Preview: $p.e..RSS.........MR...2?....h2b5....02....72..}vze..................MLQV)*, ....QMHC....]L....?5..........)CiTTth....13RCOTlk...#*...............mq+ ....|mTO..'-.........,a_sb..{r..._u\\ppHH........du..' ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..P..(.n.2.0..}{.}{442}{000050000057000056000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\299__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1315
                                  Entropy (8bit):7.448884333502568
                                  Encrypted:false
                                  SSDEEP:24:k3bIqqHKiFWnhpebxnq8GM2r84tFoze4ytP6qfHSgC0fNSZBzfteJTQRs3/L/VBF:k3vB3hw1nqiAd4M9/xJfAXxurDvBpFUM
                                  MD5:6FB838F22DF01A61D2111A3613F96B57
                                  SHA1:0666962F68916A12DAA868E8D2C6ECF6875BC33B
                                  SHA-256:741C26F45099DACC95D3736427B268FB096E40BD2FF065609DE41512E5CAEA2A
                                  SHA-512:4094F61AC016EF2CDD7DB05157A487A1F4ADACBB6C275A0C95381038B1CBAFC048E22464610CA2A2960EE713CA866BC24B5567FC2A564863714D29599792DAA0
                                  Malicious:false
                                  Preview: ...zyFS..ARde.../<....(#P\0=..4+.......!4ys%(..K..\....,.....y{)0WM..Y^xq........E%,AR7 ..`z........hwTZ....B[ID.$..`{......))ff.]..EVub..yd..R_=(...;..of.......u}Zv(0.T./..Q&....^37 >/.........."}........bxvk........._zwb.....JC....... .}}CCjj..n.WH..../w.~..UO........\Z....tv......l'.._HXS..;.:/..YP..@..9>.FIn]..cc..vj..SZ....NY.....^MJDD.....C..P................pg........AD......................#o{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\29__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1204
                                  Entropy (8bit):7.356567486721957
                                  Encrypted:false
                                  SSDEEP:24:LpmthLHzDDi7RtG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTre/VBBpFUBQ+JgWb:Lpmt5ri9t7Ad4M9/xJfAXxuWevBpFUBb
                                  MD5:F9DEC42AD3E7B1007CF1E01FDB44AE07
                                  SHA1:065C1F7989E4AC8CCD3B37FE35575EDD272DE2E2
                                  SHA-256:17EA6DCE9B6C2DA1EF44A1FD1110007695D37DD267DAF6EBE2AE89F8DD3D6929
                                  SHA-512:9171F86077A91B84D1E7A48F227527FBBE26FCB27887A0858641DA27790198BFC135123B7CAEA7A3D8A7415C745A911710D35ADF3EA023BD94816638B72A29D9
                                  Malicious:false
                                  Preview: =i......X.H_..a`]B.........g`f<y.....*(BEr}......RM..'v.....FRC..uh........fe..'.zP....BQ....e~OH...G.......@@F_..nE..!-...0..]]...%xk..0!...v|b65<.I...0YX^......@......?2..4"....................dnW....N(..X{....\V..44.......................-%......mJ..oM......%"....m*.eh..KTdv.I......|y........:=..Y[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\2__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1379
                                  Entropy (8bit):6.816807482563619
                                  Encrypted:false
                                  SSDEEP:24:zyRIDJn684tFoze4ytP6qfHSgC0fNSZBzfteJTQRzOUzfXF2tDFvy8Bp+JgW5yT:nFfAd4M9/xJfAXxui158B0f4T
                                  MD5:5B4F2D87B2829BBC7C570F50C08181F8
                                  SHA1:68266D9FFE57AFFCE3D713063C0589C20A0FB3DC
                                  SHA-256:281671E58F2ED776690D1039E928AF5C87C6F7AFC6CC1E417B9CAF2811F5754F
                                  SHA-512:C1464F9D42215F65608B57A96A073F860D1F920B927477C742216322C4E101DAFD581BA19D42387EA6E4A6AC58AC0D6279C8E87680711FA4F21996F9CDC1E195
                                  Malicious:false
                                  Preview: y...... l}n+*...bq....5>~r=0}t..?>.............M......Oy...$&B[....fa}t.......u*..........Z...ep........>8RU..\@.......AH...."5JPro.Xxu......'1....y~sskk..E.le..#4......G.$)..`.PH.lm.=$......J.._.oh....-/8l.....plX_..ff55::......I^....lq.......&J..vo...R.3Ed......../;..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..\.......]Y..}{.}{569}{000050000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\300__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.803156004431066
                                  Encrypted:false
                                  SSDEEP:24:MjFBd5biPT4S1ogJC5584tFoze4ytP6qfHSgC0fNSZBzfteJTQR9yXBUzfXF2tDk:MjhFU1ogJaqAd4M9/xJfAXxunXw158BY
                                  MD5:E0DC2D58B8FFBB77FF70992826B1BF0C
                                  SHA1:54EAA61B4F58431BBCF5AC3616B32B0C9987F6CD
                                  SHA-256:E88D1D08A94BA564F485C46CA4D876CFF50181557F4F0627156B2B6A0ADB6FED
                                  SHA-512:A5C07DE8B05918B8C6275AF32194F536F1E2CACA45350863A1A1334AD8D6DCADA0349D80A098BBA4EF65380E8A823A23930A8CDEAF44F70CAEEE465B9EC55216
                                  Malicious:false
                                  Preview: q%..K.yx...D^......hz3v<1..(/.............KH.t..SO.....@.2#.PM6)......GDHD.9..........q`..8?^T...........! .......VV......._N..+,......r*....HY........,0AJ......{`..ys..k3.........26..){.....JT...... ...p/.......uu............/%..jc...)......&Y....tJ....ELZ.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.*1.[.Q .......}{.}{566}{0000510000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\301__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.705318141057973
                                  Encrypted:false
                                  SSDEEP:24:nXKxpEJKk7IvbYb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHfiUzfXF2tDFvy8Bo:n0+y9Ad4M9/xJfAXxuO158B5fy
                                  MD5:2EA866B8304007AC2C14E62947D7300E
                                  SHA1:EDE20B504D63D4E67AEE8ED31F7E0E1F507868D0
                                  SHA-256:C899A59805AB2023BCB3553BBFB0185DE7A4EF045E49FB4FC4745FF2344E2978
                                  SHA-512:BFB6DA96F60052388AB34CD2C8CADA3185C8FA790910A3BEFE0E8274C9DD4A4227EE65BF2A0B83114B1055FD9586AC401CB1D3B27DA6AA2318B43FC0A9F1B9EC
                                  Malicious:false
                                  Preview: .....`u.....=;a2......,'VZ....EZ..../5...oeZW\]...QL*.....f;~|..YC....&/ZQ.........h{(?..: %8.O/"..8',"......nn..~!JC......cyb."a........dd..CPg{..ii...........]J..`}C. -....h]6.X\.6......g{BE........`i..!6......P]........#)BH..%9......ii....u9..>sS\{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{q+I..VV.'.c'F.w}{.}{520}{000051000048000049000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\302__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.689401544270309
                                  Encrypted:false
                                  SSDEEP:24:+8ev7l84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHXUzfXF2tDFvyv2+JgW5fs:JeD2Ad4M9/xJfAXxuh15vRfBs
                                  MD5:81D2D7CBDB7217C890C8A644ED76442F
                                  SHA1:7009E4856657570371FA9B447AA612E30498A883
                                  SHA-256:F8B7534436E9C134CC265DAED744D13685827A13EFAF7C10390FF3593696AA9C
                                  SHA-512:B6D995AB22CE0B3C041272B10FAC8918D922CF5A9840955A0053B65ACAE52C77E405FDDB91862771DCD7BC000A1FBF71F4E68AE662E8EBDB2C1CE1C40CCECB66
                                  Malicious:false
                                  Preview: ......`6..-,ezpowe.........A.....vtjm.....HW8$z+WV....O.......)(.....Ra.....N]..vg..07...J09.[.....j....................RX=i..2jS2mdOV....kX....||+7...........;1..,%1i.z......gv..7>..........FZ +..WU^O..' .u{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{*.:.5.T.N~...#.}{.}{443}{000051000048000050000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\303__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.363126981466389
                                  Encrypted:false
                                  SSDEEP:24:H4ZeNM2gOJnxYds84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuqBBpFUBQ+JgW5p:YZeNM2P6tAd4M9/xJfAXxuYBpFUBvf7
                                  MD5:64AD1F701A4D4DA91D716F0C0DD2FED8
                                  SHA1:FA9F61FE02A55B1243E823150289620D312F6722
                                  SHA-256:63F8FE2959B6FEF91B395DDC5FAA07FFD7585CD5040E6F776975C88610C5C94E
                                  SHA-512:383B99FA1672134C4063BDE23EF3443306323DE17CEAE17120B6DDC8117EBB54549E9B39ED4D9F6F8FFC51ABAF323907C5EE61D310A55DA0F922977801C4BF61
                                  Malicious:false
                                  Preview: |(.I..........WH.......29..+qw ...................jkPW..-<...."=..BC.........9%..#0<>..>%.........EW.......US48..rA..UU..........................u2&t..gz...S..O[.....t.....th....nn.G?6..VAva..ORG.WZ...;....("..2......X...3..22..RN..!>.L....?Z..,6og8.FF.8.'km..uZ......5,@..O...u/........us.x......u_kk..plG.5<....I^4.....34{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\304__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.796160258896359
                                  Encrypted:false
                                  SSDEEP:24:hWCQ2zK4C1bDh84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjG2UzfXF2tDFvy8Bp+j:hWyC1nyAd4M9/xJfAXxuMm158B0f7
                                  MD5:3772014F364FCDE2741C93DCBD638C03
                                  SHA1:23772F897D958FF9ADFFDE3B75358B533DFBFB18
                                  SHA-256:390755661969318D571C0B46F332A0807E91228362EAA2F00C1659A9BA350B57
                                  SHA-512:9948F665955C96B4F9D095BB5AF473144111BF033063736249792FCC1B09BD55031795E0BA243FF21185BBE4C25B221A950258E3C3748019BA383C7727004A1A
                                  Malicious:false
                                  Preview: ...V..........pq..c|...E..ENZ]..T...../-ST+$KNnm.......+*...D*;...>!.........*..........#8..........sn>!..^_<;....]w..`|v}(;......dc..O.ah...bb...\.........)"....{j....ak.....h1.......J.......(-....FX0>...{+.........mm............xi...x%/..QX....699..ev......*.....LE..(({ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.H.`.N...|.l./..}{.}{574}{000051
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\305__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.705978932348935
                                  Encrypted:false
                                  SSDEEP:24:ckZ9G/SMeFO4ERkA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpUzfXF2tDFvy8BXC:1FWGAd4M9/xJfAXxu3158B5fI
                                  MD5:3183CA2193665429D5115FCF7A86F6AA
                                  SHA1:DA4CDA296D83CE2D193E43E77B0F20EBDB23EFD5
                                  SHA-256:865897FB031D43082CAB3EB4925DC1BEC542AE0770BE2C5B1F0CE843558B772C
                                  SHA-512:A54D6CCEB2A68706D41C49F7BBCC612011FABF77F3A66B336F58BD609593E9DC67C4FDB51155247F9A1E5E999732A524F1B87237CFD4EC723C255FE46D7FD8FB
                                  Malicious:false
                                  Preview: ...LO..'k...........TV....$)..EZ..5~..I.>+eoNCvwy!.PGQ..Wd .............#$......~y33..JC...9..../2.T....'8OA.....<<..Q.4=TG..)>G]....zwCVSL.1......{gbe.......Y:3ZI....ou"?Y.cn.....<....~H99....KW....xx.....].........~c..zw..? ........*Gg{]Z``VV22zzKK..N]......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....m..qJ..)w*i.}{.}{524}{0000510000480000530000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\306__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.707584124833553
                                  Encrypted:false
                                  SSDEEP:24:1BicxAN7MhN7N84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtoCcsUzfXF2tDFvyv2O:LiYAqCAd4M9/xJfAXxuFCG15vRfj
                                  MD5:E1D0E04CBD54E5A52D5564404C951BD3
                                  SHA1:FA5A440A6975E43B12EDE58D925E53FEE7DF9C81
                                  SHA-256:FB7FC030A232BFE3E85252A750F2507BAC1DD535221CF8DC33E72EB40349AEAD
                                  SHA-512:45854409C0510933691150A5A9BF43D4B6F7D5FF23EB860E5DF46C8D6D8BD41F5B299C7949FE777E57C5D440BF2D1C8729C3B5FC4BBD8885272B3108714BCB2E
                                  Malicious:false
                                  Preview: ."&..TA.......l?................PQ....../%....l4........pF..&{....|f..fa......ii{$................I\SL..........vv....KX......ITU........'66........""..rr\.....*=......L..epVI....bf..........11.........GT......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..g..9k.....e}{.}{436}{000051000048000054000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\307__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1285
                                  Entropy (8bit):7.396933588937518
                                  Encrypted:false
                                  SSDEEP:24:YsdnAeHDvZLHNZm3RR84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4BBpFUBQ+JgW5m:zJXB6RiAd4M9/xJfAXxuDBpFUBvfM
                                  MD5:C26915DC5E1BFF40C18E628D4FB79584
                                  SHA1:1AB0EDF4D276ADFA2F9E3488F9B335854D38684E
                                  SHA-256:9AC18F7E355524E31DF4AA896443C53B287752A8B897E3F2623A53F57062B040
                                  SHA-512:A67D42AD94BE119A659D1DF3D285266881FBF0149BD74014563DB939C7B7B939ED429CC6162A72DED6EE876A73B6DC76130A95A3CEE3CC2D9D98128DA1798C87
                                  Malicious:false
                                  Preview: ....|..A...:;..)zVE.. "....JG=4*5\].....n{ak..yx............|!........#*>59d..{{k4?6..W@......X...._@....sz..]P......WP++VV...bq....#9_B......}b(.........!)Jb^O.....99......C1...9..//......31_Nf}wp...) |$h...tWdb..FL|Z&&..,?..DC......ii...........9.10.....@F33$.....HD....jg`p....PA............DQGE................VT..kl......\O..qbrp......j`]n....//...............C..C{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\308__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1342
                                  Entropy (8bit):7.443652979683142
                                  Encrypted:false
                                  SSDEEP:24:RuvWn3nPlISPxaxq0sGD34Rq1ptA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRiyKV:wu3P5PxaFj34Rq1fxAd4M9/xJfAXxuPV
                                  MD5:85E7677305994A082691CF370BF60089
                                  SHA1:DF761819B5DAA9075F5A17BE3B8D455DAB349F52
                                  SHA-256:ECE04DA15F653B87E2A78561D2E3CA9D97B674317C965653F3B90DC5751DB518
                                  SHA-512:5764F80326F35EF7DCE823748838FAFE01DA9E963F0E8C5390FF2009C7F8DFFC964A43B3C9899A04244FF0EC8375A686EB6E58B7A434CE95F5ADF5B09CDA152D
                                  Malicious:false
                                  Preview: 1e/.._........%$....FT...............&!..tq&%....^B.C......+:.@.....................4'..du8#.....S......./\\......................4'..du8#.....S....../$_B..;..................GQ.h.....AA......+)DU.........(p....vp\Shb..kkTMtg....88qq.....Y............./.......77..lk..OC............q`..7&-/..dq...........hj;*..>>..ll..U^FU'%....70..Ar!...........D......AZAYMq...L....:%....;.`u..O..E......'(.............?q...W.]\}A...Du#..yiGX..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\309__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1277
                                  Entropy (8bit):7.391817312141624
                                  Encrypted:false
                                  SSDEEP:24:jD/j2Yqvx63XdUU/I84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0/VBBpFUBQ+JgWk:X7F2/iZAd4M9/xJfAXxulvBpFUBvfk
                                  MD5:528A5E4C164E7E36A24EDC496DE5A161
                                  SHA1:D06269E2AC1C6C0C8A5CB16D8CEFBA245EAF1A60
                                  SHA-256:BB587E7A850FB65627EE534A8727B227A3E96DD25E6ED1DAF2AB93ACE4FBA823
                                  SHA-512:518063A09252A2C2DEA5083B7A6571D1A78FB109A8758673D4413E96BF23C5ACA2C98303F81D807B447EF1C18C7C519F8EACB4318E5E7CA045D9B73479590F64
                                  Malicious:false
                                  Preview: ...ZYAT8t....x~..h{............QN..n%;!f5..^T....I.'|WAYDpC.>.........GA).[R5>M...((.I@XK....ou.....FY..B^..-4..$...JQfp..pwbb.......(?&1.....id......(..foPX...4..ca!<..h1:6....gjr.fp..9...CC....{hrpO^G\....f2$-.n...4.....ak..gg....9%....yy....YJ.V....%:....(...Qs....vIru..2>r5.....fy....r(..........#6TK..]F...._N..dd..........q`.......6.HH....AP..>p&*..........z6U...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\30__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1208
                                  Entropy (8bit):7.3718360857942615
                                  Encrypted:false
                                  SSDEEP:24:jfnE7vv8/Av+mph84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtAtBBpFUBQ+JgW5N:DnE7M/4vpyAd4M9/xJfAXxuOAvBpFUBP
                                  MD5:FEC01ADA18608B4BD07C25BD93ABE3F6
                                  SHA1:BCB9DE04A99AB743F346EC95F4222A74DA0C64DD
                                  SHA-256:4A368D84B0FF8666822F04D4CC01CEE73D746A65F5DB197C4E4EF976C5E8DB03
                                  SHA-512:A1C2C1A2C6BABA5F88E73580B455B15497D96FB0B9DE5949C151282669C67E2E1DA8C6C5D0C45186C517B284581D28EBB2AC4A9A531C5D7656FDF9D4E7E031FF
                                  Malicious:false
                                  Preview: A..u....>h....FYFY...&+....=ga6CQ..UW(/|s......4+..X.....Y...k6..YF..BC..........YEbi....+0)......p(z.......|e...,RTZV.h[Q{....P[....&7NU......AHk3b.....................8p4.......A^..va......ss{{....fuavNY..^C..AL_J..No......cl<............-SSWW..FZo~...oc3k......Wy.....TR...+#.......z<...ta../*2'....dc ;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\310__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1317
                                  Entropy (8bit):7.41898354647754
                                  Encrypted:false
                                  SSDEEP:24:oMxcG/2TA6QKCHPTN84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZ9BBpFUBQ+JgW5G:oYcG/2TAYCiAd4M9/xJfAXxuY/BpFUBs
                                  MD5:85BEFC3E08EF15D6808E7B60D85EB648
                                  SHA1:8FC2ECC986CB4737B544273EC599B75C29E51B51
                                  SHA-256:9780EB681B2EBE34E08E5A7990DE8C265FFBF02ABE3A13E2B4B7B0F9C1ADC88B
                                  SHA-512:6E3D77D9C889FCECBE164FA5BC67C1B7B71638854FC2B36079A95CE341C6E52C5EFE41246EE27EF9F6AD72FB70DE8129BBED3F2CD0A0BAA188E4494E09537D4F
                                  Malicious:false
                                  Preview: ...X[i|...ON.......sq%.#/JG.......,67dcv......$.5#...>.......IP>$.........Pcd..${MDWDSD..XBEX@.......[RRKP].-.....8$^Yss................qd<#./Z[U]@A..................UWTI.yw.coWWE^..1X....Ve................wl.......y!>X..-.}{q~........DW...............s>ghdl3,|k....JC......zE..@zUY.B.m`yi+4..Y]../jN.....=4.......=x........ppplN........1+...Z..uu....6z...................6/..........QD....XC..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\311__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.3884554736602235
                                  Encrypted:false
                                  SSDEEP:24:dNGohecb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMcH3BBpFUBQ+JgW5k:xvgAd4M9/xJfAXxu3cHRBpFUBvfe
                                  MD5:BD1E6DBF8A8CBF63684FF65324587A65
                                  SHA1:C2A3FA5D5B1F7942D08E55E24DEFC1711C76F17B
                                  SHA-256:F0536BDAEDCB8B52CA8AE89F9AEC7947061F285E40A5EF99C73609FA96D81AD9
                                  SHA-512:FA84C13651202E218E023D9F0B101986A99374970D5C25BFE9B9B219F97EC982BC386414644CAB5B4134D27F926F4439C455A7CBF86016815CBA4F184F046639
                                  Malicious:false
                                  Preview: Q..X[......+*....qo............DE.is<o.........e>.........%x[Y..%?........Q.}z..\.fo..J]..BX...M........v...^S,.@Z.......dd....yjW@....;&*i.....63.....qx...@9\....`l..W....vmbo...{.........kw.....ap..MJ...]......kx..53....tR..e|..6*..--..||..P./<A.=2..MRxo....$-Ik~x..Iv..Ycdh.V..|q............U\.......8}78..]w..WWa}{7..XK2%,;....../({ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\312__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.779930989611284
                                  Encrypted:false
                                  SSDEEP:24:IdYTfqILjdc84tFoze4ytP6qfHSgC0fNSZBzfteJTQRq2bUzfXF2tDFvy8Bp+Jgc:6YTTDAd4M9/xJfAXxuD2q158B0fF
                                  MD5:E06A8F8B6C7F4EFBD5BF0BC2E9977B98
                                  SHA1:CE314CC59FB1D0818A5899D64E7E6B4EFA9AD17F
                                  SHA-256:91B94ECA144BBD622842023703D59671F4342860A0FBBBD44873BF976D939F66
                                  SHA-512:33085293996EFB7B487A32EEFF8C321AB79F9392D17DC5E01EABEDB6994BFF59F6C59DAA3146F6ABD0A7BF7C3396D42FFC95A9B9C3CC4FDF6EBE1312ECE3C142
                                  Malicious:false
                                  Preview: ..7...~P.ZM!;98`.d{>,....&-...\...n{..IN;4....^U..x)......j{z'....PJhieb.....>..b~........RIHOXR{/.......3.."8.....]..>.&&....bq....KP........x M...GV8i....<<..5)......j{..16......R.8c.V-)..^...%0n<HM.........){.Zyw......,...........`bO^..hoflt NG......""..yj....,..!SB.....W..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..+r:..).4.B....}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\313__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7141975204803055
                                  Encrypted:false
                                  SSDEEP:24:jjAgUufP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKZUzfXF2tDFvy8BXCL+JgW5v:8QEAd4M9/xJfAXxur4158B5ft
                                  MD5:D4FDAEACD9194E40233ED46336853215
                                  SHA1:472DE9FDD9C133C5CA37F4A213E2EF82C3A861AA
                                  SHA-256:0684C29CDA9040798A06BAA9C7FF429B4BDABEC628CD18DADB5DC2D7C48000D5
                                  SHA-512:180EEF5FE8600E421B652EAA0B015B9E1D3BF6DB0680EAEC3BA1FB7F25CD52C3D9DC00A4AF2ACDC78EF8DFF687B754765DD564185E4385E5CF8D642908ADD3A7
                                  Malicious:false
                                  Preview: .+..O.]\g1#4..kj.............D...at..<;{t..,/.....a0..^Y...N...YF...*-........5)JA:)......g`#)..|u.Kw......3...........]L....<6.+"N.M,......O....&&nnWK..AC..UR..z.gn..C1....3.HY....N.:..66......EN..$&..70.....'.,*.....#.`k...........{gix.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{+..>..[.a.G...}{.}{522}{00005100004900005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\314__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1330
                                  Entropy (8bit):6.726274296110579
                                  Encrypted:false
                                  SSDEEP:24:8vVdbH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcYx/BUzfXF2tDFvyv2+JgW5a:8vn4Ad4M9/xJfAXxuYx/w15vRfU
                                  MD5:98EDE2DFE2EF529E29EFAD4D718BE53A
                                  SHA1:6C2F3E531718159974A4A075A4ABAE6EC8CCCF78
                                  SHA-256:98865611D25C67A3BA18C002481A996F79B62A453C95BD7287973F55CC4FC9C7
                                  SHA-512:C39B6F835EE740E8B0301421E72726EED9C8E7BB492119CFBE59FC3145980B0BF8059C6715116A7FD35825DDCFEE4545946E019031E9AC34F508AB0803B437FD
                                  Malicious:false
                                  Preview: ...V.E[Z.L1&..Z[_@.............M....nl............IU.D..EBo$...........TS......q[6*......7&vm.........f..~.....OOso....64..jq....+......)0eh...sY..pp..9*13M\}f..hb.&/q)...:...O^.....1.#.......9%ibjySQ..PK.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.A:.RJ...K.e.W}{.}{446}{0000510000490000520000950000950000670001010001080001080001170001080000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\315__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.365658154545802
                                  Encrypted:false
                                  SSDEEP:24:lum/7AMiXCzNkuUxdgKKOTx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSvdsBBpFv:Um/76Ek5+KK7Ad4M9/xJfAXxuJviBpFv
                                  MD5:93443258338808B66EDCA415086AC009
                                  SHA1:B6ACF18C409FA21AF980D0D7D57C0FA6AC64DDF3
                                  SHA-256:DD3BA97AD7567E2804EFCB22AD4FE80B6F4D39A8DC3A752EB663390F614B29B6
                                  SHA-512:F0291C51F2C6867DDE6937EFFA18CF49E220E09983B8EFCF97E2BE599A1A52682BD1873B7B4DB8EC75016F144D6BAF4D9BDF137BBD94602AECB1D4AB5F016DEC
                                  Malicious:false
                                  Preview: ..........;:..t'..PN..v}>2......@A. :R...&,BO..L.....8%..*.PF.......CE@G......]Z..].v.........HU5vHE..... ....RK6;Xo..........66$$i6....nyH_....$gID....`e..0}jH(3..6.........YV..l|w..MA<<1*=0.h~.{~MPz........~m.."3..EBlf..7>.M+..Dg}{..`j.-......>9..FFvvVV].wd&k..EMB]....Fa........9>....%b.A....,+yh..........{v......nu......HO....11;(V]..CA.....HB..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\316__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):5428
                                  Entropy (8bit):7.910720602594094
                                  Encrypted:false
                                  SSDEEP:96:ufH+WjiG0fq7DQwnGgJO+YVgGrfCXqtlW5duxBWONGXQ4pBAXQuTb:+j0fqZnPgrfCXq7udaB7PVb
                                  MD5:332FA85B027F8B1FBFA86E02DFF0CB35
                                  SHA1:50D0ADE875E874B75A14F9EF365E316607EA5C36
                                  SHA-256:38B64AC54DA74D1C10FACDF629400C65FB7D12076BD4D2C1DDC744E36D4CEC43
                                  SHA-512:135808A71E0ADDBEFDE26C03D70F8AE614D420C9A068518C5DBB51153419AD20AA9D3EAA901EAA8BA44449D38F3320C44D92E2DB47FA26F565F100A7537E8556
                                  Malicious:false
                                  Preview: .RV....h$QBon....JY >......nc..2-..g,..]..........E..........P57ax(2lj.x............9*....`z....AL7"..q.[G........f}..FZqvooWWY.....fq....9$..yt+>|cAZ.hIhv~......6;........m#1...n....ht:=..44..I..................jK,.....+$..:3.....*..$$..==ZF.....`...I,ZX..ai.$bb...-....6.....<+...C.L^.....>5q'.ta....%}.su...].....;.....cb.XQ..er....snJ........D.JY(eJE..FY..;-|vrS....,5N.......oz.....tsYB..,.APwp..XXuu..............SQ..KRr*!H$:|.g.1......*0qf)"..9,..+".V.....A1>....xx((..1 4+.....-F......di.......U....),..*'..HW......-/........<<O.2!.@O..=.!#..rPns'"B..P........~..dx64\F.X."n....~~4c.....?=........8'BE..NGQS)8..&&..........LW..gT..~~....,?....|g8?...v...IW..m$....*'..mb.....UY//......`v.n........&:ZQ..hj..xc.............'(..Bd...EV.. 'nn..>>aaw;...F........yx.4..Rp....jUz}..>2...M....JHfs......hxs....SF..`i,t..us...kd..t^yy......`i%6>)..si....//..OOM...J.yvnfIV.?yo......(1q)ev....,9.."7.......AC>/....xx((.. 3+f......Kj....
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\317__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1459
                                  Entropy (8bit):7.497291134522726
                                  Encrypted:false
                                  SSDEEP:24:PxV05zoFyRUdkl2mYt84tFoze4ytP6qfHSgC0fNSZBzfteJTQR01BBpFUBQ+JgWu:PxVIowRF4mYeAd4M9/xJfAXxuDBpFUBu
                                  MD5:A57E18E0C4DD7E123F3FA9687733E764
                                  SHA1:5EFEE71AE817F5E8E8B2C022391E03BBCA7DBD16
                                  SHA-256:13991C347E9E4FF0615F1B69CA71931E789EA95B5A16AB2C881B69990061B565
                                  SHA-512:C8907021C457F98C69D4618599BF43F0D9C4C9F58FF5F824D6205FA46646D21CBCB2D6767FC4C1AE73F139B539BB59DCE5B6D94E0DD2C1C07B3B5FC1751539DF
                                  Malicious:false
                                  Preview: .7.....<&.................SR@!4pr......ba......-|*+......W.....MW............|`......^O!:.....z......gu}[......(.....r#kX......M^MO..........5<...;2......BO@J...^JF1AS...q.."3....--....${pytg..+<'=ro..........X}^K..p.2.4=..'*l< ...!!......et.............FhJJ..'.Z\[A"..........K......R^.....................vc;$......TVGV..$$$$33>-......q`za{|...2.'''uu......_...d<#@...gkWv:&p..yi1.O\.........Y...WP.napCmG..///3hy.......3X.....v KFbr..js bE.57+.BW..I\}b....PY......==....;w...<3...............z._.W...._@..}}...P.........+g..]Huu.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\318__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1811
                                  Entropy (8bit):7.628860499706357
                                  Encrypted:false
                                  SSDEEP:48:PDl3SDAsSbGXDfCAd4M9/xJfAXxujiBpFUBvfN:PD1STSSppBAXQjOM
                                  MD5:30700F6FCA0DB9783C5448EC2E3F3BB4
                                  SHA1:F61E8CCC9A4FBB1D0087D8707A1618B827DFEB1D
                                  SHA-256:2F7C4B1778C157BA5518719E3694FB77B8B510850D41E923F6AA021BD4359422
                                  SHA-512:9EB9E895F026126FB8615DB922FA753C8172F7EBED26C25A4AF8825567BDBE8A53DF5DFAE6B7BA332F93888DD7CFC4B1C4FB8AC5489CFC848055F8CFFD40383E
                                  Malicious:false
                                  Preview: &r.g..on.....sr........LA..KLf<......IK..gh..;8........ '.....RO..UO32..;8am...........BY...........))..$7.......F.....&-.........{q..r{..........*..........`Vcw.`ZHujJ'ct..)5OH++...........................+!....wz..%.~T..,,..nr1 iva/...Y5P46......7!......4.}u..fq..\...WM..-&-{c'..yl{r}%S.y...j/../._u11..RNI...qb........'zINdd....L.TG........!!7...8..}j..n6(;ge..1$he................33..33}1..Y...^V.....................w..`l..........NLKN..[V....70....@BrcohNN..rr........UJ<%....\^..tm.C...87uxl5qZOMXBK.......~q..T~..^^.......ei...v......Yl....LN...._...5e..\.........PW..r"..> .C....:>....;...............9..9%...XK....jp..`= '.....I..XKI^OX>$........4+..eo...{...ZW..!...A7A...ww.........`S..~~....t...;9.........?6...VE..VP.....Y......dxlkGGcczzcc........................nQ..JpR^E...AL|l^A......01T\{4..~|..tq..s~n{:%..RI@I......KK..AA..FM....9()2....Tg..WW<<{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\319__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.616625417794517
                                  Encrypted:false
                                  SSDEEP:24:/y8TmKYNXG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRK/VUzfXF2tA63yrb+JgW5s:zmNt7Ad4M9/xJfAXxubs1EY6fi
                                  MD5:1000769997737E145F0FF3D2EBAE4EAA
                                  SHA1:F0AA182EF8FEC5A32390287B2DAE5419F82EC858
                                  SHA-256:7DD4D0F1B817D33DAAEBB7C83BC50D4FC549F6D319A51D2478CA43EB17D3CD99
                                  SHA-512:7662C876AA33B911591C4D19214EAD90799B5E80BB3942A0E45FAFDA95F0B917DD6EFB6809CA58CA683BEEE2D784307808A8D0833A9F255BEDB6B55F9111A430
                                  Malicious:false
                                  Preview: .I.".sr....DE.........lkQ............~{..od....l=..;<..8)..MP.......7;......EN,?`b..&=..u...ZS.R=6&Y=.......... "sb..qv..j>>7I.$E-$......pC.4..EE!=...l............'`8!S..a[kU....#*.^.......II(4LG\O..4%@[,+.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..+v...a...V.e.}{.}{459}{0000510000490000570000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\31__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1306
                                  Entropy (8bit):7.424540147594253
                                  Encrypted:false
                                  SSDEEP:24:k3Tvlat7MJ+sFmb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhGBBpFUBQ+JgW5P:2igJvwgAd4M9/xJfAXxunBpFUBvfN
                                  MD5:A9872059C621CDC8717BD7B0B6F21669
                                  SHA1:6520621CC31A05C76C50106DBAFD46957574E654
                                  SHA-256:FDC0BAA68BF042EF5E6DE99F9708CE54B937C6E07309DD4AE2024DAF7F61A29C
                                  SHA-512:EB7B5EA4FD2DE091BD4AFFD0E3C27382D5D1F7D1F5B0586D4C1B36358E8E28EEA6D8352E6EEC2B9FB28A0225C0B4A19F2DF0E58898DB896143D0E0F4EE6EFD14
                                  Malicious:false
                                  Preview: g3."P...._UB......^A..8}bo..qv.B.7%RG...]R....<7...........pa..3.gx..}|....UY..j@..~uZI..ixPK.....V.....<. ........?AG.."s6...RR(4....=?..G\`g...A...]+...D_le..[o....{3Aw...}AS....................v........\...............}r..gnwn..!qjY..NNMM||NR+:fy.:6F.....pjS[|R||XN..QW.......}....k3..,........TKAFKPcj..*;........8+....zx....dc...?iC..ooMQ......{.mve}HtV.'q......n}.Y....*#..Ly....}r.%....AA....KT~0{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{2
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\320__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1283
                                  Entropy (8bit):7.398325048901685
                                  Encrypted:false
                                  SSDEEP:24:vjjB8quA0KuUKeYmBnVsj84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBBBpFUBQ+Jw:h8vPKRKePBVlAd4M9/xJfAXxuMBpFUBG
                                  MD5:99E4420FF67A88926F6A736B91C2178C
                                  SHA1:2882C3F6B51494FCC6B0AD400AF583D601547634
                                  SHA-256:027006BB52C356EDF97D0446A36AB964ED6B80C2CAFF72D03EB1A2759FE57ED8
                                  SHA-512:8FA7A94B8E404D6826711C30ACF72D2B9F4F443E09335C3E1DAA19E0F49B2D94832E50101A41CF8BFAFEB0CE6E7A88507B1F93D0D21750C683281A04F71E1B67
                                  Malicious:false
                                  Preview: ...hk:/8t.......H,?..,...oc~sbk'8~..E3)H.........X.>eXN>#vEM{?)7jmo..tn...._V..R.#$CC.M..........xe..xu....^P..xq.....7..>%1'nrY^22...q................OP......JA..jA.........#..b............43...............='..........0.{n%/KDNn.......J|O\v..II....DU..T....[.)+..]UKe..................3k...|d.....x7....\I81.CF.......an..(......c......zm..kq.......33..0|.............MGA`df....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\321__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1261
                                  Entropy (8bit):7.372488632286712
                                  Encrypted:false
                                  SSDEEP:24:6+dlk8rW09zBM2a9DMqD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRduBBpFUBQ+JC:6+zrW09z/4IqIAd4M9/xJfAXxu8uBpFB
                                  MD5:9F3A884A5029FA94EE46B2C8769C5831
                                  SHA1:0B91FED0493CDAD3FC9DB6E706FBB85B1C3A4EAE
                                  SHA-256:4A41FF3D459B6F390DEA4F2919A632BAE4D1618B4FC7DBDC4274013A9B13B20B
                                  SHA-512:37EBB34A11600B3D6BC911802DF52925A87E0519B6601261F6320CAEF7863555B35371C0EE81BF21B9A988D3CAB2161EF4AFB5FC05671C710EFB3B41943E4CB0
                                  Malicious:false
                                  Preview: &26..$1,`..UT....,?......59.......z1RH......|q?>..:,...........TNtr..r{IB.B....J.........TN....bo..hw.....OV....KQot.........`?(!..DS....zgG.....kt......<R........ynpx..:-..........7%ktY4;,]L..qv....VVY.......XO..u6..%0ze....SF....Ffxq..S^....||``.........`&*...........:,5.....}R..rp..$=..`1........... "^Umd.....ZW...1..unsz........55.........hy{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEA
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\322__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.769367980247431
                                  Encrypted:false
                                  SSDEEP:24:i+36su5q2z0o84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkPUzfXF2tDFvy8Bp+Jgc:i+3Ru5VAAd4M9/xJfAXxux+158B0fF
                                  MD5:57E0B32840A6C09D210FEF557416903D
                                  SHA1:FDAF709D5D7C43DDDEF3B12201BAFC3A93B104D6
                                  SHA-256:97F02696BE5C6E0575387C6B74FFF7AB215FFE243BEF23BE0DCD4004646F2D66
                                  SHA-512:EE38F6EF47BD865778AEA7439929CEAC63F221EED0CB00FF7ABE131658D1DCE2C72727A28901B29B9348FF0367D113DEEF43345D306F1403AD83369B1EC9F569
                                  Malicious:false
                                  Preview: .12u...PCTUO..\CPOQC^.HEIBOHr(.....64......W\....^.]\oh..#2."SN..0*........iZzP....S@.......V\c7..M.....{d....Q.aR..DD.............P........l}..........!=%.....J[..CDfl.......B~%......Jae..Z...=redxf.....$*!q..bQ.....44.......ix..PW..9m...U1<Rt....W(1&....APC^AH....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....n....S.7.'.}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\323__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.709562239126839
                                  Encrypted:false
                                  SSDEEP:24:4ddgzFoDm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUHUzfXF2tDFvy8BXCL+JgWt:4Xs0Ad4M9/xJfAXxuPG158B5ft
                                  MD5:28791B8C45C7DCDE60A28505D16F3C68
                                  SHA1:0C8B845F4A6DBBCBAFB17A9BA6CFEE0A469DF734
                                  SHA-256:C4A9139BD11B27DDDF7E420F832DAAE742BDB9D37C90E4719EE2CF2F9ED01473
                                  SHA-512:15EE7281F0F2B0D11CFA9A21F0E6A12C4F0111B1FCD7D53ABD915C12C132AEA8ECF8C78BBA73F5C41BAA80C4A68D7E9DAA104B1B5DE7F71B2E7FEAED6F0EE7B4
                                  Malicious:false
                                  Preview: ..q.@XY..zm....3,..JXy<EHZQSTb8...<........|y....`...h9........@].....~.......-..G[..</IK....X_.....P?...w.L.5XX..83.." >/........[...JS...6...ff>>..IB....FW....+!;o../w.QF..xFq`"?..p!..).....22......vtix}f.....JCq)F@=J....<1..........$$..yh..!o..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{$Y.k...Ck....`.}{.}{522}{00005100005000005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\324__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.70933730831282
                                  Encrypted:false
                                  SSDEEP:24:vfv3vNLbMT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0zAUzfXF2tDFvyv2+JgW5O:vfv3FHMYAd4M9/xJfAXxuZf15vRfQ
                                  MD5:01862E7D4D7CE6DCAD42C3775A7A5A3D
                                  SHA1:886935601351EDA2314EB27C535364DEA7F366DB
                                  SHA-256:C820D1A10D61AE51C90E739914740D3ED8F53A61C218BFED61A26E9C47274493
                                  SHA-512:6390DBEB389DD34013CF996687D8EB585434A237455C551B2B4D1074F726E497D30F08D6F82F9009E3B67AD8F37EB74EFF5CABCE49252F5ADDB4462E959BC259
                                  Malicious:false
                                  Preview: K........:-..().........-&PW..n9......kdx}....%:../~....E.O^..it..OU..<;<?....)...w|....GV.......CJ..A. 0........4(.....udMVjm....5<.R...mt..1a...nn((...\O....^E61......V...l{...`q..%,..dW..mm==;;............70{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{WQ2.1&/.].e....}{.}{439}{00005100005000005200009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\325__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1320
                                  Entropy (8bit):7.442285107352765
                                  Encrypted:false
                                  SSDEEP:24:GYSzWxkI4di0/YzAB4qCW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRW5lBBpFUBQ8:TSztFklzAQLAd4M9/xJfAXxuZ3BpFUBV
                                  MD5:F6E83220A1F5C0E20196BA8C16C75A80
                                  SHA1:010A3F32F8EB3C56FC489F10EF98941FEAFC1A58
                                  SHA-256:1D538F6FF357DDC5B055B1BF43065F931073C2041DD1797449475D86FB68C2BB
                                  SHA-512:F393DF83659C39014971CAEB1081BB27732D26F26416D18D359E9FA95E1E3ADA79DF39CA1D55412F3607F9E64232EA6D9BE2353B615FF6673D19B93C54D90F9C
                                  Malicious:false
                                  Preview: C.{..fg.K......QN..D.......R............^[..4?.....FA.....juQK-,tsNM....aK..QZ......wp..6bXQF.|....5....&5/...xt...Bh...=6..75.....)...R[..z.......V..V^..8$~i.....;/.b.......!0..inFF.....V.....FQ....Y...*?.......("........p}P.|O.=......KW..@_.......TV?%xpN`@@;-..?9....*"..w`...M....82.~g../&..{;.S8|..+>.../~.......?.......!mng..:-&1.........<<cc...a,KD....(>...46'0............JG0%......cj.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\326__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.38816517085932
                                  Encrypted:false
                                  SSDEEP:24:978ImM0iip28SBNug41p84tFoze4ytP6qfHSgC0fNSZBzfteJTQRY5FZXcsBBpFe:9nKIzBNm1aAd4M9/xJfAXxuhrhBpFUBD
                                  MD5:785C00C38C71C877BFFC6609C8862C59
                                  SHA1:6882E4BECC2FF554F36EDCFFBBFDB2E8049B0140
                                  SHA-256:CAFEAB38B513A652B3E23DB61FCED14F8ED3C31E5C704F02D9E1729E470CBE2A
                                  SHA-512:9C5C12CE7EC7D8639CF080F81917BEEBF73CAEB723B0D13F3D4DC0505456AAC16DA63FBF6E7E16DD914791799C0363EC4A30F9819A57BC1669D112BE9B004852
                                  Malicious:false
                                  Preview: ...."#[.&1..fy......ob[PNI.H.....CA..[T..`c..~a..2c....K....V^C..<&..*-...eV-.....`sUW.........J.....yguOi..6/@S./..gk..O|,.uu[G,'..|~....(/.........TU..88.Y.....OK..bh.H.....>%zw..V@..3.........hc................$|.v@SMn..ak$.yyb{.....''..RR%%.M..Y...NF........._}......%"mW&*.._..K[....>/....13..:/~sgr...nu....j{STwwoo........uw............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\327__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1574
                                  Entropy (8bit):7.549371904641718
                                  Encrypted:false
                                  SSDEEP:48:3BvJiJ+PC+3z2RBCHmvAd4M9/xJfAXxuEMoBpFUBvfJ:XiJ+lD2bCPpBAXQ6s
                                  MD5:3487AF1319B5390D236356AC6857B400
                                  SHA1:4E6AF41CC23F82012B745A86D5F2585728DDE41E
                                  SHA-256:74329FF07FB968A0A3E689B8EAFFC0B602E8542E7187CA8B138C05BA865D6988
                                  SHA-512:E5EA9246CEEF1CE7399F50C48EBC6856A07AB7C8638C057E6F871322C46483487421ACE4AEE112C4F7B4F3B33781487AB3714578AF30A1C77D199B28E9C8DB87
                                  Malicious:false
                                  Preview: .sw............]..B\AC....DImduj76V.BXi:4!0:$)......~c.4....v+NL(1..ag34..IB.y~........4#......`#................hr...............%6..avtn....AL..b}Wf..yuA....L....BM..6P...~z..j`.....................\Wxk..DUZA.......7o.t....)/.......f..........))IIn"......91..NOvQ) .0.........BN......ju....!0.......=e.&3j.py>f'v....N.*%..lFWW..........^I....)t..vv....f*TG.......oB...,.......q)s`df#&)<..sf....?$..bs........._..8uVY=5...$..-/......m...20.............-2..G\......%"//..............ov....-/cttmQ...0......N[YLCJ..T.....z?...<J`AA..:&....P.<0.Y+..uj..........zmax....ED.\....9=.......O..KU....................:<}z...7...**..q=JC....?(..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\328__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.780980368733884
                                  Encrypted:false
                                  SSDEEP:24:Srfsd2ZRVWTCZNt84tFoze4ytP6qfHSgC0fNSZBzfteJTQReUzfXF2tDFvy8Bp+d:4sd24yNeAd4M9/xJfAXxuO158B0fF
                                  MD5:0E82ED75B5CDA30DA988DA1BC7F54E01
                                  SHA1:EFC76AB849EF6D34B9F11DD108C60AA0E8BC78EB
                                  SHA-256:8001153539EFE57BA9DA92A7E3AA18FB9D2533B312CB95238EEA5A6461E2E56E
                                  SHA-512:9EA22603A65BD39DA0C16B8C9BEC0A40FE5EBD6DA655717D3B19B604DF22F03FAA3D3E755828D8B0B5D5E4E952348282F47A4BC3E42D0DA771374FF894D502E4
                                  Malicious:false
                                  Preview: `4].5r...........!>bp......2h.;)..]_).......|w....~/....4.kz.O........eb]^YU..T~..lg...'6...........Z...MRD^..be.....%........B@..6-.......I...............3/......ud......N.....J.......0{....;i.z.I\]....0d.....T~!.*_u..77}a........E^.....z..U.!,Us..................I..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....<>.)V4.|..Z.}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\329__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.69542540145099
                                  Encrypted:false
                                  SSDEEP:24:QZrqpZjv2V0Qzy84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP/VUzfXF2tDFvy8BXf:QZriZjv2V5z3Ad4M9/xJfAXxues158Bv
                                  MD5:1327E2C8C67B32D343CA5D66CA71F8B5
                                  SHA1:8F8F15D85C6762FA0EB1ABBE648AA9002C7EE400
                                  SHA-256:37E53701E803FFE146188FA95A7CD1C8E40F44D08CEC596A4589D7D0354EDBCB
                                  SHA-512:76ABBB9A4130C857936B014D03C3574088C101DF595F94932D1CF7C0C33006A02FA9B7E901B105224092FB00B54BD8B57F97BBD3D913F6B3C8BC5284C2B189CB
                                  Malicious:false
                                  Preview: .......3e........<#.......qv.T....zx........k`....w&..x.O.IX9d..gx....{|KH6:.&Ys..?4TGB@0!VM........A1^p`.dtGu_......ZI....d.34....r{d<..]Dhe.]0...XX..ZFDOUF...._D~yv|r&^W................Dw......)5<7wd....cx.)...NGu-,*......~u,.............ju...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....sr&....4.F..}{.}{522}{00005100005000005700009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\32__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1313
                                  Entropy (8bit):7.4275622273041355
                                  Encrypted:false
                                  SSDEEP:24:wy9CfT5qhNkq0jkl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsSfBBpFUBQ+JgW5Q:wy9C4hNkq01Ad4M9/xJfAXxuAJBpFUBa
                                  MD5:5E62B85D94C8A7927574C465FB490072
                                  SHA1:153844A641E73A76E4F9B6429D138A1157A4E63E
                                  SHA-256:D779B5F9C1E09153A9AEEAD18DA1DCCEE06E28A14F3AF502679DD1ADA7B562D9
                                  SHA-512:BA752844C6C87514204BFE906D115DECC264E0748A9F3F689FFD874F63FA535274C9FAABF21C5EB4E38F52414511366C41ACF0965114F0308BA4186B04403B31
                                  Malicious:false
                                  Preview: ...12..(d....{}q"............-$..QP.D..............C^Bq..~h...........dm..b?..tt.........mw..N.............9 ....lv........kkbb.i`..va&11+PM.I.......W....+"F'......~v..' ...7..aup....}...........&&.Ii`..~i'0D^TI@.#...YFLm.................pZ))..^^.....*d..s+..vt........'1..........om9....O|7..$3..%.)p..6=ha..B..ASF..py.0a..Z]..-"...9ss??..U.......`w............ee.....D/ ......?)....ac....I...UW..*?YT..tk=:.... "{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\330__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.704901905656903
                                  Encrypted:false
                                  SSDEEP:24:R7mK6SMm3O84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdFUzfXF2tDFvyv2+JgW5O:R7Wjm3jAd4M9/xJfAXxut15vRfQ
                                  MD5:E7932BA7258451D6BC31E8A0328B651B
                                  SHA1:585A11CB73E684D6B7F6D3A3049CD98D98B23C07
                                  SHA-256:D916BCDB004197BEE309FDA35F2B0557F94B6CCDAA0E57008681173333C10176
                                  SHA-512:E6772A4528945FD883FA4511CB791556A45EAAB24B7999742EA1FFCC4C843EFC9662BD64599AB5559AF729401F8C69235EC6F380965F50154D2EC3FC9B3BC610
                                  Malicious:false
                                  Preview: [...........#":%ju{iB......._.*}cq....EB..,)........h9..(/....c>@]..-7......VZ[h......`s..........N.......r.zI......GL....(9....t~l8NG!y.s.........-...JJ......egO^.......JC+s......)..PMmd..3.)....99MQ........2)..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.......H...A...}{.}{439}{00005100005100004800009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\331__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1279
                                  Entropy (8bit):7.396207473957814
                                  Encrypted:false
                                  SSDEEP:24:TQ1BUuJrlW3z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjBBpFUBQ+JgW5KT:M1B3JLAd4M9/xJfAXxuiBpFUBvfy
                                  MD5:F2B67BADBFAF4C69498197658381B1CF
                                  SHA1:D4E42ECF4D746B65BBE82026C362573F0351AE40
                                  SHA-256:DC889275309458B5DCCB86567329439CA5D45EF56AA508881CD994948488061C
                                  SHA-512:EB33A71DA5CCE022D18FA7BAC260AF8B58B05F6DD816D4FC15973A6645EE7C83701DDEAEA8E4F3DDCD01E33A542DCFBB21D8815F169C163F3D8B4E73948C126C
                                  Malicious:false
                                  Preview: ...*)#6.........*9&8........{rc|...G..l?....3>..?gx#..........75(1........hc......e:..-><+$3.......}h............%......C_.................6+!b..!4......|w2\..d.......{v{q<J}$..ZZHS........Jy....................w#......Ol....82. ...........FF``............../5...].][ )....."...&p.......li[R..BG..GJ.........]_........((....N].........................b:..XC....O..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\332__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1579
                                  Entropy (8bit):7.538910646095074
                                  Encrypted:false
                                  SSDEEP:48:BU9H0Jj5h+BkMeJWkAd4M9/xJfAXxuFBpFUBvf1s:B2HZF3/pBAXQ/L
                                  MD5:CBDF12F757C6E9181A463E97A721FD60
                                  SHA1:235F397CAA2F29B31D5CEDAFC0D77951FF41C420
                                  SHA-256:AAF9B70D0EEA9FF04151B8EAB19A0671CF07396B7E0C05C836B2976BE9394190
                                  SHA-512:95B68E5FE4757304B52E24565B1FDEAF3F357AD075B5E0101FA61B40EDD0C2EB9BA437400C1BCD1B036EBDF59C8C6A8302FED0EB17F1577CBF7A05A8B89452EC
                                  Malicious:false
                                  Preview: ...}:...\QF..)(....ft.IKF..\[.8oZHVC^\eb..........;'......T 18e..yf....st..2>..V|{g(#......IR......xq...L^.7..8!...-.....S.+....dx..]N......^Y..X....E..`m.....5..4'WE..../X..fy;V../>..af..""..k4............$gkfdq..........ghzZLE..&+.?...ww........gx..7;L.......JB|R......QK..;357&1..U...5z...<xoz..I@@....y~....%......mq.T]....../5f{....77.....3...5:IA...........ZC@.......]H....,3..vm..SQ......ll||.........|c...9..pr....h0..iOr0pd..%0MX..v.J........BqkA....bs......_H:M_26>#.F.......OC%.......2;..L.TRRUB.NA..;.qq....TE..r<...l...QN|jwB............../..$$qu....K^.......Z...|~bf...WB..md...RWQ(/)l.....=..JJ.......M..:b...).|p.O.\......F.....PE..L.7f..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\333__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1277
                                  Entropy (8bit):7.395842814943015
                                  Encrypted:false
                                  SSDEEP:24:9EOlUjT4hdEv/Sq84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5wBBpFUBQ+JgW5e:GjEbE30Ad4M9/xJfAXxu+YBpFUBvfk
                                  MD5:AB49D98FF6770B37B0FDE6057678FC67
                                  SHA1:E39FAD850CA051A2013CAB46480BA0AC890CC92A
                                  SHA-256:3D3658FDB57850376BB89A13E75C98A1889B89D6A1C6A832A639C85B7DF3C28F
                                  SHA-512:3235F6FFD6E54460CD7374DFCD31D0B093AA9F150055340E52A1C64CAE83BD451E3B769D771691D9E4059618768BC5071E288BC1650246933DD72FAC13D1143D
                                  Malicious:false
                                  Preview: .AE.....................Q\[R..@A........hbgjihc;{ <*{fgT9.DRC.CAY@_E_YX_...............tcre~dc~.......(&4(............V@..>9................[.LAH]... ->#ld.7=..?9+?...G............H:8..888..........et........`i.P....Ji....1;..............__]]........]UD[........."$TTUjUR..nb.....9)....9u..'>......wz..WH......UW..kl.................dc..sYZZ..WF;$6x{w...sh...^.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\334__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1291
                                  Entropy (8bit):7.425904607549695
                                  Encrypted:false
                                  SSDEEP:24:fxmDGLWv784tFoze4ytP6qfHSgC0fNSZBzfteJTQR7mBBpFUBQ+JgW5U:fxcoWIAd4M9/xJfAXxuSWBpFUBvfO
                                  MD5:F9F752D07235C48D681F7BFB51EAB90C
                                  SHA1:37DD873BB8B4C8D138B3307BD9B4143DAB2BBE5B
                                  SHA-256:0438B7A6F768918E7FBBEFA75C03802A5535326E06C6D60DBE7EA96C6216B44B
                                  SHA-512:2838CF5F4341A1306C7DE3519A9D519164C201F6DABC2A5E98266C085C040BC7A2E2AAFF8B04FFD3773031012A0B26F4ACD1D7B279A3B1278AE7497D4738BFBF
                                  Malicious:false
                                  Preview: .............N.l..&$........mla*.............P.\J........7j.......(..+"...F........!2....#9.........EK....zc..........jv..WW....#*$7RE......!b..)<..o^.............=.o}B.<.xlK<#1/06[....?#.....t+3:......XB........hIHm..ka.."..........'./....77< ....;u....8:....~~........Dk.....JS.^t?...9JAu/....MJ..]..X.[....,%.....QV..CL..j@UU..fz.......%2............+fAN#+.1xU.....2..W@(1{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\335__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.360903532797696
                                  Encrypted:false
                                  SSDEEP:24:k/zwUeqKUjm9iKb5Dfiyp6o84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWBBpFUBQU:0eqVqZRfiyg5Ad4M9/xJfAXxuxBpFUBN
                                  MD5:1464E1F5527832262D4E94EC559E264E
                                  SHA1:B612EC7C3C62CA722B708088759C1FB05F980C59
                                  SHA-256:9773BB592898739A03A218AECEE9E8B2C15F2C1FA735A20606E05E8F8F806DD3
                                  SHA-512:8D0707930AADC32B9EE15329A941338CBC8177B6C2CB0A6CCABF57B49489B40CC6ED019EC67409FFB336CF863906432AE98DA701C30ED9AEFA09D23F6297FB0B
                                  Malicious:false
                                  Preview: e1.6...t"..NTlm......N.....hoj0.......?8............H.............MR..>?....w{4.....!*........y~......%}B#..Vp......U~....N...Ak@@....IZ`bud.........UZ5.........>.=)..SA-2..{l..-1..LL.....WDM..........q2EH..7(/.......gh.....bo..^m........htIX..U....Fh.WU..@H.:BB..]~....LcPX....f..@.....C........0>......udMO..@U......MJ9"...........N]0;...!0..KL{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\336__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.332882516350239
                                  Encrypted:false
                                  SSDEEP:24:bhzaDCTel69Tkvu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRN2csBBpFUBQ+JgW5o:MCT5p6Ad4M9/xJfAXxuI2hBpFUBvfy
                                  MD5:061BBB09FC33EA467970A78EA7C1B4B4
                                  SHA1:0562B0AE8FCE3960CF704B7F3C343E0D86962807
                                  SHA-256:7975525F25B48C54552434FA0ACABAF18CEFF548BAA54B7AC97A848D9007ED71
                                  SHA-512:9DA47BE414AFF32737585FFB7A96FE41A4ADAE6960F4E4F4F67F60969B4CCAFE93E6168EB989CE6ABAD1FB2DBF23B62219D850EF8FF167EF1E9EA2A2F00BBB35
                                  Malicious:false
                                  Preview: .....FS.........@..,2~|5>........D......<6....^.....}`S`........A[..FA.....W..zz:e....\KH_-7..s0..9,$;xvC_..*3..Xo......THy~.....YP....wmwj.<..mx..........(-..s.{"....wl..\5....Pzww....?4........#$..k?T]...VE....ZU4>..aa(1.....qq!!..99....Z. /?7..KJ....^|......_XKq....Q....EZ..................!4fk..JU..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\337__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.362418767290407
                                  Encrypted:false
                                  SSDEEP:24:73gyVc5k9Atj6co84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjrBBpFUBQ+JgW5KT:73gyV8mjc5Ad4M9/xJfAXxuI1BpFUBva
                                  MD5:743BA3B437E2BF44F08036CB4586935F
                                  SHA1:9AD20285E7793FA32530817FACB09273FC315BF5
                                  SHA-256:87A2EC2DB03E880EAE1292F7DF9578B52E88315DAB46DEC1A6FE564F7344F867
                                  SHA-512:0D386E8816DC2B34E17B7587A9193BAF53F154F055EE07A53508EA7F52024F4FAA7E464A83B7346CC2626FD0B463489A8174F019C557BE4E5D99B744E592BF78
                                  Malicious:false
                                  Preview: ...tw..z6..^_..........w{........U.......ZW..h0.OY#>.......D....[Awq....glC...\\._gn(;bu....a|r1..7"..5)..^G......SH...........FO..XO..G]....XU.....:....( ,...D\.....ZZ ;*'K"....9.;..ss!=...........+.V_.........o`...4.....< ..iiddHHHH.G...Z......PQuR4=.%..//mR\[..zv..A...iyrm........e%3"".B...EG...2?..>!..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\338__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.3938556204354855
                                  Encrypted:false
                                  SSDEEP:24:9s5fLjbr1pQs8J484tFoze4ytP6qfHSgC0fNSZBzfteJTQREBBpFUBQ+JgW5t:9+fLjbrnVCAd4M9/xJfAXxu/BpFUBvfv
                                  MD5:BAB1316E40C14A207C28C086CB932DAB
                                  SHA1:BC299A29BBC5536945A332B6C7CBBAA1C7B12AC4
                                  SHA-256:97D84304C6C2B9A6A2970E9561B417DC89A0A4ACE76EC0BBDDF9A78D3559151B
                                  SHA-512:282E91F03B5F240F1D3ED3D3373D97F708EFCF3A31225E491CA8FEB57D3DF20053210D41B63C17843A846CEB8B9993F579D25BF80DB8DF2B6FF5B1B5A27D65BE
                                  Malicious:false
                                  Preview: ._.+.....DH_..lmTK....7r..hc...AJ...vc..TS..~{.. +.....no.....$yA\0/....%"...........................U.b...Y........#%.......QMlgN]....%>ST...}t.....e...............ZNp.L^..1\PG......................NS....op*.......!@`kb....'w......((..vg...~r.Y...lvDL........su.........>'...7-CTFM@.....IL.._Rzo....un........AA..))zi<7.......... .{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\339__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.342788876622229
                                  Encrypted:false
                                  SSDEEP:24:+C0so0U9t0wh9P84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGJ/VBBpFUBQ+JgW57:LvQ/h9EAd4M9/xJfAXxuXvBpFUBvfp
                                  MD5:8F510DA5C46A5A9A72BA8E18B6FC993A
                                  SHA1:18DC76F7D806E18B23CF886EBC8B1E75517C47F9
                                  SHA-256:23E42F8934DB0C725AD35790B730ECAED5C4BC308C8417121AEF93A5A593AA9A
                                  SHA-512:C1ACD60EB8CC35C89371858B083A106005DEADF511FC4C0D7D8E840DBC148BE8B792BC450E05439419F022AAEA64B7CC86465B3A07279B3EA4EA7010997BA3CC
                                  Malicious:false
                                  Preview: P.t.(o........89.......[ux..y~.m:..PE........:9......]......N...F...mw..:=....s@......</...6-TS..q%...Pg.ew........%.NH...dW..``........./4........z"{.5<JA..ai......F0'~xt............pC......">{p....&=..ci....`8.jbqPs...... .??..........kkyy22..g*kd|t......pWPY....."ts;....-{....9&1 ..45..DK0p..%0.....V+z....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\33__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.3751010887173365
                                  Encrypted:false
                                  SSDEEP:24:2kY652B8dAjSeA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXshBBpFUBQ+JgW53:2kGnjPAd4M9/xJfAXxuuSBpFUBvfV
                                  MD5:D403B61E710610CB6AAB05FF7EAF9021
                                  SHA1:B12D18B569EEFF73752D462C0B5DD06ECCE8012A
                                  SHA-256:83CB29A7396FB8A44FDF4D15A638A7DE04DDE6CD8199A2EDC42F807C65E32394
                                  SHA-512:70D4D9338A685E30156A4944AA9D36E0C1AED1470FB66E8C2B03AC35CBC8E7EFA18AF1427A6990B1FD8226B6748004ACEFABEC1D8839F0C66A84ACF795C80CB2
                                  Malicious:false
                                  Preview: ...=.....U,;...........QOBMFPW.@...6#....~q..zy....NR..01..(cfwZ.....~d............}a..0#Y[.........\....3!..||....U~.......#..8$......~o....82.%,"z....Q\........8>.....v/vz//|g..(A.....eO....RNgl...............%}.\O?..."-..;.....uf0,..pp..kk..e)h{<q..T\..er..G`......22...)jP..A..EH....($....-0..o1,1..G.}{...T%0............E_P........KW....^ML[#4E_..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\340__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1264
                                  Entropy (8bit):7.390298108348155
                                  Encrypted:false
                                  SSDEEP:24:Fhe9N/Nb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8BBpFUBQ+JgW5f:FhtAd4M9/xJfAXxuvBpFUBvfd
                                  MD5:C42FFBCACC32E74D5FDE5F6CA92B6D39
                                  SHA1:9B3FBD7B32CFE2B89C63A8B906BF7DD1E4B813B3
                                  SHA-256:8980D6966BAC267D231C3A8DA8D306073687324A21292F379E4EDAA5D36A9CF8
                                  SHA-512:DB9CB6B183AE45363833C8D83333CFABFEBE6F125F734BC08DA0941B608146DB8E6C699B33201652FEA2BDE1111F6C05BA87A2B0BF69B2B392FDC2A93C7041E6
                                  Malicious:false
                                  Preview: R.{.........z{..rm_M.......8b3d1#....).......YRGX....MLy~+`CR...4+..bcUR47....pZ..@K..jh......?5.....h8*.............".Js@8........l........=7......G@.e9,...Cr..$(................3"...o..G$......%1....LS..gp........ww..........lv..7t#.........H]flYV....kf3c..Dn..NN&&.......Cr~.0U..!;....gg..........KC....,5..R.....LZ..b?"..V?=..~{yl;6....&!....]_FW......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\341__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1464
                                  Entropy (8bit):7.487339416832825
                                  Encrypted:false
                                  SSDEEP:24:tQQhF8NtI0wn5R8e17Q/a1bj7A5yb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8fc:qQTipcSYkapAUgAd4M9/xJfAXxuHQvgA
                                  MD5:3B54ECF864B765A15E3A41AF642DE45B
                                  SHA1:BE907821F6F7516002523F97B891AD29206F4902
                                  SHA-256:9FF555D838F88FF559EF8291176267765330277A6BCDCD2E2FD3A1520CC34260
                                  SHA-512:EFD035C8A5A009CF18BBDB592AFBDDB5B40533B21AFA265ED00F88D9F8693DBE539A1F48A374D7B808BCA548FE59663C39B055FD575C65E715AF0B46B8AE3910
                                  Malicious:false
                                  Preview: ...30%0@.....(.Y.DW....qz........xy..uoq"#6ak..@AV.K........xn..JH..4.su\[U\v}Q.9>??............ =..r.....$*..ZScz......; lz.."%..II.K`i|oFQVA.....)$....hJ^U..41.w......GEts;4h.X...OO}f...gzla.2................f}....c7.....8+#........gg........hh......3....H..zr..}j..dC..0.KMNNtK_X....\...........'!........14.....fj.A....DQ..._.....e ..........UI.L....2%....=`....]]...WD.U....vi....?5..DF..-4..WD..SVsf7:-8....*1.....(/00..,,...|1WX....F_r_........?g...1U.-9_...9,..i1W..(...^\S.%.........IV....].............tw......M.=,....X...5573..UR..N..........&$ea{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\342__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1309
                                  Entropy (8bit):7.409752362088084
                                  Encrypted:false
                                  SSDEEP:24:3BXHEQP3RDmlzUU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZP3BBpFUBQ+JgW5+:RXHEohUUAd4M9/xJfAXxuq5BpFUBvfE
                                  MD5:C1B09945412FEA874D4C855FCE6CED39
                                  SHA1:7DA81BBD2A4DE39A3719D448E05A8D1633C324CE
                                  SHA-256:E56BC36CA7A578C8E6B59BED4FFB2CA376FE061D46F66CE0D6D30B89568E4E10
                                  SHA-512:64D8E3E0A7A4D7611D003E455E672DFB64106094BC7A33E983F68A5B19DFFCF9E66782BBEDDEBF8B039A1283CC540635291520669E4645C4C85C43D6CF93F756
                                  Malicious:false
                                  Preview: ........Z....%#....$:.........*5.... :..xm..;6..8`..9/excP>./9..,..VL..LK..JA..RUll..`i..av[Lsi......at....qm.v.......(3........77.q....reSDYC....GJ..KTkZ@I45...V0:..g ..&2.....#N....8$g`,,]]..T......(?..|a.al....1.......\S..W^....C..*T~......&:TEOP......6S....T\$...3%....hr.."*..YNwn...UVLw`]V?i.......W.z+..!&..P_=.......]A].YPN]^Ipg..it.........-a..T.YV)!..6...!+..LN.......LN..u`.. 5hw-*....B@........tt{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\343__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1214
                                  Entropy (8bit):7.343143549219229
                                  Encrypted:false
                                  SSDEEP:24:H8zl0xvt+Mqs384tFoze4ytP6qfHSgC0fNSZBzfteJTQRmRyQBBpFUBQ+JgW5N:H8ax14ZAd4M9/xJfAXxurRy4BpFUBvfP
                                  MD5:3106C6E1D4A18CB90E800F0CC72954BB
                                  SHA1:5C3758986F9ACDF2C98D7D946C64CE1C230D0409
                                  SHA-256:53A75B1418C41D3AB57BFE85093E6C38647C93D891F0A043E1C7B1E9E17D7F49
                                  SHA-512:56FE45616DF11EA2642DF0F3FEE490406D7508FCB526BE46AD143B424EA15205B7B53DAD45498852420A9596F2AE7D389FC51BE212220B8D9C5361BD07DA79A0
                                  Malicious:false
                                  Preview: ....DES.....XY......@...?4...!v'5:/............%:{g.U...)...Q...c|RH..ur:9jf#.4..c..H[......eb:0.EL..=\...............Bq................+!n:of....EN.&..........\P...."/.XN.q..gM77KK....uw....G@..+.\U..T2...:60+$......-4..\@..CC55..FFa-^M....7?..PG]\......AG..2.....&*....k{......p;........#!..........#$..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\344__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1218
                                  Entropy (8bit):7.362440645367023
                                  Encrypted:false
                                  SSDEEP:24:IN0rBdE1WSMKJv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSgvBBpFUBQ+JgW5x:VrBdE13MYkAd4M9/xJfAXxufgZBpFUBj
                                  MD5:E685B863848437C54583DDF3D612C10F
                                  SHA1:D1FA25CFFE3B8FAB4B923ABE411AF5535798AE0D
                                  SHA-256:BB6663603132C4B9F6CD1A9B62B1693664026C9DB86893B82F02E4AD2E9C32D6
                                  SHA-512:F2E9E5556BE68097F0F8FD4DA27E4D6E98420DB2EB45CC21A6FEDBDAA37E9A93BAA7D9EFB4468C41B1791111650636401C46647E2E8BC25EACB305B86C681B61
                                  Malicious:false
                                  Preview: w#B.,kpqu#......sl.....k......L......QVKD..........5d..#$..........' {x..=.."nr..h{;9....34...$-.q.}o..))cz....71......,oo4(JA|oeg..shmjV\"v...............`h.8...>1K=.0<....`m.GQ$V..................AZ..mg-y.....\O'.^X..v|f@bb..................@O<4....Kl....06TT<...A{...J.q|..$;..HY..N_n7..he...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\345__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1139
                                  Entropy (8bit):7.316291487117765
                                  Encrypted:false
                                  SSDEEP:24:jNvR5LaI+Csg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRD3OBBpFUBQ+JgW5sU:BLaI58Ad4M9/xJfAXxuoOBpFUBvfx
                                  MD5:7C9F2849D62927156AEE5F0600BCB339
                                  SHA1:4FC14BCDE04B0186BEC1BD521E1E752BE9034BBA
                                  SHA-256:293DBDDA0C42C0483CC8593D7C2148558E656FC9E7E86BF454D8FE44FF79185A
                                  SHA-512:C303B7C2B3A523F1A40408BDEB6EA8C2D7EAE6FD2EF10FB379BD6DD252860140EAD15CB9CDB5C5B6A99A827050902C085833DE621DD039E0688CD04E2A7F0054
                                  Malicious:false
                                  Preview: .@Dji"7_...$%AG..$7....^U.....{d...V9#.......................e8..}d..?9....%.................= .?2.....6*$-.....-........TS!!....iz.....4..*inc`uOP.?..UU....4.....UR............>..'P^LYFz.............8t..B.CL..xg......GfAC..B[C.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{l..<....~..p..S.}{.}{496}{000051000052000053000095000095000067000111000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\346__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.386961547287401
                                  Encrypted:false
                                  SSDEEP:24:D7jZbnAUBgtN9EshuP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKM/bcsBBpFUBQ2:D7pAG2/EshxAd4M9/xJfAXxuDM/bhBpQ
                                  MD5:5E5AE63CDF4AF10A2A926CBA1FC974B2
                                  SHA1:77F7A43A8E5CF5DFA872CF11AD0A18ADC0EF2A91
                                  SHA-256:3C7DAAED9D7E7FE41D70804B02EE366DA5FC0EAD889A465050E096F86FA5B065
                                  SHA-512:77554C386545FDACC3BA57575BF948FE1F6322DCFBA9F564BC22EF1F54529D0DF9392577AF6104AB6EC47847DDDE2DB48B7A45B2263C20EEAAC0777FB204E028
                                  Malicious:false
                                  Preview: .....HI....]G\].......@M.....[.......ST..fc..(#..PL q....T......<#A[..34.....6.*....fu....KP...........lJ,,...lG[]..............!#..>%:=...90.U4WT....pz......,...!....F^h......|c.}.9....KL....""V....................\}Kn.. *T[...IP...X.....EE..kz....CO x9\..0*.._qFF|jFeus............{e..g*qvVY..i&DHd'................"9..'%..34II......OD....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\347__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.374815798683291
                                  Encrypted:false
                                  SSDEEP:24:+Thj+DN5aHf0P9b984tFoze4ytP6qfHSgC0fNSZBzfteJTQRCSiBBpFUBQ+JgW5n:w+DrEIbuAd4M9/xJfAXxu/BpFUBvfF
                                  MD5:24E27E815FF5DF598F629D0F3C7CDA68
                                  SHA1:04CE820A52B29F13FCC710B2506496E2990BDBA9
                                  SHA-256:7FE25715557CF884C0383F9153661D476BA721EAA49882A5B1F591B087ADB869
                                  SHA-512:2847115B87BF9FD345B9FD0FB7B456C5A88838CA80A1D329AABE3E9CD917C292FAAA3EDA646745387AB0D54E86A2228DAF04826CB3A034E0D684CC18088E76C2
                                  Malicious:false
                                  Preview: ._......-{..........zhK...HC52%..J......TS..oj>=.........#$.M@Q....QNhr%$....p|=.<.YE)"</..UD.....u.^"+.$E....99....zQ}{!-..#q[&&..XS......BY.......#{g.......yHT[.......bb_DWZ..9/......((MM.......2#BY....F...+sS5s`..*,....Jl..&?wd.. '....^^.....W...CK#<VA......#.......Y^0.<0.o9..YI........<>........rm......uw..........\Oen..\^.............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\348__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.376242938350593
                                  Encrypted:false
                                  SSDEEP:24:VYvDB2phyBt9Sg4384tFoze4ytP6qfHSgC0fNSZBzfteJTQRJgRBBpFUBQ+JgW5G:VYvOhu8MAd4M9/xJfAXxuhBpFUBvfs
                                  MD5:A15E4AE626D1EDC96B5980B0BD150F73
                                  SHA1:65F0AE5DF926E3D7A1555040ECB16C198208C610
                                  SHA-256:40D5B2C16653246FB9DEC3EDD324EE20759C123DD7F8A6429029CD9BFEE3B5D9
                                  SHA-512:3E2E484503A828EF1137CA065770E7DD1BABD3BE6BA84FC8CB09CBCC32D0B67ECFA325E5FA411FAF09CAB7BD40C55DFCF47A447F41446086DA812BE9B5944F7C
                                  Malicious:false
                                  Preview: [....................................-8......>f$.cu$9..&.[M\.......................fu......wj....................=&............................5.....61..............EEWLS^_6...uiZ..?????#..UFUW@Q$?.....GN....../..HG..,.II..DW,0..jj11....*fL_..78..d{..SR......FF....oU0<.M.......FA....?......................>!^Y................!*..vt....$#..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\349__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.345654631249161
                                  Encrypted:false
                                  SSDEEP:24:UnyleLcgMNO84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+/VBBpFUBQ+JgW5xs:UnyOTMNjAd4M9/xJfAXxu/vBpFUBvfTs
                                  MD5:571C3EA55BAC5C99F70002A481E73C1A
                                  SHA1:01C84B212CE2D1D802F2E24329619EB2D35792A6
                                  SHA-256:11605076069E7BD2E02FEE89390C8B138C0F6D0874D64C5A483FC31B99CFCFCF
                                  SHA-512:D198E965D8C49A567CEACDA50DD02549E814EC8E972C24EF1A7D6D812281B6CE1F67CA9F475CDB8A16FB80AE1828A07E40146FB53DF557C16159D48D336D8244
                                  Malicious:false
                                  Preview: .....5 ..&5....#p_L..om..ma....po....uo......."# x..(>...7..=`....$>....&/...skljjq.....[L..$>"?..94..wh....(!..p}?...mv....@G....q.....*=..$>...L94.....!.."m..`s,*...Z....e.L^nq.d........mm]]..q...|o....$>....94....0...=(&,......VO....s@...mm....8)..m#KG/wo.....CK..GG.........91..CT.."z..#/..........v..{}...EkdfU......]Aq=..CP..@W..{f...)){ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\34__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.368425129309981
                                  Encrypted:false
                                  SSDEEP:24:oTd/WI1Ci2KVBcw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRG/BBpFUBQ+JgW5Cp:oROI1Ci2iB4Ad4M9/xJfAXxuVBpFUBvQ
                                  MD5:C89A5D8E61F350A55F8EECA27B644D7B
                                  SHA1:EE45F13EC625BE0F78ED65581F09328A22EBDF69
                                  SHA-256:CB7D0CBF146814B791712B56EC6482473492637B397CE2F2E13585A74FE6878B
                                  SHA-512:21EA8921C88C95D7E3BD76EFA7E74EC924108FC712ECCFE690FAFD6D24A6322835C5AC09F41D5EE460F641C684BF819A4AFDB8A8237AA6AF4D0F5D5FF6709FF8
                                  Malicious:false
                                  Preview: ^.....H......./|....LN....P]'.....*a..Q.......LMV...WA....xN....]D>$.....v...61""...0#............WBwh........3>.$...nx..jmUU..#|....^I....b....3&/0......KK....OX..QR...r.UMAoo....g.......*...77..0;......; ........F.........69..Bd........CD...........U.........&...?.|z[[..........B....op..o~......]X,9]P..WHbe'<PY....{|!!..........FD|m......<...SS{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\350__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.385637610868083
                                  Encrypted:false
                                  SSDEEP:24:fT0Qi81u4y7A1trBnvY5AjP84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6dBBpFUBS:QUu4cAnrBs9Ad4M9/xJfAXxu/BpFUBv6
                                  MD5:DA2112F166A27D034DBEFA95DBF79669
                                  SHA1:55447E0BDFA0CC3A3C91FE2B06C9B09E6D8328CF
                                  SHA-256:F253C4F30AAA854AA24A64026AEE031220C43F57CD824A6A6C271429BFCBF3F6
                                  SHA-512:29199877F34C96D0DC51397D824A163982C214873F91EF0F1123CDF6054DA4D67FAD366DB90C2EB0152B8E00F9C56F66342024716E20288B63764474C97E1C21
                                  Malicious:false
                                  Preview: .?;kh......_Yd7....!*........45,gE_..at}w....7o@...%8.6..i.7j..........)"P........s`)>GPqkkv=~..mx]B...........D^E^xn..{|77.......W@......>}`m+>....QX:<A.......~jM...........:-=,g{rull....#|..CPQF>)@Z..z9......."....!+..pP......K...!.vv........sl....f>m.....w..Q..7!..rt...(DL9;'0.f..!;..od.../'n0}&......LE....$".......:........3..(;.._E..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\351__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1239
                                  Entropy (8bit):7.3541526015706165
                                  Encrypted:false
                                  SSDEEP:24:7ZC2PT6/6mJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSd0neBBpFUBQ+JgW5yT:s27w6m6Ad4M9/xJfAXxuZWeBpFUBvf4T
                                  MD5:18F48D99CFD51DD282DA66C1AE224F2F
                                  SHA1:D5A418A6128B42A1EB19200AA9F13AC7E1EC8FCF
                                  SHA-256:FA16C222E7D9A5A7B3DDE6B0AEC8F32A9EB950FFEA672C95D0FAB43CB9171601
                                  SHA-512:DCAC99D678B36F9B4449C5EBFB5D511953DF8681AA47B382189699777984AEC3563B2274FCC2914AFB45BB88CF1F7B4576237C5DDB655BA860D40C6A08CEA038
                                  Malicious:false
                                  Preview: 0..)*vc.......B.GT..-/....gj.........P..w}....0h(s0&...+"....B64......25gn....4388|#i`....CTTN5(}>..3&....g{}t........zl..VQ..~~.N......pg.......BW..fI^M.Ss.I^..Wa..q...(7.......16......,s..l.AV....MP(k......7....<6..rR@IRK.....)..zz........UJ^..........U{..i...ce..<...PRw`;"k3h(......7"..(!..JL.......!...,,...Msz....YN..F[^...LL{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\352__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.786466175137039
                                  Encrypted:false
                                  SSDEEP:24:7Ts4x+MbVUxZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXUzfXF2tDFvy8Bp+JgW7:7T1xxbyEAd4M9/xJfAXxuh158B0f7
                                  MD5:ECB935978C151FB0E0E16A79A9F58B2F
                                  SHA1:9ADA5007B325B8482269BC3C0BE328E731AFC8E3
                                  SHA-256:A0054499402FB0384C3A0C0555A02D6F5432074267E60562E49C8D23833E86AA
                                  SHA-512:F7E6BE00B245CEED94EFD7A6EF209E9D29A48828C3FBB0A57E5031FA553E83F1275B8FAACF7B7901E38B09DFF154EEE3E4D795E96E6702B0DD229A0955F3B7AE
                                  Malicious:false
                                  Preview: [..7..cb................7<..?e.............~}od..xd-|..]Z.."3d9..? ...........!.!....JY.._N....'-B.HA..w.....$>JK>9....Ic........|~...^Y...H.....DD.....>...............nu..YSQ...I.{"t/B.}y.N....at.........GI...3c....._.2U.66....mq.......7,..W].^3:O.V[....VO+8_ ct .7.bs..kbw+....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....5.h..}..}{.}{574}{000051
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\353__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.705371306698699
                                  Encrypted:false
                                  SSDEEP:24:lH9OiAygSrVb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+UzfXF2tDFvy8BXCL+Je:TOEgSr6Ad4M9/xJfAXxu2158B5fI
                                  MD5:AA018898D33E7B59AF29E97C72BBB6A9
                                  SHA1:FEB95E2B4BEB86C43AFC35DF86F3C253FCAEBEC5
                                  SHA-256:A28367CE5BBB7AECFE123A78E63CDEBEC1AD3E2D82EF58BA3426323F320208BD
                                  SHA-512:68E7B8040585834E9457B3F4B27E2161C0D82A2E4721B4F2A02DAE183D27833C509103E21332842B316A10AE9075A291B8502DEFA9EBE5B0EC53F0ED639B2C8A
                                  Malicious:false
                                  Preview: \26ij...J..........a.64U^.............................9....q,><....f`......k6..kk.kb..ny.....(k..`u......FA..sss,....I^CTF\..'d....+4..BB.. 3 <..88..........AV............3...../.................ff..AR..[L~d...cn%0....--....,A$8..11..GG[[..:v....hgW_{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.G....)......}{.}{524}{0000510000530000510000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\354__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.717370613453951
                                  Encrypted:false
                                  SSDEEP:24:K6WM+/hrD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQCUzfXF2tDFvyv2+JgW59:K6Q8Ad4M9/xJfAXxu/t15vRfj
                                  MD5:2C97F86BF6DC7504CA162C061562A02E
                                  SHA1:203510EBC3DECA58D7109F4F69EF7A90EF3B7802
                                  SHA-256:01D3B559D39A3FC3D4317378D92463E77C336DA1AF5E558A7F8325B1E81B0340
                                  SHA-512:7A3DF4893A727F01B414D64C3A4A82CF5522AF4F0527A58C05EB997597AF687B8C32BFCE3F4875BF3716C6B69796355682C252D84DE82A003B3B00212190A5AA
                                  Malicious:false
                                  Preview: _..WT{n..=......uf..WUry..tyKB...N...........t/]KuhIzaW..F...@Y....`g&/.....%%.....fq..z`..Y........!4....II..A._V..........0=..HW.!..UL....DC**33...OF....{a.....YLmr..cB..Oy.... 4........MM..d;....l{..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{J(.........f3..}{.}{436}{000051000053000052000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\355__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.366144548754989
                                  Encrypted:false
                                  SSDEEP:24:FkPzrmHX/5TbKouKB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjBBpFUBQ+JgW5t:FoqvVAAd4M9/xJfAXxu+BpFUBvfv
                                  MD5:5A2B5D42717E3F1B6AF1F9E1064C7B46
                                  SHA1:A6903414124E228F1B822B13DF4EB1E2E442458E
                                  SHA-256:4B1EC20E7B0E1D65AB90B252034A585CBAB23C5F0969ACD71FF99D4CCC71AD8E
                                  SHA-512:0C9771535FEE190CF60D8BC7529F7AEED5F8673819E45B956BE37086E1445A9DA839620DB4449B0BC9AE0FAB26CB94A9E650E990BF1DC6036A87099B1892376A
                                  Malicious:false
                                  Preview: ....]\...~d..\C..pbo*..-&25S.H.....ca..........5*..H.()..b)m|.P....D^CB..KH@LAr.'..DOpc+)....qv.........l~........%...R^t%cP..ss..aj....]L.......u|a9...ZY45..!`I1.........8*..$I....ht..xxKK44{$...AV...XE..7:.....,..qd....dD#*qh.....3~T....AA..&7...L@.e." d~..iG......../5bMEM.....[..L6/....t(.j...z..58........tv....%%....../$$7........>4..kA{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\356__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1460
                                  Entropy (8bit):7.489148519912398
                                  Encrypted:false
                                  SSDEEP:24:b98NkD1v9wcJI3FlOg4ZKK584tFoze4ytP6qfHSgC0fNSZBzfteJTQRmDGcsBBp4:b98ascJI3zOFqAd4M9/xJfAXxuLGhBp4
                                  MD5:03D32432DA71592EB8E726B1062712EC
                                  SHA1:82E214607B6C5850E7060256D0466528DF679750
                                  SHA-256:4A3CDFAC2EC51685F1A44ED12EEA76594E0C9B9ED3BDD48944966ED4CCD43E4B
                                  SHA-512:AFA883D30B1B1F98B392FBAF7CB845E1CC0148A92CA76F8BBFE754E09A7E1BC5D7E1490C8C70C895937080D30A298C948C278742FCD91681D1111FD1374AC4BD
                                  Malicious:false
                                  Preview: .8;.j....ml..$w...acat...58`i..[Z....B...........@..^C...'...HJ....;=....g:}z""..90l.sd.9..ex.....(7 ........).......%9vq..YYK.HAKX....mwa|7t............}..Z_.......c....SS......ESj.....}}..9%....ZX..)2.....18.......69ZP..LL..]N9%%"vv.........L.je....KJ.8u|..(...yF`g.;ie.T..............b+..{|....LH..Q.... )..8>......Iz..__....t8BK..0'=*....$y............v~)6......bC..../6o7..-/cf........9>..R[ca>/TSPP66...b......5=.........."5..h0.....0t..BW...@1`..wp.xw..dN55....vg..#m..a9......nx.....qsl{JSX.O^.....E..........mxK........46....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\357__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.377984430812681
                                  Encrypted:false
                                  SSDEEP:24:ec0i4iY+laPFL084tFoze4ytP6qfHSgC0fNSZBzfteJTQRPnBBpFUBQ+JgW57:eu4iY+CLVAd4M9/xJfAXxuWBpFUBvfp
                                  MD5:57012008C87925847123E2788D8732BA
                                  SHA1:C83AE5FCD1130C229B214553FA7087AD17893402
                                  SHA-256:C3792E4C1EFAC593386882DF5DB460631B846A0AE4C798B2168675054780B2CB
                                  SHA-512:74E7A5580B5B3EE5ABA20552E4A10C04ED908EBDC2D48D76974B35381E6B8EE10B536D57CD0629C927DE002B616F71D4B9C36B62AF6DBD2723C860455C288CAB
                                  Malicious:false
                                  Preview: T....UUT.Jzmvl...............9+......CLOJJI....&:.=<..]...3n......()ur..................,+|vG.+"..p....iizc...+.......lF..!=QZ->.........z...0hc...io!)........CH...........k.fq......OO$$._V...........ZW..A^.+..zo7=.._.BK....k;.L....OO33..fw..y7.s.p........ZZ...835.......ip...a....)9*G?{..n{...3bMK..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\358__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.372711489436037
                                  Encrypted:false
                                  SSDEEP:24:VB5e0Y/13lCnA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5BBpFUBQ+JgW53:Vrev3lCnxAd4M9/xJfAXxusBpFUBvfV
                                  MD5:7DD10E758C7918C370D6824F349EF4A3
                                  SHA1:3F7FE6AD8D6FEC25CFA7F6F648567CF5D2E45C78
                                  SHA-256:8368E1DAE05AB6F936C9343355CDA22C5F678FABE019CA054E0679EF1C1C2873
                                  SHA-512:BD42B0FF7AC10B2F6488105616BC8203E9F21FA8EAC2805FDAD2481CE7CBF420FA87F90044755A02A2D08C75861A6E45FFBA8D68F65165489EE00A8937E0E822
                                  Malicious:false
                                  Preview: ...d3tdek=................GL....WYK^K................Y..jm..*;U...@_yc......q}..|VC_..ra9;..-6..GM;o...P..2.77OV..?......P.%..UU....:)..KZPK..........2)c.......H.ml....EB....<0......w... R...,pp<<..OD..y{..7,....x,....|o,.....OEiO33..8+....!!FF...._...A.\S..}b..tu..py.>{}..sL{|Ou...R.Up}6&......}j...Fk/......X.U........(.gM....+7..GN..NY+<-7........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\359__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1312
                                  Entropy (8bit):7.405898598757733
                                  Encrypted:false
                                  SSDEEP:24:KNKDU8u/iZiYGDjcY8paK4ZE84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuM/VBBpy:KNAU7igXipIlAd4M9/xJfAXxu0vBpFUP
                                  MD5:D447267101650B9E7B2E4B102BE706E2
                                  SHA1:828EC8314EFAC42899B69CDED599E773CDC306AB
                                  SHA-256:1E36AA1F840D2CF2B69BBB85D7FF24886C6DFCD16C4346B98EFA329479DB7985
                                  SHA-512:101C602C26277D531DBA4442C484E68E4F28492F05ED8C4FEF042966C1CAE8E7895CD58E14F7DACFDEE801B3489A977AC346BE78955576F6A387F77DD612F64E
                                  Malicious:false
                                  Preview: ..K[...a7....*+....VD0uZWaj70...E*8........vs....fy......)...Z..............Fu.<..:1kx;9..6-..EO;oJC6n.....gg.........)x[h......<7....sb..,+ZP....,t...>7)l..lo3<g*Fplx........{j......llXX7h......}j....,oKF~k]B..5.........yp...................4+....N....1+@H1.hh..Bay.ou..6>om/8..........b4t0ATwbGNn6q .....XW7.Rx..__....md......(2;&..#$......A...._LC..................P.......TA....ez......,..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{2
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\35__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1237
                                  Entropy (8bit):7.385487613112588
                                  Encrypted:false
                                  SSDEEP:24:wsuC949t7GQnqP0TwG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsjBBpFUBQ+JgWe:Xuvt4/7Ad4M9/xJfAXxux9BpFUBvfe
                                  MD5:20B39C75512B4077636E4D50609EE6DF
                                  SHA1:05EF7323ADBA6613AC4A191CE4639476F321C770
                                  SHA-256:871E2329937C83F8DE535E12C69B08FF2A08B7D18277EB83795CF5A3AE617E09
                                  SHA-512:7F9D643CBE432F788305E1E975E109BB9ABC9CD5D8AED0A49DCB05BBBDEB713AEA7595C050FF979EBAF8AD3CA719CC9090ACD72A3329963B58A1DC486D912D2E
                                  Malicious:false
                                  Preview: .gc..&3....@F1bh{.....................93zw !"z5n..,1S`6. 6....mt..KMKL2;...Hho..3l..#0....mw1,...&3po..=!..nw....wm3(2$WKdc....x'....-:.......BO..;$..w`SZl"..D[......Y.\j&2.YK...ck|...qv``..++..yj........f%......2.GR..(.........iZHb......MQ......r~.N+75...Hf..$2Gd^X..mBOG.......\.........kn....wb..wp..EL....[\....ww...........ST..kX{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\360__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.369255295058899
                                  Encrypted:false
                                  SSDEEP:24:DbPIAVIGVOEAqlG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFg07BBpFUBQ+JgW5k:HjhVOZC7Ad4M9/xJfAXxuqg0FBpFUBvG
                                  MD5:933E8A5F965B29BF58FA2F581A63DA83
                                  SHA1:4195C9130810A512291CEA7A14C94E195FB060C1
                                  SHA-256:9B4C190BCAB8A020B703C560F8C30B18CD5EBB94F24EEDB31BD9221B0B562A2E
                                  SHA-512:92D60332B4873460876E504E6369A4783E293B555FBA1B25BB39130286D2C0360BB7D5181F040D2F821C57BF9F4B3B2CDBA7B6C4D72F330BC4F3D45291EF3D94
                                  Malicious:false
                                  Preview: ...!"......_^........^U....?6*5....Z.@U....%$.......fUlZ../r..E\..]["%....1l....8g )..VA....3.\.P]]H3,...........................r{....j}..IT.W.............$..3jZV......r.m{[)UfxRGG....../<....}f"%,&....j.../......x^**........((......*fdwV.78..a~.........)......be....8.f0ob..nqpw..........ly.#SF,3....CJ....ru......=..............zI.'....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\361__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.395396925465914
                                  Encrypted:false
                                  SSDEEP:24:+m617768l84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWcBBpFUBQ+JgW5+:m1XB2Ad4M9/xJfAXxux0BpFUBvfE
                                  MD5:FEA775AC41E7029C2081E0618EB7CB13
                                  SHA1:09F34DCAF2B1261D8C4948796883A73FE3364A2C
                                  SHA-256:1E3482F31BF880D1F8ED5C8C11049DB147F1D2958BEC404FCCE6E007E76721F1
                                  SHA-512:414DBA413666508C5769520F16AD93E47D75A0EDB0CA99A37EB15F7DA6FFCAE0AF703260AD3CE80EFE33618D5217B7BB61563960BB8D05A587ABC64909C2D2DB
                                  Malicious:false
                                  Preview: N%!...............pn..od........+`G]..RGIC.....M..j|#>Jy..K]!|..VO..%#..r{AJ%x.....Bngwd..YNZ@SN;x..ta........$=.........plURcc......@Sgp1&..0-:y..U@......CZ.................g.....;'..==..KK..bqRE....wj..\QOZ..........(!(....i9..J`..$$.......L..0h<Y.............bd..Lc......UL....kq<+....e!.j......I......./ ............of....tcuo..,qeb....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\362__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.371891488866405
                                  Encrypted:false
                                  SSDEEP:24:FgPi9BkKkML06kALW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhLsiBBpFUBQ+Jge:FuEBlkgAd4M9/xJfAXxumLsiBpFUBvfv
                                  MD5:F664C7C7F8C0586C1DE3D379C9FE1FA3
                                  SHA1:E98AAC713C4D3AA6609DD303576374500BDBBBCE
                                  SHA-256:058FB96A516B015F2A6FE2EB040A767B8355D9D912AFC15BB50F172D0CDECD6E
                                  SHA-512:C20B79092A8076D628D2A5C6CAF94BE5BEC97E6893AD8CD648E8AE5C1B34193D9317A6F40D2760F0774E40C7A8866E6A316257EFC7F9BA717AA25D06A6D4FE68
                                  Malicious:false
                                  Preview: ...j.cb.Q........*5..o*58..WP.X......."%..........xd......du......vl..PW.......SO........cx....<h..Y..bpb..............c2.,7.??..4?'4..$55.....u!I@}%(^w............YQEzLA....7n..qq..he.}......."....9%do`s....to.....ngI..|..{X........................11*f=..^....................eZ......N..]...........VG..4!..:/......=4fd....OO......)"......D_ni..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\363__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.387846441223093
                                  Encrypted:false
                                  SSDEEP:24:DB1G2yEo+/4QJI/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMxBBpFUBQ+JgW5+:Dro+9JI0Ad4M9/xJfAXxuPjBpFUBvfE
                                  MD5:97C0C4959B3320BA78CAAB9FFA568238
                                  SHA1:B530F17AB5D0F17544D2A5322F8E1FE4671385C3
                                  SHA-256:FD9A3F3C50B607431E2FDB6BEBB2C83E4C899A2307E0A4620120578A06093E8C
                                  SHA-512:D34FAD9D0A4290BB8C2F4C0190F823EB667B3C470D4EE49A147A971146A06D02F687A4FAA9396AD998B8D78063C0B9F19DF996E28987A721D456844CEDB58A96
                                  Malicious:false
                                  Preview: ........QB..mkN.O\..prT_..v{..$;HI.R..?l..BH....)qB...>#.8Tb............./&..I......KU\/<ub.......D....#<..jvgn\E........[MOS....s,_V..6!......._..EP..../2......ed.../.......GX.`..........mm.T..........:'....EP...-wR....;4....piUX....Ci...vv..'6? q?.....b......vvQG.,|z..~Q.......^...:k..zo`u..~&A...EB....#......[GV..................::..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\364__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.607222514449921
                                  Encrypted:false
                                  SSDEEP:24:Jtx+OyaGU184tFoze4ytP6qfHSgC0fNSZBzfteJTQRP0UzfXF2tA63yrb+JgW5ns:Jt0zafGAd4M9/xJfAXxuQ/1EY6fi
                                  MD5:02092B2B5DA6F96F51BDF7D759C897BF
                                  SHA1:67EE62683511ABDA66CC3B8306B3D51EC0BBCF62
                                  SHA-256:E2E6EFDF2518690FB0ECF8E6B062A89DC6E1E048DF30CB9E341673050183F0B2
                                  SHA-512:589445F4B9ECB0564CCCC0C4237AB546E80C9AF85D8DEA2BEB9DD74324932BE291DA5AA75A72F6B80DD94D4C946885106FDD15D30178F8C4F2FBDF7C2FB05029
                                  Malicious:false
                                  Preview: ..e.........OP..gu.DI.....X..............c`....%9.....(cix....&9*0...............7$!#n.\G%".._.........Pc....(4..yj..4%7,}z..........ul.....7....BBEY#(O\....jqUR...."+.K..J]%.....3...I.M~Zp..<<....:1......6-.....py..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...?k..P3).#..4}{.}{459}{0000510000540000520000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\365__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.789779401133795
                                  Encrypted:false
                                  SSDEEP:24:PhP+wHuTjTJGhT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVuzUzfXF2tDFvy8Bp3:PhP+w03Ad4M9/xJfAXxuGuy158B0fW
                                  MD5:43BF370443A5DE2CD237300DB977EFCE
                                  SHA1:42691B954AB0069F566D97EFC81EB6AF86B43598
                                  SHA-256:AE66A1643661D4C65A89438635C60939FBD19DD3B7DC5FB260A5CEB1B7911334
                                  SHA-512:07DCA178BB9670D08D996516CFFF11FD3D7948B7C3B79619C58BEBD85230846C972245F26741138A414041C45DBC3DC4CE023DEBC73D8DA922053775FCFAFFFA
                                  Malicious:false
                                  Preview: !.......3[H..*,.[.....w|....OF......QK..$1~t......f=|jZGH{.....L......AG..U\...vq..._....tc.....X.UXI\..xZQHOU......:&AFWWmm.......$3..1,...................;;{$HA[H......6u........q(sr@.....QX..........:..xz&r:b....MQ............OF|o*=../5..n-......m.....FK.........1..ur{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....w..7..b7.}{.}{560}{0000510000540
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\366__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.697731104285027
                                  Encrypted:false
                                  SSDEEP:24:durz/v8IbjdZx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWEcsUzfXF2tDFvy8BXO:IrzDjCAd4M9/xJfAXxuFEG158B5fk
                                  MD5:FE3EC6AFDE8B925A49B579234B71AE47
                                  SHA1:D40773B07BF4FF8D6BEA70299E609E03EA9561C4
                                  SHA-256:CFB4BC9E43894927E3BB14F016678573EBD2C3085E43B72C231EFC2B722B9176
                                  SHA-512:B0D232DA8E9BAFB0D9E9F019DC0AE1A1165A4EA5DB6AB638FAB9AC858C0842150C3C6E944CF1C40CB4519792A8D641EB9DE86806A3E508A28FD271F3F7D0D8FD
                                  Malicious:false
                                  Preview: .............N......,..[W..t}..ED..: .......LM......TgsE...........&!U\..."%&&)v......)>..4).OB....bl........00?`.....#40*......5 ..Y.......8$oh....++.]..UFNY....kvT.........4.....MMvqGS......@@<<..8g~w..........j)%(xm3,'+cc../%...MJ..VV..ssVV=qkxa,{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...i..E.0Q.9.'}{.}{517}{00005100005400005400009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\367__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.718421966894623
                                  Encrypted:false
                                  SSDEEP:24:10qeP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUKb1UzfXF2tDFvyv2+JgW5C:10wAd4M9/xJfAXxuYbE15vRfM
                                  MD5:848FAF58D1D67465C0B07A9971025A03
                                  SHA1:B60E55DA2E7F7501558AD147160CE93B0175F8C0
                                  SHA-256:3FAB162CEB573406B221E0DFF00D0F7A020D7AF4979C6DE4F1052592C42E858D
                                  SHA-512:56F29E7B2248F920D6F2A4BAE1C646BFBDEF363F19E3D463CA21E51741AD9BF0A5EFD7C3D4D6B882919E6C1CEA2C0166C4D768796F9F805DFD40064128F2F3DA
                                  Malicious:false
                                  Preview: ....I...A.........TK....wzaj....(|n.....Z_....'8?#....LK.H_NS.....fg...-...7.LP.............AH.K.|.....U............:=...{r.]=\....V[.@s..LL...ZQzi........%/........;.....yd..k:.?rX..EE..QZ.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{V.1\f....=3_..E}{.}{431}{000051000054000055000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\368__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.379532126163793
                                  Encrypted:false
                                  SSDEEP:24:1wnISOXLSnYDyGfeXA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYNoK4BBpFUBQ+3:1svOlD/fehAd4M9/xJfAXxuBCKwBpFUt
                                  MD5:AA70233297DCF62F49B3062757DA2A95
                                  SHA1:0BCAAB761F43A8822E56C8BB969EAE5DEE1DA3FE
                                  SHA-256:16F04CFE1051ABF8021AF65797F29C17A0D5557E03EA18C50A6714BA5346BDDA
                                  SHA-512:3DEA8521F0F648E752CBC704A440BC2A9A5215AF4AE94C09B7886353D7F4EA3D90378E632F2395D26687B167C98D1C0006C5A0BBFA95D88F8D469B818726741D
                                  Malicious:false
                                  Preview: n:.......dsIS....IV...W..?4....I[SF..07..41....3,.......cr......BX..LO..iZv\..38........CD.....)q...sU..,5..iB|zyu..dWFluu..PC.............k3.....&.......J<..=1$$..ob..pfo...5.........s`rp........S.....h...#..._P..Ecxx,5ziso......QQ...R;(O.......10.....#......%".E...I.V......GV....jhOJ........{|..........~~PP..............DN@s.?..PPMQ{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\369__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.774033795293166
                                  Encrypted:false
                                  SSDEEP:24:KkuFIQwyhk4rV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRw1/VUzfXF2tDFvy8BpM:Kknkk4aAd4M9/xJfAXxuf1s158B0fF
                                  MD5:48D08750AA6F86700640326BE315ED63
                                  SHA1:DDB19BE599FF1C73CCA6ABBCE69FA3C401FB6AD3
                                  SHA-256:14EFD7C73E803191623562A8D83EE80F610A7C904B23FEFB9C03A17702F97F22
                                  SHA-512:12303724EB8A0A44D349BDE7C33122139654E4DD11BC69697B406613B500F0DB7BE1500BC70FA4BF8F0DC4653A78846A638D5F224F9031903B0CE2A06212905B
                                  Malicious:false
                                  Preview: ..:...:;.2%.............fa.....................[.bc%".Ewf..dy_@..LM........w];'............C.....mp.......P.1xRPP..%.....!0..&!Q[......!B..KZ..-..........&5....sh..hb.r{.A)p..TP...@D*?.TJOO......|(....Q_._g8jY".QQgg..EYZQ..GE....dc..f2........D]bq..l{..+.9(-0......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..U..."...|..?C}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\36__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.398112192000971
                                  Encrypted:false
                                  SSDEEP:24:yeoIWaxafu2HZ684tFoze4ytP6qfHSgC0fNSZBzfteJTQR8UcsBBpFUBQ+JgW5P:yCcu4ZfAd4M9/xJfAXxurUhBpFUBvfN
                                  MD5:C731F20B8DA1624A197A63CC184ABD1B
                                  SHA1:0192587ED727266D45421A6A18D276416D529948
                                  SHA-256:2887ABC265C129C2BE5B38E78F8ACE256F3F70D61186CD87785D590F3A925237
                                  SHA-512:911B14A514A76CBA60E5F368157539F90BA803919781ECDB796D79FBBEED0FFB10943F41CCA47189BED33F71802DAD7395659835A1EF900958B9DAB6B0415D23
                                  Malicious:false
                                  Preview: .P+.....nytn()..........URn4......NL../ ),gd....os.H~.FA....ZG....[Z....am..'.,0........QJ....r&...,M{i.............3../..................-y...S..R[.....>....F..."6w..............44FF.......vaNT..)j..(=0/......kd......r.....3.UUll!!th....D.OC..KJH..5.CC..rQ.....2JB...........#4..........1p....^?*<)..P..Zz|ni.............}1T]....#44.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\370__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.715323928905484
                                  Encrypted:false
                                  SSDEEP:24:2mwAUR7lZgEbSH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPnUzfXF2tDFvy8BXCA:2mw7R7ucAd4M9/xJfAXxuMm158B5ft
                                  MD5:57A161B6A42036F059EED918F036C373
                                  SHA1:9BEDD3FF86E7FA52BCC59DF3C526BEFB5EAE84D1
                                  SHA-256:4A9639C5ABC8D201DA1C24F3E2DA1339BF765CEC4B58CF95F565024F4F651ACC
                                  SHA-512:F665CF7D5F94E16CE6A22042600AA5918D6258BA87537FC71BE62A889EFE1C946D51A1AD0CA2EC212883E429343A2AD238C48F01F7BC2CAB7FF96BA6DE6B3C40
                                  Malicious:false
                                  Preview: ...\_................t1........x/..../-..........ze>"................INGD.........=.hj}l..z}..P.el.XJ%+;...t^^^....~m~|J[3(.....%,...FO..?2!q*..-............fw..Y^CI.I@..OXLv...."?fo!pl_..........M^MO=,......o;]T....%R~h......:.......hhht.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....7..h,X[.jE.}{.}{522}{00005100005500004800009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\371__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.722714328355062
                                  Encrypted:false
                                  SSDEEP:24:ctE/BABFO6P84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9UzfXF2tDFvyv2+JgW5O:O8ABFUAd4M9/xJfAXxuP15vRfQ
                                  MD5:89AD39180DD066D4C1CDB7D8D8470621
                                  SHA1:829AB59C058720955BD149390B36285B93814C10
                                  SHA-256:E80E575D65C469E69DBA3F23AAE48785608B08478B6711D7514E68BC33394388
                                  SHA-512:9F1D02926BF30D5BB29EF108D4AE6E0BEBCEB7E7D9E1719EBF9A92A25ACAE2298CF082A77E37B9FCAB586C681F2D25C8D705499744D4520B1D006382836950C3
                                  Malicious:false
                                  Preview: ...6.......z`PQ..8'...=0..y~W...dv"7.,07na...............(9y$......ut......Gt..6*....wu....[\..g3..-ue... DwDNd....IB........{|...>7r*5T..?&..............)+Q@ZA....o;ha.'....Cy........#.*..........><......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{s......@.M. ...}{.}{438}{00005100005500004900009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\372__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):7.4377816837695345
                                  Encrypted:false
                                  SSDEEP:24:0wV0IajOuS39mrq84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAyThViBBpFUBQ+JgD:0wVSSNmrPAd4M9/xJfAXxu+3iBpFUBvy
                                  MD5:7FF7F946C47B4B58F7D0BF922C57F2D7
                                  SHA1:7C0B019F51A7580E73DE5A16B490F240831E6140
                                  SHA-256:6F796CD38A7D73841CF912167F3766C35417DD71D5A5C5D7C0180F992C65968B
                                  SHA-512:818097FE24D04CB30A999786C3F058A52907B09B7D413E8CA511A4325A9C1C31B34C42DD3E685423DBFD1F3D04888E00EC7E12FD6C3D2BF343EC33A473DFF5EC
                                  Malicious:false
                                  Preview: 9......../.pv..&5..ln..ie........T.jp.}..W]p}..E........L.....C....SIf`............'4.......[`m..4+..........Ox....m{..........-:...{ft7......IP72..BI..lS*,.....co....1<.G..B0....KK.....AR......WP...&/s+.{....hn..93 ......6*....NN....=q..c.zu........@gof..WQ......=...N.....VF.........0hsx.......df..pe..QDvi....jc......>>....RA +..31........[h..........>!...q)......,...JG..XG....FSKB...D......zu_l,.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\373__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1487
                                  Entropy (8bit):7.502583033760247
                                  Encrypted:false
                                  SSDEEP:24:43NfC20cGdbFAl0O76gCrJ9NTnSWs84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFaj:WNfHoOWZmGAd4M9/xJfAXxuxBpFUBvfK
                                  MD5:325D1914A5DBDCC83F9CF36ACCE2AEE6
                                  SHA1:0DB7ADD16944B923C8C0B0DD6500FD547F3B8EFF
                                  SHA-256:AA2CFE1CFC9BB41561CBCA1481647D24F2BFCCACF80290FD0E460063067EB175
                                  SHA-512:9CD4FE82AB2627CABC0EE000DA825A2604332541AE719A80BEDB3D22BBEB81E3BFDEEB093D2F19BEA76AA2343069E619FE5DB9F5DD2491550E4D618D4199EB24
                                  Malicious:false
                                  Preview: .>...89.....VW......1t2?.....X...U@....na.....iv..j;89....(9z'....,6......'+..\@......cr)2UR.......b..........71.....7...~b..xk]_wf..%/})...;Z'*>#ia.(.....kT^v0..vb....A^.7 .............NGFUUB....f{.......#-...\V.............Hb||....NR....9w*&?g{.xz..ME9.YY..rQ....&.|~......k+T.NB...FS..QX......' ......{Qyy::......6!7 ....r/..NN........D.........$..._]....[qb?=..)<......}z.............DD...-`..........&3ca..T......ua.I:/..(!..a0..af....L..TT!!......... RIN..:,..TN......Y@..J[.....gx......4!y)..vh(}.....rv.].\..=(...p!..TS;~]RzI;....A...GT2%..0*WJ8e{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\374__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1209
                                  Entropy (8bit):7.359891296845281
                                  Encrypted:false
                                  SSDEEP:24:2orA6JT/lQoSJslC84tFoze4ytP6qfHSgC0fNSZBzfteJTQRriArH3BBpFUBQ+JW:2eXlQdOAd4M9/xJfAXxujATRBpFUBvfA
                                  MD5:B901F3CFC9FE35B8AE29FCEAD566F67C
                                  SHA1:B70A0E02082E5264714E5926F8109542BD8B0CD7
                                  SHA-256:6DA9810482EEA7D72E5C1217DE7A7EBD6FB264E81C4EDE72BFE7CBB4F83876DE
                                  SHA-512:620BEF1E48F36BC13E07E76BBA144E66D976AFF5A29B7354E86671843BA9DCBB906089AECD552B9733844FB4F7408CDFFAEE14AE1AE454FB6EA5C58FF5EB3F86
                                  Malicious:false
                                  Preview: !..MX...BC..L.......lg..XU..vi..........TYbcR.o4....-...NX......TNLJ.....g:....9f...l|k..hr..3pkf..9&..fz.........+0]KPL..((??..v.....~i>$(5p3....uj..$..R..7"1"..h1....~e..g...............fu)+%4d.g`..`4.......Uv....sy...........TT......Q...:w..........cD....SUhh......Q]>y.O.............8:}x..M@j.d{....~w..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{v
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\375__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.799018742365879
                                  Encrypted:false
                                  SSDEEP:24:qZztw828cYcAc5r884tFoze4ytP6qfHSgC0fNSZBzfteJTQRUDUzfXF2tDFvy8BC:q7w82uG19Ad4M9/xJfAXxuw158B0fF
                                  MD5:C97068A766F69A1E3FF53FCCBDF33339
                                  SHA1:7D11F6B289732027BC6B8EEDDBDA433C2DD9CEE0
                                  SHA-256:32E6AD63ABEE0E84DE50E890437A5707DAAD34F38F50F560BFF81C2DBCAB481F
                                  SHA-512:B72C44BB05494CCB2485FC27F4222647BD8B1015220B179D8F94D0D4BC181B3E87C32DE90E5B26557B76FD974024A8E5FF3253C909606799FDCF947009558759
                                  Malicious:false
                                  Preview: ..c....z,.......EZ..)l..',..v,/x.......q~..gd..)6..e4...).^ZK.........uryz..../.XD.....}........cj...5*..89..>{..fL.......UW8)..+,..U.;2......#2....j@..oo..*!...........?k...P.....+z(c........CB..|r...^2b...@..%.zP....||......XZ.....................'4....~D&.l}@]#*...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{IjX.....).3_Wi}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\376__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.674010715985079
                                  Encrypted:false
                                  SSDEEP:24:7Efo1kT67rz84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYcsUzfXF2tDFvy8BXCL+V:9o6P4Ad4M9/xJfAXxuDG158B5ft
                                  MD5:9BC57C0F9A73A6B29E98F71938F527DF
                                  SHA1:8756F46EAC9FC401C21D13D968DA420ED5F7DE98
                                  SHA-256:D563108E19ED70CD66B8F3371D6269979A3032CCE0246C4F0E4C402ECEA74934
                                  SHA-512:4DE29230B32101D0C5DA0BA946C98CFB69C84CE4A168C813160B9AC55689A48F797C2D1057078B83EAD42714DFFCF628C078939334AE96C25B9EE878A5537BFB
                                  Malicious:false
                                  Preview: "vn.3t...........-2`r...U^....HweepVT........od......~.....f;....#9fgfa..GK..bH..........IRX_* .Mxq..K$xh\8.&...vj..|ozx.............0Q.......=Pz00......l.....yb..u.r&r{h0,^'0..|B..-0..u$M~....||........jh..hs..GM.}to7..?H..XX..$/Uf>.ss........RC.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.*g......!s.3."}{.}{522}{00005100005500005400009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\377__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.719097042541775
                                  Encrypted:false
                                  SSDEEP:24:i9fPW07eCAao2T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSjyUzfXF2tDFvyv2+S:i9HW07ebFjAd4M9/xJfAXxufJ15vRfBs
                                  MD5:EF9867B78BEEBCE6B2B46DBE73112C7F
                                  SHA1:A2AAFF43B2E05F5EF2AC3F39C84C5124F994B5E2
                                  SHA-256:393AB293BF9927D4EAF089D8B0518C9B37B2AD9E8AB58679FAF88F58C80F3BCD
                                  SHA-512:CBACC3E88AB2E0BACE70704A176AF0642BB0DCCD485D61D05DC263CE3D9A9BB9D3DA3FFC2C9060BA1EA08B149F42F5B7391E0ABC510020F0FEE766BBE4703B5C
                                  Malicious:false
                                  Preview: Z..)....x.'0..mlVI..:(T.{v..(/.....K^+)kl'(cf....8'9%..45...........KJ..........jv..'4 " 1+0....;o.........|....nnrnK@[H..6'.......XQ..Z;........|O.!dd........SQ........%q....w..".nP.....r#;.........nr........|g....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.F=..C.d...2...}{.}{442}{000051000055000055000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\378__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1533
                                  Entropy (8bit):7.542017017947113
                                  Encrypted:false
                                  SSDEEP:24:E4wqq2CbofmonwELczOdpbHDxp84tFoze4ytP6qfHSgC0fNSZBzfteJTQRqBBpFp:E9q1uoUzMdHDxaAd4M9/xJfAXxujBpFp
                                  MD5:013BA260923953D024C6EA25926920A7
                                  SHA1:423D1C5B4190CD237CC20FE30A7327B8A4D1C969
                                  SHA-256:A218ED17A2B7AA35430980F2722EA317D95058845FBC83200002C6DE9EA4E0D6
                                  SHA-512:42F93F9812AE6197032237DB6DA07350F7F49B71EDC42A071405F8E3C619D168C2E1267C5235FEEE6248B9BDD81CFD6963B92BBEDA3AB03EFF78B0FD98A468FA
                                  Malicious:false
                                  Preview: ...K..`a.)..tnih....cq..boU^....6agu1$....."'..JU...[,-......*w..FY..xy..feAM..U.......ge..<'{|...B...d...(.....o|..wqma.Jy....~b.%...........b6(!.:N.......J...O...RGo|.?f....ir^S..........ZZ~b..........CD7=q%...P6...|z..nd..ii*3gtA]TS.........3 ....T\C\......dm..us...(....JFk,Z.......SA\...jogn..d)vt...g#*?...............DwSygg............z`...*-,,..//..PC...fn'8..LZ...........XZ;>..%(..MR....................S...........Y[qf....Z.be.G...x..#h......nl....DI..SL(/.......*-tt...._.3 `-R].......DQ........m.....G.$1EP..>f..?8.....}W33..5)..!o....g`..XN...PS..l{...O..A...4e..BB......>+W.67vhb7..mn.}...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\379__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.367571074030205
                                  Encrypted:false
                                  SSDEEP:24:7XV8VA4/cqazwJJf84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4h/VBBpFUBQ+JgWD:7eA4UqazwgAd4M9/xJfAXxuxvBpFUBvb
                                  MD5:4055E5AFD5A1CD641C2F936304317B67
                                  SHA1:0EA60354859EF8B79AA517F034B22A116FB5029D
                                  SHA-256:CFD9383448C9C3DE78CEF1930722B306D6B2561A9B24F1D0E627D7135D2FC2DA
                                  SHA-512:79C30523FDABE5D3F8A4B12CD3FA8E7A64A5D042A66CB2EB1E0DAC4AF7D872D21D4BA55F5DF136465832CF553C3B3CEF6B12D67554384409D76E34213FDF8BAE
                                  Malicious:false
                                  Preview: .q.>y...7 ..ut'8....e ..=6,+n4b5..+>XZnir}....(#nq3/2c..HO.e.......#9..34.....1^tso................W.....tR..nw...6RTmad5.%8...>"..2!IK......$.o;t}C.*E.......H>D=(k|da...x.RQ....O98a..77........g..=......0,*!RA..DU........YP.PU3iz..?9....z\]]cz......<<..//;;"n...NA..<#..ed..T].!..}}.._X....+l9oM@......45........(=....JQ$-....(/....88..............AK..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\37__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1303
                                  Entropy (8bit):7.429890696910568
                                  Encrypted:false
                                  SSDEEP:24:h3SkpZaLGP64ynj1bZ3S2b84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1BBpFUBQ+M:hikpZhi4c193xgAd4M9/xJfAXxu4BpFx
                                  MD5:F670D3A36FFC055BD410E9D62732AC19
                                  SHA1:AC4D6FC4EBCE9F8FBCF3C223C427A5CBA7415C3B
                                  SHA-256:79388E4C9484A2DEA87E0AA9B3DBF5C94916485408A48440E355E718973BF1DA
                                  SHA-512:FAD7995A6526FA5F01C800162B6C2C767BCCE70A892549A0AA14D74BC3D08C30D5631225ACD687B72FE5A3EC4FB668F83E4C0FED89166BF027775BB7F4D22A90
                                  Malicious:false
                                  Preview: .tp.......ml..q"FUE[.............b)..$w..-'..,-../t../2......b?..........#*...s...........................................)v..gt..(?..9$........|Gru.dS;.?6..70J<..GK....GJ..YO.yJ..gg......XK..et..be.......AR..AG..........zi..........i%..........ER................iS.........? ....=!|m_]..*?............<-..........7<=...KZ..G@....kA......ud...AR^x ....(0...B.M..XH.......sf..a9O...MJ..dk......ww..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\380__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.768405398031038
                                  Encrypted:false
                                  SSDEEP:24:H0zd42VckgT5ITha84tFoze4ytP6qfHSgC0fNSZBzfteJTQRg6UzfXF2tDFvy8B5:H0z2T5I/Ad4M9/xJfAXxuH1158B0fW
                                  MD5:115D15BCA2B68B14C01C723FDEBD10A2
                                  SHA1:6716663A4CC050F5A865CEEC0786B09F1C7F6CE0
                                  SHA-256:81DACE70B16D2E9DDE462DADAEF4970361BB2610C4E5BE8B7E20A782FE433462
                                  SHA-512:0B1DEDF955BAE0E09E0B32EA9C74EC6A511CDDB7880B1BB8FED4861D0DF2E318A25727797B3DB56469BD5B245A3898BCDF8F2F1597AEE12203530CE20C0E889D
                                  Malicious:false
                                  Preview: .......T.KXed%#.....'%29....18........\.U@....67..7lpf...+k]......sj........%.<aMJ........i~....%8..q|]H....y`0*..ZS..1666..Z...h{..ER..|a5vV[4!..Yk{m..c.LK.......szJY......sn...[N.....VA@[....3:...O..u".....]_...\moNV......]]..GG.T].....&<LQ.........byp!8..n3Wb@a........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.\.z.....@6.(.7?}{.}{560}{0000510000560
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\381__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.7087405765802375
                                  Encrypted:false
                                  SSDEEP:24:KD5zErk8Do84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7CUzfXF2tDFvy8BXCL+Jgt:KD50k+5Ad4M9/xJfAXxuIt158B5fk
                                  MD5:D0B16992B638B2505193779C2729DE64
                                  SHA1:F4A61D56169DCC381E04DA3E17B56BEED4E6FB10
                                  SHA-256:0686162FE0848744C49CFCF6798DC6A2A710B6517830E42980EA4F1418A9FF7B
                                  SHA-512:703E308961E8430C03097FE5902CB19DD9CB8C5AA7C8EEA4ED94BC28407FE23E401B298289EF6930A678097D57CCF4F1BFECBDD97258EF638C0A9613A988CEC9
                                  Malicious:false
                                  Preview: H....sf..!2..BD...ZDB@....&+..PO...A............v...UC..eV.....C13....+-...p{..LK//*ulearRE.......<di<)......cd....... 3....CY..;xCNU@po........nrVQxx....^.......)>-7.....ZO...-...yy..1%=!....RRPP.........<+si..........//........99..........s`..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..4.nj....TC..9N}{.}{517}{00005100005600004900009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\382__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.693582161519573
                                  Encrypted:false
                                  SSDEEP:24:p9ULplrf6Uu+R84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6UzfXF2tDFvyv2+JgWM:MploAd4M9/xJfAXxue15vRfM
                                  MD5:B280825C6759D1B024FD0265E25B7E9F
                                  SHA1:C8E07AD87096AA96F56B2860C431162536B40C41
                                  SHA-256:9B516F49BA275AE25050D7D4AE27692170A9D3DEFC8C35B4C47BC83D248093CC
                                  SHA-512:20FD731518984A353DEBBCFE62674F7327CD91FA4041DC4472A99AC5698E79E805843005026991BB9363D0CCFE188F2A28A49E489D324470DDDECE59C2BD3669
                                  Malicious:false
                                  Preview: ...\.....B..;!`a......p52?6=*-.B......Y[..DK..YZ..............@Q.....|f.............OD=.......@Gka:n.......2V....MM.....df........#w......(1..3cJy.3....ja....(90+*-...]!($|.1&:.....$9..,}....ww..::....[H....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...#..L5e..E.\.}{.}{431}{000051000056000050000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\383__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2054
                                  Entropy (8bit):7.6690004577221735
                                  Encrypted:false
                                  SSDEEP:48:mCWJeUww9qALCZK8StC7OgCEAd4M9/xJfAXxu7BBpFUBvff:tOyw9qkp8UC73EpBAXQ7ze
                                  MD5:53AD1C05374AA2DB59ECADF1ADC537A5
                                  SHA1:EB07E992F07F9A3554DBEBEA302EC5CA773631A5
                                  SHA-256:984C44DD15BF610B74DA7EA31A6D92704E6636DB6244C714635907C7D92C44EF
                                  SHA-512:00D7A0ECFBA4C273B26189049C549CE9CA236D1504D8FC51AAE587EF4CD852229C5590167113CFD718571B6792101C00D7FB860137F72BCF51B06B62564BDD1F
                                  Malicious:false
                                  Preview: mlh..vc..........GY:8.%Q]..'..........ty.......`SsE{m.^@B............U..)vv..=4..#4..-78%...XM....2.QX....Pg,6...uibeOO..Z.....sdavF\mp<.........i.o..tLWtr.......lj......~eDI~....}5....''..........PKpw%/.....O.yRA....R]ysGaCClu>-.........gg.XKp=........]\....`B..@@]b>9..>2n)...rb..........FCwb85..QN..OTYP....6100$$..%6<7........HO.$..3.==......./a....`..RJ~B9u..>3~n...'cMX........VPjm+n..RaxR........IV0~eiJ.;]:,............N\.?......j2...HO...3.]w....+7....'iMA......G.#u- ..QN;"K.A.....OZdita..jm-6........gg...I|o........_z....Df..FC~/w!..*:6)...32H........A..b}u..__.C^.........tqpe[Vi|b}..........JM....!2........}f.....,....-14?..><.n....nd.X.........Q..9....[R.{EV....dR!4,[pbOP.v..........gg...Zu|........{f....QD..wV{^'2..96hH....kf^.........#?<-..L...X..p....U].QggJ\jI06........MZ+2...Jqn.......{v....RU..]T/-xi....++...doM^........KA=.Fl..LLRNM\EZ....^..zhsNVjV............g#..9,dm....."%h-fiBq........6'..N....T2K].I...vf....Y+^A%'......epls.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\384__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.362573144995503
                                  Encrypted:false
                                  SSDEEP:24:q8GzDn0UcdWNtY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZXBBpFUBQ+JgW5k:q86j0BdypAd4M9/xJfAXxugxBpFUBvfe
                                  MD5:8E90DA08BC133FF9DC57429993041455
                                  SHA1:49EB5A69963AC35903291854022B03DAED24066C
                                  SHA-256:B9A3C108131BA286C03289EEC0AA6A00AB11B15B0824287C578BF52EB131A1A5
                                  SHA-512:EB3EAC4329C8CFBA3BB8B92E5996B209C3FA30DCBA3838C136A7684DC6421A1425946E887D82A6520210F523106194475957DEAB88C68881D844491653A0F421
                                  Malicious:false
                                  Preview: -.............O.......ne*&......lm|7"8e6..w}xu..L..NRDLQ."...mo4-2(HN.......{|...M..o|......`}k(|q.........^G....MW..]K..?8.....E......}g.b.A....tk......`h.......\Bt-9;Ll~8'*G......25OO..++7h........~dzgJ.]P)<......../%2=7.............--......sl@.95...ki$>{s..........5/....hj..........^[GR.. 5qn:=}f..-/..&!..............[J.......'.1......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\385__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.804857324321453
                                  Encrypted:false
                                  SSDEEP:24:BjW0Y1JTH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHZ4UzfXF2tDFvy8Bp+JgW5n:BjJOFcAd4M9/xJfAXxuOZj158B0fF
                                  MD5:C7D60846BA13310E3F087F7E491A3466
                                  SHA1:2D36DD2FF117723AA282C53CEA2533F89BBC3206
                                  SHA-256:9DF1FE8049C92FD8CF2A25ED31FDE0A1AE667E767207F691E77A23DB715D0865
                                  SHA-512:E95941AB7C1A7D2545B9CB2D69765F1A4221464ABC4D8DBEFBF6831122D3A10CD62164DC78F4A67F885189640686BA0BA3B25E761AE9F79DD94ABE906FD26D81
                                  Malicious:false
                                  Preview: ...,........UT......(m..........5 ....CL......wh...../bey2O^..RO..;!..52FE..*.kA..w|):....=&wpDNK...`8.fti........Ve.6..:&....*(..0+AF@J....U.o.......-..KKJJ....dw31cr.......) o7G......U......f4...aa`....{/.Tx(+%y)>a....%%..__G[]V....O^..WP_UY.5<..iO..cz..g.zm....%4..AH...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..'d?].....zL..}{.}{570}{00005100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\386__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.695241607542444
                                  Encrypted:false
                                  SSDEEP:24:PxnChH4ahpOiYy5V8DCC84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7sacsUzfXF29:PxnpahRtV8DqAd4M9/xJfAXxuaHG158h
                                  MD5:A1AA43BB6FE14988583B36F342992F6A
                                  SHA1:832B6435AABB739F2DB190616B2789B79EA2D62B
                                  SHA-256:DED5AF73E0B17AB48A9E35716A6AC9E80D6D1D4E49FB3CA49FE49F3C39838ACD
                                  SHA-512:F4D5DF148DC0696B5D9F60216C3F2525A6426EB7E02C25878587709BE2793AA94E5BB985250683BB6B793A5CA94BEB7C70A47DBD6F15770481541405BE8CF72D
                                  Malicious:false
                                  Preview: ..........\]......k...$/eb....SF..07......")...c;j..EB..8)..+6NQ........xKfL....;(.............\......r..ZpSS~b..?,TV2#..52IC....t..........(........{p.............................,........,0..m~]_..QJ............\+..77........rr......RNte..T...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.m......4....N`.}{.}{522}{00005100005600005400009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\387__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.724666629714556
                                  Encrypted:false
                                  SSDEEP:24:8LLmH3lg84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2KSUzfXF2tDFvyv2+JgW5O:kOrAd4M9/xJfAXxuC15vRfQ
                                  MD5:349F3C34A6918987A77B91A27D069D37
                                  SHA1:67F90885192AF75B3C6B1F83E667196FCF809643
                                  SHA-256:01F5727FA932FEACF73FAD16BB949CA0417738BC1BB015F5F3AE2ADC597930E5
                                  SHA-512:E2573CE0224F0864D1FD59F33D97AE1F91B0AFE2A8A4FB5382938DE07268B542631EC4B1F35DE4DAF22D1E807E5EB79B6DF6D29574B68318FC6D2FF862BC3D53
                                  Malicious:false
                                  Preview: 7c.v...U...A[....8'-?.wz_Tho...+9.........ji1:..">,}..MJ.P.......^Dlm......dW..6*......../4......ha.X7../KfU..cc..JAN]............`i..a.W^*3kf!q..9...RRWK..,?....RI..6<....L$V7 ..zD..:'..C..*0.....33..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Q.g.........}{.}{439}{00005100005600005500009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\388__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1940
                                  Entropy (8bit):7.654758286061784
                                  Encrypted:false
                                  SSDEEP:48:ULLPH3KZ3hFE2iyNVAd4M9/xJfAXxuHBpFUBvft:UPPaZRS2xspBAXQJU
                                  MD5:82F8BEA597B2F11F21B6FCE643A0F277
                                  SHA1:573F986EDFB79569963ECABB75DD76BA0711EEAD
                                  SHA-256:D1D79B85A4ACDCAA7A162E5DCE9994DC1A9186E17A5F1BE9FFDCB84E31688DBF
                                  SHA-512:A2E0AC0F9865C81F240772C08F632A4E0E11EC6DAA98EDFE8959EF674D46B15F19B785E1E2CAE374BCDAB3E42F25552012BC5AD316B22A1E53829BE5723EC10D
                                  Malicious:false
                                  Preview: ...HK}h.YJbc &..?,........ehU\..w<>$.XM.......I......-nX...J..ul..BD......T...................s0............3*94....wl..........D....J]....wj+h.....y@upMD")................((............2RRCC......................EV..@F...$iOtt..|oRNwp..ee..^^A.M^....b}......t}.0..ee^abe..Q]O.Q.|q....-(wd.gl........Y...............IJE......PP..V...jyVA.........!!..yy.......ld......hbIh..ZM...Y..VT.....PEYF......8:L]&!.......G...............|e..A5....?>...6#0....dq........NI...$..WW##ht....NBt,.b................:z....N[......HO..PY........n"FU........Qt..HTEg......I...o3,2d....C.JV..F\.AH..QY+>....Rlnpt)zKI....EH..........2#..YYZZ..IB.....VM........AA......"3....:0.XBKA.M9.......Q........D..$>+]*........RN..]]...RW^......;!F[N........%Sv.............._l.......xd..WH].......Y[~dEM..JJ>(.............9a..UO{l..J.4-..T]gl| .DO...oz.........r7.......]].....'........kv...yy..,,..DW.JIF....(...... TV..............m`........*#PR......yy...J5&:w..ld>!...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\389__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1533
                                  Entropy (8bit):7.526637984908847
                                  Encrypted:false
                                  SSDEEP:24:GfhmIxT/sm8DQla6SUirnFKUmeBtHIO/SYrL84tFoze4ytP6qfHSgC0fNSZBzfty:ETkm8DQlJ9irFKU/B/tUAd4M9/xJfAXU
                                  MD5:F1841D719EE48A73D41DC961046522E9
                                  SHA1:EAF4D2CA9C2C2092F718B93608699E5F889DC9D5
                                  SHA-256:5ED68DFADE230DB7082BE53978AF2490795295AA948E18C4E7CE1CA7D57E4ACA
                                  SHA-512:907FC1093FCDD42255AD56DA147A511F3924869922E1E6713A252F6BF520DCC57EF6AE236EFE3C318669602BB828A9ADAD05DBE208209320A04F74F58BE17596
                                  Malicious:false
                                  Preview: :n.6.../.L[3)..KT..........W.(:.................`1.......]..UJ...........8..2...........~yfl.....G&i{.......xSec?3....U........?=RC ;dc..3g...g...........!B..`y0=6d....F]......-09U..}u0......^........ih>H8a......gj7^wa......rr..........ET.d..0:..^.D"):..~x3<......&?BQ....**....[[.........3,gp..7...Qs....c\]Z.....W..TDNQ....C_..|&.....9nf"~k..MDI.....DCS.if........plV...DW'0h.f|..."....11uu....9t..s{......@J..hj..1i......-8,!.......W^..5$................8!......UB..~&...!cYM.@..3&......F@...!.....ii..wk}lEZ'i<0&~...)#<...........xa=e..]...........4!5eut7)..C......."fb&..*?...G.8>................OPd*..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\38__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.370354177437692
                                  Encrypted:false
                                  SSDEEP:24:veCD8PAl+HvK16y4coZW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGctxBBpFUBQ5:vhD8PgVoyxqLAd4M9/xJfAXxu+BpFUBI
                                  MD5:A3ED73011B9E8926DC4607B21B703301
                                  SHA1:B8622AFD658648BE5CEC951DF24BE1B8BE767E17
                                  SHA-256:543DD1822FF702C5E4A3353B408B14F8950CEB4A8319D6D73CC194C71F4A38EB
                                  SHA-512:4A714F6272B2DFDA24E2A4D6C3E4B0C4E71ED1A6CA55B70187BD0A5F0807B23EBF993B9D0F20DD8F1907AE28DF2B83DF61AF9E365A9DBAE778EF89FCEF8A20A1
                                  Malicious:false
                                  Preview: .....e)...............!,i`fy...Kuo....v|......f=.......cu....|f....JC...S..%%.X..ar.9....8%*i.....1wy8$....-.........9>99665j......."8,1..AL..HW.........%$.....lg...........);.....,=................6!..f{m.........7....|s..&/..94R....#......6*BS....VZ.]....dl.....%.@F........w`.......vlk|`ka7..@Uj......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\390__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1138
                                  Entropy (8bit):7.305515894373026
                                  Encrypted:false
                                  SSDEEP:24:AlScTordqQh084tFoze4ytP6qfHSgC0fNSZBzfteJTQRC+a/ZBBpFUBQ+JgW5i:A02UdVzAd4M9/xJfAXxubzzBpFUBvfs
                                  MD5:A07D3678F4E41EF90572CEB3DEE9CA3A
                                  SHA1:5D7E8B261970FBF539BB8C428CF71D902E7970D7
                                  SHA-256:B9184EEE00A5771F12DCBADADE3D181FE89E1CADD1E3F0FE612B0F91F90D63D8
                                  SHA-512:2050D90DA68D123706F2362285EAF2C82A922D24AFAEE679F4E57D4F9B839B84A51B059B9B2F40F6C8FE68A0A039865CE4214F6E41490EC967F401435E114243
                                  Malicious:false
                                  Preview: ..$n)....<+............la..kl.F.T....ca......+(.......[bc..a*..8e..c|.........'..89%.......AZurYS&r.......XX..UFV}.......+................................;...`......8^..SD............sl....WK..66..........LC..RM. ..5?..]_............N[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{c..3..}..a..*..}{.}{495}{0000510000570000480000950000950000670001110001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\391__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1221
                                  Entropy (8bit):7.350365312118817
                                  Encrypted:false
                                  SSDEEP:24:XHI+BNipP5UC5KbmaG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRr/KBBpFUBQ+Jg1:XHI+BNit59Ama7Ad4M9/xJfAXxuyyBpD
                                  MD5:BD57D4C09D23EC2270D92AF2F69F3D72
                                  SHA1:B69C17CAC478EBD07EB6E8E7C38868C462691570
                                  SHA-256:53DBCC72D5269E314F05B1EE5331F8CF067DDC521CB1C476A969BAE1DDCB286B
                                  SHA-512:BAA17DF41238D18701FB9EB7A7C6B43B4AA1C87FED881B8064140DF6B68FB83ABCF90ABB9627B367DBCC091C82A6643D2DEA832E74745D76B004ABD61EEDD867
                                  Malicious:false
                                  Preview: ........'&<:"qwd......MA...............HBGJ..C.N.....Ra...........MK...........(!...................................DC......%,................aV...vi.j1K..9#.........I.....U"hz..,A.9..JV....FF;;............E..qdxg%...(=....^~....Q\...'....11//A]ap..........G]3;OaEE..SpNH..wXLD....WN..J........t...(/KI'"....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\392__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.796106571155042
                                  Encrypted:false
                                  SSDEEP:24:qj+SFjKlh1A84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8/AUzfXF2tDFvy8Bp+Jgz:KBjA9Ad4M9/xJfAXxuRD158B0f4T
                                  MD5:AEC674AB6E139E312225DB71B8799194
                                  SHA1:93381ECE135790A5561A3CB4BF2B1C62807C0EA9
                                  SHA-256:FF0EB0EB7EA6F771651EE6DA7EC43BCDB48BA35264FE82688E1E46E8BFC85633
                                  SHA-512:581D036B3F62838EC7E2D5556A0DA7D1DECC683797D85E00F5093B8E4DAF2DEEFF9B010EC438E4695037BCB956915E1E32DA4243CC0DCFAE6818D90474E23FEB
                                  Malicious:false
                                  Preview: .QU..........:<......VT.............tn......s~....................?%......GL......l3......#4..............................;2..................JM...||//.. ...ar....':........skp)98.W........LU..!&.....N.....=%................3$.......ob..{d...?&...O/.<..."...=:....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{h.....b.L.. ....}{.}{568}{000051000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\393__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.706604173399158
                                  Encrypted:false
                                  SSDEEP:24:EbtLWtKmawi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRV//UzfXF2tDFvy8BXCL+a:EBL73wnAd4M9/xJfAXxuk2158B5fy
                                  MD5:9446FDBC6C33AFAD5600E116D59B9905
                                  SHA1:CFE753F55962CA6C0F3145AC1CC6C416BA85E64D
                                  SHA-256:65551B62C27390E72B13961FBD9DBF1097BA120C210B3BFD2C3B9B2CF195FFAC
                                  SHA-512:38739E3022DCCEBFEFB3E3E5752C40787FA37107C11563BCDBBA88B04D05CC20AB9D5AA59C2F81BC3131F277D03AE701F01A9FA34CBBE605B207CBA4CBAE4BEA
                                  Malicious:false
                                  Preview: C....k~c/....JL#pTGsm..^U..~s....! `+............E........oy.75sj%?..WP..AJ.R '...............R..........#?....bb.py........= .Z_R.;TK.4..qh....jm......u*v.$7............aTnOLHUcww..3'..43.........._Vyj 7BUou%81rS^..POhdww..........33WW00..]......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.......5.P...,X}{.}{521}{000051000057000051000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\394__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1324
                                  Entropy (8bit):6.720101326909298
                                  Encrypted:false
                                  SSDEEP:24:IpYM5EuHyVqI784tFoze4ytP6qfHSgC0fNSZBzfteJTQRI22s/+UzfXF2tDFvyvQ:0YGE5VjAAd4M9/xJfAXxuvDsR15vRfG
                                  MD5:439AAF84EEE42F018F84EB3CB67B2956
                                  SHA1:B16D36CE947EE237333FCF7240ED8C2D8AC085B3
                                  SHA-256:FEB8586780B048F30EA3FA1B040BD04841F8353C6A6DAA3DEB8F965EE69947C8
                                  SHA-512:90B3620B5B6822D4F0FDBD249E9D658FA22BA5052C0A0E54A3F3500C4D14CDE1FFFFA67DAE47F3E1A8A2E8DF3467035093A0752772C15A85B8B9259896333EBA
                                  Malicious:false
                                  Preview: .@.$c.....d~32ez......V]kl...T9+..........MN..;$..9hHI.........6)......KH..=.....ja........\V.i`u-..QA........VJenBQ....sh...d0NGm5...........zz....BI..........)#.KB*rI;6!.......gn...).))...............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{_.*j;?...t...}{.}{435}{0000510000570000520000950000950000670001010001080001080001170001080000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\395__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.389761635602494
                                  Encrypted:false
                                  SSDEEP:24:4TPt55XfiuHm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuf/9BBpFUBQ+JgW5Cp:WtyQAd4M9/xJfAXxuNfnBpFUBvfo
                                  MD5:8350A0D97AAA82D72E42D20F3EBC91B0
                                  SHA1:88655C865FDBB759133D8434EFA915C4F1D2C052
                                  SHA-256:15B17A1390929DD6F11ECE130915685C9CF6E1113FF6BD919C45FED98AD57D19
                                  SHA-512:0D281AC47D5B8FE73F9CEB3B4017C889DD5FCC4C9C0EF5DA9C9BE54FCD483564107474F9229E34AADCA96ACE9C35F6FACA69D9DE80EB495AC6A21EC4E3CB63AF
                                  Malicious:false
                                  Preview: .26....L...76..t'..............*+..cyI.....PQ.P...S`..QG.~|........`i`kL...??g8...........@._R.........E\eh|K..mv,:........B......... :..q2.......>.."..|.f`.........5 Y_.^Gq.............TH..GGss...............j)....gx*.Wr..93.........4d..SyFF....nr`q..(f.......is........X{vp: @o:220AV...........8|%0..sz*r....Y^.78.+".......)e.._LK\....KV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\396__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.809352147479234
                                  Encrypted:false
                                  SSDEEP:24:LGBuZzPd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjmH/acsUzfXF2tDFvy8Bp+JA:LGuZzPOAd4M9/xJfAXxutHCG158B0fW
                                  MD5:B810CA5B9403617F0C9D4DF9325CB56F
                                  SHA1:3796833F6FF6F9A389EA3A20A7BE5724B6473BB2
                                  SHA-256:2737FED1A270FDF21AAB583A24683E2B42AA0A51BDF46C4BD105A400AD634927
                                  SHA-512:C7483A22DE61F43C4402D452020D2FFCB7B87074236118E2020DE81506341F3DBAD2E2A34091B22CF4A420699A41525472E0CA0620FF88097B8AEC0E91424FB6
                                  Malicious:false
                                  Preview: .swtw...8+.. spc../-7<....yp...............2j....uh.......EG....\Z........TT.J...........n-....GX(.............``......CP~i.........sfgxgUpf..@\..))...._...`s..mz....2q.......H[Z.....]....U...........S..JCA~f....ZZ....YY......ds........i|..........P..@a..CuNN..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.].7.u4.......}{.}{560}{0000510000570
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\397__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.711902146139469
                                  Encrypted:false
                                  SSDEEP:24:hxZ1+Wqgn3NlMYP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRG/7UzfXF2tDFvy8Be:hxZ1+sn3NlMPAd4M9/xJfAXxuzS158Be
                                  MD5:1D6B22B5186EDD7221D988199776F3C4
                                  SHA1:2D5D32437E0BFA2A97BA9EDFB6DE6ABCB5913185
                                  SHA-256:627CCA2E14129D1C8DC1043B457D4C48251D035AE684EB538105F3179494D226
                                  SHA-512:86D4BC0D5C2D4A46FDD5C704F7D773C8043E6B412765FB055A42622EA880BAC5274843C27E8387CCFB00810E171F5E2BF561B3FAA6F608CF4DB4BB9A8EF2EFE0
                                  Malicious:false
                                  Preview: ...56........#%.QBuk........t}.......u&..MG.......M..]@..ZlV@.9;zc......%, +)t....*u$-..gp....ql..BOEP..........cc;d4=....{la{b....H]............ddVV.......QF...........^A..Fg..Oy^^......fa66\\cc"""}]TTG........`#..at.......RXY4/3VQ....&&ii...|ov;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{<3Y.h$^...ni....}{.}{517}{00005100005700005500009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\398__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1324
                                  Entropy (8bit):6.699624748683296
                                  Encrypted:false
                                  SSDEEP:24:zpwJ/q984tFoze4ytP6qfHSgC0fNSZBzfteJTQRo/s/43UzfXF2tDFvyv2+JgW5Y:tqyuAd4M9/xJfAXxuP/st15vRfG
                                  MD5:64680F908189D4283649907C8796B55B
                                  SHA1:02691E2FADE6B9EEBF3BC30C93776776281D3D49
                                  SHA-256:499262CDF7D8998497A5A551D52EB7500B34EAC9216EFEFC38C0135B6BCB155A
                                  SHA-512:C4D421EF781A532D319B953054D7D2823DA8C22572879E933035CD94DD932D4454028C0621D8C76B71CA614CBB0629B6B25A276D1D43BD7030FB84F7A4CCF8EF
                                  Malicious:false
                                  Preview: ..f....|kOU......I[.W- 0;..;a,{......+,[TcfTW......N...}zW.'6w*........z}....@s,.....DWlnM\.......M...y......_uCCYE....LNud&=.............v{.........YE..RA............p(.| 7D~..=,..ZS..l_....aa......WD.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..|.{..v..{...Z}{.}{435}{0000510000570000560000950000950000670001010001080001080001170001080000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\399__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.392067588393305
                                  Encrypted:false
                                  SSDEEP:24:kmecGGbzKx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLs/L/VBBpFUBQ+JgW5Cp:JGS9Ad4M9/xJfAXxuVDvBpFUBvfo
                                  MD5:5E665A86A8EC8C8D1906C80BA5AB1874
                                  SHA1:DFF8EAA839E7DBD493E7C3A1C9E8C6BA3F6C65A7
                                  SHA-256:5F0893CFC9D4F6F48C990E5957261BCC7D5CDE93551DBBF55343972C679FAD59
                                  SHA-512:00C33BB21E02877CA2E2DD62D4D021266944B37970508C5201EE6C1FDB06A5381B1E069E7D893974E4D5A2D6FC686CBAAC8F5D5302F8B7E98C799A0D397F5DE0
                                  Malicious:false
                                  Preview: ...:/.@Sno...S........`m..{dZ[..SI....v|..kj..C...ex.1..%3]...hq...pw..FM...ii..XQ......4.,1.....EK....mt..i^8"e~..WKBE..vv....&5....]G..Z.......)0a.R(..?%..!G..va.......O[...."=...2#....11..KK.le`s..TCa{ =D.......%...5 ..('....<%&+...yS..hhxx....\CO.84.....$>...&LL..:...rh....^\!6..r*.........Y....{|ge.."7........*1........JJ::......xk..rcTO{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\39__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.380189393239487
                                  Encrypted:false
                                  SSDEEP:24:cBVj0Ceme3zWUrx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRe/VBBpFUBQ+JgW5I:czj0c8XCAd4M9/xJfAXxufvBpFUBvfS
                                  MD5:6CFEAE70A72568521DB92F4B255795DA
                                  SHA1:63D33525AE65E350B972B9ABDDFAD5C16B8F730C
                                  SHA-256:510DC550E08EE3915E44FAAD489B5B965A9A28DF2C206C932A194D766293EAD4
                                  SHA-512:1AB8464BDDBBF854D2F28AD8B95E608B05B19822F3532736F1456A5712AA5C65EC4D987EC20B593806DB565A97F821D92EEFB6A811F4B90310B730E0DC943372
                                  Malicious:false
                                  Preview: .BF.........P.........."..ofpo.....e..>+q{..{z........|OSe..3n..NW....90FM[...II....fu....mw\A.@......QXxa........<*...............ZM..b.q2....gx..Z]..%.....)s.....PB.....WFye..pp.........YNXO+1...AL....bC......EJ...f.....&..1......}a..d{h&..4lq...................LcT\..sdzc...&<..%..VJOYZx5....6m;.OZ..haM..f`..>{....*...................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\3__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1380
                                  Entropy (8bit):6.714258992456915
                                  Encrypted:false
                                  SSDEEP:24:zrIcY/fvQsPy84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkUzfXF2tDFvy8BXCL+J7:zsc6nQkAd4M9/xJfAXxuU158B5ft
                                  MD5:8423E997D68BE39E94A79B649DE8B6F5
                                  SHA1:7ABFFE4810C9226581792C085DE7247A1CFFDFE8
                                  SHA-256:1A654A97B615BDC2718FF5FC4BE7D23F076E9F5BFBF046EB98B83BBBFE8FFCF3
                                  SHA-512:107A71ED6130ACEB604CE33E74E0E14CDE5029DBC9FA2053D2200445D2EB55D9F4908227830BF0C9763524297825BFD15FF663466A8035261FEA8AABC61C98E7
                                  Malicious:false
                                  Preview: w#....JK.fq...~......I....:=k1...\I.............&wVW,+.\..K...\C,6...)....Cpt^....]N....E^_X39.I....j........dd....[H$&........&r...U4..f..#....1WW..soU^PC*(....WP...Y..P..o....=...F[fo_.RaoE~~..~b....&$....in'-..|u.\pv@7..OO7:......MM....||>"......#/{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.#..W.hj..0I...}{.}{522}{00005100009500009500006700010100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\400__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.357223641790652
                                  Encrypted:false
                                  SSDEEP:24:PGsaH2lWC8nwq84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjOLEBBpFUBQ+JgW5KT:u1Wld8wAd4M9/xJfAXxuWOABpFUBvfy
                                  MD5:FF8ACFB0E6A38A2C795883DF9DE1B76D
                                  SHA1:49FD228E41CE186B41B83E48F584193F07CB4E84
                                  SHA-256:6E0591C5FF570073AB330E68AF530C84E4FFF6C54E53CA1C66AB81212C34937F
                                  SHA-512:953440E5691E7DD2FB2999CA46D8AE302AE5E3C246A34D36216C5E325927F6A6E83FB3366B4C817084AA65D73B5ADA90B16BF8ADD90B87B81EA91335909F38C1
                                  Malicious:false
                                  Preview: ...x{...L_.........moDO......tk...D..;h..YSeh....+pV@..Dw.......(1..EC..fo..Z......O........E.......................)?A]..11SS.Isz..~i...............f..z`......[L....N.Bt....=/}b..w`..EB......\.2;cp..ox{a..^...!4..,....j"(.....ov...........jj..........\..vt..h`dJ..3%....wm.........../d..XODO..K...XM..=e q..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\401__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1226
                                  Entropy (8bit):7.34601316467214
                                  Encrypted:false
                                  SSDEEP:24:1aqcSWrybLEMMVDdB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPoBBpFUBQ+JgW5Z:3MybLEMMuAd4M9/xJfAXxuEgBpFUBvfr
                                  MD5:1CEBE1D39B8C5474D89C1AFED150431A
                                  SHA1:D2617680699856AD64E0F49C5C77A5A73BE8BCB1
                                  SHA-256:C4D9D162337217F320E2CB1F855C700BAD4BDA07515E98AAB804086217B1EF13
                                  SHA-512:948A78DF8828C3D2B27A711B3B9AB1C54D6512F3D5892EE4D560ECF1D59F89A8DA6E004376714B6F65987D1EDCD64A4ACCE499020B054DB6F9A6E53B22BCAB61
                                  Malicious:false
                                  Preview: .\<......Kdsrhno...............P....OZ@Bruxw}xuvbi...........7jyd}bxbml........dNNR....XZM\KPur93p$) %}......jj......17......U.DDDX....#!6'0+jm...Q\U.Q=....?.....YA23}8[w$-..........NONY....3t.....q.....zm..c..)LL::...2;..yn..|f..(k..OZVI.......69*.v...GJ....DnuuFF$$....b}s=GK.W....='..,.......GALV<.bj........l'.....h2..0q.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\402__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1142
                                  Entropy (8bit):7.314607370508276
                                  Encrypted:false
                                  SSDEEP:24:jcFvrhUvmnvnrvo84tFoze4ytP6qfHSgC0fNSZBzfteJTQRe7BBpFUBQ+JgW5u:4vrhUvYvrv5Ad4M9/xJfAXxu3BpFUBvI
                                  MD5:77ADA871EB90DB70DA1BF4950C081B4B
                                  SHA1:CD7655E67D2E135D73DCBB7B9FCC5A53C5CD7DCB
                                  SHA-256:0B0B1A3D09924A2F33F65C0F906594AB4C63155FFBD12EB94A03404208D750FB
                                  SHA-512:DAD82BF5304681886CC97E537A6872EE9D7910804F05D60142E586A98353D57000162D33E7EA3C98A9D2F2E0DC89EFFE19637549212D504F8A0AFDD1E401CE12
                                  Malicious:false
                                  Preview: >jI..I\].E5"......=".....%.kle?.ft....in......QZ7(KWA......B....kv..}g......./..+2.MFev.....FA|vh<..b:.....||vo....)/..;j`S..tt...................T.x.hqz..'}vSUKB..PR..Cd>><4...TU..C^...o....LL.........yn]..........\CQ.Q]S.........K.K1<&6.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...l3.. .?(...3}{.}{502}{000052000048000050000095000095000067000111
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\403__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1259
                                  Entropy (8bit):7.419082934783647
                                  Encrypted:false
                                  SSDEEP:24:rJ1HaSvcL3VMGV00NtLA84yhpol84tFoze4ytP6qfHSgC0fNSZBzfteJTQRc+BBj:N1HbvcjVvvUGjAd4M9/xJfAXxuX+BpFT
                                  MD5:269545273A67579C01DDBA41B0A07315
                                  SHA1:EFF67CEB0BFEB5A99274D9B826DA2ACBD16E1AB4
                                  SHA-256:DA2B7FCDFCBDF687CAD568123703AE2385A5605A3EE0E6CBF849260901FB7A79
                                  SHA-512:614B9C24ED1EFD2FADDA1CCF75C085A2D6F310695C0977E147D6D3C7115CE907B7D690CAD6B66E8C17EA380903EF54F0849E7041BC51B40745C55751556F3FA2
                                  Malicious:false
                                  Preview: .`d..................................bwxrwzyx......O|{M...\...............MJ``|#(!PCAVGPKQroe&r.vc..jdvjLE.....,)3....EY..>>>>"}DM.............dqwh..euY/|x.........<ii...Abrs.......a.U]Q.......*<~....6......lg..vtO^........u|L.q...kH.......'.........AA....WW....#n......,;......-...__....!.l`g ..obXH....HY....qtk`w+k<..^K......`f..h-............Z81..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\404__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.3820612117599715
                                  Encrypted:false
                                  SSDEEP:24:KtdueD3BvKG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRICrBBpFUBQ+JgW53:KtdPD3OAd4M9/xJfAXxuUBpFUBvfV
                                  MD5:174E2CDE93C3C20C069CC68B80F07884
                                  SHA1:99D6F6504307A04243CC8F1F1E6BF949F63FDA28
                                  SHA-256:933DBD9B9F4B7E8FC88516F2F436783CD2BAE6AE1598E1F3D8E05BAF1FED4A32
                                  SHA-512:E4AD6F6121EF279B4A65EB852528C9FBB7C9D1BB184161F258855CEFA176EA04346E660D1B0DFFFDD9B1173340CDFD31FCF420CAC56BB2E63785C1F82A72B260
                                  Malicious:false
                                  Preview: ..~...F........;$..]...................X]..............X.RC.....E_45...p|..............NUPW...:3...1.......'........Dn@@......+)-<....\V....;c...........*..ZR..gD..IZ.....}$P\..LW*'.......llttdx..n}......\[..S........4...'(SY..||....ht8?....aa55...6{..2:{dgp..Be<55..........AMZ........[\..~b....3(..R[..;l.^K...D.a0MK.....iZ..mm77+7....O\....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\405__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1284
                                  Entropy (8bit):7.371570298835329
                                  Encrypted:false
                                  SSDEEP:24:5kCSe6UNtZNJ5z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsPBBpFUBQ+JgW5D:vrLZf54Ad4M9/xJfAXxuX5BpFUBvfR
                                  MD5:71015E40168953C6AD73E8D84695ED94
                                  SHA1:F3E10DED196443A2964D064E0A7AB9E3EEE06AE1
                                  SHA-256:AE73844071AC304F5962C17D5B5E9D83594AC3C123C8EE3AE157678EFCE68703
                                  SHA-512:95AA3B674A4BBA2C8A7B1C85F6CE6F6E09FFB103453716D5110CDC32ACD50C6CEC282BE922E422FB075A18B74F56C5FB4C0FCA897C30A3E591ABCC0F978A6CDF
                                  Malicious:false
                                  Preview: ...EP.54..@W#9....YKr7- .......=/BWzx@G..41........!plmwp....E....+1..AF74..!...IU1:kx.....\[.uO.!(g?[:...........<nh\P....@j..OS;0VE..$5..-*..I.+"..p.....3:EM$.GG=5f(yZ..):....k..IE............9..!!LP........$?..* ..AH..sl.....KD............!!..44##.F....$,}bi~........551.....R^....>.._X?.....[.....d3..wb..@I...X^qv}8..@s....< .jc......4.B_..........S..~3.....1.~ht~{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\406__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1257
                                  Entropy (8bit):7.362623776601554
                                  Encrypted:false
                                  SSDEEP:24:rOIEM/flolD0j984tFoze4ytP6qfHSgC0fNSZBzfteJTQRalcsBBpFUBQ+JgW56:rOIHNolDUuAd4M9/xJfAXxullhBpFUBw
                                  MD5:A186783554722EA1D196C73F27C37FE8
                                  SHA1:7739C18F64D2190F645BF5EB58CEEF01F7B530B0
                                  SHA-256:048FCAEC9369BD66286E968A2E1F7B537533620F20390E9E919FDD9A542012B5
                                  SHA-512:2EDAD3853DAEEB29D2E31DE8CD0EF31ED8595F5A8E22C3521BC0088B57038EC594A7F90FD486D589E40F55CA82B11D8B911F7AE3C9A096E9F1201B9941E17157
                                  Malicious:false
                                  Preview: X......h$6%...H...............qnrs.S....-828......Fse..=......YWU8!....RU....r/hoOO....[Lny..............~b[RUL|qw@......ht......b=..CP..&1.....|qh}..a]:=....w~& ....Z}..em5{....2!1,./..T...ll..M@.l%3t...Gm...]A...............V..../I.. ................OH..``ss.....Z.....4+6!..aF..wU..UU.2.xXb&*....,!_OLS......CR.5*-qh?..?*u`....q ../(.._P........{gk';2bq..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\407__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.794361645077324
                                  Encrypted:false
                                  SSDEEP:24:FYCQBcDZsd/cdR+84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1XqUzfXF2tDFvy8BY:FYCQ//2TAd4M9/xJfAXxu+Xl158B0fH
                                  MD5:4B6B79A698D234CA2A92B36B14E7F2C2
                                  SHA1:3DDAFD2FA4866370F703AB51DA19A0A66FC5B2D1
                                  SHA-256:30EAA89AD1DC3F26A7BF93AEEBAFFD730868C09A0CE90DBD33DA899BF15F8EF9
                                  SHA-512:03D5C7F6CF1BA9EFAD5413AA901F0B4724588DBE8B3CDB0051A49F017E3BB371DAB19B402FA4183765B89F7BDF1DEBC2C61B9F41955047EAF38039D58790CDD3
                                  Malicious:false
                                  Preview: D.F.L.........sl..r`z?....{|.6aBPly....!.....v}qn........S....= ........W[.........GE`q......f2..A..........ts.Zi...........KZkp....})..l4.o...+z.<lF....b~..S@...........g?..E....N.A.....k9..2}..sm[U.L...~...Tx'..!!....>"..EV....[@.....A@I.....&....%6a.>).._a....$-..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{u...B.....kb.B}{.}{566}{0000520000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\408__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.7075441974968815
                                  Encrypted:false
                                  SSDEEP:24:esbTpbfS8z9W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRN9rUzfXF2tDFvy8BXCLr:esbTpbFNAd4M9/xJfAXxuR158B5fy
                                  MD5:53C03123CA50C6B56E336D261BFC378E
                                  SHA1:8B178113A5C6953899ED827A42296CCF8526FD28
                                  SHA-256:490D59E0C327A867D3E89B4FC9466D36439059BB7F1F00B9FDAC9B06DAB683C5
                                  SHA-512:55C04F80053DAD53B4C6E564ED88F5F5D55E21638A568BD8764769C57B86485A60904A04159095A5022EF59EC258D054634F8CBEC3A7B8BFCF5B27F5678F8916
                                  Malicious:false
                                  Preview: .....LY.B............}..vz}p-$..+*......W]..^_.H.F..SN.3)..."...e|.........Dg`.....fuPG....@]b!.....DJ....(/??55\./&..w`..RHMP......zeiO....... '$$.....$-..FQ]JYC............Bc...6....J^....kk!!..99h7..PC..*=...o,- ..HW-!.........;<..ssGG........Q...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....._.q".....+.}{.}{520}{000052000048000056000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\409__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1324
                                  Entropy (8bit):6.699067829595731
                                  Encrypted:false
                                  SSDEEP:24:iPvE584tFoze4ytP6qfHSgC0fNSZBzfteJTQRx/VUzfXF2tDFvyv2+JgW5Y:gvEqAd4M9/xJfAXxuMs15vRfG
                                  MD5:AC56AB23E9F3DB7CE5575DFE11585769
                                  SHA1:23F1D4F0D131AF81DC799BDE9FE515018D11D033
                                  SHA-256:C82125736EC2FA44C672EF3959BB9025B92B4DEE5FACA5A81A9B6CFB67F996E0
                                  SHA-512:AF6E16DD565104F7789ACB09CAB0370AABDC359B5A32DAF3D92A90C68C8C54EDC0CBAFA8F94D70AE3B6CB27508226D06965EFBA902C139B5790F354492A98E66
                                  Malicious:false
                                  Preview: .EX...~H.FQ.........$aR_......L^AT..DC.........^B.A! .)S.zk..9$......st..IE..0...../<WUDUhs..ci....5Z"2..Bq......K@......nu[\ *....n...;".....4.##....sx@S..ap5.fa..F.zsh0....|B....+"D...ss^^++....o|-/ET..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......).,fz....}{.}{434}{0000520000480000570000950000950000670001010001080001080001170001080000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\40__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1280
                                  Entropy (8bit):7.386538514424022
                                  Encrypted:false
                                  SSDEEP:24:6RnJd7THYP00pz+W/k5184tFoze4ytP6qfHSgC0fNSZBzfteJTQRKiSBBpFUBQ+v:6lX0pzfk5GAd4M9/xJfAXxuCSBpFUBvv
                                  MD5:00114FCBD68CE16744B90598BB456533
                                  SHA1:192F948691F13D541DF01EA811ED8ED17BFB4C5E
                                  SHA-256:808DBB5B1ECAF855FCF1DAE97B7821D90A9DEE33768DBA612CD942A29A9CA288
                                  SHA-512:536E8D6442CA256EAF6C079D253792F2C762855F8DA9FCC65470C700B0120A70BE465FD688787111659BF8C7FE2233DDCFBB6203389328BB3FEE31F0B8B5FEB8
                                  Malicious:false
                                  Preview: ...W.[...U/8.....`..I[y<....ho...P......16...........'v.....HZK..rm@Z........jYOe..................:3l4.mQC....y`...6..2>P...q[....HC..|~;*..IN..A.....,,...w|6?.....j`!0.....X....I.oY..4C.....`w5$%9..yy....c<....K\....$9.<..LY.....Z8-nd..wW..QHtyq!Xk..11pp33qm..:%8v..`8r.......]s.....CE..2.2:..J]KR\.U...ZMEN]...@.ZACA....HEI\zey~"9..WU..................ZKPKmj$.."......THET....xt...e..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\410__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1513
                                  Entropy (8bit):7.51568614646218
                                  Encrypted:false
                                  SSDEEP:24:QC4sUQqE169XL74b3IQNGN+DBvNbMo8oXZ84tFoze4ytP6qfHSgC0fNSZBzfteJf:QQUjE1697AdNCWjzp6Ad4M9/xJfAXxuj
                                  MD5:D0E7027B488D1795A2E11ECCE14E4B09
                                  SHA1:AC1D435B6F23470A09A4458E80EF7F914372B526
                                  SHA-256:E136ADF45CE5C3A8D014C29F8835CC8116A55C64BD7D8005E0C081F3A9C4E48E
                                  SHA-512:EB278488FD2418EF45304905FF5F7EBF4E5F600A52AA9A3BA8BA7E7BB683D0496D4271D2BEA72E61B5DF9B0F9A9C028B0A75A0589983BA55F2B3426EA51BDBFF
                                  Malicious:false
                                  Preview: .Q.5.....yn;!~........XU....+q.../:............,0y(.......U.....pjFGlk..am............1 ..ts93!ucj..(I"0iO....!2\w:<....Pc..6*......BSE^$#..7cle..M"..*/.OS(my........?..I>............OO<<YY.................dq........LF..Ww.........^t......ui>/...G...2WRP.........."....?....%2...|.OH......5<..-|..HO.....Gm77CC>""nahIZ....@]..4355llOOu9.....ZRa~V{...u..64................!4..52....(*l}..%%.....+8.....kt3*..OZ....XA.....=......`u..#{...fa.T..................6:..UR..H}..kh..AV......@..?n....LH.....B.ML:$b7.x{..51.....yl.....F}{"%..je......DX..mr...c;.....59'`....sc..#9.....D..CV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\411__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1218
                                  Entropy (8bit):7.377809762431074
                                  Encrypted:false
                                  SSDEEP:24:m/WFB7GH+qjAC84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuE3BBpFUBQ+JgW5x:6nHBAHAd4M9/xJfAXxuLERBpFUBvfj
                                  MD5:1521416967987D9C7FC7676C18C91D7E
                                  SHA1:DA1A8ECCE3BB2B2BEE2076B6FAEE5D2B99328D56
                                  SHA-256:7181EBD82B915E469E3A7D29031FEDA6186D6B6588B4EE0DAD62F528B4A28ABC
                                  SHA-512:C7D45F8661FC0365E3CF211691DD86A3E3F014731B91E042CA2BF09F30B535C47A120A01335D7E1C6A321F8F73289825FE640C3155E47C0FECB8DA4BE5946DAD
                                  Malicious:false
                                  Preview: }).oA._^..2%..A@....L^.V\Q.....H....AT.. 'LC8=......fz....g`..`q*w..8'.._^af.....1]w............cd......%}q.<..*QQ..ev.......J$.....[G......<-3(..'-9m5<.....?L..,!<]iz,'#b.ZN..#B..@Kl$.>......JU..........FF..-r..1"MZ?(NT...........2lyZP...33:.....E.....NN....^A..dh3k}...YC|tu[&&...<#%....W_..1&..z"..g$.......+>GN..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\412__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.318418447280273
                                  Encrypted:false
                                  SSDEEP:24:3eTB5Zf/Mw7W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwBBpFUBQ+JgW5KT:3eTB5ZfEeAd4M9/xJfAXxurBpFUBvfy
                                  MD5:918BA860979FFB6E14B8C769E6C6A01B
                                  SHA1:F1217D6C252066ECBBC49146EF48BBE84B7EB7DA
                                  SHA-256:6246A19B65B26C0B871C42F5B6FB6CAF7DBE96D9F50C8AE6C181FF89E8991FAE
                                  SHA-512:8F4D3AD8B5E4FE9AE30E5E77D85B39AD8FA9402EAB06A692D0D7D8D85EA7B62073C3D87266F3FBF3839C3E2CE9C05434E3AB53E6DB0EFD596220FD9464F265FB
                                  Malicious:false
                                  Preview: Oy}SP*?.U:)wv.........4?...... ?.........NDla.....uc4)..(.%3e8../6........EN...MM........pg..$9s0$)..nq')lp..TM]PNy..7,ESiu>9%%.......SD..YCxe._RTASL_X.....)$3R....F..;....sa....ny..#?........Hkb..@W..jp...................xX......p ...*..dd........7y..z"+N....7?........OI........i~F_d<T...yr..gk..DVlnLI..UX......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\413__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1261
                                  Entropy (8bit):7.350897942216328
                                  Encrypted:false
                                  SSDEEP:24:SXyCFu8H7u6oooT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5PBBpFUBQ+JgW5O:Niu8bjAd4M9/xJfAXxucBpFUBvfU
                                  MD5:1A13C84E6AF3D343EDB61C54B0683C70
                                  SHA1:206895B06DD11F5861AAEC3CEAD70FD371E22725
                                  SHA-256:FE6B394342A214DEAD5FC16A52A33C0BD263D89E578AD155FAD42F2A139753F6
                                  SHA-512:DD214DAC03DC3044342041DAE5BEF625B6516D16B99149ED25BCC9D518044BA1A583508907325D69782C3BE63FA55C425113E318638F2B985A7A665D017C8F4E
                                  Malicious:false
                                  Preview: .....ly"nev......1".......OB...1...H......$.DI....!zdr...2....$y..d}....WP_V.....22E..........e&..mx........E\kfJ}IS/4........SS3l..l.l{OXJP...E`m..B]fD?4..-l..........x.....w2a`..I.....&..?......@...hd..WL....x..)sY..RR}aT_dw....>%..<6..xq.._9+8.........kklu..HT..!!::....r>...........45eB..........9.......,<PO..32....HRG?*09.P(yDB..v3.....9..TTfz...'{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEA
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\414__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.806694426564648
                                  Encrypted:false
                                  SSDEEP:24:ZbuvRXYglb1TUx84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1UzfXF2tDFvy8Bp+J8:ZsImTUCAd4M9/xJfAXxun158B0f4T
                                  MD5:08B4C188C90998FDD1D5424FEB695E7E
                                  SHA1:38ABC597823AA4BE7CE8665A3EDF69A075A65AF5
                                  SHA-256:72793B1FBE8D41438B6396F5C38668AA590597B57B0B444D6A07691DC27C0B75
                                  SHA-512:275EB348F9832CA58BC36F8D117D7D5224C25415045F00DEAEC3B2BF84382CF59437D7E0B93C4572D4F4766C2B3034CB1490F13C0E9D9ABB3EB25203999931A4
                                  Malicious:false
                                  Preview: ...56.....#".....4*......\Q.....?t#9........IHl4.......,m[.......vl..`g........i6....<+W@....j)?2.....#......ts{r......uu...+8....mw...R_xm........EYcd..cc..E...........XE@.;6..mr$<[.TU..=$.....7`...*-7#......Y.rp..]ATSbb..%%,,[......-:....Y........uMDsj.....)-.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Uz..$)l8....]..}{.}{568}{000052000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\415__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.688067981352303
                                  Encrypted:false
                                  SSDEEP:24:PjX13hzhIM9xi1vZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRU17UzfXF2tDFvy8W:LXXGMu1vKAd4M9/xJfAXxul1K158B5fy
                                  MD5:94010AF2E43FFC8A2E12D5221962C337
                                  SHA1:C5D0654F815053100219F68AE23A5BBD0AE81DB6
                                  SHA-256:8BC11B3C0AEA9CDBB61EE2C509D54EB6B5707D669C510B94316AEB152401145D
                                  SHA-512:89BD4AEE1B2F9344AF6C4707C5BC169788D7885E97C0D0A28CC3A142010261C0F5918F0FB39CF993E46D6BC435280664CE47ACB8213D62FFD61C5069EDDA13C7
                                  Malicious:false
                                  Preview: .Z^QR_Jr>.......W..)7/-....>3......"iVLc0zofl`m....Y..it....2$.\..F_..x~..kb......+tpy..0'5")3...Pkf..........@G##....90..+<`w...3.'*.................lliiy&OFTG....HR.....{n...0._[.?CCOH....]Z##..%%..........k|....*i..+>QN..99..+!6[,0...\\ZZss,,.Yn}...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....T..Ai..&...}{.}{521}{000052000049000053000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\416__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.70699666056447
                                  Encrypted:false
                                  SSDEEP:24:3OotFhlG33/b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLYcsUzfXF2tDFvyv2+Jw:3LhKgAd4M9/xJfAXxubG15vRfBs
                                  MD5:9B3D04183E765EA44225C9555387BCB7
                                  SHA1:4C8DE680F0CD6EFEC9C0452F845D79DD49455CF3
                                  SHA-256:AFEF24FE19D23264EE598603559C2158313C9BA1FF210D6E3306BBE3F1822EA3
                                  SHA-512:852E5D5EA64686B121CDE75FB0735CD4EF3028E4326D14DD101E22C10C7D2D6FB6652CA290E9B3FA124A4B40E4D32C077C05D4C4D56282197F75A27414A976F5
                                  Malicious:false
                                  Preview: ..}..SRO.TC..{z......@.58..DC.U.Ei{....$#~qcf....!>..T...|{.........*0+*..RQuy...=......#!FW..`g=7..\U.J....H{Zpaa1-.......d....x,..F.k.ZSRK..?o.)..33MM-1..........mg#w.....YN5.Ku........@j.......@K..-/'6.._X6<{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..7y.....I..E..}{.}{442}{000052000049000054000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\417__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1703
                                  Entropy (8bit):7.5951925988110105
                                  Encrypted:false
                                  SSDEEP:48:F3tKOV3k6fo6KOO/UlAd4M9/xJfAXxuxBpFUBvf5:lJ16/ppBAXQjA
                                  MD5:7E040693B1C459FB57E337A70DAEFE47
                                  SHA1:A9225FA3B7E9C63FE1ED03CD9E452A916A642417
                                  SHA-256:A977605D0DCA823446DE54866273010326D63E334F8E328FBA8607B6C9CF5465
                                  SHA-512:6C4AE81EAD482DF8C46E415A730798994D801F7BF3620BCA84D88B74B4BBED91A8CDDD87D3C5E099333E022AB2DC096CCB3A01592BE52495D442D44B2C68B5C6
                                  Malicious:false
                                  Preview: ..`..U/.C.H_9#LM..{d...kAL.............Z]................lk....e8...&<.........5)yr..tv....61..{/v.W.y.......!8ZI8.8>R^..#.....`k 3..........^.(!..\*..p{....@v^N#+:L.am...........m........\W..LN..PK8?....F............cE......,+..FFJJ..Z.9*.Q..5=..J]NO..>7..SU++........"e.S..2"........)8}...8-[V..\[SH..*(..............OMSB..ND....((..XD..nqX...........R........^MQ.......h0....dc.VY.#....!!..YH........wv....[...=0K[..L]..T.......\.F@<;...#..................v`.._r...rm.6..CBs!}zyh........wb....>!..-6....J[..bbEEYYF....Ygh....@Y....ac.....S...-oRFI.xm"7...a0=;fay<if/...AA..2.fw....ZV...~.......X.Z..p`..fq..eg?:[N.._J......=4+)..ST....dd..n},a?0U]hwNk......-(F..G......D.##xy....xzxb:j.....N[ccl;.B@x|,.rp....gj6#..%"..?6...........B.*98uhgEMmr..j}:.qy-/oxhq}%.....%0-{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\418__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1289
                                  Entropy (8bit):7.40366035502488
                                  Encrypted:false
                                  SSDEEP:24:ldJIvVnoKKPk8AlD5J6b84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6aABBpFUBQ+o:tHDARXAd4M9/xJfAXxuTaoBpFUBvfD8p
                                  MD5:B1AD618B86C8E9F961337C108EDCD1EF
                                  SHA1:1F50614D1B696F287FC0C94EAE4F8147AC84A74F
                                  SHA-256:80B3BA75FB72207E459F6287EFBDD6A3C541131927CD02363816959D341CC087
                                  SHA-512:1EA21D6AE07E7D492C1F2F0F271805D1F106D40013A375D88B8CC37D5C1EB59573CF57911250EAF063E812942457E6668570EC42B732F04E0550689B979313AC
                                  Malicious:false
                                  Preview: .<8..^K+g..! SU.RA...............Y....k~..M@WVo7..i.......&0T.............ja.M....g8V_N]l{dskq..&e......................v`....88..-r..FU.......`#..DQfy.:..#...^W.....4#qz.["X../8.....]]..ZN.."0xg.[L.nDXHO..<<....|u1"%2....1,.....[~..MG....}t..&+.U....``zz00rn..!>..{wl4........==....OI_E..>6...........$//&.............w~..............1:dw[YBS..\[[Q..Hb.....|m..6x........Ey..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\419__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1525
                                  Entropy (8bit):7.524582470923356
                                  Encrypted:false
                                  SSDEEP:24:wiKf8G12wMYV+zIxM4t84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVou/VBBpFUBQ9:RK06oI4Ad4M9/xJfAXxuuNvBpFUBvfU
                                  MD5:63F6021A3848E8F4FC24D29B3181FAB1
                                  SHA1:B919D856E81577193A633D4A4BE6C60ABC80D402
                                  SHA-256:BE097592D069613840FDF04139268999277DB0418A9152D27DFEEE4A14467730
                                  SHA-512:AA23DC3427423E41F16A7C97541F8B8C6DF0FE77F7ADA8AA3E4CA423E01E2003010F9FCD5A5DBE517C0E4F31ECCD42BF861CCCFB5F71C0A7F6DDD71E3A10FD82
                                  Malicious:false
                                  Preview: l8.?6q|}9omz..XY..op:(%`../$hoy#..i{/:#! '.....p{+4..},z{.......C^VI....UR......mGDX....UDTO..]W.....K*7%2...........VZ.............. 1...."(p$.........8....8.............#1b}-@....?#..<<..QQ. ..4'*=[L*0.......mr..#...-'JE..5<..V[./ . ...""......A^x6...T.a..z`..^p.....5....9.=564...YS...........rg- ....x...md+)>/..((RR...._TGT.."3..,+....Zp..YYVJ|m,3...g?r.........CS ?......?6.......T...o\.............._...drY.f0...... \.eh...O.(`n..%*={........Q.<:jm......11.......\...u-......%(..a~ZC.T.R....PEq|dq{d..hsmd....NNcc^^2~H[...JB..oJ....|^)4mh..4b....ivU...........L.Z..ld.............Zom...;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\41__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2329
                                  Entropy (8bit):7.752775961631613
                                  Encrypted:false
                                  SSDEEP:48:V1WrsD60VsDkayY/pWOPOSJDE6xRZ3Ad4M9/xJfAXxusBpFUBvfD:V1Wk/qxNZxSpBAXQ4O
                                  MD5:C7E315DDC013D640E313DF4B1FC3A70A
                                  SHA1:EAE89AC39CAB55EDFB27EEE0650DF2E6BFAD626D
                                  SHA-256:6E31BD5BBF8FDAC3DAC99D6A94FBA783A7E8D337BE0CE2993A1B2DCE6CCB62BC
                                  SHA-512:A9FF4DA5B432027AD4A73651F6B6EC99B027BE9E52147DB91C55E3BF4B02F8E68D693006E7FD5B0C1883007BACA9201CEAFDC035183820901B03839E65AC09A9
                                  Malicious:false
                                  Preview: .^Z..WPQ{->)..,-.......1<0;dc..@.............ij..]B}a.................?>9>....o\[q..........PWJ@...q)6Wjx.........?.....}N....C_........7,....._.....TX.....ce.y..00..TY.c)?.vKx....cc.........#8OH93O.....l.......akiO....fu....qq.........6{......pg..@g..5...............<j........AR..rp5y..@.......M.......X"-...QQ.....XQ.... 7..wj.I43....bb.7$r?AN......../%..nl1&../wzi......ZW..XG?8......+:........_....P..H@......XZ\KF_.[........CPYV......1<CV...........eeHHHH=q..g*dkGO.`....;............1%........P...............SSSO..QN....P+Y....sF...........Y..I......))....UR|i.........&$,(%ac'..PE....[.~x...78\o....< l....4#,;...........qxcprect.......^K..('....R_...Y/.FS.z.....:-kz..kl..........GTVA.......T1<CV............ )....s#...***..bb....9&.............hF.......................].....W.......}h......G@........inDD.......\Oy{....BE-'.........c|=s".&~O,]F.....[*|....*5S@...}hv....#% '.............ixc|1.gk........X....YF......[JC3
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\420__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2054
                                  Entropy (8bit):7.653782078618699
                                  Encrypted:false
                                  SSDEEP:48:YsRR964GrYRG2zlmxofO42iSuIK1dD5Ad4M9/xJfAXxuIBpFUBvff:bR9kYhfO4dSuIK0pBAXQ8e
                                  MD5:87DD09D48555E28BA456237DC1AC64B4
                                  SHA1:D902AAFF2469023F24C5F2D8763AB12C43A640D2
                                  SHA-256:4AFCF2F7333BBDC2C7F3CD6FEC1770A5989CCB89FB13958AA0AD12B3E1F0388C
                                  SHA-512:D174A7C5E4F28FEF23D194C4091BF36FA1C95FB25FD052F1540929E1AAF757D803D1CF7FD6C0E6A2C53EFD2861E9244A46A748C1F05BA03255F15F2742F5991D
                                  Malicious:false
                                  Preview: .OK'$................-/..$(GJNG......bx.CLY..DI&'.V.7!or....`v...7.....:=....j7af::p/kb...........<.....BLrn..=$..2.bx5.?)1-)......^....NYH_D^snM.ZW^K..........V-........G1.^P\......5\........hhhhht]V+8+)>/..UROE.R.........................((((........E......ny......dF........YcL@H.'qOB[K..^...............L......V......<<.......:)+<-:WM>#)tG@.......V......................*9*(liQD.....[\.....................@H..iHtd..XOB[^.........^?.0...............r{........hhhht8_L'j$+'/..ovr_VC.....................*{|zafB...............[D......u........BX]^..qfB[K...^.........MISJ....._WVC]G......-).......18-uj;JL#$-hje..,.............................zik|mzLV.....XM......]L.....BD.........rr`{NC.nyo~..6......................T......yj.........-$$=$_LhtG@jj.......V.........................af|Fie@...............L].....Q\........CJ..............................dNNNNNTH.....}q:b...... &jh>_R..wh{h.1$GR_V..8i......@O........zf.....Q]9a.a..0qp&yt1!..C|).9I#+X......K
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\421__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1786
                                  Entropy (8bit):7.6320866373356315
                                  Encrypted:false
                                  SSDEEP:48:4jlOoI1PSrviSQkU84Ad4M9/xJfAXxudBpFUBvf+:GOoIQ15n7pBAXQHX
                                  MD5:DD849AA8B0D82D8E422C1FCAB8E78CB8
                                  SHA1:969D34AAC8C34ED819AB8CBFA7EBDE7FEE0F3018
                                  SHA-256:104F04219FE0A7B76A1404B4573F11400EEC6DE54B8E64DF1145A87550C245AE
                                  SHA-512:A2D335F72E6698CF35ADF5EA271CD59924E45AD0135A452A80A55CF88831837F292F96FD28CE9B5BBCB01544BD51710489EFA5CDE8FB84EAEBAD868DBF33AE08
                                  Malicious:false
                                  Preview: .............z).................I.......0:S^.~.......Uf..;f...f..........r/.....R[......YC.....VC......YP....5......8....PP...............k(..8-]B.7%6.....ST..UJ...6oma.....U<QG^,#...]]..ui.....,...................../%Lj............XX....0|?,|1?0...."5..-....!JL..ViG@../#..../"......70................tk(/..(!....$$......bi@SNL......'-...ii.....\C.....m...(0...T!w........c'\I........G@........cc..ui......3k...P.K.....5*%>..9#......L....3:...........2.4.--....@Q.....a9`...90.........js..T.\^.....^K..52../&..IX....vv``..,?....$;.._]QM......!w58....4b....s%....6,Y..X........?h.SQ..;h............KL........ii....... "....`gBH$.*.++......$&.........\U5mf.........0...GVTI.......HW..[L"3....))...@...."5`w....v5..........@U....Ttqxkr?2..."........LP....L...........R|........CYvYog~|l{...{*..{j....ly..~ka~%"........jmdd``..$7XS....4%\Geb..-.W}..WW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\422__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1210
                                  Entropy (8bit):7.340365072729348
                                  Encrypted:false
                                  SSDEEP:24:VZtsyaYyAltPA0eom5HK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBGSBBpFUBQ+D:VkXYjlK0EHvAd4M9/xJfAXxuUXBpFUBb
                                  MD5:7E1721809629B502CE1F8D10761E8646
                                  SHA1:1590646A7EB3C6BFA807FDB51EC7C2BFF9967B81
                                  SHA-256:B4B8FA79E2A2F39377440D5D39CB31E9BC146F02D5497FEF3A57B37CD6F3A134
                                  SHA-512:F55CBF46FDAA4BA4B29BDB4EF81C36345AB91BC2797189D3B1553DCEE8028E970B3A666B13B6A38772D89880B1F52761CC2CBDEF4D1A972036A545AA9BE9C5ED
                                  Malicious:false
                                  Preview: ..q.-j..y/......[DOP...].........cq..02ur`o........LP&w..>9.AP..wj....XY.. #..O|....V]............._PY.......}}..7$.......1.Xr..........wf..~yxr..3:...gu..47....A.........[6............LL.J[R7$..&1.....[}p,9..No..........PY..!,......__}}.........OKGM..fd-7......dr:.....iF..SQ..ul..)dD.....^U=k........N.k:.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\423__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.352780949647883
                                  Encrypted:false
                                  SSDEEP:24:Tw246HP6ofidX63SUENx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRlUEhBBpFUBQu:824iPnfidqb7Ad4M9/xJfAXxuaUEBpFa
                                  MD5:A2BBD64245A3D81C04870811B8FCE90E
                                  SHA1:7C1226329B1D6F477A1F1C59FC704802ADE874E2
                                  SHA-256:60B2DE3BEA3AF7794B23A00EC71881BC24F3D32B3D0DC997A2CC636E19AA0B86
                                  SHA-512:3CE796996D86A5A38841267026A757F24EA340FF0C786DE12246A6F5307D7216AB1135CBD18FA667F72BC49FE2D6E5DA13F40B901B85C56AE2F3796A401D3667
                                  Malicious:false
                                  Preview: ..%..^..F...VL....9&|n........t.1f....57dc)&........_C.DYXwp.R....zg:%........|p-.....t.ve)+.........R...[X9hz....}d->........-..3....t.ve)+.........R...[X5 3.........h eSUAM:CQJUh.l{..........==.HCJ.............b}@a.<....xw....RKr.|,0.-.RR..........., .`.....>6....v`..*,........YN...G........HC.4!......f`...../...,,...2~..JYi~..tnC^...##..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\424__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.3514313838671494
                                  Encrypted:false
                                  SSDEEP:24:WXhuWlDz6x1eSNL6G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUNkBBpFUBQ+JgWm:WoWJ+x1eSc7Ad4M9/xJfAXxurGBpFUBm
                                  MD5:7BB3534D5741C0B22EFF583D3E6A4914
                                  SHA1:6DB3A39BFB49477C92B85EB9E432DACA21E0C695
                                  SHA-256:DE4DDF5ACBAAD7D1C49C0736D455C31CAA214DFC45FB85BFF21CCF514C2241DB
                                  SHA-512:28076A31137B9DB86EF9F1D60BF01A97209115357C0DD2937C9F5395CF9ED398738D564A8AD3F4AA4F3AE968FD4E4A78658CF61CA3065958AF3D6FD892931BF5
                                  Malicious:false
                                  Preview: .pthk..........._L..64yr...........U^D........Y.....>#..................<7.....t}....TC....7t....XG........fQrh..........XXZ..........HU....ly..................7......k..84..?$xu....v[h..EE....o|..`q)2/(0:J.....|!2......FL..::.........................QN....dC...?~xII........?x..49YI.........................AHnl............:1+8]_yh`{^Y0:7..U{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\425__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.363456457323231
                                  Encrypted:false
                                  SSDEEP:24:ALRD2iPAZdSA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRak+rpjBBpFUBQ+JgW57:ALt2DTcAd4M9/xJfAXxuU+3BpFUBvfp
                                  MD5:58DDD17048EAD5C46B7BE8D937F018A2
                                  SHA1:1FCCA86BE30E440F290568670D301FA605689D0A
                                  SHA-256:FBDFEDD4DC6876AE82EC5200F3CF9E2EE1C6E2E908CDD9E81056F8833BDC170F
                                  SHA-512:4996AC2B103EC6A4F26969CC1C35562215429643BDFBBD30FE6DBB815C559E2B79B560CE7C5DADB340F38E40F331927E3F468D4E2B8D155BDA9E4DA377CDFAA6
                                  Malicious:false
                                  Preview: T.<......Y....KJGX}b|n.......J.......,..XW]XOL..<#xd........+v"?&9z`........:.#.......B@..4/.......+J..|Z......P{US..4e......\@6=M^FD.........^W.J.i...PUK......&$W......I[..!Lzm..ye.xuu33==q...}n)>....YD.bo{n..eDfC;.%/..nN\U..CN........uu...GV...Nxt...u..(2zrhF....Sp~x.....fd............r$.............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\426__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.343210249199295
                                  Encrypted:false
                                  SSDEEP:24:t9uVtyP9JbHBs3fRJU9sV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRB0XcsBBpFU+:tktyTOfRJU9BAd4M9/xJfAXxulhBpFU+
                                  MD5:EC2271913701E88F1DF6907BD81558DB
                                  SHA1:7B785B0A94650E3ACBE99C6C815378EB71AD94CB
                                  SHA-256:B0E0057D57A733789327410C4A1281BFBF2F143488F484471AA84C3820CEBF69
                                  SHA-512:67E9B2392E8D0D2227BDDB0C67692C48B19D3CE3C251F99588558D753036FE3BA8198286CE31E1B220B180EF79AC752142B109054312E1F420630610D9B1886B
                                  Malicious:false
                                  Preview: .\X............FYJ................LYCA.................qG...V.................AA]...................86$8.....................]............_...................wp.sE..N9..<#.CPGbs8$....tt...Mt}uf....}gJW......*5^.lI.......5foMT...|O..44cc......2-......N+..2(..Jd.............NLER..E.k &<..T_(~T.wb......{*Z\..S.`o..Mg....~by5........!;XE..).++{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\427__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.787219128865055
                                  Encrypted:false
                                  SSDEEP:24:JeSoNiRIG84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+FlUzfXF2tDFvy8Bp+JgW5A:QH7Ad4M9/xJfAXxulq158B0f4T
                                  MD5:935F40C77822145B3639678583D4F65F
                                  SHA1:76981A10E7569927F2E8F126DBE28E84F4715302
                                  SHA-256:917235167C1AAC738259F99278F6D8C588C97F83E6E8E6045672C8945EB77926
                                  SHA-512:0228328AF4BEB288C562DC0412DA70BD1D79F866B692707EA60CFD584CC6B8320588E9D35FBCF7249600E8C7E6343604E579858D4497BD0C1B7E74E5E58636A7
                                  Malicious:false
                                  Preview: 8lhc`$1L.VE..:<....9'.....|q) .......&urg.......}&9/...-..$2...xa......v.#(......ngtg.......<.(%PE....<%....y~GN..61............8%N.....xg................I.4=.=......U.%(....tl......WN|/..5,.*3.....3exz......%9..,,oo..88...............M@.;...i`..fk..At....tB""..\H..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..<..V.L.......}{.}{568}{000052000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\428__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.690660511477379
                                  Encrypted:false
                                  SSDEEP:24:ogoZLLb4nXCjCF5FP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhcoUzfXF2tDFvyJ:ogoZLXcXCjCF5GAd4M9/xJfAXxuV158W
                                  MD5:6F0760ABD90E0FE5CB54536FFC085A14
                                  SHA1:DF0417D8513208EB02FBEC5CD93B473E2E889114
                                  SHA-256:22B2E98DAEC53C69610047D0CDAEB944CAD5EBE7CD26EB4286A57A2CC034790F
                                  SHA-512:AECE9F5B3022886345C1A64B4DC34A1A9EBA0DC9A095E91F3D78A7F8FD2DFD238DDBF25D0887CB06ADCCA70FA2C808768394EFC784DD5880873CC56876EB723D
                                  Malicious:false
                                  Preview: ...MN..,`]N2360^.......t.AMux.........\.....kf......SN..{M.................P..NN.2;..9.....sn..R_..5*....G[..PPNNy&......PGnt..3p....KT.................Y.5<yj.."5....A...k~oppE......**-*........^^\\.........h..: wj............XRys.kos52........77.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..e.F..i[.(.....}{.}{521}{000052000050000056000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\429__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.709989503049863
                                  Encrypted:false
                                  SSDEEP:24:X8rKfgW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRI5l/VUzfXF2tDFvyv2+JgW59:XqWQAd4M9/xJfAXxurHs15vRfj
                                  MD5:31D5F9AEE0A6A9B3FA0D6DA0A1D5E92A
                                  SHA1:45F97D5684B2472C7783882447845E16E66A8A06
                                  SHA-256:5CA0E396633A1304E7AAD85C83FAA12BC2F0D4B2752B95D8924D3665E0BBED74
                                  SHA-512:6A5723E247EC4200A18B657323E5F13C41A14E07D2BDEA5B0987B21E7350D561803BF20354BFC6EFBC5C77609381CE0AA38C0559CC86E54FF3D7B69B6E93A46D
                                  Malicious:false
                                  Preview: .IM #..H.O\Z[......6(..!*tx........nt.?*rx..hi.`; 6........:g75........NG.......X..cpREtc7-kvY.....ls....a}ur++..L./&....pgqka|......gAUU......oh....55..#*....pg/5TI._....6)..eDfb........fzIN....dd...QCJ..3$..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{{.|.."..(.3.LDK$}{.}{436}{000052000050000057000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\42__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1272
                                  Entropy (8bit):7.430811453908062
                                  Encrypted:false
                                  SSDEEP:24:VlG7nn+JLSDnb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYA3BBpFUBQ+JgW5N:Sne2LgAd4M9/xJfAXxuliBpFUBvfP
                                  MD5:430395C4E15D67168682A013720A7E49
                                  SHA1:DCB39277A5932C42CF29ABAE961B5A69B53E6313
                                  SHA-256:8AA807EA4666F402299C7349D29AC833DD23DED78059DBBAE041B0B6BA1CB969
                                  SHA-512:BCE67F7E9B41668CE458F34E5C3F3A9127AA28EC1F977A2B381631B39EC4BED98725893BEE489E5CB0BE1B6531271E13DAC5CA129A8538EC98102438E6E6B182
                                  Malicious:false
                                  Preview: ....{<..T...JP67.......EH..g`r(.K~l5 .}.......YF........}l............<0Pc..os..IZ..~o....28...M...r`kM............_......../$....-<MVni..d0...I.vdJ/..3M.f.......[-.M..??..fk..Q#.........XS.........v|.NG..B$..~]GAkd..Bd]]..wd....@@TT....B...W...S[....[Z?.XQKi+-.......(yu..D..........U.....lk........EPSL.............ff.....t_Ly{O^....<6?..3....dxdu..I....L/......V.).{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\430__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1316
                                  Entropy (8bit):7.440206869119337
                                  Encrypted:false
                                  SSDEEP:24:5zX0HcYgp81/8xylaSnaG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTQYBBpFUBQA:5bEgC/q2aUYAd4M9/xJfAXxuYQQBpFUj
                                  MD5:140394642E8B1A5EB8A675D912FC3A7A
                                  SHA1:521C68ACE91894BFB533B77DD554752C4C212BCD
                                  SHA-256:C8BDFAA841769ACEEC19B523E849A2690FF26E5CF3464A6F5A202BE77C24B85D
                                  SHA-512:25A1EF64A8C80088156E5389ABB33D8C86B1DE82669B518BF97FA2E2D7939E34B08FA393457B7109116B667B2A25463950D77D3FB5C08478CC973B84904A1038
                                  Malicious:false
                                  Preview: ..M...2d..rh....LS3!........G..vd+>.......vu....RNr#.....XQ@.L.........!">2....7<}n......PW....6?.M6W....kk..6%%.....M~....,0..ve....}f<;...<5.'d................i}.......-:........uu//.S......,;.....%(.......%..ZP.....BO...#.jj....;'`q..t:.."zu...HR*"......aB..jp..........:q..$3+ ..YC............q|..1."%....PR..kl.....M^....\^}l....T^kX....vv......I....cx*2qM.O}+.#..............ga......8...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\431__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.24423149658632
                                  Encrypted:false
                                  SSDEEP:24:StVm0484tFoze4ytP6qfHSgC0fNSZBzfteJTQRXgkMJ+JgW5z:StV1JAd4M9/xJfAXxu8gkMUft
                                  MD5:CC6C3107EE59BA5CC024E7A150683663
                                  SHA1:8B9E2262314B835E4ECC2252DD44F98AC12D92AC
                                  SHA-256:FA9C1CAA173453E19D4ADCE6FAC66B3833ACFB27691ECA0B1C890135D3577170
                                  SHA-512:2D60DECF92678A7F77DF62CB5C7ACF065AF2EF101AFB3C2FF226A08BA4961F66C7A1AB3AD9364B9F248167495FF01BAF60D1BC0C6EF3A38AA4561FEAF367E8F1
                                  Malicious:false
                                  Preview: .gc..i|H.jy..NH...@^..AJ..bo....ih..\F&u.........y""4.....#..} ...vlRT..GN....00..^W....J]..dy..obVC]BdC..xgd2......,0.....]Q..s..WYBC..%2..y!{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{7.ln`..HT\.....d}{.}{297}{000052000051000049000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\432__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.353594300199803
                                  Encrypted:false
                                  SSDEEP:24:ru42nCAXfhx3MU+Kg8IXZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRDHz6BBpFUBv:jhAJx86yXKAd4M9/xJfAXxuuWBpFUBv3
                                  MD5:148C8F3E463188A7F8BC5E262E42A637
                                  SHA1:2B4345C069C052874B1E77F06E63731EA037B544
                                  SHA-256:286B3A6D40EF8FABBE4169C84B69C511056BBEE1F39131F218B28FC408781707
                                  SHA-512:6F4BBA72D5D24F5A417656A6940E5A9AB47A884415E9F672682E37B4D3C0E790F09D1124BB096E74068975C70FC94330D449170A6352A2AE44C1796333ED48A2
                                  Malicious:false
                                  Preview: .A.I;|..9oER~d......cq.X....U.~)N\rg.......~}....xd...52$o......="IS45ho...S`..LP0;../-......flq%PYQ..}..tR..E\..T.....8i..............!0......kb....DMd%..'\.....v.._UY..#..0GL^..L!..?.....hh..FF..............^85..(7hI.."7GM&)........t$...;..vv446*..hw*d_S..a..[A..U{.......G]..zr..DShq>f......FM_......pyT..[..qv-hVY`S.......N.....ds....N...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\433__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1218
                                  Entropy (8bit):7.334541519907762
                                  Encrypted:false
                                  SSDEEP:24:l2qIihmPsDPy+A6d84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIBBpFUBQ+JgW5x:lUsTTOAd4M9/xJfAXxu7BpFUBvfj
                                  MD5:EDB50120C8A6E4639A719C1D74BE3A8A
                                  SHA1:EF254F4EB0B4EC5F380FC81E1EA463D3CACCD959
                                  SHA-256:C0B11732DB4C742AE29F3EF6AAB52FDF6F8D45388798092C9B7F4F12F9C9F66B
                                  SHA-512:8ED69AF808CD88D9F073E10A900A29AC7BBA360B2C52F6D2DDA2A1901C80D043AFB6EBD55F8916BCF10BAE255340F28C163B6E433860B9793BF79F706E3AFD4E
                                  Malicious:false
                                  Preview: .D.d.iKJ2d.........ug....oh.~)+9~k....)&-(.............vg.&;$;CY......$(O|{Qb~<76%..CR....{qO.>7...&4........Do....o>...8..=!............dn.09r*2]VLK8='..Q0wc........a......1.....#1...a..N_..z}88.....C........)3pm.B........:....hgTt.....!q[h..............>2.;^..+1....{{..Mn........xz.h....%n.. 7...[...`u...^{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\434__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.801403548313321
                                  Encrypted:false
                                  SSDEEP:24:gn2oZPX2c84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjPHqUzfXF2tDFvy8Bp+JgWF:g2oZf2dAd4M9/xJfAXxucvl158B0fF
                                  MD5:856C868BA8FCCCCA58822520C2901F96
                                  SHA1:7C5B98E0A1F03C170E0ED93AD31907FA22E360CA
                                  SHA-256:8EFE2B6E4C4066089668E0EE2D4F64CDB72CCE18ED9B0950CC263A4F138D6E92
                                  SHA-512:A29123FB509FD2018798A3C6CFD5264ABBCF085C5890025AD295D77E3A39CA99F555B5ACC7A771991E233FB206833C4636A317BD6EEFBD090C184079F7ED5696
                                  Malicious:false
                                  Preview: T...................w29483>9........IK.............A\]ni_...F.....JPVWPW^].......[PYJY[L].......2;.vi.9$........3vjY^t.............W].!(......`qH.wD............eg..wl..)#.fo....[s!..I........rwY.......=i r~...........@@.....ARIK>/qj..T^...........$="1|....+wI........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...r..1..q..Z}{.}{570}{00005200
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\435__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.676572532773965
                                  Encrypted:false
                                  SSDEEP:24:HkmErxow5r+GK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQUzfXF2tDFvy8BXCL+V:HkdZNAd4M9/xJfAXxuI158B5ft
                                  MD5:8D2F4541F83242B3D13F204176FBD226
                                  SHA1:60DA211843CE171A982D90B1B56106670F0B5FA8
                                  SHA-256:987E3E3657B0C54688A05657B57C6CB6D439BEB3239A4ABE68ADE8C18FFE964D
                                  SHA-512:9D20A428BC6E9362213D66D14C11E5D966878C099E7960B0D1F135AF660BC98BD0258F52B22409F835B2921079583C156477B4857CF83C35F9DA020CDD4FFA86
                                  Malicious:false
                                  Preview: C.R..........SR......D.6;....h2..3!.j..VQ..Y\.._T..RN......E..m0ti...NO..`cNB.$........XZ.....MG....p(.....fUHb}}..w|..NL.._D....M.szW..}....49...."dd..LP........ir70......vt...F|..n......yJCi....55..<7..~|..sh...\...?g06.}....dilg.:,...__..||lpgvuj.ZV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Yj.^4/b..T..<..}{.}{522}{00005200005100005300009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\436__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.722381138921682
                                  Encrypted:false
                                  SSDEEP:24:rVFxl1i/Rbv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRI2sccsUzfXF2tDFvyv2+o:rr1IdkAd4M9/xJfAXxuSG15vRfQ
                                  MD5:B055B3B65E4D69845FA4EA1851E8FA9E
                                  SHA1:624106609039EFABD33C26552C0DAAC27919B8B3
                                  SHA-256:574C9693E03C90EDE94C0D9B1A6EA4EE91EEB7561B67313C3A21FF5A541697A3
                                  SHA-512:00E8287E54071F54B77C9C43BF6622E6EEC9EEC03C52F168E6D0B7E9E22423A1215083AB3D566ABA96DF2C75A4EEED2CCEBE096DC8CCDF7AAD138E5B7D72C463
                                  Malicious:false
                                  Preview: .P.d.......IS....=/.Z...x..K...............P[....P.<=..D....A..YF..........4...DO..PR.....5?0d..k3....o.PcJ`..@\..$7......be..r&T]..........Ev....PPui..........jm..8l..d<......$.<-.....T~**..||.........CXx.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Y...........\Z.}{.}{438}{00005200005100005400009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\437__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1525
                                  Entropy (8bit):7.525070744124302
                                  Encrypted:false
                                  SSDEEP:24:BnR2xONKJCRXOM45UyprXOhu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRV/EBBpFB:1R2xGeMKUWXOhDAd4M9/xJfAXxugsBp/
                                  MD5:72140614B51AE4B6E4D17E54F5564730
                                  SHA1:1DF34781F2D199DD89CC5A32C907EAE41BC8DE56
                                  SHA-256:65D74A5E38FBF48BBCF448972494206250D600759590A7F2C1307BE7BF88DDE0
                                  SHA-512:6533691EE723BB98728000188F008ECA8049C36492646DE021385DDC90C5820003E6BAF88C3F7A1F87465541E4476E0F849C2FDBB97867ADFDC4B6F9279BF057
                                  Malicious:false
                                  Preview: ...%..*+}+....HI..)6xj~;..0;!&..........yve`..........16.ZK............{wm^....HC..y{....JM.._..../N........... ....(y......hc3 ....F]..ka.T...CN:...........*0..!@..^T.8.......uj......(/zz.....18......xb/2%fux......Z......Cc....TY..........MM..........57..{s..==..fE42XB-.....ds.....=,....pr...-8xm.."z......@...&.Bh~~...cg+.............G......RRc/->.............Qp..yn..g?......`u..sfslDCD_3:..ix..dd..........?7^A....|~$3..Z........d.BZ*M2v..!4....=;PW`%......}}....8)............p7.DR_-=..)0.........#........qxPRM\wp...........................1`....dt....pp..m;.....s#j1.I..#6..}*...15..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\438__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1411
                                  Entropy (8bit):6.661229995752491
                                  Encrypted:false
                                  SSDEEP:24:W6Cx2bxQfJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcUzfXF2tA63yrb+JgW5E:WVx8xQf6Ad4M9/xJfAXxu41EY6f+
                                  MD5:DDB2F74E2F55FDC549CD1821058714D8
                                  SHA1:31C4AA21DBF60BA178E504AE2E752B09A00C1B7A
                                  SHA-256:DE297A96E253AFEA6A3D03DDA70064202C6FB2882D182F17855AC70A339A483F
                                  SHA-512:6EEE8409BF1A16BCF27E6F7CBB16453258DFE063734AED43E45D7B6B024E36BB388A40C3C2DD85980DFD32287BC45E555A8BD8C0264CC0C5F49D7EB5BD6A48CE
                                  Malicious:false
                                  Preview: 7..............WN]....;7......jk..A[.bw.u....T........7Aw...;9........YP<7...qq.....PG....ex........P^LY..ur^^QQD..v....reZ@`}.\..;.....gg..........]]l3...dsqfou.....PE...5....K}..qv..< ..GG....;;..~w......<&......u`NQ......xr.........##II((....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{;...(...i....}{.}{513}{0000520000510000560000950000950000670
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\439__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1395
                                  Entropy (8bit):6.79507169760561
                                  Encrypted:false
                                  SSDEEP:24:v7xsvozxLR4xok84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZA/VUzfXF2tDFvy8Bx:v1svoUKFAd4M9/xJfAXxuCAs158B0fe
                                  MD5:26735E3ECD4256A88C339D07B2959B0F
                                  SHA1:6ED1FE27C4963FCAD757B34B051448995FD96D14
                                  SHA-256:EB099270A4141DE8BA0A047310A9698E4604A73AF30490DEB6D381779B7825FF
                                  SHA-512:D865F4DA1BB3C99B7343DE42CCD0641B8E06898AA59EF3772CC8BDBE060BDF63C0E048F7E6CB819EF85FE096638F2117F11BEE46168C6AC8D99283D0A2681CC0
                                  Malicious:false
                                  Preview: .RV..K^...ut~x.EV..qsp{..]P......<w..............h~= .....l1CA..Z@..#$..)"p-....~!U\..FQ....K._RzoEZ7.......JMPY..-*..%%..}t........#`_R..)6....>9..70....c<6?..gp-:.....6;1$....../Q.........%<m:......T..^\PH5))...............tcuo...\.......;2....c>.?.".............PF{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{h.z.....%W<...}{.}{576}{00005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\43__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1783
                                  Entropy (8bit):7.624475207260482
                                  Encrypted:false
                                  SSDEEP:48:y8QKydv/+113OanKsVF4wCC1K0Ad4M9/xJfAXxuiBpFUBvfn:yXd/W9nKe1XipBAXQOO
                                  MD5:BB5A548971FB1D8234B79D1AD9774DA9
                                  SHA1:6DD4244A81DA9A9432726076ECC368F091DF5814
                                  SHA-256:CA31FD2C2F6EF55F80D3D0180914FB13CFC9B5710D881D40B0A382120127D3F5
                                  SHA-512:938D280E6040FD79FAB9EEC9632A2632E7BF4F2E8A3FC502BCF86C416C9A31F4162DC87344CC3EB12B3E5F64CE5D821F95DC8455C7FCB6EA6C7CC06609892267
                                  Malicious:false
                                  Preview: J.m.6qMLg1>)..}|5*/0..C........{iRG@B..P_pu..ja|c..(y.~..h#....RO..XB..<;........]A..(;(*HY....$..Z....?^'5F`......U~....{**.dN........ud....d0..L.U8.=....-G..-#..X....TT....H!...VehB......od.................ZI........jLkk..n}..VV..AA..........................2..Hr..3t.....*5uo......C.....<5.P.z|DC.Puz....qq..}a3.....}j..uo..z'..##00LL1}..D.....%:..NX%/.......=e........JGPE0/..lw....yh.........l!..pxd{..rb..........HM............/:..ta..70..CJ......mmKKQQ'k...I+$..SL....BW~|..e|x .......2'....D.k:....e ('#.Hb..........?q....iQV....3...^]......5m)8..I.........ru.......}(J.ol..04.B..pe....................*6n"185&7 ...............DM.._H..6,pm{8p}..`.8%....( ....ey9}\j..W ..<#$IynBS....66gg...@..FU;,..(2<!..zw 5..[z........Tt..LUGJ`0L..3..rr||.23".....+s........wY......ce..0...31....F..]O....YL'2...4e|z(/c&....cI..))..E.ZSev,;..tn...' %%..??^...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\440__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:DOS executable (COM, 0x8C-variant)
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.704728299660574
                                  Encrypted:false
                                  SSDEEP:24:pL4NQhAvXQz2sz84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtHPUzfXF2tDFvy8BXC:QoAPQys4Ad4M9/xJfAXxuv158B5fI
                                  MD5:E6D001F54E771813886777DBD443DE87
                                  SHA1:4117F18E1D75B0A166828A4455561EFC355CB8A3
                                  SHA-256:921B148C0519A60C114CD1DE7D124815F784D9B4682D5A849D96B434EA1CA56E
                                  SHA-512:B6F7BD9672160E4836F52934DDF04C21EF57C0B4B798C02992DEDA0C00E48605E70734373D5041129450CE744FF39466F40068D181B7702BC6C212E7979314BD
                                  Malicious:false
                                  Preview: ....{nc/yj..pv......y{dobnS^.....]^D....* ......!7....Rd.............SZP[Q.?8...U.....QF.........H]....ii99S..............m....*5.$....'4..16..}}...T....bu$3......7:.. ?..........FA...EB..qq@@...... 3........[.....8'..tt....s.B^16.......H.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{,.!.C...V....B.}{.}{525}{0000520000520000480000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\441__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.694106746235878
                                  Encrypted:false
                                  SSDEEP:24:bpOJuvWaL2ExHGzia884tFoze4ytP6qfHSgC0fNSZBzfteJTQRF4UzfXF2tDFvyd:bpOEvWaCExHGzia9Ad4M9/xJfAXxuCjJ
                                  MD5:68D01C9B1E5E71E65F7A3F2A7F3F46AB
                                  SHA1:A89655853276F96EE90D858EF597844114C9367C
                                  SHA-256:657AB01B3A46D148D71E4BFBD78961FB3A72CCEE45C3CCFF649A00F7AA572485
                                  SHA-512:27F9F0F77AC6A49A4EF2D2193EBC587C52117EFFE4FB617E45479398CDC3395B02C3D479F2DAC6B9ECFAC9822F3EF44264DB7FDE49F7CC5B4C1AF28586B2C77A
                                  Malicious:false
                                  Preview: P....>+N.....35...tj`bQZ....cj...g,........,-...^.. =uFZl..............zs.t..........ynqf....U.~s....ao..HT..//..Z....._HYN............Hn..................) O\0'..{a..O.....NQAt0.....MMoh..:&.......55h7..qb..>)..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...".2..:4.3.7.}{.}{436}{000052000052000049000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\442__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1658
                                  Entropy (8bit):7.575686140101034
                                  Encrypted:false
                                  SSDEEP:48:ZXeAkEf9NvQGu+6Ad4M9/xJfAXxuxBpFUBvfd:JVFNoGrpBAXQjA
                                  MD5:1663DF126B91433B523B56384068FB01
                                  SHA1:3D23915D241C2EAD84A227720231ECC876283553
                                  SHA-256:873ABA9AF810E3149391FD0698859D692B0BDC351A7531C0DA0FB6E2F62543F7
                                  SHA-512:F4E56613E337AB968E6B0F3B97C1341C5956D00E2632B31F57E012DF3378034C98E7CAB372D43F301FAD31B9E5270F766DB0B38AEC8E355DEDF26A7A4320D593
                                  Malicious:false
                                  Preview: j....>r..YX_Y.o|..pr.................T..#) -yx.F{ ..ql.+....t)EGE\;!..,+..... '88....IZ....NT6+.Q<1.....fz..rk.............{{...q.. 3@WYN..= .\QWB..rP..oh..........dR........i...%4G[..00xx....$-N]....4....IDdqwh.:....{q@O..[R..GJ=m...............yu1i>[(*`z`h^p..H^kH..bM*"HJ]J...........u)......(=....,3..HS....j{..GGgg..}n....,.4%..25SY......mm.......`l.S..XCBZ.C..k=..2"..VEZ........R.U.._X5p69iZ..........{dW.............!1......y~?,... 7.....J.......[.VP..f#..&.............B.....C(.....Kl:*'DT'8..............9&......|~.....--..p<..5x..MERM......AW..zm....p...BXBW..m)..3&...U......J.....>..[[.........d<....-;Rg..DG022%cz..7&......OP....VOZ]..............,...No+J_%0..~&[.....e ....%.....soet.......n...fZ....l:~s}mb}$...cd..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\443__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1310
                                  Entropy (8bit):7.433571104187793
                                  Encrypted:false
                                  SSDEEP:24:tJ57maaeOGGLdk/FbYbP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRplBBpFUBQ+Jp:tnxVJzhXAd4M9/xJfAXxueBpFUBvfv
                                  MD5:66A908B3434712AF5130246BF658E045
                                  SHA1:37A3434C163066124D5F9162E34F08748164694C
                                  SHA-256:F579C34E75F027C1363F00169B2535CE8F7169D45975E22D66480E8DCD64D511
                                  SHA-512:1171F2F700B887E167A2FD37C58EE7E1C39C993D7369F8CC7C056E67EE209564E5EA59E3FFB6FD87CE75F6B577C306E54A4BCB851DE68AC9FBB3A661AF9A9E4C
                                  Malicious:false
                                  Preview: A.K..[......jp....KT..l).............~|x............-|..eb....B....cy........+..........}}lE^..7=...q)-LJXnH....H[....1=K.tG....b~p{........ZP..`i'.&K.....]H3;*...c4m........?V..1C7........ODyjik....QV../{.....l..X{/)..]{..nw........zzzz...Q7$.V..fn%:ZM...8\U.&`f..Mr...9.........VI......1 ....yl.....IN..4=...n..%%......*!....4%|g.....v\......j{TK..zv9a.....Dx.C...HXrm...PBW..JC......L0?.._uHH..kw....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\444__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.360809456565973
                                  Encrypted:false
                                  SSDEEP:24:9B6fsHq3+Aen0GlQaG84tFoze4ytP6qfHSgC0fNSZBzfteJTQROBBpFUBQ+JgW5I:Ofuq3sQYAd4M9/xJfAXxuBBpFUBvfS
                                  MD5:FE489C54DEA7D62BDA2260C577B33EBC
                                  SHA1:14307D532BD522F7721E56A5BBC5EA9B9F8E8BE5
                                  SHA-256:59B3FB2A382AC03A48F9C9754FDF25B06D0AA97A0112D8D2758AB0766547F6D1
                                  SHA-512:B5F0E76786F949D62ACEBCF70D9697DEAE3C08875B93554AA1ADC31798D1792B8A909FD5E266F86B9FE34CDB6FA8E8AABD122872973A69D0B9974A0564546180
                                  Malicious:false
                                  Preview: .VR....v:l.hi../|cpoq..29483>.................ZE.........0&g:gexa&<~xy~yp..A./(...Y......ds{af{q2v{sf>!@N................^BFAkkkk.......0'rhorx;.......18........kHYQV.!.dp|...MRy.}j|m..........m290.............r{n........pzJE......R_.XDw....KKKKPLQ@...)%...........7....lO& '=..<4.......#lnwz`$1}!j|................;2......22WW.........rc.......+.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\445__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.8066037387336555
                                  Encrypted:false
                                  SSDEEP:24:/qPPHwwf1VBdl84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/vUzfXF2tDFvy8Bp+JT:CnFb+Ad4M9/xJfAXxul158B0fF
                                  MD5:95A96FB43B23F41274806A72744650DB
                                  SHA1:A6875E07731C441AA79ED8C8970E955AEBA73115
                                  SHA-256:FFFFC6671BE6012CC0261090332C75CD7336AC98217996535F08A2A44067C3B8
                                  SHA-512:365D068FC653ECDD951678183086DECC0E02F932458908BDC4C56F57E050D661CFF585C2242EA0604397F6D77FDA167EF4252C02F8F71564DD1E0EF2E264B3BE
                                  Malicious:false
                                  Preview: ...\..^.DS..ih)6UJ..........S.P......\[..DA..CHju8$....:=l'...........KL.....u_..bi..02..; MJAK_.....j...rmA[sr.)..%T~;;eyU^bqnl.?!:ebnd....h0........).3RR....w|........C.cjv..F.....6go$.*..Y.......JT...~,....._~!&..!..kk||EYDO..PR....XR....@... jj..izv......-....*#.GW[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{,.A?xJ.^....6.Wy}{.}{570}{00005200
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\446__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7261648251171
                                  Encrypted:false
                                  SSDEEP:24:tarx5nlUXdLWXJG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxcVcsUzfXF2tDFvye:t6lYYXRAd4M9/xJfAXxuXVG158B5ft
                                  MD5:6CC8D982FBAF856652C6FC1716F6F4A2
                                  SHA1:6169F3AF5720663705A992567991E967B7842B96
                                  SHA-256:28F039038A04DACBEB4D59AC5CFD7DB81F5681F447C0A4C019AB861769AF3AB6
                                  SHA-512:300C7028821815763955B5EF685777FCF6D4B2E8D74525748A14C11B97D6F1352CF0C261A70F69C616D9F8C9AC4F897A02A633EDFADE8C8953FCD0118E6E1FC6
                                  Malicious:false
                                  Preview: W.?.#d..v ..xb.........S........#tR@/:..............MQ..... k.....KTa{kj' vu....5....XK..*;........u|Z...eud.(...<<......pr....61.........<5*3..N...............sq..........ng/w.e..........................`s...................jg...~T....ooddyeRC..l"W[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{n.j.[.... ....}{.}{522}{00005200005200005400009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\447__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.730641896127227
                                  Encrypted:false
                                  SSDEEP:24:GMkFz0hWfEpvNe84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzGIUzfXF2tDFvyv2+o:7kFziWcjzAd4M9/xJfAXxugGz15vRfQ
                                  MD5:00301AF0C5DCE3F4DFE03437C1BB8051
                                  SHA1:9F860A41296936493E83C63B2FAB032739D89F65
                                  SHA-256:E961F5456F5360D71275C5B639EF3E03C441C2C6C19FF2AC9A50701F8B12F366
                                  SHA-512:9457D016D1585AF13D256817F0BA5D6F30DCC67A4B0D489D3864E9AB38C9B8BD5B6D9A1B0134D04A3A85DA8A9D8BB4013BABB6F03C4441A69F0D2DFB3D159E31
                                  Malicious:false
                                  Preview: N...n):;$r,;....VI.....L...../u...oz......kn.......2;j..pw.V..f;................w]..mf....{j..OHgm.....B.8(G#...8..B^.%..!#..RI..~t(|MD}%H)md..........qq..?#..h{.....g`AK....|$....]g..J[it..U.H{'.??||............AF{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.@.6.un*1..*t..}{.}{439}{00005200005200005500009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\448__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1994
                                  Entropy (8bit):7.649702130190736
                                  Encrypted:false
                                  SSDEEP:48:6sBggho7DhRk0xRI5SBTtGEn9EAd4M9/xJfAXxuziBpFUBvfr:ZOBRk0xRES9/RpBAXQSS
                                  MD5:59E836DF4FE09C11B93B92BA42293F56
                                  SHA1:AB149FF55735EC48E0DFB1D91BDC4563E3D6BA47
                                  SHA-256:446C0B99E29300FBEDD839E0238874BE862D5AAE6F4CB321F73C5E8C5B1188C7
                                  SHA-512:0C36570978D106733122E88B43308ABE136EBC5C94D85547826C2B55FE24871755BD310CD71DA45149CC0DD7DFC0C7161E597DC6C16F8ABD6E47A060E4D82629
                                  Malicious:false
                                  Preview: ........O\......XK7)..aj............P.ly.......N..YO?"....>(.L........TS..YR..34...]"+...9......#`..4+..VJPY.............(/..##..AH......JW.JG:/..;"......`...yh.. V\.....;6.....(..##............LW..W]j>..(p......%#..Jl..|eTG......RR....DW.mb.............]..MM.%..9......!,....hj.fmTS.....PR.....U@..pw..GN..............)"..,.......)#....))..)5ET......O....Vj.#u..\L........_J..[.h9..$#....J`....)5..{d.[..........P@..b`..FM............J_>3..po......b`....))..)).E..............U@..ub..L.........Z.._J3:.o>.....`o....))..)5ET......O....JW.#u..\L........P[..Z_>+..=(.......'........))...............WU..fD..\Y............~..`|......#x....1$..o8V.......PR.....U@..pw..GN.............N+8.#,....%2..+)..e|P...........DQ..f>..][........4.......I@2!BU....UH...DD33X.90\O]JK\\F..n-..........EL......o............m`..OY.t....88.....H[....=&.......0h........fl!...KR....X_.......U.......^A......?6.*....:...$.....Oxu....ck..+"aw-s.........
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\449__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.275415769705372
                                  Encrypted:false
                                  SSDEEP:24:REKw8T8L84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkN/+gkMJ+JgW5z:REKw4Ad4M9/xJfAXxuzNGgkMUft
                                  MD5:78C2901D1AFDACC3F36BFE98390922D8
                                  SHA1:D4D7B8786E44E33434FE448C859F1675601BEC3E
                                  SHA-256:14D89200B6AD06B0421358F19C58E4C9B2B560160AFF6CEEAD537E799F069BFD
                                  SHA-512:40A70FACB4856E77BAAF9D05F4B653CDB52D9F3739A57BC07EAAE7102C7DCAEEE30CD10F769B7E249EF8EE90A18D34E650F835B92E8B3D101837FA202CEA30A0
                                  Malicious:false
                                  Preview: N......9uBQ..........sx.......ml.K........diXY...nx..Yj......_]..[AOIjm....8eKL........ER......3p..%0..nIy^....bQ2.&&..ZK..t:...E.....76vt!6..~&{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{jU.e.k..j......}{.}{297}{000052000052000057000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\44__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.8016705703668014
                                  Encrypted:false
                                  SSDEEP:24:xgs56vSCtT8W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhUzfXF2tDFvy8Bp+JgWK:uswvSCTAAd4M9/xJfAXxuT158B0f4T
                                  MD5:AE67DDE8603C51C7A96021A6A40AE5A0
                                  SHA1:323DADA1ECF0A44DD2D2BA1BAA0038B46CE58157
                                  SHA-256:A1C927C68663B9ABCF77465444DBB2295EA1D2A99018A485C6B3310699C040DE
                                  SHA-512:E84E8D107ADB35A15982E15AB8A6A1EF3D705675AC625DA24BF40D03F283CCA27807335BD93A871A08DFCAE9056C812D91E2397425C6EFD32DF3A7A530C8B5B7
                                  Malicious:false
                                  Preview: k?;)*.............ikCHEI..w~_@...9#[..........[M2/..........................//m2...............<)qnkI.................JAH..,;...."?..s~wb....%3"%...........~wdw..1&....I.NC$1iv...BCG...H.!(=$...J...(<.AC.Ew/QSNV..........//.KBQBqf......2q.....o..1(HE.Y........VV..k...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{........2>.S.]..}{.}{569}{000052000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\450__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.379091989128021
                                  Encrypted:false
                                  SSDEEP:24:MDVY/GTfKof84tFoze4ytP6qfHSgC0fNSZBzfteJTQR12kUdBBpFUBQ+JgW5n:M++TqAd4M9/xJfAXxu75BpFUBvfF
                                  MD5:FF4C35BF4B93306C2956AECA457E4622
                                  SHA1:3A38DF660F5D28AA6E8742F856E9E79A691C2830
                                  SHA-256:5CA090E471806923DA5BF3DE9A03C3C9D5DB92CA84D08BC1ED6EC702C65BE52C
                                  SHA-512:8023CDAA6F29ECBF5736E9A1448CEEB1B036A6E95FA30B14513F802AE2B28B4C4527AF5F73DC521F3DE1446937AA320FD465523E93E0554C4B9B6DAED616C3EF
                                  Malicious:false
                                  Preview: ,x..........YX.......\,!...+q..................D[......in....R..po6,..z}....=.....xs............k.R@....ax..#%<0....5.DD..',3 "..8#....!uDMD...h`....$,Y.H~lx:M....m....n....EE.....^W..tcpg....$g..........j.)#XWyY}t#:q|.V(...mm..&&..teKT.F....]_|f...(..........{T....er.......vaRY{-#g..PE..$|s"..tsw20?..)){{..[.....VA..kqUH-p..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\451__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1519
                                  Entropy (8bit):7.530719687631722
                                  Encrypted:false
                                  SSDEEP:24:V9bFHc5N27FCEqY4f6LjDIzJAOB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRhgCKs:d8b27FloTSAd4M9/xJfAXxu3CxBpFUBq
                                  MD5:E3F922CECD3FAA7B210E42264F224BDA
                                  SHA1:1061666AAF06A64E2FDB136DFEE986C0A7129756
                                  SHA-256:247CD4D9FB21DCE2178931862903154D445AFEB09BBA7810CC979B173501A29B
                                  SHA-512:78E10CC7BD077677DD56FCE6A71FB22E99F0108B258A28ED5EEE49D42A3B325A2C7027B206D4BC67A302FA44AA16B6BB9FB35216065CA0FDEF67A59094814DD2
                                  Malicious:false
                                  Preview: ..8.|;yx..'0>$...6)..{>../$WPH....ZOSQ..&)........jv..GFIN...T........mj*).. .......L_VT..ot..MG..I@$|W6VD..............CpEo.....H[...."9........o.....&A.q..?SQ^.............n...Kx......-1..........qv[Q(|...&@..1........<gg......==..aa...U..Z.`ofn.......\U..!'ffeZEB.4.......P@b}3.(%..}}..e`n{..mx>!oh.........XX..pp..)"...........1.QQNNJV?...b,-!c;K(..+3uI....EU..ev.........OI8?B.lc......jjVJ$5EZ+e..h0u./9].....>4+....qy....)-..5s*n..3:I...0670.U..pC.......IX]B9w...HY2LH.........{dPI........oz<#......IK.?VQ....wwP.....clDL..1...6*].....y(...td..H.44....|~...H.;w......g0.H....@.IK..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\452__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1210
                                  Entropy (8bit):7.356986975370672
                                  Encrypted:false
                                  SSDEEP:24:sJmfq7VSl984tFoze4ytP6qfHSgC0fNSZBzfteJTQRbvBBpFUBQ+JgW5J:gVSQAd4M9/xJfAXxuuZBpFUBvfb
                                  MD5:B4B618FEA3E954CE3FC2935F3BDD95F6
                                  SHA1:C52536BE90C35E258C3AA277E1FB14EBD4430619
                                  SHA-256:0E47E88BCEAAEA4C61A47D85CA208466264C6CD693A8AFEF5759519F44D19195
                                  SHA-512:B164F9996F3A87B354DC735A8103BBB64E7A983FFEE123DD71EE19302EDC18594C4FCFDEFA836746677589D90CC2BBEC8C7E6576D055D09BC0067F850F790914
                                  Malicious:false
                                  Preview: ....Ea`F.....8'TK....wz....._.\N..|~..@O....ez*6d5%$..p;GV[......YX..uv*&iZNdth....><........r&....`r......`st_..+'G.).T~rr....`s..2#.....of.I.......Vw<u........4C..mr.......ho....00.J.............~k...............*'..ArKa((YY..!=....?q..;c......=5S} ...<.._E..=5........e.......h}..@U..).....><{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\453__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1209
                                  Entropy (8bit):7.342268788014437
                                  Encrypted:false
                                  SSDEEP:24:eMWLb2EnO/2b06BU84tFoze4ytP6qfHSgC0fNSZBzfteJTQR43SBBpFUBQ+JgW5K:eMWLbjOkjAd4M9/xJfAXxul3SBpFUBvY
                                  MD5:33B7500D5D34EF9D6F943902BF1FF70B
                                  SHA1:DBF34BC93D9E5C433B0E15DEECEF93D1274FA909
                                  SHA-256:9D1177943EA3A399DDF4548C0DBD8BC55FDDB99CFE5ACD58E9E36EEA456EF94B
                                  SHA-512:ABBB609223254C5B88D48BC4F63AADCD4A3BA2F61F0DA0E5C181C7439AAE14A4F141380CC731290D462E29CF82066A2BB67F4212FB941C957ABED724FE9CAEC8
                                  Malicious:false
                                  Preview: /y}122'........r!....UW....cn....S.bx...%/ncPQ..d?&0...#sEFPa<rp........"+83#~..II'x........?%..E.........mq09@Y{vL{..^E..< ......h7.......^D...3>....Qj(/W_..RWO...........o1&..../(....XX..JC...............lM.#3&.. /Kk....UXq!7.'...ss..TH~o4+3}MA.E.o...........8Uv.....>KC........(c........Q...~k..q).Tus...M@O{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\454__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.351159194323828
                                  Encrypted:false
                                  SSDEEP:24:Pf/EdzuktS6aKAwJiS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvBBpFUBQ+JgW5o:PnEBMqAJXAd4M9/xJfAXxuOBpFUBvfy
                                  MD5:A5C0BE264A9233708FE820BD6200D931
                                  SHA1:8F525455B49C7F7BE0E479C0DD33F0B3B871335C
                                  SHA-256:8EC2CB1BE3243E19EB2E1F0CD09D97854BC990B3E081E941690BA7A84F3C0917
                                  SHA-512:144E80E0C4995C46F9F314BEE906FE48254F2CC2D4BAC291F1A326DB4493D4E4B64839569E91D0A1DFF30C20302A52A6A22EF2429C6432ED0FC9F65D67F89F89
                                  Malicious:false
                                  Preview: \;?47..b.......}.H[.........W^..LMP...H...|v..ml.^...............HQ3)QW43LEjaU......81..........al..(7..{g81HQ^S..PJ......25..''....ny......\AL...............YX..#.}i.t..%:..5"............T.........nt..G.........jO...uuz......vE....gg..g{sb..v8.........{s.........]G..DL......~&.WZ.....2;^V....CZO....H.35{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\455__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.643300247215013
                                  Encrypted:false
                                  SSDEEP:24:TWYzsHsDXITFT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR62UzfXF2tA63yrb+JgR:TfzsHsDYTGAd4M9/xJfAXxuZR1EY6fE
                                  MD5:747C07A86E8D39E4F6CB6148967CD920
                                  SHA1:C849CDD6819A7E09C8B06742E63CF3CDF542C5A7
                                  SHA-256:383E744A8A53D1E2D6DBA5F9922761E82E3523AF0F7705411557C0F86A2C8C27
                                  SHA-512:6549781CDC146E6F04B64E90F1934C63B018FD1F3A44D56FCB62B523A3326D8169D24749BC440044B748D9DDFA56709D92DED132144CE61BA20DA246703F0CFF
                                  Malicious:false
                                  Preview: ..1...lm-{....\]..`...x=.........Jhz........sv..IB..}a..vwlk..l}.. ?LV}|....vz..5.MQ)"1"...................oo?#....`bn..........Y......P]%u....yy..pl..zi...........v.u-7EUB..!...PM>7...#.%%....MQ....:8..^E]Z...G..........__'*',{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.._@....qF....u}{.}{478}{000052000053000053000095000095000067000101000108000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\456__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.796029336135309
                                  Encrypted:false
                                  SSDEEP:24:ozTduEwYxT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWcsUzfXF2tDFvy8Bp+JgW7:ozTMEbYAd4M9/xJfAXxudG158B0f7
                                  MD5:7AD750D134205420CF4E521E0C8E0C08
                                  SHA1:0688B1A03631C3F04A0652DDA94BA7F3DB560FC2
                                  SHA-256:3E4FA1D2D91C75C88138ABDD54DC856D392E600AD333E5F2308A535CA544E730
                                  SHA-512:3B29BF3473E47D2061153EF186B1E82E85A6DAC9472883154B4709D3DE02FEF3B542376C7C9CD7C32DF68127E6F00FFAAD3A04A56F61A4F58D412C35EE108EFC
                                  Malicious:false
                                  Preview: &r!...67..~i......C\jx(m..#(' "x....%'pw......5>/0..........PA...>!......RQ.... ..._T.............\.......&91+^_................crirY^.....6n.s99....5.;;......DW....wl...u..i`...E`;E....F..RGo=.........."v....r".....&&....ht..RA..DU......FO...@f..(1ra..rebX..{j..BK`<S_..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{71D......IH.tM}.}{.}{574}{000052
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\457__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.674073906275906
                                  Encrypted:false
                                  SSDEEP:24:9EjNTxArfp6PYMG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRc9QUzfXF2tDFvy8BS:92VAd4M9/xJfAXxulr158B5fI
                                  MD5:2DE4079F1786D9912F45CC0C7E49A63A
                                  SHA1:79EFFC8583B61F6FAA8623C033DC9EEB5C5625A5
                                  SHA-256:9A1A2D09B916C0A73F1666F868510AE165F661DC33A0160ECFC3BBDB20FEC135
                                  SHA-512:519006921BA3505205C3F79F7AC3F74F403CC2012D0F9084B2DAC24174130E2489DA9E1816F79848644FFB90CA43771F74CDF696BE94FBC982F628E6BBCA5C21
                                  Malicious:false
                                  Preview: F(,fe.....wv..6eVE..rp..HD..zs-2....5/U.qdZP{v..6n.....kX5.tb..13..~x{|t}^U?b70..6i............+h49..#<DJ~kzf%"!!tt!~....?(9.si.....r$1..)...f.dwa}CDMM..bb..............R_K^EZAt<.........4(..dd44cc!!....'0.......<....`.......U_=P....JJ......pp}1......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.$.g....F.g|=.q}{.}{524}{0000520000530000550000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\458__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.693563780730577
                                  Encrypted:false
                                  SSDEEP:24:KpGJkJY2GQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQREjyvUzfXF2tDFvyv2+JgWQ:KGiJN4Ad4M9/xJfAXxubye15vRfQ
                                  MD5:C249AECD662C48BA394B9FA5886BD443
                                  SHA1:A2D80E0D1F1C36DEB8699FEFC8A6FA0845A1A576
                                  SHA-256:91ADE4E8BE287547232B691A3BF27599FA76977A52E29578B9930BD1DF8C7F55
                                  SHA-512:F69BE6F50D8E51F69D110C560BC3E05EC63AFAC512EB5F9AA3C98D67C803D0E96DB9E47CE0385B45B0D54887C632CB94B06803737B3D89E79F97C1E713E90278
                                  Malicious:false
                                  Preview: .\....n8XO....yf..v3/"....N.M...2'<>....!$......;'..)(ur%n..)t..6)is..OH..xt.......uf.......LF..2;K.....f..SyLL(4..../-zk..ts...I@v.m.=4....b2.......ht......xi..).....'.p(5G.....FWyd..\..*....55......8+75..shAF{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...5s.W...2.A.A}{.}{439}{00005200005300005600009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\459__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1518
                                  Entropy (8bit):7.470475404468398
                                  Encrypted:false
                                  SSDEEP:24:5HrjVsjej/j7eUq99RX7JYc84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUG/VBBpFU:hjVIeLj7eUq99RXNYdAd4M9/xJfAXxuj
                                  MD5:592D5F61CBE88409DC7E239EBF06EDE3
                                  SHA1:6A8ED8C181F63226824D4468FE114359059CAACB
                                  SHA-256:32C664B3824E57F67C43AC55F1DC633012F775D074DC1CDB00D88412063BFF75
                                  SHA-512:AC8A315C4BF18FBE9CD44FCC2095FAE548618CA6594B4101E4403A1A63E971DEA1543362132FB616C10675C231151BCEF3102ECCCB6A19D5D0BB720560ECFBAE
                                  Malicious:false
                                  Preview: ...8;|i..ra.....=#13T_p|.........DQKt'..w}xu..|$.UI_...!5.H^%xOM.............T....._V.......................$=hevA..vm......33/pYPar....[A...I..$1TKQI9]..xIM__...[I[ZQ..<..^));5*2_....HT.......................8-uj6.>.tagm..gG......-..3..33....BS..I...1iK.IKJP..vXOOI_..CEQKq^80.......^T............DR.......................xhh..22..glUF...........<.3bbvv.......59.Tq...jV..R...YI..qbu1^K3&5<.^T...`g.H...&..............".......N.P..=--2....a`..AC........`g..........00ttII.&5..wx!)....xUh}..#4SJ.Tf...B.)=4p.....`8L...X_)l..........NR....j$.......b}TB..`z..}._H6/.^^O..10~/.....*..AF......xf>k|.%&31....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\45__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.7244369242470245
                                  Encrypted:false
                                  SSDEEP:24:f9WS72Az37QGn84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpsdUzfXF2tDFvy8BXCA:f97S+7QG8Ad4M9/xJfAXxuqsc158B5ft
                                  MD5:CBE80564653FD74F10E7D293FF2A8D93
                                  SHA1:7CB164B5C3C8E1B7C8EA9FEDA84C1FC79F520B99
                                  SHA-256:7A30EEBED733854B8B2E26D0C36E481FC2E5BAFAA3874DD07E6256703F3CAD33
                                  SHA-512:09F34DE4C6BA2026528380367718203BA0216623827A024FD6B6878C51FC69AAB295F91AE97642B8BB8C356A6ADC774EE1D9F5FB694F97D27A8451611349FC4B
                                  Malicious:false
                                  Preview: K.'........+1)(TK....u0s~..,vX.*8..NL........~u.....PQ;<.@..D............3?....~b..uf......ur.............,.........DU`{..5?e1 )..g....gj..1..7$$..9%.. 3..?........+"+0h2@fq3........K....([[mm**..w|S@%'.._D..~t..W^.v...m..yyob..._u..TT..........!o..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..g..D&.uj.....}{.}{522}{00005200005300009500009500006700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\460__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.62307854700571
                                  Encrypted:false
                                  SSDEEP:24:7iHNdLnU5E84tFoze4ytP6qfHSgC0fNSZBzfteJTQR87UzfXF2tA63yrb+JgW5q:7CNtnclAd4M9/xJfAXxuPK1EY6fE
                                  MD5:CC7D81A0375934C67743F275C3CF9BB6
                                  SHA1:4874CC559A31FBC6CAE00955E729CF6951D3F713
                                  SHA-256:985A62C554F653EAD2A41B6D81F6DE135113866EA2255985259BD1FA69399C3B
                                  SHA-512:128DA383CBEFB830547464B8AC5B7EB9E16F32A81EBC03052035CCFE85719FBA166BF297F79FDB8D11C90149F0E1DD73519A4A061DCA0CD30671E5C3C09DF9ED
                                  Malicious:false
                                  Preview: ...=z_^..L[....? ..YK......A...[I..QVhg..,/....7+T...ind/|m..= 2-..`aY^:9...=.............9>...F.....>...1........?,#!ZK..*-..r&BK.L........)y....MM..dx..FU..8))2..OEP.r{..+Y..qK\b.......Eo........+ yj..$5.....>j...IOD3........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.*..n.3.b..,...}{.}{478}{000052000054000048000095000095000067000101000108000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\461__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1508
                                  Entropy (8bit):7.510686636320317
                                  Encrypted:false
                                  SSDEEP:24:PsluzkpyrzqRyNQ4GSrCClA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR86cBBpFUl:P/+kuU1FPxAd4M9/xJfAXxuG0BpFUBvT
                                  MD5:BE0284E3DAB37AC2F75B9F71402810BE
                                  SHA1:57359D0ED7711A24CCD90F4EF81948FAF246C48F
                                  SHA-256:04DD4E701DE484DED30B6508FAA889A8F6DF001804867285239A3D75D8A68025
                                  SHA-512:E76DEA825D321E6E334D3D71B4B1B5812851A600CDCB9789E4406B404BB73B287DD6474185F0B4173523A1A0926C52FCDECAF61C80C692058B4333A0084F9A0A
                                  Malicious:false
                                  Preview: . $.............M):%;..ne......_@[ZH.OU.]....m`.....GQ......K].........^Y^W..S..................bh+..{n_@!/....B[BO..@Z....!=.......N.....................Y"GU........X//=7(4YK\J[....BBBB..^.FO\O..K\....o,......fG......ZU...........=:.............P....ZR7[YXB..dJ........@Z`O........f>.....LC...............B]......@BFWNIII22ssN]QZ"1..........5.hBSS....1 ...r~.....3+b^z6Q.....+4..t0..ZO....j;..FA...<.....66{g.......$|s..............ihdo...........-*..ZS..}l.......W...M....PO......46sd...V......L........0a..vq....=.aK.......XG..)%......i..,1+vu02ub...TGVO.HI4e8'...........*+..%p9k....QU.e!{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\462__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.396431836052254
                                  Encrypted:false
                                  SSDEEP:24:oK0naPlZsj1NnkVn84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5iBBpFUBQ+JgW5t:obaPLsj1s8Ad4M9/xJfAXxuiiBpFUBv3
                                  MD5:954E8AED7ADAB7EE6C8EEEDC22D0697B
                                  SHA1:FDCB409827501C03F937F707365DDBA983AC6148
                                  SHA-256:7143F1554F74308C1CC201776E97820F1612B9BA93BD16594F5ECAC528C8DC75
                                  SHA-512:B84ED5DA427BE475A8113F4F0B11E2FB7A2DB005BC0A5917E7F5D6385B70089D34E12005B58CCDC94010DD018743E9BE6CC720F379A8BD345B4F27F223E380D9
                                  Malicious:false
                                  Preview: B.,.X.|}.tc..ml..3,hz........W.(..*?uw..69......[D......PW......."8..8?..#/(.Fl..29..02....VQ....PYt,.j..;.\\.....*..-!.........}v...}.......Z......>9.....L.'\..kj..%..d......m....#?..!!''...[MD..0'J]: ...........}X..AK............Zp.....:&%4..y7..................LJjp.............`wmf.:,.}....m`..TK..........NN..ggra..,?:8[JQJ......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\463__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.348677266674745
                                  Encrypted:false
                                  SSDEEP:24:SPuTjQHyqUuZc311/L7tA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKxxBBpFUBQu:EuvQS861NtxAd4M9/xJfAXxutxjBpFUt
                                  MD5:4C00C8C5CA10E7E8EBD5BCEF924B80DC
                                  SHA1:FD11A543B80A554AA08908A373EFA75A70B3724F
                                  SHA-256:74DE7B877ED586B48479025C7F15CD4690E7970E99DDD6ACAD3037802EDC8E53
                                  SHA-512:73C691A1FB9DDE9CC9E0CEAABE12BA5BD5BB1F94384976D636BD548B79F0B7CD1F3E8E0DD39913089F1A95F741932E13A177B2F4E157F981C6A049CB24D8A8AB
                                  Malicious:false
                                  Preview: ._..I...ZMF\PQ.......ne..2hw dv....X_....TWV]..HT....25.B^O.O.......ho..:6kX.0..HCJY....JQKL...E.....|xj|ZSS........hd.NkX_u00..HCJY..WF......m9..n6}.U\K./'Qu.....j...........nZi.........../-.. ;..ak.;2.I.......!^T..hh..H[#?...........B...E......}j..}Z.......D{ho6.;7.iN.......n=...S..J.ZE...|i....3b+-70..,#_l......>"F...,?...............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\464__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1216
                                  Entropy (8bit):7.359934462246065
                                  Encrypted:false
                                  SSDEEP:24:s8lhUamYUFEv+C84tFoze4ytP6qfHSgC0fNSZBzfteJTQRL0BBpFUBQ+JgW5v:sMmYoE+HAd4M9/xJfAXxuEcBpFUBvft
                                  MD5:56BE2AE925AF93907115DC7920D2C45D
                                  SHA1:225F0FE0301D4706E75F3397663BDCBC5446EFC2
                                  SHA-256:1EB6A9F0C2BBC8A642CBB791EEC71E79F3B15DDEDD92EF19DC961CC0050DEC8E
                                  SHA-512:C6365D41BB35F23EC63F2E4A6D99D1799BBAC5FE86384089CC48B6BA95BEC96BD06AB5097631BE2D93F411D4F2133A00C25E1013B5E798474566283CFB75119B
                                  Malicious:false
                                  Preview: .8...,-n8..LV....'8...Wp}..~y..-z);|i...vy..{x......`1....kz..........qvEFEIuF........pr..............&.77/6..1......M}NFl..........IX..>9dnU....]............WVod.t.. ,..kpNC.`..K9..).....VJ6='4-/....RUeo..(p_9......?0......*3......||ZZLL.....M.dk............6.|z__wH@G....2u........g`...."3........C2um).....K/~{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FB
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\465__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.34227241966066
                                  Encrypted:false
                                  SSDEEP:24:63AqGtF+ImP3MABit84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrlzBBpFUBQ+JgWk:zWIgvBxAd4M9/xJfAXxuwlNBpFUBvfk
                                  MD5:B0308B944A69ADA8F2861C5F1271C605
                                  SHA1:C73B7F0E72B3D19C99FFF41D424CC4C022D672F6
                                  SHA-256:69B30EF7AC25E04C9815CF3239651510AA871F209EEAF1FCABA3F7AEE4EB655F
                                  SHA-512:DE1F6B58C88ED490948D6F6568397C0F4A917F283134F4D062720F8B150870E92853BB76901C288E6F100B701833C7B88BFE43DD9533C02414EF90E820CEE649
                                  Malicious:false
                                  Preview: .......V....f`........>5..YT{rvi..3xBX..5 bh3>QP.ME.j|......tb.....3)ce......(u....I..'DW......`}.gj....N@HT.'qh........OY+7..]]MM........W@7-.......rm..@E...z..bc..>.::M....;VTC........QQk4..YJ....C^S...`uD[....qd..EJ|\........~T..??{{......0<@...7-../...nx_| &..An........I.....y2..bg...{y......#6......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\466__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.772297205817063
                                  Encrypted:false
                                  SSDEEP:24:NcBkmSu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdr8EcsUzfXF2tDFvy8Bp+JgWc:BmSDAd4M9/xJfAXxuI8EG158B0fc
                                  MD5:817D704BD8AAEE552E2EB2628AE58354
                                  SHA1:7213B729A15ED0E896B6EFDD665D24DFC3F2EB42
                                  SHA-256:92FC0FE99B8FF9D6A14285240C2EEDA2F1AC12A9F588BACF14A08990050C23FC
                                  SHA-512:1627C43B6BC7ACA5A5B04530DB58806F151B0F9CEE7870AA71ED34D8E87D136BDB30E0EFB8D1DFE434D2FDDF20B4AD16A8E945389ECCB15DD76A8E53CB0CDB83
                                  Malicious:false
                                  Preview: \..dgSF.BQ`a|z.......92ei............x+..........~c..-.pf>cVTOVmwhn+,dmyr...66...RA..4#..}`....qd~a...........NR......].6?dw!6....TI'dp}TA....TB..{gHO........'46!.....=03&..2*q(.......D].......B.$&......#?^Y``............!6.......D!,n{....QX..DI..2.......$$&!..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{ .3.&...p.{....}{.}{564}{00005200005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\467__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.709949871078135
                                  Encrypted:false
                                  SSDEEP:24:G8ZyNjxpb+j/zP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRqD1UzfXF2tDFvy8BX9:QBaj/zEAd4M9/xJfAXxuPDE158B5fP
                                  MD5:A23B69532236AB03E3D54472BF05481C
                                  SHA1:1614B8E64BAE69B2122959DD30E9C2B0EC52FB24
                                  SHA-256:2174FACCFCF06272628B80AF020DD28568CA8F0415067AABE7E7B34411E62A1D
                                  SHA-512:6F074FD26A9A24C0EA4E03F514CA5E743E7A682812CACEE9C1CCF39D031A69C7B20BFFD782990B2DF66F783CF07B3D605B2360BB2ABD6E45A56E968A4BE631F0
                                  Malicious:false
                                  Preview: .Z.(T...........ktZE..Q.eh....y#....MX..afUZ..AB.....E........@....../........76.+7../<...E^pw........dEU....?....GLve...........YP.XV7SZip..S...>.GG((....#0..............{l......;&....gT....}}..od_L....VM....N.....oi.....=0od...6RRHH..uu....IV.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.KL."cv../*...1"}{.}{519}{0000520000540000550000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\468__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.68948195231015
                                  Encrypted:false
                                  SSDEEP:24:dJx4gsLOKpmLwHM84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsW4UzfXF2tDFvyv20:1cX0WNAd4M9/xJfAXxu1Wj15vRfR
                                  MD5:C3A64D47CED2829A080E08B8FF56409E
                                  SHA1:DCF13B6EAD5C850E765B612C9284BD35B5F44772
                                  SHA-256:4C4519CF471CE36C4D1F2BA8BAFFEE94701EFED53A170DB598725679F2AC5E04
                                  SHA-512:9910250CA702D81C99A675CF67350DB5D943AE4FB2EC24E904AB9F91C5D827BC65A53573422353722F46BCC342BBAEB473D666306EC8C1BBA9FA7FE9EF5D7747
                                  Malicious:false
                                  Preview: ..{....................id...?>..rhj9..IC....]...]K....Tb.....F_......18...T34PP.]V_..1&......#`......igu`a}........JYSD....%f..}h....--SJve#?16nn......@S..2%..c~..+&....0..._[.....MY....<<.....i6..iz<+bu{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.........F......}{.}{433}{00005200005400005600009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\469__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1217
                                  Entropy (8bit):7.363151754151338
                                  Encrypted:false
                                  SSDEEP:24:rglIH4LpF0aRoKYXw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRahp1/VBBpFUBQ+w:kqARoKYXhAd4M9/xJfAXxuj1vBpFUBvw
                                  MD5:A551ECA0C402C39D32E050CD2A8926B8
                                  SHA1:B72108A20AF48D056954C54319FAFA7207C85EEC
                                  SHA-256:9D26353C4B8267180E3C5D5E769436C0759FCEA1F0C60FFD9FED1AAABC8299A1
                                  SHA-512:5A02764533ECC53520D9022B6295A8B48E5CD4C57802CE6629F0BBE64D902C9B177BF93BF62A9BC1243487F4A35B417D9977A165CFA3102AB5C1182C8FC1892D
                                  Malicious:false
                                  Preview: D....GR.......l?M^xfOM',....EL.....kqH.....85....N.I_ =..Yo 6.L|~....DB61.....F[\...M......\KZ@YD.CDI..a~...... 9..PJ.....eb......_V......$>......C\Xi'"R.3.QZ]N.........s.nb.....o...E7+.@j((YY......vg...BH%qt}V....l.....w}........YE..yyYY..[[....O....;$5"76......HN........q6E...vf.........]*#..Q.9~....U@......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\46__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):6.730936649344109
                                  Encrypted:false
                                  SSDEEP:24:5dlq7D+gb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvtcsUzfXF2tDFvyv2+JgW59:5H+PgAd4M9/xJfAXxuQtG15vRfj
                                  MD5:4B1CBDA9B3FE73254FCE345DC4588044
                                  SHA1:C5A60BD5983724C02CCFD6663CA4C3C938B7E9A5
                                  SHA-256:A04CE53F8726D6B32252173A26B1A0F9CEFCD73E4AAA91CA35F2E06A57E068B9
                                  SHA-512:BA26FC45E0E1499B2C16A3120E3BD99C90D9A36A2FFC67EEEB56C2C137B200932D9A58F5E982F7DCBD4E43AA43DCB5B5160BFE57301B9AF6E4ECF51D4A484DDA
                                  Malicious:false
                                  Preview: ..{..%0.........IJYYG..\Wma.... ?ED.e...]FS..fk..?gA.j|......t)..wn....07....A.........@WAV....L."/.........!!.R[.........S...[N..Ag..@Y.......................ZG....+>HW.5..MI....PWCW`|......<<ppw(~w........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....z%'.<.....}{.}{436}{000052000054000095000095000067000101000108000108000117000108000097000114000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\470__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1518
                                  Entropy (8bit):7.527874166525087
                                  Encrypted:false
                                  SSDEEP:24:SLXPjEjTEHw4UQrlv8rA4Qi09rQDSHiR184tFoze4ytP6qfHSgC0fNSZBzfteJT7:SLXPjgTSwUrlvIxQi09jH2GAd4M9/xJL
                                  MD5:13F42AE734E0427724F319FD009610CB
                                  SHA1:0808C33389FD7A3B95B6F0C5D1375BB6A91F1974
                                  SHA-256:A78B265290E0E38AF7EC196648FFCAF22BDC6C7F5E28D53C631A95341F57DB31
                                  SHA-512:CE5E98A33072DA98E5ECFF5DC7FFEB4C35498B45098F769B8CA5300E8B9D71DD6183577823325DE599DBBD3FBEBF9E111525D8A695C6A4DBFBF8F3C6DC6BE0E2
                                  Malicious:false
                                  Preview: ...c`..3.H[@A..\.!2....w{>3..gx......h}5?..45.j1..jw ..&..j7XZAX..GA..YPJAT...88.py........1,.gj....oa..I@....Sd......@\..||..4k..L_......wj.....)62.,#........np...Q.......Z7......%"......FO..MZ...........$.3.cv1;uz.........Q.,......BBc....1(f>2m5.y..a{..lB.....+{}#9.; (.......L>u..>)....)<..gn.8i..AF........DD..DX....jy.......HOrr..rr...A.................?&..XK........WP..JC........@@...F....;4..hw.*..|~..<%..r....._z]..ht..XZ..I\58..|c....<5..kz..##....~24'/b..s{..WNwZ..B@..ul.R|. ....... 5..N..A..&!.FI<.6.66qq......485m.....cuQd.........`q.....--y}....+>.......^......HL...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\471__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.35149357271176
                                  Encrypted:false
                                  SSDEEP:24:MncraiwUWx+vV084tFoze4ytP6qfHSgC0fNSZBzfteJTQRNxBBpFUBQ+JgW5e:5GUaeAd4M9/xJfAXxuGjBpFUBvfk
                                  MD5:40DCD02637CB543D6C06C78FC64F50CC
                                  SHA1:841CD03CC96A79D2DCF7D097422B585180BE7EF0
                                  SHA-256:0BD8E7407088C410AE9DA2F4424017334350CAD882CDABF984526DC18E6094E9
                                  SHA-512:056A6742C554F955AF20707DF0C30E9DA050473C67B479B1E1407107BD42ED8ECC4B81BB2F48FD6DE086E6BA7DDB8DDCC0683CE1FAE1491E55732F225AF47216
                                  Malicious:false
                                  Preview: .....sf....$"r!>-RL..........PO..(cTN?lk~..wz.........(..=+...MTVLDBCD....O.!&WW.CFO\O$3......$g.......+7............FP..NIcc.........J]...........wQjv....M61/....S^.....Q]..&="/..7EYj..55dddxNE...........w~..L*....+-=2=7............''....zzL.%6..cl<4hw......gnPr..||.6G@*...@.D.......]L..^O......(%....).<'{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\472__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.788582975543388
                                  Encrypted:false
                                  SSDEEP:24:Od3/Zjyuvu+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKAUzfXF2tDFvy8Bp+JgWF:MjX2TAd4M9/xJfAXxurb158B0fF
                                  MD5:26F2AD4F34197709049DECF15A55C92A
                                  SHA1:7B957594DD615102C6703DFD3D8FBC5A93903A27
                                  SHA-256:AB3048458E25283585F674D895D5FE59334BA2E21252A38DCAA4863D26DAFFCE
                                  SHA-512:C39394F26BB21748A2E20F0E1DC8F0D12CC44D27ADA53009ABABD966BB2C8B4DBE2DA32D4E97710DDD7AF920A9CFD3D830A0DD031C4616DAFB3823B8792CE2E3
                                  Malicious:false
                                  Preview: =i......J....32..d{../j....07.KX.XJ..RPMJ....wt|w..eyC.....4..nb?......67TS~}hd{H.........)8....oe.......$9tk....QV.........&5......34......)q....L].Y8...............`{.)......Q.f?......[.,(9,f4......GY.......Z..6f....LL...........>/.......XQ._zw....xa[H....5.Np....:3R...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....(.<..9..v.}{.}{570}{00005200
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\473__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7179827286041105
                                  Encrypted:false
                                  SSDEEP:24:WsgIF6QZKw84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0EUzfXF2tDFvy8BXCL+Jgk:Wsg2ihAd4M9/xJfAXxuz158B5ft
                                  MD5:2BD6258235DCA50148B95E0C5D4E2B51
                                  SHA1:A38AF9CE45923F56D4C64979956093186AC1BF03
                                  SHA-256:2D1F290EEDF123EC7366689DE2C3A35BE45F0B493B663A30052C743AC3AF9D68
                                  SHA-512:5DFA469A232086483E5C6E9EE7FD21CBA33A4BD781140A656D86F53D5C96F8CEE3A5C33F2DBE0B3BBAB63700B3E2C93A464254C387E207E7769AD616C03E18D3
                                  Malicious:false
                                  Preview: ~*..].@A.Y..MW..nqOPJX..'*..8?S.1f?-]H............/0...Bxyvq&mL].................XrOS...=...zajmIC.......%ArA....LPqz......NUaf..c7...R3dm......6..QQ....t...\^...............BU]g....3.'..1.fL$$.............\G.....|u>f@FV!..{{xu....bH..yy..%%|`..|c...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{6........O#.(.>}{.}{522}{00005200005500005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\474__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.710536406676805
                                  Encrypted:false
                                  SSDEEP:24:yqFs1qxAQOQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQReQyIh3UzfXF2tDFvyv2+7:IqxA3Ad4M9/xJfAXxuah215vRfj
                                  MD5:D8F5549CAAC9B72EFF1EFB90A2B121A6
                                  SHA1:FC792714037D805FAB1221AC9D61C094DF70027E
                                  SHA-256:D4CACDB0D3798C7108DCFA4192B194D30A1137A2EBDE38D68DA8AD3BCD5677F9
                                  SHA-512:F0E0D57ECF553A8652B0E5DDD9E2EAC466499BA905AC6CAC0F6C94724EC20CB4E9CF871EB5875C0942AD0EA3867315FA7A29362632064BD2AB424BF081492AE5
                                  Malicious:false
                                  Preview: .......ev.....VE..QS....fk..$;fg:q.....93.............(>.U....: ....jc...CCDOO.N....erH_.....C....>!..........^....yn......J.........JJ....(4..==..kk......-:HR........Yl...qGSS*-..)5MJ......^^._..\OI^..SI{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{w..S..~..8..3...}{.}{436}{000052000055000052000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\475__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.39048992981436
                                  Encrypted:false
                                  SSDEEP:24:GQziCCCxVMFX4T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZBBpFUBQ+JgW5Cp:3mCCeVO4YAd4M9/xJfAXxuYBpFUBvfo
                                  MD5:314712FAAFEC68C95A1D58DFB1940A68
                                  SHA1:AA59DF32250633C1E0C439568FD7A09CB221E1F3
                                  SHA-256:54A65A577C5504F0310458830580E867FA34DE3E8DF236247BB9010D0ADAD3AE
                                  SHA-512:A1FCD59DD28A4B694650D3A2DE9D103D4766548FC5A76BF4F15DDDFEE2749B8DF6A01264BD5FC9E375082575332A574CA347A26E059B4BC60BAD633D1ABFC8D9
                                  Malicious:false
                                  Preview: .@D............Z......U^....908'wvd/..l?..........v`}`.................._T.OG@jjB.......%2PJ.....h}C\=3dx..mtm`Sd.........SSSS.......^ISI.........)3......#...FY> ZU?rtB..-Z.<-2E(......cd..ww......N]XO........zoezYxbGMX..&).'^W.......q[rr....fzN_..,bma........PP....A[......gp..U.o*...AEhriy../bU.o+5 ~k....:<.......:.U......"n.....h....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\476__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.385382042170658
                                  Encrypted:false
                                  SSDEEP:24:xSlHRkuJykNVqTTJf4q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkcsBBpFUBQ+J1:xSlxku/NVqTTJf4PAd4M9/xJfAXxu3hg
                                  MD5:CEEBCD354B30C44A8E045C7D950AF8E7
                                  SHA1:FC92AD5398789086F6456C1AC5E40063AE925FEE
                                  SHA-256:DF4ECA1F8E27DACB45213A0ECFFF5261B9449514BF6AC06219521F1AEABC841D
                                  SHA-512:341DC7DA5F73FD5C0EDD202C102896ADC623501965D07977813D3F9ED819361801B954F6DF8F634DDE63B2292D815F3A31F2C05ABA33EEDFEBB6DEE7314892FD
                                  Malicious:false
                                  Preview: .OK.H.........|}....GU...........ZO........ef.............rc..................WK......{`....W.........Pv.........am........WK........{`....W.....y...v!H@}Y.....:5....`t.q(:..(E;,4%+7QV......m2..kxpg2%$>...xuTA......WB....Uur{..eh.:...........cr....tx..f..G]..`N!!...._Y....dlOM.9.....4....}v<fcr....<7..63|i3>..4+..]F>7......................ho..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\477__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1208
                                  Entropy (8bit):7.375038918420887
                                  Encrypted:false
                                  SSDEEP:24:zbyGoP1Y84tFoze4ytP6qfHSgC0fNSZBzfteJTQRl0elBBpFUBQ+JgW5H:fZ4Ad4M9/xJfAXxuO3BpFUBvfl
                                  MD5:946DC7597DE3603C7AE41C5C30574453
                                  SHA1:35A5EDBFD2E2AFF9DCBC14CD81BDD901BC29DBD3
                                  SHA-256:11D05FD0DD63780E9F9037C6291D16DF72605A2E8EB8624D206E8C9BFA6A8E79
                                  SHA-512:0A36A1899043E0029253CED8994842D802F9F35718C49C0936AA4C212CA4DF7A94FB185E3BA42285F845353260B2F5AD490E7715F816BB376F5EBC7941AE660E
                                  Malicious:false
                                  Preview: ..V.A...........................YK......P_..........y(..ru.M.n.....5/..70..%).4.)......uw...d)...z.....:[......5,....~x..y(2...........~|4%..$#........w....?.<'o'....ky...t....2.43KK....g8..5&zm....C^.85..$;..mHGR....tT.......................Q]..I,GE|f..>.==........ia...h..._#h..$3........WB....35...S..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{."
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\478__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.3559732941268035
                                  Encrypted:false
                                  SSDEEP:24:t1EUzp8HxucIXrm0k4y0zQc84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4EBBpFUBy:t1EUzpCMcr9fdAd4M9/xJfAXxuDsBpF3
                                  MD5:B2671FE8191DBBCDB75FC4990DEA63FD
                                  SHA1:9806FA895C643D9F0C1EF537C57EE33A9DDEC18B
                                  SHA-256:F6A240CFED74BC34AC6BA39B5C69970CD92537FF47D2F8C2178658798E28A513
                                  SHA-512:5439E20FAFD5D9974A0BDD60EAB483CE7157C1ECE12B96AA7C4D4833106954AF689DC6D9CBDE6D7D92400A14030A6BEEC9BAC0B908A4822D48998EB0DDE2CDA0
                                  Malicious:false
                                  Preview: .ko..oz.RA}|^X........LG......ez..q:kq.FS...TUx .....+...?)t)KI..5/..fa..........kb........UH<.......=3jvzs....*.............22.]]T....%?c~y:....ls[qAZ....px.....J......0"....`w..#?EB......yp</~i..HR =.F........kNLY........9 ..E.vE@j::hh.........%}f. "....!.........is.:.........K.(9...S[..."..Np4..H]HA..},..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\479__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.767890153076367
                                  Encrypted:false
                                  SSDEEP:24:cKzTqbILLu7DDgGHjB84tFoze4ytP6qfHSgC0fNSZBzfteJTQREn/VUzfXF2tDFA:lz6ALu7DFjSAd4M9/xJfAXxu1s158B0d
                                  MD5:9DA80D25480DA781A2E4E7D746814BFB
                                  SHA1:A3C15CCE937E90A3D4BDA98D1C4D0DBDC8E159EA
                                  SHA-256:964EFBBEF15D49D3110658052395D81E2F507111204789CFAE361167A06C57BC
                                  SHA-512:27C05C52A4629F0A1E69F80D0268E5EE960696A54CCF1AA2410482E968EF9F3675F29E03845B7B29FA6A33204D14330CF29FA26548F108B45A8FD771D27F8B43
                                  Malicious:false
                                  Preview: ..O..qp,z....ih......._V[......E@R..KI..3<..C@..NQMQT.ed...]zkV...YF]G23........2...YR....ZK..61.......>L......oh.Wd....plIB...._N.......elu-..xxGVF...0...||@\..wuRCby\[{qk?NG...d6}y.O.)-4! r..+d......[..].CP^..M.....II..77PLLG..<>..UN..=7..bkL....)''}d...k.....$gv.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...%@.<..6...&.`}{.}{570}{00005200
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\47__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:MIPSEL MIPS-II ECOFF executable - version 138.22
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.400881272187147
                                  Encrypted:false
                                  SSDEEP:24:VbuFn1WN2xM+p+tA784tFoze4ytP6qfHSgC0fNSZBzfteJTQRzBBpFUBQ+JgW5Cp:VaF1XxM+p+HAd4M9/xJfAXxumBpFUBvQ
                                  MD5:BDDA4D900C883745ECED4FE2BD3FA11E
                                  SHA1:BCE4B19428738C2E1219C0CCF9C5DB80766588AC
                                  SHA-256:36AA605A80E293A5BC24AB0184C49BD058BE44E5F4CD4034D88C41366098A7DE
                                  SHA-512:2754E99195B0AD9A9591ACFED31BFB5D216063396F431BF164C3462FCF9E1C63DE64480D1A31072B590123A54023A22C7A0DCB4219E62FF5157C43665274EEDE
                                  Malicious:false
                                  Preview: f.......qb..nh..../1....GKXUJC......F\.I[N<6NC..............................>9...P......YCpm..p}....tz..........mw...........................U..n{................+o..4 X/..&9...TE..`g66..66@...S@..^Iz`JWp3..$1$;.1................*z..Eo..??ll......W.....r.fd..ia....1'2.......91........d/..ub..R..........F.8|2'...m5c2....o*...........c....UF......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\480__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.699918782930265
                                  Encrypted:false
                                  SSDEEP:24:kOB+OjOzU0k84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwEUzfXF2tDFvy8BXCL+J7:kbOoHAd4M9/xJfAXxuHP158B5ft
                                  MD5:A4A317ADCC2AD09F622A9B9FF61D85E4
                                  SHA1:AD1B6B41DD3192D9F41647DE54A76A909DA27046
                                  SHA-256:B3070E0A2445A517EC9D13118CE24B663C5A3708CAD7270D567602DBEA411FDD
                                  SHA-512:136335E8D9334083AE19472EBACC4122CDFD5929A79D9EE3149517FA768426A89E783CFD6AD69BA6687848F2B2D157C9FD6450994602DA85D16371ED8223C302
                                  Malicious:false
                                  Preview: ....YX^.ub.............AJ..v,......................A@EB;p..../2.....~9>..IE...7..qzGT....sh....@...B...[?..|V...@K</$&xi........%,.2S...........AA0,....XZ-<}fRUOEq%py..BU...........\.......!!.........ru.....F.....@@..w|..........yy....B]....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.a.P...81....9}{.}{522}{00005200005600004800009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\481__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.720770402720054
                                  Encrypted:false
                                  SSDEEP:24:0rSwuAdkG0LssW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxUzfXF2tDFvyv2+Jgo:0OwuFG04sLAd4M9/xJfAXxu/15vRf1
                                  MD5:155683B4807147FD75D6E3F02784E746
                                  SHA1:382BA4496AB74478177D7566797D1E48FFE57F77
                                  SHA-256:C51416074DA075D531CE82ECDA6A58CE0148F8EFDED9A31E02724F759A168ED3
                                  SHA-512:72738DF072984A1B892FF844792E92511E01A44B4C0A1DD44DF7534E902F507A445F5466BD039B69BA828308C80F87300C57D92FCF2872986E71D74F1D5F0B16
                                  Malicious:false
                                  Preview: ~......o#..;:.....@^....FJr....1qpV.'=.......'.q*$2hu<........UL.....XQZQ......I....ub5"....o,..;......@\........U\....ny..5(].+&BW..$.....%6..........}"..s`..PG..!<t7........9...*....eqIU..ff.......t}~m..ny....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{a.:b.......y..k}{.}{440}{0000520000560000490000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\482__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1580
                                  Entropy (8bit):7.543693726190816
                                  Encrypted:false
                                  SSDEEP:48:+QrJVnwvQ++wvB9gAd4M9/xJfAXxuoKBpFUBvfT:19i7vpBAXQoGu
                                  MD5:DB52785B28F532A921FA49393A23CD83
                                  SHA1:789A44F446D93DBCFE28067A4997706242F8AC4C
                                  SHA-256:611E56959F642551BFA1E4A767A2997DC65F8E17A8F4C9A3CAF9427E3779ACF0
                                  SHA-512:9D010EC87DC2509C06DC8FE71309B29D869D6588CDC7A511A6EB63A42910C497B549E2DB970DC1654AB2B60B40D70E2C3E1CB0C91502A3A796A1937C24EAE25A
                                  Malicious:false
                                  Preview: ........o|....w$..C]vt..bn..r{<#..I...S...PZv{.....UYO............ :......4?.........RA....IS........YW....?&CN..='..0&..~y...g8.............P....0/iBD_jecu...0}c....U..tt.....k.........RR.......m|.........4lS5...!vpLC..Pv....FZ..OO<<..99.I:)t9...&....SR....@b.........!...O............................................CH...........N}..ss....#2..o!...N.nu.....Y..m`....BQ}9..ly..../~`f|{@.4;........+:NQ.E..................ot........!0....50gr.....1....V_FD........99....t9..NFPO..Ux....w`....f#.[....Z......I............. ..............H.k.......dg_]NYxa.Z/>.@RSa0....gcsjni..?o_^....H...~|>:..\......I..Y42....0?Ar6...!=.v...........jmvv......bq....B_{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\483__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1209
                                  Entropy (8bit):7.361021925431856
                                  Encrypted:false
                                  SSDEEP:24:MrfUAlVLnVrH6HIfE1i84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMi4ruBBpFUBQx:kUArLnx6ownAd4M9/xJfAXxu646BpFUK
                                  MD5:3D975D39FAE7A0F989E8EEF4F1E322BD
                                  SHA1:7117763A69E90B75BA1AEABB6A95124429A5BEE1
                                  SHA-256:D7B5BB44DBD5B271A3FA22A1E40568816C71106134633F5FFACC86F8B12A32CC
                                  SHA-512:8E253E3329B99B2F051C971EAB4C6548B96C2B12FAB1CFED6B6E751ADB41EE06012EC57B47E5B6840CCFE7326E7DE53FE5EC20FEAC8742BA3E9816312566B466
                                  Malicious:false
                                  Preview: r..........db..L_......)%..5<..! .Jjph;....xu..9aw,..<!.. .9/!|..]D..+-......P..[[9f......<+[A..4w.._J..BL..of....Av....&0...................... -..-2iK....l%.f.....#."6...c|.vzm-<..JM....pp.......AV..-0H....4+.=..`u..69................CC..&7nq..w{...}......}S44.........GOhj..ov.E.....FEG..TA......G\..HJ{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{l
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\484__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1404
                                  Entropy (8bit):6.663721119351873
                                  Encrypted:false
                                  SSDEEP:24:2klp1eR+TjufW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgn6uUzfXF2tA63yrb++:TLeMTjufLAd4M9/xJfAXxu+1EY6fm
                                  MD5:85B7628B79A6FD7372315FE5B227E107
                                  SHA1:95AC2C282E33FC6C01B0E9E19EA230F3B584A35C
                                  SHA-256:F51857505622FE96181E29A34DEFE7B2A00C9A1D0F944927B1BA432CFB852C01
                                  SHA-512:506C68643B6D2DB7C15816D1A4401797F550143E766C939DAD655F958AB150ADF1CCF85071FE27A455829D90EA5941B9A32A4B70FF6CB4B9DD364618C295F794
                                  Malicious:false
                                  Preview: .T.W0wSR....z`-,....);{>ob..HOS.P............c`.............m|...VI....kh...[q.............YP......Cp.&..`|K@....WF..NI...M...J+ha/6XU....."........(*o~..:=~t.XQ..f....Np..MPmdO.........HH.........PK.....]....AGB5..............CC{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.8.N3...p.U...sz}{.}{498}{00005200005600005200009500009500006700010100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\485__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1396
                                  Entropy (8bit):6.792502283791148
                                  Encrypted:false
                                  SSDEEP:24:4uQjzwShaWxU44rnrQX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRyDdUzfXF2tDFk:4/jz3aW0rpAd4M9/xJfAXxus158B0f8g
                                  MD5:68C94BF47FB02780AC0569614D52890F
                                  SHA1:D50EE92877792EDCE0F66C48FDC2A98498831B3B
                                  SHA-256:ABAA4AE85DCCDBA73D5A4D175A10595B1916720793BD3F3B1C26F0E5AFCD033E
                                  SHA-512:105E8E707A4900A89ABBAAE935FBB27954C256D1FE7DE4B11544EDFDEBF9E6EAC56EECD70FF1686BAECACC6A4488EDDD6F933060A3E4657A09D14CFC4C6D11AC
                                  Malicious:false
                                  Preview: .DM..32....SI.............^G.gu......4;..KH...1..t% !mjA....kv......(/..........=6....TE.................|}UR...._u......ra..sbmv.......|$r.....2c.........=6...........p$.......PWSv'.D.....c,.......]...4:.. ............P[..PRm|....xr....+s..6.KK.f.......lR..,1.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......6X....>g.<}{.}{578}{0000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\486__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.72821008199382
                                  Encrypted:false
                                  SSDEEP:24:NDvBg90GhOqe84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8/iCscsUzfXF2tDFvy8f:RZgh1Ad4M9/xJfAXxunFsG158B5fj
                                  MD5:496A8C5BC9E59E833151123699B43CC5
                                  SHA1:0ACB0F0B8C021658B4B7AF7FC129A462075B7539
                                  SHA-256:0D39B714E41944A608B3A3D75D73AFBFBB987D65894A385049DCB9C4BBDF69D2
                                  SHA-512:1AD02B3F5641D3D977CD1D3DCDA0C8A5FF9D9833389A22102822E4042F8557AD04BD1E5E4A1EC43043AD40494EB32E21F97CB778B38298BC10B091E32D6A5CC6
                                  Malicious:false
                                  Preview: ...K.P&'...............di....m7.\..gr.................. '.K_N.........ST........;(..........i=..$|t...I-<.......IB..;9......... )..............rrff...ts`.............Ri.2%7........Z{H..$$..II..p{........FA...XQ?gjl....dd..en}NSy.............59..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.=.(n]..X.d.)..}{.}{526}{000052000056000054000095000095
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\487__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.731802564701715
                                  Encrypted:false
                                  SSDEEP:24:4yLGgzD1K2bTLO84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9UzfXF2tDFvyv2+Jgv:BLZzo2HLjAd4M9/xJfAXxuH15vRfBs
                                  MD5:85A44B11A0E67EB510D3CF7990F9AAD1
                                  SHA1:60311DED5DFEED5F6AB3754CB816B9A300E8ED73
                                  SHA-256:4966C50B7F2495ABDF6FBF2DBFF2B5A4C5A17FCC57F125800B41F9400B53DC18
                                  SHA-512:2672F4F666C5F371AE5FF33AFC47841900C41C01E84C00721782958AF545CD2904E887501AF92F3791AC380B9C7C3EAA689FBD3045A1001FF198401FF558B0E1
                                  Malicious:false
                                  Preview: S.4...-,^......op.....\@M.....@.vd..............(4T.NO.....`=......lm..yz.....)......JH..lwz}......K..b..5..uu..QZ......?$..$...EL......mt...=.....jj..ry..GEKZsh..,&.......9.tJap;&......5...gg*6..bqXZ...5:=rx{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{D....y..Hl...g..}{.}{443}{000052000056000055000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\488__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.383504060459166
                                  Encrypted:false
                                  SSDEEP:24:ufUJ0uvTYY96ov84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkBBpFUBQ+JgW5I:fTvkY9rkAd4M9/xJfAXxuXBpFUBvfS
                                  MD5:90C0641688A20FC74EA9155D1F647887
                                  SHA1:2C4CD4981B913595F6D654C2BAAD92D19BC5F13B
                                  SHA-256:BF27ACD48C63D97A477147DB9F175FE43735F3B040A06E5B2BCA0DB83E7103EA
                                  SHA-512:778C3D6313EE4206B98DE7C9CE94AAF79517A083211561A65E041196EC2E20D4297CEDA771FE7E7E77299F75C2426E538D7493F1AFE3E6BA8F48D2DBCFD1244F
                                  Malicious:false
                                  Preview: ...TW..f*..fg........5>........[Zm&....QD....=<x ....4......|~..>$.......Y~y...MD...._Huo5(*i..RG..}s......GJ....NU..9%be..%%R.#*....DS.............)HV<3....upD....H^......7@....$Iva..iu8?........{h..fq<&..3p7:......i|J@ /..AXyt.....00...=!.........'%......BBgq............./6|$...4<+...R+o..wbi`S.....25..NA..Q{//.....G..1"..1&D^......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\489__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.376729938984218
                                  Encrypted:false
                                  SSDEEP:24:Hns6GUTEYBPInA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcE/VBBpFUBQ+JgW57:lTTqnxAd4M9/xJfAXxuREvBpFUBvfp
                                  MD5:5D781504D091FC06F2472DF003E839F7
                                  SHA1:DDC40CFC584683E56C3F64EFAD6BE403B277759E
                                  SHA-256:6BAEA9FBA89C90BB192652E4A697D179EDB0A5631D0751AFA51CA3960E618F52
                                  SHA-512:4E0C1147389A42F3645F424AD40EC7536A644090832B20A842E25DF7906D3AC9DA4038168B6B3C0BC1AC7604AE2CBE393CF885F80B11FABFF4CB32DCBCBF0E07
                                  Malicious:false
                                  Preview: .S.....Q.............NEH..+,.ZE.WEyl..zu..............................|.Q].3v\iuodm~...n......v"W^K..~...,%%....]v.....Bq.....JAIZB@....!&&,W.....X.gt..Gu...........&.......#...cu!S!...........kx....+0.............6..........."1jv#$....WW..R....$+...."5a`..zs.....5..rH....s%..|l....../3[J....gr..i|3,......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\48__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1009
                                  Entropy (8bit):7.291206430836917
                                  Encrypted:false
                                  SSDEEP:24:f1GVFQ+cQMP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcgkMJ+JgW5z:NGI+cTEAd4M9/xJfAXxuPgkMUft
                                  MD5:3CB784B8B3AB3E28DF544177F3016FF8
                                  SHA1:3C22C48C8DDE997E0A0E099785A6820D5333680C
                                  SHA-256:0C04623E488333382F9D70113772FA33A5FB58A716E2906C2525067FF6814F10
                                  SHA-512:0C2F6737CC22BD4A27171A8BAB7C1D5E1D70C1BB6EB8326A6C1C0EE4E44B74729ED2A9A52181B16868BFD3640952DE5D552FBDCA8F92EB4B9F201F740080CEF2
                                  Malicious:false
                                  Preview: -....*?................[PEI................r..J..]...3..1....Y....>$..[\=4..(u!&...^....4#fq..B_.m....HW%..<..d2..W}..?#l}..R.........RSjh.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.j...W1..s.HG.k.}{.}{297}{000052000056000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCR
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\490__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.610375231686799
                                  Encrypted:false
                                  SSDEEP:24:46hDErkl6fHLVE84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcyb/ZUzfXF2tA63yr2:xarRZlAd4M9/xJfAXxuibw1EY6fTT
                                  MD5:89743905EE429A1D09EEBD3C73040BBE
                                  SHA1:D7F2DCE4D026D6D06BB82058A6975E2E361DDF76
                                  SHA-256:5C6B2FA387D5136FAA2D8D9484D067232BAAAD543DA5911925FF56D90F3324DD
                                  SHA-512:7CDA51ED4389AC68B75C6A20C24341D2EAE739F6A20A30BAF6FE7CE9DADB3CAB019A1C09E1BC205C6A3A25BDDC078212BCDE8BF6BEE7D0E04C6ECB8A67C26C61
                                  Malicious:false
                                  Preview: K........</.....H.l......P\cnxq>!-,....@grRX..de.D.........zlJ.....XB..@G.....A25..(w....DS}j.....he......=(....FF::'x....PG.....r1..-8..iO......g{....FF...........+1....................WP<(LP..}}~~KK..X.........IS.....epIV..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{N....#...].'.X.}{.}{460}{000052000057000048000095000095000067000101000108000108000117000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\491__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1780
                                  Entropy (8bit):7.62991803474711
                                  Encrypted:false
                                  SSDEEP:48:zTgVkSKFMXoiHOhAd4M9/xJfAXxuDqyBpFUBvfeZ:7HiHjpBAXQDnx
                                  MD5:3CDD352082855AB7C7D1691E04728106
                                  SHA1:FC4513503CDC446D672D9E328700F30B69CEC9DC
                                  SHA-256:13D57059B5E8C5A16FAE2A9BBC17B7AE262AAE008ED00C3679A7317011C4B035
                                  SHA-512:DAF4BD89775C4FF641280BB389AEB586A8E95B8BD9DD0FCD0D8AC100DBD5C37415001863C54B8C9F89EE9295548AEE3595F1C632128B82F1AE793EFCFAD390C5
                                  Malicious:false
                                  Preview: &pt.......*+ljC.dw..... ,.r..d{45T.<&...+!....+s.'1nsjYLz......................BB._....`w..z`JW.\..........>7......UO........EEDDe:........-0..bo9,SL.......km......69..(qCO......3Z...h^m..\\LL..............U..L...ve8.........xx=$>-soebaall$$..N...............~w..SU........j-n8..%5..........,........._Dbk_]RC........s`......(9..NI.....:ss......3,...S.....IQ.....^N....f"......D..PVQV9|......vv....1......6Pxn.Fl:......HW..q5.....#uu1xm..%,N...io.."g..,.q[..HH......p>...BY2..t}Z...KF..ZEHQ."bVT.......;..................=.J.yvJB..bG'%g{..0-_Z.K....NQ8n..<=x.rn..jp..G.DL......=hwuy}....................ik`q....II..&-$7sqet........5.!!rn..zi.............0h..W\c.....59.#_s{TB..'................ggzzs,......CT....h+........3...ICT[....;":7.T..Rx......]ACREZ,bfj......V^Yw..^H.......;dl..zmnw...C..%%+ ......S^PE|c............jjQQ##o|..JY!#..3({ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\492__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7914482746768075
                                  Encrypted:false
                                  SSDEEP:24:4+HYoBG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRb/AUzfXF2tDFvy8Bp+JgW5n:4+Hn7Ad4M9/xJfAXxu+D158B0fF
                                  MD5:64AB47087B726FEB6AF29C7B2D627959
                                  SHA1:9689EE425A3359907D3FFFD110B8E3CCC9966474
                                  SHA-256:FD6BBB557B8557AD5DD9A437290997B62AE3454B7AEFEEDE87895B8DA7EE3CD5
                                  SHA-512:36A02F81022F5B49C9FE239E0B6C93543EDA2307208BF9943D2CF9D4B6DE0ABF04B5AE51A1CD20AEA04305FE228AEDF73B15D2D6976ECAEBBFEA84558521E8F9
                                  Malicious:false
                                  Preview: .M.y>*+.N6!HR....0/..e ......{!.Z..........|y...........j! 1........z}vu......_Cqz....%4>%.....W......<!0/6,VWMJ....yScc....iztv.......$.....C.}66........]]< ....fdUD....}wr&..'.....lhD.k ..+>..........s'......%.....,,&&fz...b`........R..J...&.QQqh...l..WmRl..7*R[..]Q{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.m.4b...ef.L.d}{.}{570}{00005200
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\493__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.683446963703112
                                  Encrypted:false
                                  SSDEEP:24:Reybf2r/dy84tFoze4ytP6qfHSgC0fNSZBzfteJTQR96//UzfXF2tDFvy8BXCL+V:JMd3Ad4M9/xJfAXxu12158B5ft
                                  MD5:CCED1B519D3BAE0BB3A2123D1829474D
                                  SHA1:56F1F5E0C3FA151ECA7CCAA2946C79065567CA2A
                                  SHA-256:6614C8080783A30D5807F3FDB142FF55221984441C6A507F10F7052CBD4A2F31
                                  SHA-512:F9858ED8A788D0C120F6BF53E770049AF7D9D010BBED7DF551D01C32706E857E265ABC8C6305300A4573B692622DB6E760493B88554205E10BAF13E7ACFDAD49
                                  Malicious:false
                                  Preview: x,.J/h........PQ/0hw....zw5>.............cl..<?..7(............T.....rh..43......+.YE....`b..{`>9BH.$-....UE.<..1QQ..........:=AKr&&/$|....}p.J...............IX..%"LFR....D|...iS.?..,1..j;1...||cc...29..`b^O....ZPD.5<..\Z..OY............<<..ww..'6QNi'..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....Bl2..(l.W-.V}{.}{522}{00005200005700005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\494__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.703040090290456
                                  Encrypted:false
                                  SSDEEP:24:wC8p0jMJpL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwVc/+UzfXF2tDFvyv2+JgS:h8xpQAd4M9/xJfAXxuxcR15vRf3
                                  MD5:A3A0D866958EA071E20C502221A1C314
                                  SHA1:B2701D20A436D274F073145DBB07F1A233771CC4
                                  SHA-256:870327A5362DAB8904BCDD9A44378AB5A3864A8BED6F950F60DA83A9A2BB96D0
                                  SHA-512:566D4A6C8CBE0A80FD68BBC69A435BBA6F8209734EF22E00201BD77BF0CC185FEEF634B8555CB0BD1A0F78C57879840A8031A57DDC4CD39E02B2FE2A8D727B28
                                  Malicious:false
                                  Preview: y.......DW.~db...vhzx....jg`i)6A@....V.wb............Gt....5h........fa{rqz\.................._.HE....LBRG.........AQXyjh.mz..@]W.LA..9&Ga....8+{g.........O )....CT6,a|v5..yl9&j_=.@DUc^^34..lp........00.....i~....|a.Z{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...'ws..y....R}{.}{444}{00005200005700005200009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\495__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1252
                                  Entropy (8bit):7.350082718697566
                                  Encrypted:false
                                  SSDEEP:24:LzdYGHeFmQrQRPLj84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrBc/9BBpFUBQ+Jgw:LSDkRPLoAd4M9/xJfAXxu2cnBpFUBvfx
                                  MD5:45FE0DF92743A50CE115A2EB31638DD1
                                  SHA1:4C9BED21E29A1E8A3D2541491D6DC79BACD88AFB
                                  SHA-256:7C774FC17E08D4C7053FBB798F8B13860D1121F8063EC9FC7B93F6AF7A51E790
                                  SHA-512:DAC69EF358E8BB544EFEB6F15EF1A3EC952BFC7A40E0ACA8D78D06A131AB53A776C945EA5D7884ABF2CD4428549C7664F258E7FCBCAEB615B2BBEC981DCA46DE
                                  Malicious:false
                                  Preview: T...T.<=.GXO....{d..;)+nkf..;<5oB...QD^\....'"......*6n?...I....kv....wv#$....&......):..dush.....xq.......?........@F...R0.$...........8)tox.^T.,%.EL8ja/-...pJE..af...}..|g...*.vb.we..v.....ui..]]....#|..7$........8{OB..c|...*../%...1jc..ALd4S`."gg@@....L]{d{5..2j...............,6..08pr....d<...~i`kl:.E.....E.....t196.........c/..N]..}j..wj._X{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0975
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\496__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.816002784694684
                                  Encrypted:false
                                  SSDEEP:24:jVf8nuT/ihqrN8iw84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4SYRd/acsUzfXF2x:BEO9rNRAd4M9/xJfAXxuhdCG158B0fc
                                  MD5:7D90EC7EA9F5FDAB3CC05492481B7832
                                  SHA1:7009365BF8F385F1798162CF7D2DE8C8174BD9FE
                                  SHA-256:761427DD540E091CEB910CFBB44EE7147E99DB56D9847929B6B8CCFE457F5B36
                                  SHA-512:7F2080499C76784A2CE2928E7B5FCC1C1D817505016CDB44E1DC8F6F5D54B521D1447CF41AB20ABBF162D5F4B6057FAD94CB32CA64E35CBEBE72ECF293A4BB00
                                  Malicious:false
                                  Preview: .37"!..c/.......N]......'+..]TPO......E.......Yq*..wj......`=....!;..NI.............fupg..>$...Vjg.....KRlv....fo..#$.....B..O\BU..>$XE.UX....Dv..ruKW......%%.QXO\.._H5/zg....>+vi..t-,-..{b......"u...HO.....R..........oo..KK.........[L+1..$gP]dq{d.....b?..iH..cU<<Z]..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......bL...'.&.}{.}{564}{00005200005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\497__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.671450808888433
                                  Encrypted:false
                                  SSDEEP:24:em9UmwqD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRz/7UzfXF2tDFvy8BXCL+JgWP:emPQAd4M9/xJfAXxuKS158B5fP
                                  MD5:522D4D7B7DBEFCACDCC6E6A8CF091FC5
                                  SHA1:4C7CC35762AD8AA6D111632BD299505D9FBC6A1E
                                  SHA-256:0ACD652EE278A91F63F396D96A25BA9217A43BC4B3D5E55F0215CF2F5646E40F
                                  SHA-512:BB4A67B36BB76AB365E239F598557975FF32C707195627DD18F1C65B81A71BAC9EEB195FEA7B0F52F9E79CF92267B3B8AAABCA508079C82A1C961C310CC7F091
                                  Malicious:false
                                  Preview: s'k..[..1g..,645D[.......@KRU?e1f..7"..........^URM..L.HI......B...............0..zf-& 3tv.."9,+hb...1i...<.w]........;9...TS...].....m..]D...RJyHb..!!..!*............I.W^.E7W@...3M\..;2...*............'6....;1.....WQ3D..jjALW\gTRx--......-1BS..P.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{#.V..'.Jg6D.....}{.}{519}{0000520000570000550000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\498__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1324
                                  Entropy (8bit):6.7120702443613895
                                  Encrypted:false
                                  SSDEEP:24:td/cUF84tFoze4ytP6qfHSgC0fNSZBzfteJTQRo2/43UzfXF2tDFvyv2+JgW5Y:bkJAd4M9/xJfAXxuf2t15vRfG
                                  MD5:3964E091ABA32E4B9B629EA21624F33E
                                  SHA1:A2A9C7D4A8B4579917B0FD9BAC19FCFFD24521FD
                                  SHA-256:84DF894161916CD96E67C5DBBD6F40E74EA61DED16AE5804B13E0C3BE4CEDB9D
                                  SHA-512:E5BB202CE47016E85363926AF03003C23D0645AA6D646532D51A78027F5C4FC231C7AF448102979D760C28FA1FD2B4A21B4505C7C0D1ED964E4F1FE5820DD985
                                  Malicious:false
                                  Preview: ..".i....................ru.\...xm......z.........h9..G@l'....= whOU....`c..1.aKLP........UNMJ=7V....Bu.iy.mN}0.{{JV..:)&$..RI....`4...E$..:#..R...}W..||LP..</qs..[@@G...Sle.......(90-...B.$....PP$$......Y[....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{W.Z..F.O.VT...T}{.}{434}{0000520000570000560000950000950000670001010001080001080001170001080000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\499__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Sub-key -
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.352197718754569
                                  Encrypted:false
                                  SSDEEP:24:4g4qMIPTkpasjXyW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRuk/L/VBBpFUBQ+JT:h54p7LaAd4M9/xJfAXxuFkDvBpFUBvfF
                                  MD5:E8EEF96A8158049034B9EA5385994E01
                                  SHA1:FB6A3149622D4F5B9ABFEAF1499FE7923C2980C6
                                  SHA-256:F486100773D1EE8EBBDC97F6FFE552B35C45176F487D7DC653B6E392D547865A
                                  SHA-512:92AEC7AF96833F41D5585D2761E14C16DA965F5DFC0AEE3EEF7104C09BAFF8E8E8B07C4C1744170780319B3895535A33B265DF91D812BF3D2A88D5FF8E6AD05B
                                  Malicious:false
                                  Preview: ....\..H.ER........{>EH...........JHOH..}x..JAYFth.......?bC^..`z89@G........c...TGprN_....ys.V}t1ip...{]..<%......hd.....yy..386%.....DC..8l-$.G......S[.........<<..id.}............... 3ZX=,.......{r..L*..gD..........|e>-a}BE..FF..NNf*..(e......ct...6QX...........3?....JZ..@g..C_....*/sf......43az....ud]Zoo..HH.......n.+0......2.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\49__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.411216193919849
                                  Encrypted:false
                                  SSDEEP:24:fHYhPW1YMxL6J184tFoze4ytP6qfHSgC0fNSZBzfteJTQRk/VBBpFUBQ+JgW5r:fHYhezxAd4M9/xJfAXxutvBpFUBvfZ
                                  MD5:0C2E4F9DFDB4C113FFA308D75FE62A6B
                                  SHA1:1A7CB126C18D7AF4773CBBD88E7FE9DD943B304A
                                  SHA-256:1041DCD8B7529463B3DFBF3DC4403A732A6C0543BB0E8E0F6806290ECD86E352
                                  SHA-512:DE620DF8041370CB09078E64882037087C76966BC51F9F114C83BC0B4B3D4B950A83535D02B38E548B9E49A8BFD046E02180F0CB7B1E741349F6927E859B6A36
                                  Malicious:false
                                  Preview: .I...._^.fqd~........w2........=jft......$+SVPS@K............':VI..........Zi........DF..........(!...lN\Ga$$..cH.....K.........ra....qj....|(...F&.O~OF...F....XP...4%8...D..F.........MB\*.J..GGmvjgf.....O|..<<__...%....XI.....h<....%C*9......v|oI..ZCDW9%TSCC....II.bS@...4<..gp)(...........16..........p`..&$.....O....RW?t..AC....al...LK/4....=,....cc....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEAB
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\4__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1317
                                  Entropy (8bit):6.7424744916773935
                                  Encrypted:false
                                  SSDEEP:24:g0ye4sdRVmV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKV+UzfXF2tDFvyv2+JgW3:NyY7Ad4M9/xJfAXxuLp15vRf3
                                  MD5:71FF3542E92CC4FAFF2357981C696704
                                  SHA1:6881E62F9D7C9EE78DEDEA0D3E0CCD99D9C56552
                                  SHA-256:F14F4D0394CE07644F040DB1C3A7E00D7EAC041AFFD191DDD677471B4CD3ADFD
                                  SHA-512:F2491BF74BDE74C6904F1CF5F5A120E0C9AA8E92E262C98D1DACEFEA667E265D1D9C525A64982FEFBC190B404D8EA923A0C4955AF61782E9F2874D96BF4E385B
                                  Malicious:false
                                  Preview: .*.fe^K...................- ......u>..;hN[....de....\J...9k]fp4i..bx..>9.......HH....M^..yn.....\la(=........_XXX..e:......=*xb..j)..^K..(.!!...._C..............qk@]..IDSF...............OSkl....cc..{$........"8...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..yy.R..!..9...}{.}{444}{00005200009500009500006700010100010800010800011700010800009700011400009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\500__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.35671781214176
                                  Encrypted:false
                                  SSDEEP:24:kAhnYMVFQ784tFoze4ytP6qfHSgC0fNSZBzfteJTQR5klhmlxBBpFUBQ+JgW5e:LYMVLAd4M9/xJfAXxu0XVBpFUBvfk
                                  MD5:5E75EF4582C15079060ED2C07C32BE5C
                                  SHA1:59242E842EC67961F9BDA8DB8B22CA58F752F8D0
                                  SHA-256:CDE5F0E0B52AAF5BED1888620B514174AC76F5965667592A5BCEFA4800A4282B
                                  SHA-512:5E4AF1C5D24C8866AF9702C9E30182B5ABAA649AB4E4BD1F19D41C9B95A1CFC67BF2BC71A2AF5E846ADDCC7AC10A6746DEC45A7DE4F59090612316E7CE429313
                                  Malicious:false
                                  Preview: z..}~U@........ >............-,.J.4"q............(>)4.'..1'........try~..[P.F..RR3l....5"............n`....LU...&..YB........kk..\U.......HU:y...ivVF57..Mq....r...........m....?.-.xx..KW~u.._]........l8..1i.VE..us....bD......thlk""...ZZ;w....YV@HB]CT....ofcA....lSCD?.0<........vvB.3#\^...,0,.FC..;6......`{{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\501__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Sub-key -
                                  Category:dropped
                                  Size (bytes):1277
                                  Entropy (8bit):7.400843183743275
                                  Encrypted:false
                                  SSDEEP:24:aWhtmag93nB8wJxAiW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRYiBBpFUBQ+JgWk:dyag93nDRLAd4M9/xJfAXxuYBpFUBvfk
                                  MD5:D847EE9ACC3D76AA509CEAAB6C20248D
                                  SHA1:76B095FFE2DD51253EBC80FE444CA8CD01A93532
                                  SHA-256:EFFFFDF051A9BC7DAA91D686A1F8D977A5A80C52AD1B9105227A18FEB9F28F08
                                  SHA-512:412B927A383DDAE04F4583D92CAC705A4BCAFC4F6B55DDAD66047EAAF71A89D02AEC60A168EF3A97B0709ED2E27282B3A6CFE6AD75A35816840E9076670F9EAA
                                  Malicious:false
                                  Preview: ......jc/s`..hn.=......)%.....1..@.QK[.............<!.......K......)/VQ..........'4&1......al..fys}htV_....\k..yb\J....bb^^....ZM...............LC57..........3Ek2fjllBY..f...B0..gMwwOO..)"....?.......W....'D"wd....)&mg..BB......25]]vv..gg.\..u8CL..}bva..........UU.*.......I....rm..........oj..=07"..61; OF..@Q.............<>..YBMJ...._u..[G......0<..\?xctl.?[.!w[V....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\502__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1283
                                  Entropy (8bit):7.3754061904155135
                                  Encrypted:false
                                  SSDEEP:24:xh6u43xSmbP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRyPMIBBpFUBQ+JgW5s:/6D3xSmwAd4M9/xJfAXxuRNBpFUBvfG
                                  MD5:6D779AAA7D74ED2462734281D067774E
                                  SHA1:AB1316628E3DB1F9131173F6D828EF58AD9E3DB7
                                  SHA-256:060F65072C91669C9E59D7209ED8648A07D50EA90A5E154A3FA696F52CDAD082
                                  SHA-512:D06094BBB99580BB6336EB6E35494B994DC9D7064945E7C9D8A7BD80B5B0AB926B0FF91ABC44977EEABD48C81D7D25EE9655E79BBA077E69C69FAC030CD22EB9
                                  Malicious:false
                                  Preview: .'#.....?,......(6'%..DHr...FY..t?&<d7..=7..01...<*6+Zi..LZ.ca........'.ja................,1.......<2........OU..H^.2ni..CC..(!..4#....f{.....1%.TF......A[]Uc.......~s..TB..$.6.dd............=&..xro;......aBOI..oe..BB.......)..&&..gg.........a~............cc....kQ......VF*5.........nu...........KN..0=QD>!..XC........**YY..dw..`sSQ..~e61...*lFpp..........}q.8[..ks...J{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\503__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.360623905498773
                                  Encrypted:false
                                  SSDEEP:24:XsQgaIWh8pRLj84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8I7nBBpFUBQ+JgW5k:XMZ7sAd4M9/xJfAXxua1BpFUBvfe
                                  MD5:2527F0E1C228E10DE00F4FA2AC80FE99
                                  SHA1:897AE687A50059C4C93D72A0F4FC4D507F3FB27D
                                  SHA-256:D075FFF99C1F57DD0250F5449B8DD959B3EC9769122081E385DD1823AF28BB07
                                  SHA-512:191E2E1EF1678FDD000F7197EC70B0AD401F0CF367DDDD4B6DF2B36E81810E8EAAAD0FDE8F4E697868385EEE5F6E8C7E24F845042C723E419ACA000480C092FD
                                  Malicious:false
                                  Preview: "....at....^_..B.uf....NE......deD....Q.......0k..0-!........D]..BD9>..}v........BK..W@]J]G..~=ALmx$;..rn/&....%.....';cd..66..~w....`w...b.S......nY......1(..j.b;UY..<'P]....K9......@@..P[..64....mj......Y..n............RR.........--...........qy....SR..YP".............\....WH......5$...................ap34..JJYY..neGT....YB.....-..nn..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\504__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.3826838271629684
                                  Encrypted:false
                                  SSDEEP:24:vpu2peajr+cesEYOvNlr84tFoze4ytP6qfHSgC0fNSZBzfteJTQRf4NxmBBpFUBD:v0sqVsEY8NOAd4M9/xJfAXxuIBpFUBvb
                                  MD5:698CD1AB4EC81E2F690AA5F5A3330103
                                  SHA1:E19AE3B3A4C7136ADE323840167FC513320FC036
                                  SHA-256:29859BE3F91A8FE60F04F079C09F9F55384164E4D40F5B9B11DEC2E967494F69
                                  SHA-512:7317843E37AC50B6380E95CAF839DE7CEF6C0D323B60DD496BFC3BBA26B73E4F2B92722FFB26761F0E82767E5EA24ECE7F6E6D18EE4820488A9BBF207F3A8682
                                  Malicious:false
                                  Preview: .....R:;....;!..&9*5..(mZW[Pni5o:ml~SF.......+........U......e 1.......=<;<.._S......en....N_.......T..!yf.!3x^.............dW......NE............V^W&~a.fy..oo....UL...#z......586_....xK..xxxx...........Y^CI........CP......&,......DW......//rr...F....%*&.......Ru6?.1?9==Hwni....s4._...o....GV6*..1t.............K^..be.._Vki......>>..0#..EV...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\505__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.772268857050762
                                  Encrypted:false
                                  SSDEEP:24:OS1ZX0oDiCI1b184tFoze4ytP6qfHSgC0fNSZBzfteJTQRIFUzfXF2tDFvy8Bp+d:/zX0oDhI1bGAd4M9/xJfAXxuC158B0fF
                                  MD5:0DE6328C5266051097938BF9499782FF
                                  SHA1:5F517DDA03CF41F4ACCC7E944E05F42A75BAA49A
                                  SHA-256:4D4ADB1AB070C3C804A622BCD1DF49AC351D2196B89D53B5BC30964593EB80EA
                                  SHA-512:0D86F08555B84D14F5A689993B731CCB259986E93D688551691F770DB10A01EE065558914E07891FAB17C094D7FF759B55325415453F6359860F1265E08E15B5
                                  Malicious:false
                                  Preview: .]..Z............B]...X%(.....q&......pw_P %..ry..>"...OH...f;....Z@....EF........;0L_vt....Y^......{.0-B]..RS......)##....EV...?g|....)}le...##......3.......lg->.......x..N....w........e.......fc....#=FH.P..c3...._l.&OO}}...bi..RPq`......u!...- .2..8!$75JI^xB..du....4h..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{%2S...h.-.0!S..]}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\506__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7122319036358435
                                  Encrypted:false
                                  SSDEEP:24:x5DyaMHdOGG84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/ycsUzfXF2tDFvy8BXCL0:/yieAd4M9/xJfAXxu5G158B5ft
                                  MD5:023542573DE6BFB816B9609614E84977
                                  SHA1:8EF04323035FD843CF8400CBE1336771DF88320D
                                  SHA-256:FD6D09213F86B56E9C017D41D6F70D3356CDEC21FDE2F0490FB8E5F268043D98
                                  SHA-512:F95F9158B172BCE755D6FA7F54BA3705474C2F3243AF1CEA7260F6DD38E4B52622FA5D10CBCBE7B5707E6FD18077622C969F2AC3586A827B1307DEE05D09AA7B
                                  Malicious:false
                                  Preview: ..........d~:;.......R....WP.I........"%naKN..RYhwHT......"3.[4)....JK.....Uf'.......qs.....CI...._.9V......W}..................^...D..........5...uu,038....bs...$.....K9{l.9....1,..M.!...YY))..UI../<........xrJ.....|z...SS....).==''..BB..FW...S_{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....Y........}{.}{522}{00005300004800005400009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\507__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.696644470834107
                                  Encrypted:false
                                  SSDEEP:24:o2puuo2d84tFoze4ytP6qfHSgC0fNSZBzfteJTQRyFdDUzfXF2tDFvyv2+JgW59:o2pu2OAd4M9/xJfAXxuFFM15vRfj
                                  MD5:D63E935532DF7652A385A78981E4FAE7
                                  SHA1:D0A35BDB0B06EDA34AB2B519FDE9AD3A95861009
                                  SHA-256:028B21233E161C425E9D7004A927AF72A7193F48164D7ED1ED9CCF3DA0CD48DD
                                  SHA-512:577808DB6C56CB6B2FF5DCC01F9A1F8EDD7E78E04BDDCA3FFCAB6E152E4888A364F815996720C3CE9F0375E81E49279A6B0FDEDF1EE3DCEDC33ED6B52E0B438B
                                  Malicious:false
                                  Preview: ..PS..j&->23.....@^..;0......op..m&7-..}h......A.\.....Jy5....@02(1..vp&!..;0.....g8...............#<..!4..8?.....\'.....VACY..P.....y_......IUHO....!!n1$-AR....E_...J........'.....WW...soY^mm<<ff...SI@~m......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...SRd8f..N....}{.}{436}{000053000048000055000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\508__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1782
                                  Entropy (8bit):7.611280713993648
                                  Encrypted:false
                                  SSDEEP:48:S7e5WTRM4UME4agk6iwp/+JYIimKSAd4M9/xJfAXxuABpFUBvfy:d5ER0IikmylpBAXQED
                                  MD5:F557BC9302CA69D243C9EDE4A48AA9F4
                                  SHA1:3C131F36DDC7B8EDE1431CFFE055F32684836801
                                  SHA-256:55769E2F1C6A298503AEEF977D6462C28654C5BD491C7B555AD0F05F7E808547
                                  SHA-512:63D047365B881D3AD7D061993A34B4D87FEFB5DF386CDC5FBE0439137DAD7B9A464B059B914C9B1AEB279926C80AE9F99C7DC3B6C5075CB6CE76E7F2626EBBC2
                                  Malicious:false
                                  Preview: .RV)*mxy5VE`a{}|/..;%75p{&*....XG+*.......)#&+()..JV@....uC...R........61........QQM...qb...............VXJVpy@Y............hh........8/>)2(...H......,.....__.......5Cu,84.........V$8..&OOwwwk4?........;<39z.#*(pJ,..;.........77~gjy)5..GGGGGG.......2=AI..k|..................'+#df0XU..\C,&.>z.j.j..................*****6e)t}n}.h.......[..))))))..!2-`.!.......xr......t,3 31..PEP]TApo.....................!l......TuO_..J]Y@.........EV"........N[...................c/.......:%.............T.k?.[.YM.L............c&WXIz}W.........6xw{s+........,.....CT......x(......^Z@Y.....QYXMS........:~|8=(..foz"=l.......qB.......dm~mox..JPWJ@...............3)"?5v"/..]B....'!GG...^WN....r*84......g@V..8..55....CH1"DF~olwho..~*..x .b..Rqnh..EO......ra+7vq.........D..c.EJ.........%kb....YY./]Z.._Sj-...wgd{..........P]:/..,+..EL....fa......*9......j{LW.....$.1......?...P.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\509__CellCore_PerIMSI_$(__IMSI)_SMS.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1296
                                  Entropy (8bit):7.0674965003506625
                                  Encrypted:false
                                  SSDEEP:24:bPEMPnlwih84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQNz/V4vPXj+JgW5t:bPXCiyAd4M9/xJfAXxulmnifv
                                  MD5:AF71585CC46C66ECC7A1271FE75F0EBE
                                  SHA1:F40ABAE7E8F67835D0F6EA9F48D86E7F4B77766A
                                  SHA-256:C2AF79805A0CC27FA1FE856DEC1F1522F39DB6B8585C0B323C013FF7F664DF32
                                  SHA-512:6493B7E9296A7C13A74C03099782DE2F9342FF74002E18079659AA2BBFD46B9B6227546FA18574456FF11F438ABA5419E65A9B7D152ACAF4A804104A4B878850
                                  Malicious:false
                                  Preview: ..:."e98.]....no.................LY....<3..ef4?ju..f7NO.......B..qnis....NM....."....o|uwud.........m.....jYmGzzIU:1fu......%/.ZSq)........8...............20xi......i=-$..........th 'ZZ.......QXxk....!<.....;$6:..uq....yJ...HH..77............z}FLz......................ll#|(!WD{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.-..=K.....7....}{.}{583}{00
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\50__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1252
                                  Entropy (8bit):7.400120044481465
                                  Encrypted:false
                                  SSDEEP:24:fsz+B+l2k+eET84tFoze4ytP6qfHSgC0fNSZBzfteJTQRU3edBBpFUBQ+JgW55:fszs++xYAd4M9/xJfAXxuR3cBpFUBvfL
                                  MD5:DDF2B197DEB1E1CE5F94CB9EBBBECDCC
                                  SHA1:6A495C85E8D48105BF5810371A6D9361EA6746B0
                                  SHA-256:C644C32E46F1F15BC0151B04901F9A89C6B064D9375B9A8C02A98315A51AC5A0
                                  SHA-512:A5A75FAB68A0D9A1B31792AF840C754F8CDB9524F0CF8F9DD4F8DC92C5D5C740B4335B8AD5CDB621F6A0D403260EA2D13D4CE8C07AD0DD26113EFB06AC4C8579
                                  Malicious:false
                                  Preview: x,.u.BC..........7(bp(mOB4?..e?.R...........dg....wk;jJKPW.^O..................!..92@Sca....70-'........]O'.AA'>......r~i8........NE.......<;..c7ah..&Aitgl.tY....?7.........m.;,......p.p......F].....p.{HQ{......GL..#!..3(....k?..,t.... ...........pl..rr......T..<q....{d..rs..of<.NHSS".&!..$(b%..s~!1UJ:-.....k`............D[..ZA&/......{{mmBB........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF8
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\510__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.797811098915557
                                  Encrypted:false
                                  SSDEEP:24:OzXt409z5B/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRqKUzfXF2tDFvy8Bp+JgWF:+4ywAd4M9/xJfAXxuB158B0fF
                                  MD5:0478992B9B2583BD74031311F39BCD39
                                  SHA1:A055C8D650B59CEDC259FADF1B6268A4CACC7865
                                  SHA-256:22C9E89AF579C189BDDBC1C36A1DD7467D81CBBD49B58B7B1302648FA14F2B99
                                  SHA-512:E4CC8A0A347551CE48DEAD46096A995FF19D3246F3FB0ABD8BB2B3026E66D6B9DDF09DD9ACD85AE92816C9890F63B55E8BBC79448FC7294976B368779D3F7B78
                                  Malicious:false
                                  Preview: M...,k"#......JK..D[..2wWZ..$#..............]^....< o>.......)t5(|c0*10......wD......ev,.......~t.V...F.}dy..OU../(....Q{<<pl1:..!#..e~@G..\...3k#@....].m^Ka..PP?#gl........PWOE..[R...\.Q...O.o$....p"....sm..t ......,.*.99||....V]..pr}l7,.xGM.A....... ..6/5&......1...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{d.-.`!.&....E`_}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\511__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.696082897124674
                                  Encrypted:false
                                  SSDEEP:24:SoitBvLd4UbggA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPZ3UzfXF2tDFvy8BXf:r8vLd4UXAd4M9/xJfAXxui2158B5ft
                                  MD5:3200C70B830CC3427013FBAF0296A4EC
                                  SHA1:99CCD0B1249C0AB268AA3A9138D40F04A27E1F55
                                  SHA-256:4BBE63523CC2D08362CE3C32645238AD0E1730F3FC5319CB4C359A0B7DB5611A
                                  SHA-512:840917961B9482EBDD8E2889D51E19628B37BDB382B4E39CD070B616D54529D4CBCDCA03C322B1622DA9F22BDBF6808D3AA13666779489D055505276EBC299D2
                                  Malicious:false
                                  Preview: 5a....{z.]re..HID[..dv....|w..\..I[....yv........b~.Z.....\...QLrm: ..st..UY.. .,0..>-.....WP..})...L#......$...]A5>PC><..nu70...F...S..`i|e.....Oe..--(4............<6's_Vl4....*......I@.Mh[Rx......5)bi!2?=\M......-y%,...l..........>.!..........FW......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...b...>. .Q..[}{.}{522}{00005300004900004900009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\512__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.7039593102042545
                                  Encrypted:false
                                  SSDEEP:24:RdLe2iYLFw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP6zUzfXF2tDFvyv2+JgW5O:vS23FhAd4M9/xJfAXxuO15vRfQ
                                  MD5:A90DCE6473B8DB559980299875882BCF
                                  SHA1:FC1BD96DE5EDB0763A4ABF343299F7084E28D7AA
                                  SHA-256:9B98FF961080FB4CAE8CC992C0D2985DC508DCBE1FCF5C2270F48B2B128A6F1A
                                  SHA-512:00011E136B346215524E61CC834E022772504D05484E1597FE29D0CFD8F5F9BC852B092920C756D49BBD6A7AEFAC7BC4AFE3A5FFFA06B575C597A40D5FCDBCF6
                                  Malicious:false
                                  Preview: ..u.P}|......jk........JG................cf..........8?..2#.Uql....01..spkg.".=....yj............F.....-I&.+.%%-1.........&!!+.Y................MMdx....GEq`RI~yV\.....A.yny.3IwCR......3..kkqq.......DF@Q..52{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.w...HE x.....3%}{.}{439}{00005300004900005000009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\513__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Sub-key -
                                  Category:dropped
                                  Size (bytes):1313
                                  Entropy (8bit):7.440507816153138
                                  Encrypted:false
                                  SSDEEP:24:jOB2gQm+2rVAkFU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPj0BBpFUBQ+JgW5y:M2E+2rVl1Ad4M9/xJfAXxuuoBpFUBvfo
                                  MD5:9DC3CF2342409CD95DEB1DE2259274EC
                                  SHA1:D4E700E64364DB6E04B24C5AFDF05F5806CC2A87
                                  SHA-256:D3EAB0DC0CF3CB510B18ECCA86D9BD652A1DB886C02A3A26178AB02DA6E4988E
                                  SHA-512:39243D9E96FE2254987B0DAAE1BE933755AA427B729FA2B78270720A1CB3DCA8E4F1DF6420606AD27B211C8D44D64E5629BBBABBF0D525734B410CDA96B130E5
                                  Malicious:false
                                  Preview: .sw.....:)bc &i:.......=1....fy..n%A[d7{n..yt..-u..+=...(.....P..}d.............T.......4#....E.- 6#....HT..y`OB..../9..43ii..${.....k|..kv..^S.....1_Zcj_T.2@{.../!N.. MY..juA,...........,,Z.JC..........k(CN..nq..Fcqd......qx....\..+............xgx6`lA.-H....S[.......=;........"5..m5.G..^I...t0..bw....qw..e ..&......jv..v.........zg.in..vv....cp....+#..[v.......i~_F....TV......FY!&..&/..ET..yy......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\514__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.769774012589984
                                  Encrypted:false
                                  SSDEEP:24:uWSnLLQNuRHl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaKxUzfXF2tDFvy8Bp+JT:uWSnINusAd4M9/xJfAXxup158B0fF
                                  MD5:C238439AB2F11F114EA5E1E1948E89A8
                                  SHA1:47D8C243FB4B81DB8B6979AC35ACC7A53BA11E79
                                  SHA-256:317AD20CCE7C645482A180654B5623592ACBB1FE43092A57F8FA09C467DC50EE
                                  SHA-512:FB290ABE58EEBC437CCBE94E7069755BD2E7A641563CA638A25EDC3CFF1E1CCD02CAC3224B85468CE0069775C8DAEFCA6156AE87019E27E2B1C6FE018862F6A8
                                  Malicious:false
                                  Preview: ,xG.r5........IV-2...KF....f<u"8*.......SV..SX..........D.HY.L0-....}|..PSp|1..-..k`....#2..*-..W......ydqn`z....L...Xr__........RC..70..{/md....33...pC........ib^M..........J.7>@.)p....... 57e!$..=<yg86e1......!~..*...........qb\^............GKF........~.....o~.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..SUK.5..Ez2H..>}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\515__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.711782191027864
                                  Encrypted:false
                                  SSDEEP:24:WWb0+Qt3Q184tFoze4ytP6qfHSgC0fNSZBzfteJTQRPiUzfXF2tDFvy8BXCL+Jgk:NgAd4M9/xJfAXxuK158B5ft
                                  MD5:7CDE5BBF397FED76D84B736C61870898
                                  SHA1:E3FE0BEF8FF4A419DD112E06F13D9119E9133D90
                                  SHA-256:924265F850B602FF7FD8563538D9C9A43DF7E4BC615B3C36208AA69209B7AC3B
                                  SHA-512:D970978CC4D787046BA7831486A8817AD714FB46EF3AE751D4F21AC616D5CB1BCD15B5F67AD9222BEFE1B9E9EA0366DB0CA99D6FB4D68B2A8684FE53A71AEA3B
                                  Malicious:false
                                  Preview: j>.'.AnoV.ox...........hc....................~aYE.C..07C.(9...........30......#(..31....vqgm..........gtGW}......YJ..hy..........*K.......O.&.)......`k6%....$?...._.......yn...6vg..el....Sy......:&fmS@JHGV\GY^IC.u|6n9?.}......38..ySoo==.............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....o.tP.y...7..}{.}{522}{00005300004900005300009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\516__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1328
                                  Entropy (8bit):6.712680766527938
                                  Encrypted:false
                                  SSDEEP:24:ss3mZQYz84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcr3csUzfXF2tDFvyv2+JgW50:s0LAd4M9/xJfAXxulG15vRfBs
                                  MD5:F0DD02BE6B1B266291F29CBCEF2298B9
                                  SHA1:1F088F755021CA78FF799AF7FB46871B29DD0318
                                  SHA-256:F091E3A38625B21A994F6B09CB18EF34298BB9DB1C9F5682E534092ED8AB958C
                                  SHA-512:D280FD26D2DEF35DD8EDA6B68E6F3177FB0D13620BE7E9148B1FF929D0498F2A2CA13533C665FDE633FE5C21B37DB0603CB22E51195EDDB9D539AB7070B570DC
                                  Malicious:false
                                  Preview: .m..Y..a7?(LV..|c.....................NI....{x.....S..,+..&7..ZG="\F..............38..nlyhyb..>4.+kb..wg>Z............SQ........2felH.a...tm\Q.W3.......>"........"9..6<....W..Bx..GV..V_..5.>.EE....ey......?.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....>QI7W.(.[X%}{.}{442}{000053000049000054000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\517__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.376541093809846
                                  Encrypted:false
                                  SSDEEP:24:oz8MnEaGqUhxNq0HWevrA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRU4BBpFUBQ+P:oI2N7Utq0HWGAd4M9/xJfAXxuSBpFUBX
                                  MD5:F8F8B7F5DD31CB92B02DEB51AFB18F5C
                                  SHA1:7107929247FD96FB4D3CC073426EB8831779F994
                                  SHA-256:764E6629CE8A2E6195B8E5E550A795BEF9225305A3CDFA378A06B12BDCB95A4C
                                  SHA-512:CBB2F8A3DF0FCB29BDCD63E655DFC2D79502D80C299C2A6D903CC91249A14E68A63F1C285D2A89F9F26053CCE7E69CC879BD5F048539736D37F40712B3316A91
                                  Malicious:false
                                  Preview: .._.......! ....FT.........&4"7..|{)&UP.._TRM...UPQBE...............84..v\..BIL_...................&&........S_<m..Eo...........`{..........V0..DS`.5<..=p....lk..Dr?+..PB..~.2%......EENN..u*....va.......)$:/whjK........(.......'w.1..%%......;*..5{UY6n3V......yybtX{.....5KCom......I.TW.11....EZ..?r..........]HSL......DFM\..............FW.."%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\518__HotSpot.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1015
                                  Entropy (8bit):7.289451912220905
                                  Encrypted:false
                                  SSDEEP:24:FuodO584tFoze4ytP6qfHSgC0fNSZBzfteJTQReegkMJ+JgW5z:FucAd4M9/xJfAXxuWgkMUft
                                  MD5:7BC5C4A47FFE45494367D850184A3847
                                  SHA1:933F0F607BB96FFB9971938076351C34C4FE168C
                                  SHA-256:B889DF29C37D960DFFF0CBF515648A4299580EB63B98E043B10B707A4E606FFA
                                  SHA-512:25F5CA16D0D0BD758453BB53324C78E2549C97BADD5AC540CB2F8428EA9001F75B8EFE4BBDB9072FB8D5BE056345B0EDA46F89E90229625761B7D360768B30D6
                                  Malicious:false
                                  Preview: .+/..WB..9*..SU............of....L.Z@..........*q..SN...IOY{&46zctnoi#$2;.......7h4=........orn-......3..3fy8n..(.&&....fy.........TZ..`b%2....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Jw...V=|....%.}{.}{297}{000053000049000056000095000095000072000111000116000083000112000111000116000046000112000114000111000118000120000109000108}{bNbWbPbRbWbNbNb0}{4}...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\519__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:JPEG image data
                                  Category:dropped
                                  Size (bytes):2346
                                  Entropy (8bit):7.741474269636064
                                  Encrypted:false
                                  SSDEEP:48:XOICxMeickiRMWHiWM3BaLXbvL7VHfRAd4M9/xJfAXxu6vBpFUBvfE:+FOHeWL1xUXbvXVH4pBAXQsh
                                  MD5:75F5B7DF7FCBD803BC22911C98E9D7E3
                                  SHA1:DE9C36FCBD7961D11F8EA07FBEEC0FABCE231F2A
                                  SHA-256:A912E0791F4828BE899D8F0F7BAA57C8AC419643E7F0D01C19644F64C02DD021
                                  SHA-512:D083614130BEEFD559667EC979ED2E2AC0BC3CE9859AFD60AE4E17D906642BF052ABD471319BD666D835D66ABCCF9E32F51C6C66B80A9DE60F1BD93A97F563DF
                                  Malicious:false
                                  Preview: .......Y...23..V.....LNjaZVFK18-2...RH.V.......H.2$jw.......E&$..2(35KL.'...Vqv..................ux_J..ke.........*..pk..XDqvkk......6!...........FY......$7{s....qv...(..=Jzh...n...RNEB......I..ufAV2%.....JGzo..gFMh..'-dk..levoKF..fUoE.........EZs=FJd<m.|~D^U]..MM....*,..kD...........ii....5'..)...R.UD...........vq........~y........evDFO^..ru4>Ve'.........YF^......9"KS_cs?..P]..~a..D.N[.....K...........Zp......<-.....y!..btW.k=..(8KT...n5).....'6>3........QNVQ.....,=..LL.........XW..[D.. .....w`.....)...0$........O..[].....yJ....((..............rm...?.._\.......M..N....H>!....hqwp..)y.... u5g.......NW..........)......Katt..)e......3)-0......ww..w~........~=........"=..AR..(.wdho?s.....[I......l}nr...~~.....&5....{a..1r....VI.6UpXM.....%........m^zP..BB..-1......<0.._:........WW......<.....w`...$qxx e....OZf:.. v.R|i......X...70b'....[q..............BX =t)16..__""I.@St9..ia...<.....$........*9..fc..q|U@*5....,%....z}ww.............kJ2".....
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\51__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Key -
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.377766650474088
                                  Encrypted:false
                                  SSDEEP:24:c3iwk9T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVeBBpFUBQ+JgW5x:c4YAd4M9/xJfAXxu7BpFUBvfj
                                  MD5:656C8401AB8C4B8F71AA23D5F9D77740
                                  SHA1:824020C945E4246A6181B629D16D15F5FDB3017C
                                  SHA-256:3AA5B6C7692F686ED3A792C9C4609BBC4DA62214C400EB9C7B55A87BDEA1DE2D
                                  SHA-512:31F0219E53EFE8A70D3BD3AB42DC9C296A3946E7986E1770D84BA7F185CB6AA66D099612D7D704FAB36A0760AE61F265A771F393DF24DCBEB47BF4B9306638A9
                                  Malicious:false
                                  Preview: ....m*.......a`*5.....X....ebq+.<.rg64..IF..EF-&KT[G......i"`q......ih......5...RY..;9KZ..AF........N/VD}[..F_fu..........%..PL..%6....|gST......x .j....!)oB........6!...w? bmm..ML@''.....}.................@BkzWL.....W.."z....>........11......pp..............S[.......%..Xz.. ..lkF|}qJ..............ev.Zi|7"...V{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\520__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.392795266788061
                                  Encrypted:false
                                  SSDEEP:24:XJp+UUBzTAN3Ebl4P2+S9vkr84tFoze4ytP6qfHSgC0fNSZBzfteJTQRInRBBpFm:XJU/FTANKluShkwAd4M9/xJfAXxuBBpk
                                  MD5:01894ECB86A20FD5CCD53ED52F15D3BE
                                  SHA1:803EDAD9A9220C113BE30113B2B6FF4461C8C55D
                                  SHA-256:D55BFC0B1E8B9D4790D79B8F584A96DA2DCBEC30BEDBE4AAD580E633FB3240B4
                                  SHA-512:2AEC0CB1E184EF63A055CDA27C564FDB675FD36012F442FC1B9BEBD637B05FDC255F50F9A51DFF67AF687756A79BFF8E42D1CD00C8FE23B956C393B66EF6AA0C
                                  Malicious:false
                                  Preview: 5a...J......wvvi ?:(.kM@=6...7`.............U^....S.................rs....P\...'..}v.. "~o..vq]W.U..]......"...}nlGHN..S.(...++so....HY......dm.I..BK..~v.. 3tsL.0....r..WH.... <..ss.....VngO\....-0.G......?...........?&...V..V|....77;'ap..5{W[(p..75....!.22..X{....dKOG...........p{u#.Ccv......Q......Pc...........=.....%?...TS{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\521__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1210
                                  Entropy (8bit):7.365159584735765
                                  Encrypted:false
                                  SSDEEP:24:68AhrIYlBtPV784tFoze4ytP6qfHSgC0fNSZBzfteJTQRPFKQBBpFUBQ+JgW5J:6N1FfjAAd4M9/xJfAXxu2FK4BpFUBvfb
                                  MD5:C419932271912068CC34FDE72A2D2200
                                  SHA1:64FB07FF17898338C797BECE79D3AFB67A8C101A
                                  SHA-256:45FE9CB04130DEDCE41AF25907FDC34A60D0AAFA2383785631C4F77928BB4665
                                  SHA-512:75DDA4A26E3F300007E5AC575619D76407ECBA264780FF41851BE185EBEA985D7E42BEF7E2B29CB682324276E5BDC10263DB2516A7BDC1FAB9C23802EE4E2163
                                  Malicious:false
                                  Preview: z.p.f!..=k...........Ns~do..,v..M_........rwmnHC&9)5......Jzk$yZG!>/5..52.....@j..=6....sb....{qq%....z.....&&..yj|W60:6..#.pZ........KI....KL......Hy.....9.5&....(.bvw...........TH"%&&....${:3JY..2%[A..."/)<RM...#6..{tMm....&+.Y..Ka......%9....c-..A..omNT..4...fp......~Q......JS..6cxx....._J.......y....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\522__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.3732288038749
                                  Encrypted:false
                                  SSDEEP:24:75zT1WsoB0ruLv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdkpzBBpFUBQ+JgW5e:d0b0rugAd4M9/xJfAXxu9NBpFUBvfk
                                  MD5:6218D2871079FF76031B8E6DAB4EB584
                                  SHA1:69720ABC7E78E2BC632F5DC03BDBD8557C558C66
                                  SHA-256:4E839C8698C859D39D9C79B1EC111D5B0913AD54F21E88A7ACA68A0486CF61A0
                                  SHA-512:6F6AA44DCAC1EEB0D6EA44838F7657C2F8E098B1E7713B96E7D24C9AD2D1997A84E01A41A9FD582BA83EBA39B4FC772E49D29D1E0BA1F0EF703D6EA29C2CC126
                                  Malicious:false
                                  Preview: ..yz=(........C........CO....>!..............k3.....=.#.^H.Y..........gnmf.Z.."">a........"8sn...,9tk....$-VO........xn?#..LL99%z7>9*....A[kvz9m`........#J.........od(^.S......3>....s..Gm````....VEVTm|..KL....5<......uzrx2.%%*3..........//......HGRZ9&`w{z.7BK..km..Hw..Ou..Y.7a........o~.....bgep....%:..G\{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\523__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.357056763384864
                                  Encrypted:false
                                  SSDEEP:24:JNcbOrqWeDSP+rYpg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkBBpFUBQ+JgW5xs:JNaW6DIA8Ad4M9/xJfAXxubBpFUBvfTs
                                  MD5:DBFF1357D7C912AFFE174B46B871443D
                                  SHA1:CEADFDB8E4A6780CED0DA891EDB341D563DC5335
                                  SHA-256:4B7E5C67D63C7C9D3600BEC3696F59059E272DD7DFF0245EE344C6EF599E0101
                                  SHA-512:CB38D91AD6F54EFF2A789CA752AD08F424AF0F3DB8787C8D577B419B51D8A29C8E44461CB99B97148592A04147B833924C84A986BC3FCD974062866C815BD86C
                                  Malicious:false
                                  Preview: ......V.o|..<:p#......t.>2..U\.......*y?*=7AL...........3.gq....ip4.....!(.....x........#46,....ob.......FOtmgj......m{..X_QQ..t+........SI..%f:7......=5By..ML......+......i........1*....._-.........4?....rc[@..FL....5S_L......RX..""........tt&&....1}..........................{A..d#...P@..J[..*/......)...+"EG....uu$$**...VE..j{..WP..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\524__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1215
                                  Entropy (8bit):7.347970363118145
                                  Encrypted:false
                                  SSDEEP:24:2u+wFwiqd8uos8IYLBUtz84tFoze4ytP6qfHSgC0fNSZBzfteJTQREwBBpFUBQ+a:DqkBU6Ad4M9/xJfAXxukBpFUBvfy
                                  MD5:3AB286D09D61F7E705956C491F4DF68A
                                  SHA1:3217CDE9249A301AEF68B385F9A1E3545E0E356F
                                  SHA-256:38C3F3207D1CB6DE78442D880CE05B67CE7353592388B900CA574AA420B6263A
                                  SHA-512:EBF142006BE63838CF9D689FD9A3CB012C503166FDE0E1851A6B6CE64581A59FC90DBBB1007BAE61A28BD480C15F96594537FC9C49E16E1DD786506C203A925A
                                  Malicious:false
                                  Preview: ........L..<=24......df..........>?..0*=n.....mlU.F...........ikhq.......DO....::.....GP.............. ..~w!8`mYn..........rrqq....TG.....JWk(*'....3"........*;F.uF_\....AR.......W .....(?......CC??.....H[...........'2B]"..?..* ..@`dm..&+...^t..........b}..l`u-<Y........$$!7.:..fIW_..[L..A..."u.I..{nMD..\-+{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBC
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\525__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1220
                                  Entropy (8bit):7.350297772825175
                                  Encrypted:false
                                  SSDEEP:24:JZzie8rK9yHIuz9A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzBBpFUBQ+JgW5eg:bieeKMHN9xAd4M9/xJfAXxu2BpFUBvfR
                                  MD5:C84D8BA01C603D83B7988BC5E12388BD
                                  SHA1:4ECC2487604DD6CE7A28462EDDC1A5660C53B8BA
                                  SHA-256:057DA579941C4465CBD7FD8C4284CFE452738F1A984F0DBB9777EDF1475AE8AA
                                  SHA-512:879C4F83B84A6CD7017AF2D73C4FDCF05F4619619340D1F4841861C498A7F115014DAEE98F301FE4F8C0B045AC48E729C609E7FA70DFD0EF343BFD0F5502DBB8
                                  Malicious:false
                                  Preview: .O.R.....^I...........GLAxs.......\ISQ..,#......NQ|`v':;vq........pouoihafMN..Kx.3......)+....q{!ukb.X A......:#.. ...XT.Fu}W.........;*..........z..we.....9>WF..Xk.............24 ..$;.........yyooI.FOTG/8&1....|?0=U@.....).....!.:....r.;k.5....LL.."3ls....I_:..{a6>....se.....4.XP=?.......?"..R_.....cf0%....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\526__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1225
                                  Entropy (8bit):7.346424861817971
                                  Encrypted:false
                                  SSDEEP:24:u6zE8orj6cWRU884tFoze4ytP6qfHSgC0fNSZBzfteJTQR98XcsBBpFUBQ+JgW5a:u6zqX6jRGAd4M9/xJfAXxue8hBpFUBvo
                                  MD5:411BAAE223BA0DBC08CB5ACDE4203BBD
                                  SHA1:1C7F1923176A07868274A5EA4F2F0D94DD1DCB0D
                                  SHA-256:081C174029AAE103FE7E6DFD3903920E3403AD52A62584FB58D9FC02B00134CC
                                  SHA-512:9BB4AACEBD4D6F9F8ECFAE5C043093399D617FB3A1570402694BD837B91328D8E7997A5A69DBD57438CAC7BAB68FC400BD1640399A3BBA198DCC704D8CE782CC
                                  Malicious:false
                                  Preview: .AEQR...B..ED...,WD....YR.........WM......|qXYv..N..2/L..,...qsG^.................,?PG......e&(%....]S8$.......1..za..,043ZZ......*= 7....B...%0........._......w`..DD...&:...@.................H......XJ....;,..G[z}qq.....................#6....$...#)...........Gt./.............ei..........ll 6.?........ip.b7......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\527__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1260
                                  Entropy (8bit):7.365201471861653
                                  Encrypted:false
                                  SSDEEP:24:Yz3LA7IZKOwR3HmfHxa84tFoze4ytP6qfHSgC0fNSZBzfteJTQRssBBpFUBQ+Jg4:qgEKOwR3kR/Ad4M9/xJfAXxu7EBpFUBZ
                                  MD5:46799E930645E018D054D1C1616CB7F0
                                  SHA1:249C2C0C4BE8C7C9A707CD84050F338B25D76A77
                                  SHA-256:173D3DE0B0CE91A87B8AF3E8DB80409491DDC0DC7CAEC2DEEFB8388817A51C03
                                  SHA-512:E6DC45DE0551AC87D057390C4ACC062C82AAB02801D3D1190DCA2DF1546B617FD5C0CD1587AA3DCEA8661E784DE5060F48DF995735F591387BF3E1549997EA16
                                  Malicious:false
                                  Preview: .V..........+*..]Bcq..ux.....B.....ik......]^ +..os.T.......a<....XBYX]Z....Pc.=3/sx..?=3"..Y^<6..*#.V..Ec..G^..Aj{}..v'..u_00_C|w|ob`......FL.Q*#.....M..'..ma"o....isS....bogLw..GFY2qvFE..M;......|g..D-........1-0;...RC..(/..o;..u-J,......#,..wQ.....JV+,..%%.......r?<3#+.........`B..........S_d#.@M$4UJ...)%I_(*......!0......- ......g|...,=..}}......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEAB
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\528__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1382
                                  Entropy (8bit):6.5972843538088926
                                  Encrypted:false
                                  SSDEEP:24:4znLKs484tFoze4ytP6qfHSgC0fNSZBzfteJTQRntUzfXF2tA63yrb+JgW5m:4DL3Ad4M9/xJfAXxuj1EY6f4
                                  MD5:C206DD15F2955F5B1756E076C3FCA65F
                                  SHA1:878FF12D85E7FB19902B22BE012C90C4EF8673DD
                                  SHA-256:20D40C9A1EBEFC79F7C1D31FB5DBD03D2A801CB04595494C3CCC29EABEEA3C3C
                                  SHA-512:5E2FB74BA39DE8CF44A60E8FA6B21D40BCE7AEA4A305119793A4991D7F9977ACE522302E7CF660A31CC28397712E77134304348E9CFC2A3A91D3B4BDE9E3FF5E
                                  Malicious:false
                                  Preview: ...C.......CY! )6..qc....29...Z w..ep..ur......CHIV9%.E`a....n..ZC^..4...DC..fj3.#...qz):......LK\V.Rv...:*.u.'Gm....29..75....?8RX.....q.....S.7..00....6=....l}................A.....09..-rXDDoo..C_..........DC......^.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....V......+@.}{.}{455}{000053000050000056000095000095000067000101000108000108000117000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\529__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2682
                                  Entropy (8bit):7.721694064682434
                                  Encrypted:false
                                  SSDEEP:48:k/5rV30qIPNTSv2Yv8Ynq1213Bh9opKRjcAd4M9/xJfAXxu9HkvBpFUBvfR:2xVElTSh03Mxh9opknpBAXQ9HSU
                                  MD5:5E5A6C8D68ADA7E080CA56A61D0CA17F
                                  SHA1:94A4BD6C7C0A77A4247B572B1C74182B999F9082
                                  SHA-256:71B28D3540FCD26F197BDC07545DBFBAEDBCF93F5AE01B3F374EE47DD470A33B
                                  SHA-512:108A8C72C15C4F09EFA5F79044EEBD5C41328483A496E94AA067F73D894C1ECD314EFC56942A774BF670210C5ED848F2B59FBD25C4C0E3F5063DD8ECE85AE1FF
                                  Malicious:false
                                  Preview: ...AB..A.o|?>RT....@B....7:..d{....wmU......YX....YD..=...R.75....ECpw....s.......fu..gp$>1,..jg....AO..jc_F....F\jq~h........R.^W5&..j}..xet7..............cd.. d..4=.....*....?-..E(DS....z}..@@88.C'.......e....ux..LS....@U........TM2?............QM:+..9w...}.....JB./..YOTw..TN....}.....p(9v.0....j+..\^....'*YLb}^Ymv..wusb.......bqAJ......%>`g......~~..OSte......v...{c.(./y....[D.._.~kLY..O._.....@...pCDnoo..';..LS.T...5S=+..C.....ju.\,.."$XTO...-b).....'E...,/fl=?,)..p}..GX,+HS...'6=:((55SS.X...\S..<#........!6)0.E.l..N......qd...,}..?8.^Q{HJ```..?#....D.Q]..g,>........)$L\....SSsk....IL..85xm.........)8....**..u9...,#..;$kN..[G.8KVVSj;...MR............./..Z......l;..B@.........{v..8'?8....fdCR+,NN.....FU...........O`[S75{ly`..D....D6r&3LY>7Z.......5:...5..FZ...dw$3...4KV......)v..gt....yc..u63>\Izep.......{|..q5.......OI.vc7@..iv.........--55..Z.....ub"5D^3.\.......cF..v|...%....zw5e..Mg........gx..tx..D!@B5/xp(.OO"4Lo..1+..75..y`..D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\52__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.378264180144471
                                  Encrypted:false
                                  SSDEEP:24:T5OYghwWUtG1gWHL5Z84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8dOBBpFUBQ+Jga:8NhJgqL5KAd4M9/xJfAXxu9OBpFUBvfD
                                  MD5:230A86C7E056B0B5E7F402DD2E6B4AC9
                                  SHA1:2E792A2D81B0C56CC102C8F39CB8157E2326AADF
                                  SHA-256:E7937C2D39727B37AC39DF127D0D42FD68A914691B0EFAC0C4ED8DD09A62E90B
                                  SHA-512:AFC0C04692D5607C28B23BF855D23E139DF91DB4AA5C0D61A63ED6B9AF039B528E127822ED38EB93056A349D8D225F8E5838F0A02B9C7BD942ED85FE5425C676
                                  Malicious:false
                                  Preview: ....q6BC.gp........guB................OHQ^SV.......6g..@G;p......6,LM....uy.>...2..o|..+:..oh..%q )]..a<.Db....#0..........<.........../4..pzx,..=eA.HZ..8u..........\q..*<...f?......_6....L...MM44so..wd75|m..in...) ..&@`s......sy,...HQ....)...}}......#,..2-..ED*.NG....VVA~......L.P...VFwh......7&....b-B.,9QD..'...][...ej.>v\..BB...\Utg"5..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\530__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1313
                                  Entropy (8bit):7.414574583133874
                                  Encrypted:false
                                  SSDEEP:24:D0aBP9VS+1e7D84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKa/7BBpFUBQ+JgW5y:wqPz1DAd4M9/xJfAXxugFBpFUBvfo
                                  MD5:E174ED586526B1A455B1FC7E6C9504A0
                                  SHA1:D4E9D5E6C433A3F2DB599CD94313575F6755F41C
                                  SHA-256:18CDC34C911C71291BDF83573E847CB5EA2823BED4783CE90821333267F1D470
                                  SHA-512:4CE498D389CDF28DD6414159C440695172C21C3277A6E035BD243380045B4FB8C22C0BF156D63D0123FFADA487D681BB47E8D501E11FA1F470E6E12D6A9491B5
                                  Malicious:false
                                  Preview: ....9,.].....Z.@S..`b....QX..76...l?xm!+.....:,PM... ..E..........."+.....rr'x.......WM9$.H?2..;$....7>.....g}....KW..XX.........qf......BOATZE..go......)B......2D{"59....%(T=wa......GG&:7<JYkixi....DN.CJ.[......ce...Hn..tm#0JVUR..WW..~~.............8.....jja^.......r$......UF....CN..zx..XMp}......LW......|{qq.....M^...............!!..ixd{Y.;7.U6.....9/c../"......E.........K42...Rif#.&.--...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\531__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.620791783610782
                                  Encrypted:false
                                  SSDEEP:24:1J/4eKIEXr5S84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZUzfXF2tA63yrb+JgW5s:1JrklAd4M9/xJfAXxu71EY6fi
                                  MD5:1F5C236889643DE5B9AB398A1EF67814
                                  SHA1:0D691A4D52D6C4838231A004C4919D8693474D8B
                                  SHA-256:F662742A6DE05A1F931625B9F7295CBAE7499E70F383F23622475A2F9A7C380B
                                  SHA-512:615735E5F3D74A0C560D1936DFDE79D68B84390D37BDE5BFB8670CF36E6C218562D2AAE9D19EE3A815B17C1D04402E44DCD79E2BE49C0E6B47A62D8BEF0515AE
                                  Malicious:false
                                  Preview: I..m0wCBj<...4....8'+9b'...`g..[I......je..TWsx..ZF...LK/dcrz'.....a`....P\%.Nd..../<~|@Q................-............vg....(".Q,%...dm3*..!q..zP++..';....XZ1 ..]Znd.7>.[..BU.<..>/c~........aa..th..ve20.........n6..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...m?.Q........}{.}{459}{0000530000510000490000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\532__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1284
                                  Entropy (8bit):7.402503057717018
                                  Encrypted:false
                                  SSDEEP:24:ZzZvPYblCKP0tBYiZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRnSM5BBpFUBQ+JgQ:ZNXkYO0b+Ad4M9/xJfAXxubMbBpFUBvJ
                                  MD5:69B6CC76508D7A72F8635F13C2D08073
                                  SHA1:746831D596AF5125F6C087D2DDB1EF3898606EE1
                                  SHA-256:E8E7B6FFD1BFC6DF5C45DB44E6BBF3E0AFFD24C98A47C7D5DB1954D4E4661993
                                  SHA-512:581AF9E62628146674FABFD7645547A16A2212A7D27D4C890EBCB857C96499E675BBE9F2DFCD283E529FF1D7079A9890A4DEE83B33E424BE3C725E678E6156E3
                                  Malicious:false
                                  Preview: E.:..K^_..k|3)/...po...................>1NKFE....@\J.....w<*;...^A[A)(..ABIE......BI):.............5m.........%6.*ECCO[..%......JA.......wp..D...m5.mohmu;:.....+:..............x..^AL!...?......[[&&:e........HR0-...EP..............MD........____ZZ......l"..t,3V..........;-......../'`b....w/.P07..`a....... 5WB....*{......clcP..;;22......]N..TCBX..........!m..B...$,B]#.k}.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\533__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.791653678325051
                                  Encrypted:false
                                  SSDEEP:24:m66zaBckske84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7uUzfXF2tDFvy8Bp+JgWF:rY0bskzAd4M9/xJfAXxue158B0fF
                                  MD5:15A0D0FB97C767EABCE1050308AC9627
                                  SHA1:85E043051ABA3F681D86627BD7F0F22A6022681D
                                  SHA-256:9312802CDACE567BC01DC6C3ED316C2B99E7F55BA3B57F4423650DCA8A358E94
                                  SHA-512:0CAB9F762BC85979DB8B10B90335EF2F36B9D3E66B7F09048F506FAD67F97F0235A69986A0D18461C5429774BA228AD338423134E8891C9CB43A9A320B3F04DE
                                  Malicious:false
                                  Preview: -yh......ny....{d..$6....]Vtsq+....AC..........(4K.....L...b?ql)6..:;..;8.....g{........D_..>4...?g.h......)(..A.5.....3/..'4......\[...X!(...<<..........FZ..............B.7>.....j8..(yt?D@...N41....UK.."vW.:j..... .</.....>>....@SOM=,....FL....o7HE.1''....V))>..#..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{5dcy.wf.f.)./V..}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\534__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.71217335037936
                                  Encrypted:false
                                  SSDEEP:24:b0ECIV8kqqVj7b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZUzfXF2tDFvy8BXCL0:pV8k7gAd4M9/xJfAXxu7158B5ft
                                  MD5:C8A2951832BAA957E931AB30F0E99920
                                  SHA1:713AF3AA2958182BAA421D432E5A0C15D5E4D3FF
                                  SHA-256:C06DC281271208994DFFC65B333C57E8FBA4E9A549F780CFA718E353D283D7A7
                                  SHA-512:936AA979E3F6D7CE8437FCDBE53F015718B9FB3B8938D1839853F96F6A26F3D5B2ADBDB7CC4D7AB49C2ED87DD8DDF11E5B015A5DEBBF91DE7D61D7CA0BEDD85D
                                  Malicious:false
                                  Preview: ..8.........rs.......xsst.K...h}TV43................[.........QP..UVUY.....83...}n.=&........u-.*:.m..mG....CH..kiM\.............;2.....<.....oo.....OM........@IT......*..q`ns..U.....||JJVVFZ6==.....sh43sy....~&^Xx...ss85XS........yy]].."3nq....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..=.....c8.O<...}{.}{522}{00005300005100005200009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\535__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.702404688456705
                                  Encrypted:false
                                  SSDEEP:24:zr/S5mIzZL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSYUzfXF2tDFvyv2+JgW5O:zr/S5QAd4M9/xJfAXxujD15vRfQ
                                  MD5:1B5F47AE0D1E829D69A8A5AFB69B94C7
                                  SHA1:97E54E11D8770BABB50D9E417144C6FD157749BE
                                  SHA-256:B1CC5B16C90A67A0FA011D798BB219E5AC9156CFD6FD6DA4EF739D606D7FE2EC
                                  SHA-512:B20250349D29909E55451C934A3A9FDC99D4472AD3230B5046299C8D6B9F4EC112CC3D223978491D90C38C06E57C2876811F0FC98B18CBE16F4A428E2F1C4C62
                                  Malicious:false
                                  Preview: v"$........JP......jxQ.......K.K6$......!.......tk..e4@A.....?...D[..>?..&%YU.)xR+7/$`sdf%4......2f...U.ue.<...........}....gm..+s.&/....l<H{(...**[G.......; ....[.GN~&.p..vL.._Nuh) b3 .1.::BB....JA..64..VM#${ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.3.2Mw.l.>@.K...}{.}{439}{00005300005100005300009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\536__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1654
                                  Entropy (8bit):7.57766459368047
                                  Encrypted:false
                                  SSDEEP:48:sAVUdS4twu594ItAd4M9/xJfAXxu0hBpFUBvfZ:Tq4454I0pBAXQ0T8
                                  MD5:060A0905B5083E3ADE0F7CBA19BC16FD
                                  SHA1:FDF827073FF40F91CE29FB64505D9B44955AC3F3
                                  SHA-256:BDBBE069D566050FF854F19048C62EEF3B862DA8483A66BBE0D3F9D4A2593514
                                  SHA-512:EFD5CBB428B97915E30A245B6D42AAE3D3C5C367CAF3098EF4686BA475F46A11C17B628E536054B69AB0CDE1CA9B97DAEE126FAE8A7B949E9F888DD6FF7A2F84
                                  Malicious:false
                                  Preview: .!%................lr......[V..JU...]........"/YXl4e>rdWJ...:..g:..(1..GAJM............2%....>#Z...i|............sD: UN......gg..u*..........or...)<KT......}v.n..,QX_...W.........bv$S.............55::......zm.......QYT.....6..TA82an....6/......ff.....4%...F....*O......Zt...........YQ.......R.....JARU...........;u`..0h.S...!d....;.xx..2.)e..L_.........K....uu...l!..{s..Xu0&..Vw...?&.......-8,!....jm....._N....SS..J.wdu8.....Cb..KI..`y._>A@.........M...\I..W.(y..CD..........LL....HWz448.I"....k,../?..6/.......;..5 ....&=.....%"..HH............3,...............>kM\.......mxZE....`iEG....__.....FUl!..ld..7.../3..DY..........9&k=xxZ[.W......C.h3B....FF.R.V..ok..<>..'285)<..]Zmv..{yHY.xNN((...VE1|....Pv...<.......^{.O^..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\537__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1397
                                  Entropy (8bit):6.616991938298343
                                  Encrypted:false
                                  SSDEEP:24:y/Lbqm9lQD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRlUzfXF2tA63yrb+JgW5l:yTbqm3Ad4M9/xJfAXxur1EY6f7
                                  MD5:1113A530541FE4CAE5031CF4323F39D5
                                  SHA1:4E9F6310AD87F6A472931652D18386874518F6C2
                                  SHA-256:16573A646092D63E83E5FFADEE59CB21BBF9CFE0C99EF9FB7C1BB5C3AFC414B2
                                  SHA-512:F80E4779BD6C62255876532691E8388249ADA2F8C02D1F8923CC7AEE222F2177ACC1200005EA3D09F9BC5558494CA738975FFB150EF92996B325DA009ED60512
                                  Malicious:false
                                  Preview: '..hk..*f..23.....zdKI/$..$)}t5*..2y"8.[MX.$......v-..ql..J|.....;"+1.....'294i..tt......#4..wmHU7t0=......zo....tt...MBK2!...... =......}b.4....5&......``..y&18&5......4)g$....iv. ./..lZ^^}z5!.........uu.."+.....9.....LAat+4hd..lf........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....u.{$h....8s}{.}{484}{000053000051000055000095000095000067000101000108000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\538__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.800950635848861
                                  Encrypted:false
                                  SSDEEP:24:9kWK6J1NbTSMYp6waTk84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNRVUzfXF2tDFB:aWKq1NoaTFAd4M9/xJfAXxu6k158B0fc
                                  MD5:E12817A81ADF427F6F0007EB7184493E
                                  SHA1:5FC3F68A400C53C168E1CFD0712B4D2E1330469B
                                  SHA-256:7D4A5567F296B95C7AF346731DB37055100FAAFA9C42F5B77B04144BA4F3E482
                                  SHA-512:0AEF8183F00DF3C1D6A8975F6078E5B2A4953525699BA018D85C389AB2A0629C1FBEC739E76925EC6D00605F3EF78FA8D81C054D6032B9132C7B5DE92CBF234C
                                  Malicious:false
                                  Preview: ..ablye)....agt'o|....v}..%(R[.....F.........#{y"UC............)0....9>|uU^..y~..u*....ynBU)3..)j.........~d......nr..--55.O......pg........&3....SE*-MQ.........XQ</w`...4DY.A.............Gng,5...........ik.r*....KW..]].....C>7ev....JP4)......_@h.........6.?;Uc..,+..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.v...B..a?|.X..}{.}{564}{00005300005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\539__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.684580042084861
                                  Encrypted:false
                                  SSDEEP:24:i6/srnIAw84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJ/VUzfXF2tDFvy8BXCL+Jg+:ihIgAd4M9/xJfAXxuQs158B5fP
                                  MD5:225ED315D9DACA73868E36A226307E46
                                  SHA1:FA0F4E0ABD4D419D04B985A870B651EE280C26B2
                                  SHA-256:0BE89E63D7F5C550DC300C1A46465B1CAB610DC0DB669CA56B8BA6FF3E4C80DD
                                  SHA-512:84B9BB3A97FDA3831CAEEAB0BB4B80FAC41BAAB1355AC026272776F506A5390C881815D59A13883947340D7C3D53A5381F830B1386D9EDD5AAA61B30D55DF15F
                                  Malicious:false
                                  Preview: H.L.b%01m;1&....d{..*8:...92DCJ.....h}ge................32y~.....gz....QP..]^UY..........................:*?[9...................W...y!.}R[......*...++....92.........q{.R..f>W%av..9.L]C^..k:,.......``...FU.................}k88q|4?L.....FFnn<<~b....V{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..J<L.......7.}{.}{519}{0000530000510000570000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\53__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1236
                                  Entropy (8bit):7.39673488335289
                                  Encrypted:false
                                  SSDEEP:24:GJ+uG4sFFvO21pV84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzyBBpFUBQ+JgW5p:GfXs3H1pmAd4M9/xJfAXxuOyBpFUBvf7
                                  MD5:6D0D2D07FEBD0982B9E5F30A2E8EAFE2
                                  SHA1:A2A0C18F361530597B9195E25036C7CA91DFBA12
                                  SHA-256:CCA0CE52E3276FAF1C1B7D0CDD63C217A2421564EDE23198132A24E1DDABEFEB
                                  SHA-512:D04DE99A7ABD243CCA16945DC990982C377A197E54DB8B37CFEAE2B79E2D25655C4DED6DDC9C85B50C345F665F1A0A9A09099A7ACD76793677391F2155FB7FAB
                                  Malicious:false
                                  Preview: ..x....1g 7..98UJ.........}z..Cftyl....`o..{x.........!j..F...d{.4NO+,ol....3..")....N_..Z]YS..2;...<.Nh ...yR............IB.....:=U_W.../w.~h.d..tg....#.k.a.pb.........+,..........ny..tn.._.94wb...)...fl........k;`S4.YY....ZK..;u......pr....Bl..yo....?%......g~..o:........=?nkcv3>+>..qv........................VM....rA..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\540__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1793
                                  Entropy (8bit):7.608020806592055
                                  Encrypted:false
                                  SSDEEP:48:1CjBvN93XBUBnBsyrNAd4M9/xJfAXxuVBpFUBvfT:8jp3xU1BsjpBAXQPC
                                  MD5:9E0F86821AE1CD0A3D97EFE9B46C2336
                                  SHA1:D673DD1E3CA791619A161985B4C7ECF5206DD8C4
                                  SHA-256:E41738592DDD2CFEF0B6F2DC11FE7A03BCDE3AA38A50DA63B07469EBCFB25F41
                                  SHA-512:F7CA5765141ACBEF36B7F59A007639C24E120EDE396715A331CD5C15A939A5E361278F95DDB0B2021B895822C00FA1B7B7C63E6BD267F386ED3689A50EFEAE1E
                                  Malicious:false
                                  Preview: .7...ihR...~d45poOPAS.\..aj(/..EW..KIg`....ps..@_...P !=:.e9({&..............b~...................U0Q...Yhh..5&......j;Ve_u..~b....VT..un_X..|(i`M....~^R."V..........rg....g>+'@@....N'CUM?.......B^%.4'wu........F.;2........,#....ZZ..zikw..ppCC.......X..............iK...../......S.........cs?1& .......3&le.W........$+...+33..........[L......B..........,avy...........57.....}n................4=..bsz}..VV...................)04lu.{fTQ....02'"..2?....=&'...(9..pp((...S................K\..#{..gA9{...."7..........DKm^..<<11%9.........Q#`g......#965....JS...u%..4e`...XA........$:..>l)*..ae...........R...STR.@O..}W.............e...i4..55.....zi^IFQ..[Fa"..9,.... g..j...+............I...KY..j....)5......##/p....9.gp.._Bf%...;..Fg..N[.........`mB....*AA......ET..e+../w...HR..Ywpp....db........mt.MB...9;............{v..FY....!(....ZZBB..MFH[LN....' ....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\541__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1221
                                  Entropy (8bit):7.362290244847232
                                  Encrypted:false
                                  SSDEEP:24:s3oAbOiJv23ca84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7BBpFUBQ+JgW5m:ibOiJwoAd4M9/xJfAXxu2BpFUBvfM
                                  MD5:0AE95B46EE09EDB0050EE7E3AC5AAD94
                                  SHA1:E74A250496F25DA9D946350825418EC0A591A172
                                  SHA-256:621CE2154D0202E4D2CB1135346ABB1DAF8E8C9A3803A311D8412964EB4AC270
                                  SHA-512:27561FE5FD40497A446254DC3080137CA11C879ADBEAD096A0CDAFE6DBE301B4EB89D56B7CB4B2085155BBABE798E67B6C2C4607E9658808FD1A17401EC59F7E
                                  Malicious:false
                                  Preview: .....ZO.tg.................R[ZE...F........UXvw.r)........YOO...!8XB71.......D.............9..7*..LA............2?Ny.......gg....FO6%....LV.....\IWH..M\b~..5a.............IZ}J_.....@..aa........./....MM..xs....|m ;..MG&rbk....7$yZ& .......HQL_........ZZ.......p.pxD[........Zx.........>_S.X.}p..$;...........P.dq.. ){ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\542__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1272
                                  Entropy (8bit):7.378938027764356
                                  Encrypted:false
                                  SSDEEP:24:Jb/zhY10rJVmbRIXQ284tFoze4ytP6qfHSgC0fNSZBzfteJTQRfpl3BBpFUBQ+Jz:pVtJVGIXQrAd4M9/xJfAXxu6nBpFUBv9
                                  MD5:489F7A279DCCE74FCC87B6F2B8EF1E95
                                  SHA1:0CCB1696BB9571D4A37DFEE406C9C2A4EB7559DC
                                  SHA-256:498BDDD515CD7DE7EC23B079F36D1B47577EAB5A113BC2E28B5DB84D626CDD32
                                  SHA-512:776C77D2458F5981C5FF8E3628C26B0BAC030A92702E6B4AEB7887DB4438A99F79AB820BA2F5FB78EFE754533BEECFC49079D72D0C197BBBEF95024A34D99508
                                  Malicious:false
                                  Preview: ......89......45kt........pwD.'pugLY..<;yv..=>.......RNO|{K...`=............".BhhtDOCP..........3:...R@..GG....QW..........dxbi....2#........K.........EW.....qy..ql...]..%4b1..........:;/(...U\hm.b....?H..9&'J....FZ..FFNN...V>7):..I^.......fy1......u0?...........+..??..........IEz"......ck@nEEES(...0*....31....Y..BXMI..YN....`u......>9...........0,..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A13302
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\543__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1225
                                  Entropy (8bit):7.357653339702544
                                  Encrypted:false
                                  SSDEEP:24:gBSyrQCSM8JOT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRldBBpFUBQ+JgW5hs:fuZZ8oYAd4M9/xJfAXxuWBpFUBvfDs
                                  MD5:3D6BCF79321F329E3CEE067F177F1BD9
                                  SHA1:F7CA04E7BDC062AB9A6B8E1663FAA82E5731735D
                                  SHA-256:E3D82F1195D0FCC108E8AA763363377404F2770C1D298357C58388A891D689A4
                                  SHA-512:9D843DACE82C9C52FBC5D0CFEFCB9F3FEAF3F623377ADC14F57E8D22F45AF07792F32BCE818890B43D39EA2EE5F9AC682D0F12CBCBE3E3B51797E0E8A1DB25E9
                                  Malicious:false
                                  Preview: .....<ptg-,.....WIki......QX..tu1z.....[Q......i.....aW[M..B@......pw..$/.sqv.......}j-:F\it#`GJ;...kedxAHip..Yn0*..SE..qv.....F....RE>$........*5+.....fi3.....C....9.......".........&|..{o..6$..J'..&:..tt.....|uFU;,.......3>..........q{..Rrzs.............,,-1`q......" _E... 11....>$.-go.....S...b+...2......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\544__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1220
                                  Entropy (8bit):7.359938179721393
                                  Encrypted:false
                                  SSDEEP:24:Cg6/7XlChjX0JYgBR2z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHBBpFUBQ+JgWR:NG7Qhz09n24Ad4M9/xJfAXxuyBpFUBvJ
                                  MD5:65251E0E02A5FF0C569AA0DB52EC1AB4
                                  SHA1:2ECC715A3FDD32C90CA670AAB16D0AC007B8F30C
                                  SHA-256:622E0154A76C46E1580AD75ED9CB07686E3E06284C43D572E4C10D8A5DA3B222
                                  SHA-512:CEC78AE05BB7217CF32E43E6CEC2CBE4F923966EA04F323B00C1892CF5485642126DB6B0B03E9744AC561F4688550A46A7951A9250CB41C4D663BB4DFD66942A
                                  Malicious:false
                                  Preview: .0.....+1....fyzho*....PW.JJ.+9cv....DAQRZQ..HT......:qdu%x..LVYX?8.....0XD.......qjVQ6<.....@!.mNh....qbt_>8..F.Iz%...iuJA........ho...z...E..CN?...n.>%..&0..`.AFpa1u..ZO|j./v.....2?.drW%Kx..ss..!=........5.617=...............y_..............GG..</U.('..+4..tu]z&/Xz)/..IN.....X...#...]A^KMI..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\545__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1227
                                  Entropy (8bit):7.366643247872011
                                  Encrypted:false
                                  SSDEEP:24:jH/mvgAHwHoG8PLXT84tFoze4ytP6qfHSgC0fNSZBzfteJTQREeBBpFUBQ+JgW5U:TfAkB8PLIAd4M9/xJfAXxuyBpFUBvfO
                                  MD5:C03C328080B2D08F30C2B2CC9794EDE6
                                  SHA1:A6E54C3EEE7B466148CA408C81F8CE089F3C3D0C
                                  SHA-256:A7354584A11D678AEBA1C1B6FA5C61B8653886465B8783A335F75DB667A65C83
                                  SHA-512:3F312C4FEF472C17CD078D544A0C9D4B6A0B892116926CB645EF4A314F9EED1704C3BAD5CCCD5FCD1711B1E16395551EEBD6789CC94DC55FC9C735D1DDDEEDB9
                                  Malicious:false
                                  Preview: .EA..i|T.......I.|ob|ln......ZS.....K......._RHI..G.6 ......k}.........LK...........n}PG....3+h....3,N@.......]j]G........yy..._]T..{lzm.....)$../0..........tmVE.pm..VEOR..F}..|}....._.Qg...l~po*G........LL..44.......MZ....<.R_VC..5.#.....78mM'.....#sWd:.....##+7CR.....Q.........n@..nx|_..A[%......9%<.I.....D...m/....N.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB243
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\546__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1217
                                  Entropy (8bit):7.345525278187314
                                  Encrypted:false
                                  SSDEEP:24:jmQs0A/Y/DAeQ684tFoze4ytP6qfHSgC0fNSZBzfteJTQRZcsBBpFUBQ+JgW5ps:CQs0sQM7fAd4M9/xJfAXxuChBpFUBvfI
                                  MD5:462D5E6B1B748BC179D6875F262ECEF4
                                  SHA1:0589301C6402D7F460D9A71834779556200168FB
                                  SHA-256:FDAC4B344D80039C147D655A377F53A36D25D36C664DE55B40427A71A202CA51
                                  SHA-512:6327C918086605B5272CE0D02437E34C591B75168E921C9B0FAF2C84143756A5A4E09E7F389324588C09334852B0321B363124C4EDA1FCA6DBFEE26482C5496D
                                  Malicious:false
                                  Preview: ...........32..J...?!xz..........yx.....N[..;6/..Ih3../2'.;.../ry{..A[..+,....../(II.HA 3....1+..b!]P........of....]jJP..M[..}z......md.....yc..........(......QLXY...BS..=..b.FTkti.av....lk..66++.Iw~m~AV..&<..H.......,.wR......BK..Q\/..3.8;;..ye.....`l5m..JP......XN....g}#.....[L.....cf..;!>)..g1.S`u....M.i8{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\547__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.608486618622115
                                  Encrypted:false
                                  SSDEEP:24:TAH0bIe984tFoze4ytP6qfHSgC0fNSZBzfteJTQRWMaUzfXF2tA63yrb+JgW5ns:TMciAd4M9/xJfAXxu0V1EY6fi
                                  MD5:B55FA495A09CB1F8F9DE9E4910BBEEF6
                                  SHA1:E05770BD3D00B32AA491FF8A63C9B57C182FEA23
                                  SHA-256:CCA9B938431426A61720CE41D431DE21338F5414F22609E2BE3F2336E51B51A9
                                  SHA-512:EDFD459C84F5F0A22A314B2FEF057B6CA5144F1D08E38590A98E10C1D84641344B0180A5CD5F229FD3449E55FF40B83A01BAB4FF063C63FD9D7E655101426E6F
                                  Malicious:false
                                  Preview: *~z.`'TU.O\K..89jufy........,+.QN.......KLYV.................1 } "?..d~xy~y{x..N}zP}a......PAsh16hb.........:......-&TG........("/{....q....jg8h...::""..#(h{........W]M...B..h..qK...........w]oo((..8$..(;&$..ho......vp{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{i......]......h}{.}{459}{0000530000520000550000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\548__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.396676277319641
                                  Encrypted:false
                                  SSDEEP:24:5lsC2c3s+PAL9fI84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6vd9BBpFUBQ+JgW5Q:/B2sYLjAd4M9/xJfAXxuBvtBpFUBvfa
                                  MD5:07AEEAD6A13531DC251A865DD85402EE
                                  SHA1:B2FBCEDC04AEC5828BEC5D4D26F09C86FF0F7E67
                                  SHA-256:15DDBA32BA53FCFFE7DF7869E33237989496E7D73DEA4EB47A86A02373DF7B31
                                  SHA-512:001888DA4A531367B1B7E7E317304A41B65BB81DC8BBBB6A89B03AF552A133A9C916FA51CA29ED57B504CE7F3063C3DAF24E3099634A59607C511B67FBCEE2C2
                                  Malicious:false
                                  Preview: .......(d...?9.................,-....j9..........6 ...'gQ.....&?3)......GLL.........|o.9......"adi.......2;..............mmII.A!(....}j.....:7..lsh..........ai...bDE.#6...Nx..b.......6!YH...))..TT.....................&.VsN[..............)33..HH...^A....w/...0*........^}......'/......y!.K%7Y....81d)..uw05...."7........<>...........|wm~......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\549__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.397535248959225
                                  Encrypted:false
                                  SSDEEP:24:DLsMpIp5jwfClaTGN84tFoze4ytP6qfHSgC0fNSZBzfteJTQRh/VBBpFUBQ+JgWa:DgM0wEa1Ad4M9/xJfAXxuwvBpFUBvfa
                                  MD5:53FBC6F37EE73FC2110DF1DE40BBB8F4
                                  SHA1:3DFF619C1AC897B1DF4184C1ACA93410145D4B62
                                  SHA-256:94F409454860613362E1E9BB251B06F66AA909ABDD55911EC1B53D2A623DCDC5
                                  SHA-512:AB376FBB0B20BEDDFDFDE9E8EB6FEE0D3668E6CD7783E2F659A7E70C2F3663CBCD3AC0720780395D5C468A239DA3CE2A4E9174D78BE5EE4629976CA76CE057D2
                                  Malicious:false
                                  Preview: .......L_:;F@...................='.........D._................\F......BI..........^I..PM. -........6?rk..`WD^....#?....iiX.....gp..,6....P]....}..(.. ).sn|cy......w|........p...1 ....B5.....L[`q..ur^^((EE...gtH_..A[ro..]P?*..=.iL:/MG..=...mt...h[..55..AA.c.....C..2j.UW...........-+..iF....%2....,yJ[......yx..[N'2..d<(y..afC...H{.U<<........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\54__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1236
                                  Entropy (8bit):7.415888064241544
                                  Encrypted:false
                                  SSDEEP:24:HjQwboolimu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRT5/BBpFUBQ+JgW5p:HjQwcktAd4M9/xJfAXxuEBpFUBvf7
                                  MD5:72637CA7D0BB4A04216413FDD2E83435
                                  SHA1:CBDD99950D919F8E45F75D879FCBACF55C9D091F
                                  SHA-256:B61A5D68478FC9DD5BB1A2D849A6F02C0D2F4D0D822A04CCCDF229A38CB68E80
                                  SHA-512:2966361FF1E05B8AE2660B34F2BBCD9B3C0A6B87BC635E7AF27C3E264648E9FA93015C26E291D949FA52FEC3556A153A62FC3B7B85F4D7669F274014DBAF8C34
                                  Malicious:false
                                  Preview: ....P..0fAVTN..0/fy..D...(#...%...........kn..............fw....-7........rA..`|..N].......[Q..J...f@ZZ}d...2AG....^tKKos..bq..............'0]...ev................WK.......P...........ex.Ebo.....=......7.....0=o?......!!........P.......JP.wkE../9uVWQ7-9.DL.......M.....ecf+...3c....'2u|...ecst@....)....xxiu...m~....LV|a^.ST{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\550__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.397323278713267
                                  Encrypted:false
                                  SSDEEP:24:SvmxoP8oScTkYAXkROVIBTng84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCQdBBpFJ:SvbYh3IBrRAd4M9/xJfAXxuPqBpFUBvk
                                  MD5:E580AAFD38648257F6DCC9D56ABCCBED
                                  SHA1:E23EF5CE9D080C4A727E930B2C85686DFA698749
                                  SHA-256:99D5AC58B352418B2493DBC98FED91A52BA4FAD220D769103626ACC8389ED88B
                                  SHA-512:1E2E5FABDB8F87E38CF68E31EF4FD9C157F99F355F0E437849D7078D5EBCC4B4D08BC0D1EEBA5C30A25F86F033862CF2AC2601193338779E768E8F48470644E1
                                  Malicious:false
                                  Preview: .......j&4'@ATR.ZI....<7YUbo.........1b..........P.{m..Wd^h..'z8:..4.............6i.......E_..P.;6........[R'>....~d; ......ee.........................gE.....uzhxb.....RUvg......-;...KG......;R....!.....KK......SQud..........;(./;=.......=$..(4......33..f*):..T[/'.....&....-....QVlV........]B.......WVj|.}.......JG..;$>99"81-/cr..CCJJ..=...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\551__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.380545026397764
                                  Encrypted:false
                                  SSDEEP:24:zykbFqmiySQuG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzM/BeBBpFUBQ+JgW51:zykpbaAd4M9/xJfAXxun/kBpFUBvfX
                                  MD5:9473766AB7C348F4CE344C3D89461AE6
                                  SHA1:89A6241DA3FBFE28A64808E4D040621119C15E1F
                                  SHA-256:5D8907C208BCB3F13AE31142C57024E3DAEA9907B517F6DF1C39BE5327002C24
                                  SHA-512:0E8871B99D12B1F80C171BC8388CFFA008AAD000C299AB343D2CABA4D53E59270B35187836968FD0E5230BB26808A231A8409EB9BC66D8317FD21CC93A59D119
                                  Malicious:false
                                  Preview: .[.(.....W]J....>!!>=/q4..|w[\"x.]....mo......:9..:%.c..=<..c(sb..DY..xb....!"~r......")..... ;-*.......w.(:.7HH..l...ce..A.....GG......&$..[@...&r_V..2Dr..........b.nj6*H...W\..+#.7....-8.n...2....,>@_..,;..=!VQ.........'..w`8/..ql.wz....oN..$1.........P]q!zI.-++MM....m|...:6.].....ld...........xW..../8..\.]...?#.^../:90l4d5....z?..fU]w..cc......CP{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\552__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.387140220053077
                                  Encrypted:false
                                  SSDEEP:24:QvsaW4qx6y+9H1ioKGG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUoBBpFUBQ+Jgs:ks3lwy6VFK2Ad4M9/xJfAXxu2BpFUBvt
                                  MD5:FB2FEB9483CC32A61703103B6A9BCF49
                                  SHA1:7963ADFD3A0A4EAE1866E6AC6A7D2122E8BC6C9D
                                  SHA-256:3C054BA083F8FB18FBAA1595F939589A673123838A136B96E92CD1F930BCE52A
                                  SHA-512:82A28C2699435EC7951B053B5F706A963DB81F8298A8E409DE026C7A14911C71EF0C7835AE535E64AE363C47D473CDBDEE6A12CB4AC0E56830A25542E5A5F82A
                                  Malicious:false
                                  Preview: |(.?...<j...../.......ty..[\..-zug..hjru..CF......_C..~...p;...K..$;7-........./{Q|`JA_Luw.......u.J...s...@f......'.Y_..Z....:.....1"......8?..6b..._....- ..q4..w.!V....-+..g\....[(..;*e?......cq...ub....RU.......u|(;......?"q2....kt6.Pu..u.....r{..)$.^.>.+SS..GG..DU...kg.@/J..........AW..ec..Kd...w`'>..w"HO....!:8=...i&.J......0a..x....3...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\553__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1252
                                  Entropy (8bit):7.3912168453570475
                                  Encrypted:false
                                  SSDEEP:24:9g/s2SUfrHxo5A9vN302z84tFoze4ytP6qfHSgC0fNSZBzfteJTQRyBBpFUBQ+J3:mEIrWwlD4Ad4M9/xJfAXxuBBpFUBvfx
                                  MD5:BFE03695AEC36F87DC41508ED9ED323A
                                  SHA1:0FF5A6711870C7564059FC954820B669A245A1CF
                                  SHA-256:2AC37CB6DFBC9083D392908C236C58E95BD72159B6EFFFC25F8E6CC8290F3318
                                  SHA-512:4DD872433C3749387FBED270987DCD2A4A247C124E40FC02C742FC91DD609514A1CA5B13C2EE4CE3274FAE7CCA2F524E6593544595933E732C9B6CEC627489F2
                                  Malicious:false
                                  Preview: =i.{.Lon..|kRH..ZE....g".........S.."7........RQchWHDX..pq...N..@.':..jp98&!..yJ#...........PW......Ak.QC..ccSJ..........*{Q.....VEfd..pk&!..j>......&+..+nag.....L...7<_Zob....~c.........].8....UG.......RN....99FFU...->..'0...........<..#..+!..Xx/&b{..1a.....ii...........@.t...z`....oy.7{}...!V^.............Q....}tK.Q...wpW.}r3.....WW.....N]{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0975
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\554__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.342999459190611
                                  Encrypted:false
                                  SSDEEP:24:ljPsRk2s6DhNvsZBMqNkk84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxBBpFUBQ+JM:RsPs6d6/NUAd4M9/xJfAXxuQBpFUBvfa
                                  MD5:66F2CE1F2C7BD9379D12976A28741839
                                  SHA1:4E4E53336484C4684E28720CCD9374AC8B9AF1D5
                                  SHA-256:66A060E09B77FE738BEAB08821A80BF85BB0E66453D56FA6A25631A1D5E1F88A
                                  SHA-512:CD3C998151A2A8F18779D1C5A3E9602E6295D70208E476776692EA1EB0DFE9D6FA715B1209E682C1AE11D65295D0CF7B0A79A1BCAD03DD7B50F9C026373A2FC1
                                  Malicious:false
                                  Preview: .QU}~..6z.......JL_..XZ....|q.........W....YTa`...M.......&...s...... &..kb...V3455.......~i3),1....7"....`|..........*<a}BE....{$..../8....*7!b=0..ZE........,>..." .....@{pm........F...:.."0xg......@\..........YJNY...........Ml..'- /..{r.....................^R.H0U02lv..P~..ZL..PVsi....20....D....<f..50..F.F.....ha..9h..16=xMB..+.......I.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\555__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.390085046869678
                                  Encrypted:false
                                  SSDEEP:24:ajRYyLYMxcYdWvL4EeSt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtBBpFUBQ+JgX:atBY+cYdW9eSeAd4M9/xJfAXxuUBpFUM
                                  MD5:92A77D74F3AF903015A9C39C8BFE33E9
                                  SHA1:3AC60CD44C6D879B6A694DA44832ABD70A5C7480
                                  SHA-256:E78269B25DC0A2790B436BE9254086599FCAFC57992DE0DB0E68DAB5800A24C1
                                  SHA-512:2CCEE9AC4C6F3A19134D09B6CF994B71C2351A8D3031AFCF16FD8A285E9D26DF9FD0B30C62A7AE0D7561EB7C6DFB84E3DD70DDF6D494325201A91787D23370E9
                                  Malicious:false
                                  Preview: +....`,O\pq:<<o_L=#........GN+4....\F.........W.......;..QG4i..pi..-+OH....#~[\)).....H_..b.v50=k~....+7....L{..e~.....WW...@...............JU..Ki.....v..7-........J7wp-<.....s.....@[(%c........!..WW............>9HB..!(...&5:.......5...QHM^..TS~~...wwP..........:-...4..6....)..@zKG.....UE..1...H^...[._J....y!Z.RT...T..Ev...&&..u9..6%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\556__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.389088923418778
                                  Encrypted:false
                                  SSDEEP:24:GljWbaxR9yZbnqer14g84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaq0csBBpFUBQZ:UjWYzyr1uAd4M9/xJfAXxua0hBpFUBvQ
                                  MD5:E3795347C7620705DD4A984BA20094F4
                                  SHA1:0AF6F2E57FF06D46A6FB974E31D6273C47FB039B
                                  SHA-256:B8AAC327B505F1510C0210EB503F54B12C81D736A46080B020A2459DF3771E83
                                  SHA-512:51FCAD6859E62EB9BC2B9F09D553EEF1AD3DA5BD938BED0296269D178A2DE9772D2F8F551F46E90721390228A10243DF83E3257B577462FBA2DA35A5CC5BF85B
                                  Malicious:false
                                  Preview: .mi........de(..@ve........hev.....L.+1..I\....}|M.....QL.8........^Dhn..LE....25.....WD..`w.....T..;..........S^Qf....ES....mm}}.....?(......>}nc...........sTF...............~.h..+:..".-9N9..-2y...L]..!!.....B4=JYsdzm......@UKT......lf}r......?2.......((........[....V+N\^\F........dG17..Kd..........8}t.........{n.......pr@Q....%%..{hHCs`..ET ;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\557__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1252
                                  Entropy (8bit):7.38985275837474
                                  Encrypted:false
                                  SSDEEP:24:TRc5rnhfAWhDOWVW84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6n5BBpFUBQ+JgW5j:Te1nBAWhDzLAd4M9/xJfAXxuxbBpFUBx
                                  MD5:302AC402FDD6650E5A6DEA8B8AC4143C
                                  SHA1:2A191BEB891DF65057C223D67DBC3A79AB873D6B
                                  SHA-256:E92EFF2EE0D80FECC9E7F90CEF4C49E3FE46067212107E6D435161FF7798ACF9
                                  SHA-512:CBD9A4F1ECFFCB4C2F395BE44219DB5925F4215FA811E2943B146F62E1A3AD9C5FFD685C314F3C3A9AA63D65951827EBBD62FCE4C782AEC71BFAFF6F903791F4
                                  Malicious:false
                                  Preview: `4.;8.\].XONT........o*.r....)s..*8sf.._X...........7f..+,.Q...........[\UV...=%.......gerc.........L..lbp.........?:<...."/.......3 ..........]T..3E<\:7.........|qffj........8K..........&46)..6'...xRR)).........sd....../"....Xy....bh....I@..........BB..mm........nbC..`..-7..Q...........Fi.........#rbaJ]....SV..............ZK........3 .... "l}{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0975
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\558__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.799921490225425
                                  Encrypted:false
                                  SSDEEP:24:n40+ptc8W99rTm0SW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkUzfXF2tDFvy8B9:n+fVOxS1LAd4M9/xJfAXxus158B0f4T
                                  MD5:D590DF80ECD1177150C7783CAA3502CE
                                  SHA1:384FAEE304BA88C8C300032EE21AE13366EDDF4C
                                  SHA-256:0B1F582068557B2E89F3F3DEE9AAD06D6FCD9C515C86546A457A24D321D51E59
                                  SHA-512:7A93AC767D13215402992571387632A35676C275D2C2C60575375A71E6F755D9B2225C1F00B5DB8E5E32E65F9424F8B71F5CC6E95427070C131EE60FD2C7D8D5
                                  Malicious:false
                                  Preview: &.."!ta........arOQ..;0uyKF..xgtu7|a{6e..ysjg..?g. 6..o\Uc<*.G..qh..$"st..$/.<;.............#>...&3B]..`y..ce..#*RN..yyBBb=........MW5(C.r.....".....th..EE..TT.qx....tc.........tkC[P......)z..WNa6..,{..:.B.&$......#?......PPBB...xk*=....]@............`m....7...Wa..qv....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.E......V...r./.}{.}{568}{000053000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\559__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.702341323123025
                                  Encrypted:false
                                  SSDEEP:24:6V9TD/PrtF8ylH384tFoze4ytP6qfHSgC0fNSZBzfteJTQRass/VUzfXF2tDFvyJ:29X2Ad4M9/xJfAXxuvs158B5fy
                                  MD5:8E73E08AE95127C2ACA8252ED23EF85D
                                  SHA1:61FD5501A1FB66B6C55361EAB8619534D7304732
                                  SHA-256:881F46BD0C745CD362529DE106F8E00D4FA3835C4D4342B0EA9AA415DFEC740D
                                  SHA-512:486D42B243015EC4A50AC2583C1925F5A1B7349C6AE20C3A6D86FB9677EAF03526367430331B4C67B443F663ECD6016CFE04033DE44B02CA65B4A787E45C71B3
                                  Malicious:false
                                  Preview: '....FSY.]N...........}....UX........e.8k....TU..*q....Iz.>tb.DUW...."$....1:.TS.....jy..XO.....ux;.......RN....|#......nt..}>....<.hh......\[//..wwG.of8+..?(WM...!,,9*5.=lM....../(.k..........................PO&*CCdn4>.SO........??.Q..3~..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{~/.O.OLi .<..T..}{.}{521}{000053000053000057000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\55__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.394509159236485
                                  Encrypted:false
                                  SSDEEP:24:5fAImV/mTeWiYq3yC0uL84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwkuTBBpFUBQq:5FO/7YfNAd4M9/xJfAXxufkYBpFUBvfD
                                  MD5:F6CFD1295378A9B9D9D621A57D90F46B
                                  SHA1:C058675C856E41B44A46C24142A45C683BDDEE3A
                                  SHA-256:B9849F439C4733F17E50C7DD84F57BC365051805DBD32022D780C12B62EA752D
                                  SHA-512:5805F1EC5BE3A3E363F9C0687A4E6D1D2F71E84CDD8001C9A91AD086018FF59C5321B5BADC2F981F5B19A5A226B0E3AE454BECF3D4FB3661D7BF457B183C55D2
                                  Malicious:false
                                  Preview: ..0.....[...............[VT_RU\.................................= 9&<&vw......=.[qqm29..........Q[.LAH.)H*8$.]]....:.PV.......3}}...ve......vq..+.r{C.../8....qytD.......84::.....~.........zf5>....pa!:FA&,..EL.:\cp....2=..........8?..YY33{{. 3..@Okc....jk.!........kT<;......a7..rbEZ....wu.n.....]....CF........... )......@@......IKYH...._UDw{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\560__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.695988701861349
                                  Encrypted:false
                                  SSDEEP:24:5x31DOt9Ah84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCfbVS7UzfXF2tDFvyv2+JV:JcAd4M9/xJfAXxuPfxSK15vRf3
                                  MD5:C7819FFE9B8F6A1148B4B64BB073E3F8
                                  SHA1:44555E54F11B6D78EFE25CDC15526267CE5EB5C3
                                  SHA-256:B631F6411413C1C9B1D9AE870932A7EED4026DC7E01D1EECBB2D5887C6358C2C
                                  SHA-512:B21212E548CA0FF6286FD667023628896685A475C6D9D5CF38F8B41DF6907A802E6379542F835488CFAF6687FAF7F206D09C0795471249A291BC826D18CE9C9A
                                  Malicious:false
                                  Preview: .gc....|0'4tu....%6..cayr..BO..SL.............BC..>e............hq..ag..(#J.<;..'xqx@Sre..LVroG.#.I\RMlboz5)PW..g8yp............sf..5...5,....be..SS......%2....(k]P..-2......YoLL..XLSO8?..,,ss]]..el....6!......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{I.q.UPY.......7}{.}{444}{00005300005400004800009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\561__Cellular_PerSimSettings_$(__ICCID)_NetworkBlockList.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1358
                                  Entropy (8bit):6.646555775669788
                                  Encrypted:false
                                  SSDEEP:24:EDRK9npDb0hK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsicUzfXF2svp3yk+JgW4:EdAp0hvAd4M9/xJfAXxuaX1RRCrf4
                                  MD5:1F5FAD22C7EC0CECE03AD715DB22A381
                                  SHA1:82DE58E5395C48AFF359E439F0954389908CE8AD
                                  SHA-256:9274DA15D7CEEC08B804B0ECA000494085BB25D8884406A52FAEC10403D458FE
                                  SHA-512:BF4DF8C1C483B7976995430D8515570A26A85331D24F7F911C04E5CF52F4B0F495A07A0A691EA986CF6E67F6723A0B05DBA988235A0636B1889DE5FF73930252
                                  Malicious:false
                                  Preview: ..e..DE9oAVLV..PO........")[\...........?0sv..ibc|rn.. !...............25C@...........ET....eo"v...........G[hc..OM..hs....Z.(!./N........;..--jj;'........=&....2f......=*...7*;.......sY??!!....fu....`{....|(...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{(EO(X...wB..T.k}{.}{455}{000053000054000049000095000095000067000101000108000108000117000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\562__Cellular_PerSimSettings_$(__ICCID)_SIMBlockList.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Key -
                                  Category:dropped
                                  Size (bytes):1332
                                  Entropy (8bit):6.714114162465912
                                  Encrypted:false
                                  SSDEEP:24:7axjIN1wV2+4ME84tFoze4ytP6qfHSgC0fNSZBzfteJTQRiiUzfXF2w3yk+JgW5w:+x04VWaAd4M9/xJfAXxuBN1pCrfu
                                  MD5:F46223C6B2D56346960171CBDB612EB8
                                  SHA1:1B3177E4F895E3FE9F246D6C83BB052B72AE7103
                                  SHA-256:523E1BD42D83EE80F20CA1482B300767D59DD37906B0F54A5C65C42600784CD5
                                  SHA-512:41C12712F7FF901D260ED64059A3F2DB0056C5B25D77305FD232250DC7424107947E7AC92ADAA707EBC54D2EE257BE099D9825D4A02226CF67DFA15B9C65E7C6
                                  Malicious:false
                                  Preview: ..I..:;........@_l~._....x...QC....vq]Ril......+7.X....B...O...VI...X_..BN..^t..^U1"31..............IY..bQ..uu!=........vm>9DN.Zw~.r.MD_F,!`0h[Lf..11....QB............N...?(-..:......r#..*........ODJY...HS..zps'..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{F.._O..O..D...u.}{.}{451}{00005300005400005000009500009500006700010100010800010800011700010800
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\563__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1975
                                  Entropy (8bit):7.673037152669638
                                  Encrypted:false
                                  SSDEEP:48:3e76io/M9SNaeht7VCG3Ht4aWdV0GAd4M9/xJfAXxuP/gjBpFUBvfE:q6zE9z4t7skOvV0JpBAXQngN9
                                  MD5:00EBBA7A29BB7FE90B37C365E9A199F2
                                  SHA1:18B8735B50354F4576EE61F536919BAC6D6A7AEA
                                  SHA-256:A1C6F05E05DC5C9F698E78FFC00197DE2B6A4C651C2EB7B73347BDA037940829
                                  SHA-512:132E5330F37AAC89CC44BF99CDA39733FB6359003824C692134B2FFBFBAAB2A1BA8F6ECB77B4E6474A33595EC2CBE222EA6E9F1B51F17A78D0A2638F0BEF4DF6
                                  Malicious:false
                                  Preview: .J..|;GF............"0.Gal.......vd......AN..........5drs....UD.U......98..~}...-Mg9%...." ..E^....I...M..........f0#.7..;7&wrAeO........'%_N........6?.D...+8! .../IT?>o...i3..&/...24!7@we....pg....FA]]..rr...EV............zo..).....mg...$ng..%(......44ss.........;cL)><cy>6.5..5#.......U]LN.....K.......g+..8-....H......G........99os........va...B.61--.......|1........ 6...........N.....RG....^A[\...........||..~m.c..08.....w>:.......lb......4o.BboO_.....8-..[RK.........lc./..99...@QD[.K.....ntp..d#E............KI....fkj.HW..6-..........66..,`....=2^V..iLqs..Zx......C...9)..])....,+>P..G).qtrg..P;g`v.........zx................20!0..........iz..+:..OH|v..............:!.......w/.......RZ....:;......q+7V!!^h..6A.................@@....#0..&1........]B..Gb.......................)5..-2/aDH5m.dfvl......3%..vp..nA*";9....&~..M@...I...I\......cd6syv\oXruullOS.......#4BX......ooYY.../b /..|caL-;6<....l{..'...y{adk~\Q....CD..ikRC/(rr.....$i('-%.......
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\564__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1211
                                  Entropy (8bit):7.378195154815538
                                  Encrypted:false
                                  SSDEEP:24:5QLHAQnQsHB4MCWko84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+wN0BBpFUBQ+JgP:5IHAa/HluAd4M9/xJfAXxuaNcBpFUBvm
                                  MD5:7CFE50EC368B9B862B152A80784715C9
                                  SHA1:26397F42F29AC4F952C206F36C6FE59364FC6192
                                  SHA-256:6B7A61B9B2B82FD9718F226ACE1C0938141DD7DA495A798BCA2B45DFAF1BF715
                                  SHA-512:E2D709A8CB4D3D3D7400B4B70A1B39378D958DB686E35E87FC90DC26C523DE5FCCDF38F72D9D73A6F4E905276D9998AE8B08C6174C643638D0E3794D8463EE6B
                                  Malicious:false
                                  Preview: .../,CV[..........HJ..|p..(!....D^......85..?g.R....vE..NX7j....BX..ST..w|......&/2!!6......v5nc.."=....) ..xu..NTnu........HH...):..@W}g..u6....&9.........ZH....T.|p....'*..v`....9...........DFfw...........g...-.AG-"....[[...._X..**??QQs?..Z...`htk....^y.........#RU..ZV......#3rmav..._..QXsq.....#}h|c...."+{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\565__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.370511694595983
                                  Encrypted:false
                                  SSDEEP:24:P8Faw+owAybCA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNzBBpFUBQ+JgW5n:kFF+nDCxAd4M9/xJfAXxu+NBpFUBvfF
                                  MD5:C9E3D4D602B760246749DA54F35E9C7F
                                  SHA1:242856CF93EC726AF67DF0FFA3B4B75D376D5E21
                                  SHA-256:15BAF99E1BA5F897933548041FBCD1B6333B451708BB0ADB409B6D9693F25644
                                  SHA-512:F277659EB6D3AD674C30D15B01C1C93E5B3C0AEA6307B2751B87E6BE6AB61F1A14C9EAAEC5C18493493360886515A7C62E62EC043A2B93ABBF244213F6473F0C
                                  Malicious:false
                                  Preview: .R..2u..l:....IH....&4}8ob29...{,........ADEF.......10...ix.@zg`.vldelk`c......LG..NL......p$........]].........H.-......[PfuY[...........F..<1......|n.........Y..PO.v..>/....oommoo.N/&..$3/8pj..z9........qT........$-..- ..Iz..WW..........G<0L..ySQ..me."..CU....yc..zr..{l........8b..{nGR...N(y..EB.......>..CC......(;..{l..#>.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\566__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.7761282273096475
                                  Encrypted:false
                                  SSDEEP:24:mLRLPRXZYcT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+SEcsUzfXF2tDFvy8Bp+j:YPZ4Ad4M9/xJfAXxu6EG158B0f7
                                  MD5:A31D510EAECBFDAA2F518A1B4633218C
                                  SHA1:ED5EC17AAE931E33F06BE0D69DF9438A2A0A5CD7
                                  SHA-256:7345FB4A07B4BB4CB1EC00C23EFE0F9CA6203BA53AEEF0DAEF5E5897C2389B66
                                  SHA-512:8EAB0F066296CD89F7D68DC7A98C0FA2C3B03A3028A9351EFCC98BFE9B492ACD1CEB69F0452AB4276282FD10C054BE0D2D8E0A32A06D6801EC98397DC87E3AE2
                                  Malicious:false
                                  Preview: g3...T...fqpj..juze{iw2.......OX.ft?*XZ..BMGB..............0m&;"=nt54....598.....en.......jm]W.@`i...............wD....iu+ ......34)#n:......../>...kA&&..............xr1e.v x...O...B[.....6d36..&'....n:.......yJMg....aaa}...........T^.I..i1.....VON]....Z`.2..A\|un295@@{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{c..].n..,.?]y.}{.}{574}{000053
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\567__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:DOS executable (COM, 0x8C-variant)
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.678062150525981
                                  Encrypted:false
                                  SSDEEP:24:XNl3eT8F84tFoze4ytP6qfHSgC0fNSZBzfteJTQReBL1UzfXF2tDFvy8BXCL+Jgp:9xM3Ad4M9/xJfAXxubE158B5fI
                                  MD5:AEC993E3977BA1371FB23193623FC92E
                                  SHA1:057965C599F578BC141B7E622330555C95CABCFB
                                  SHA-256:5E8E5FF8EC7F25820C6E3358DC7C69FF50DDF2D9B3D37892F2D5170BF8D6AE26
                                  SHA-512:4F72AF55387220935EF749289300AD92A80790B76B1411043B4A39AB523214067F0C45548DB1EBC4D188EAF32EC04EFB08FE69C7377DE426057B7158E9F361BC
                                  Malicious:false
                                  Preview: .37..#6....ut...}......p{.....ze...ou8k......)(o7.\......nX,:.PR-4..%#EB...].......kx........[.$)5 b}.....X_bb......l.^I....pm.....}[....PCC_..{{.........4#..7-..0sFK....eD..Rd......lp.....,,...Z..................._Soo....X5..inrr..\\ppyy.Z..:wR]h`{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...Ey7..Y.......}{.}{524}{0000530000540000550000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\568__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.685259118324718
                                  Encrypted:false
                                  SSDEEP:24:KNHQ7QMGUqFEUR84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAwtg4UzfXF2tDFvyv1:qFlUeEUiAd4M9/xJfAXxuZwtgj15vRfj
                                  MD5:A04292A0E8CC68953D60C2FD12A395C7
                                  SHA1:A98AF2DA641DB80E468148A687501A6644399303
                                  SHA-256:B9E9D0E6271E278FD2F298CC4C4FD7EC9DC85C99A8641D811A449E5F9BE680AE
                                  SHA-512:B8CD03A1B1608F3467CA56CFC552B20CB51EDA99A4291DAA762E396D18BD3020898393A2D5478E1172939F556B7DE25FFA6949E5352CAAD1046B1DC95C861EBB
                                  Malicious:false
                                  Preview: .|xWT.....................le(7..5~E_.]H..3>.....gq.....7....FDMT.................sz....%24.......h}...q.........G......qf6,...7:.........."1....++ww..i6{r,?...........GR ?....&"<.........?8....kk.........TC..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.d..-.F..K.....}{.}{436}{000053000054000056000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\569__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.385271070484777
                                  Encrypted:false
                                  SSDEEP:24:sCgmU1NyUzv84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0B1/VBBpFUBQ+JgW5G:b61NXzkAd4M9/xJfAXxuN1vBpFUBvfs
                                  MD5:345A041BCF98685459B85CDE72FE9C3B
                                  SHA1:2E57863067C490BF7614A99D1AE3CE308C67214C
                                  SHA-256:B5692BA3126E79482C3DBDA241CEFE902B20147DA90B92D395E387DCF47D31FD
                                  SHA-512:A7F8410949D74EDF8C9F2787B05628BD978EEC6CFF83B2FDF0B47E5F685449BD75B929D8DBAD036F865E8B19F99B743EA1A69EA06FCBD52218D04AF347ED6C16
                                  Malicious:false
                                  Preview: L....-8.M..SR.......aj($[V.......SI..FSNDM@....X..vk(.7...)t..rk&<..CD......vq%%............D.ux*?..%+LP......nY......JV....<<^.DMev5"RE....Q.............Y^<>%-..FTMY.F..1%...-2......qm..??....=b..DW..tcBXUH.Rux....cB..XM..|s.2"+'>..../........."3C\...W.W2...jbdJII........dK..b`@W........].SQ.............d ozozI@..X....0u..H{j@vv.....\..~m..h.BX{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\56__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1300
                                  Entropy (8bit):7.418272907253266
                                  Encrypted:false
                                  SSDEEP:24:gmJAPOl2HcXMONRPcU9so84tFoze4ytP6qfHSgC0fNSZBzfteJTQRg3ZcsBBpFUp:gmJZM3O/j9GAd4M9/xJfAXxuD3ZhBpFm
                                  MD5:0D29CAF34F6D6AB7B843C0593BC96175
                                  SHA1:03CAD17458FC782518632B4047BF458FA2C48FCE
                                  SHA-256:109E496CFAA6F47D81EEB8A5C0BC8D893B6876A8BDF51CFA5FAC3A44043762B4
                                  SHA-512:4049442CA0687E2E9A807E6878532775471473B6878BA30414283AA2CFB8878D4D84748443C771FD9C80051315C29A5F5541783C9525711EF32F891C3ABA6AE1
                                  Malicious:false
                                  Preview: .P4..onZ......2-..GU.......T.....&$......AB.t..............}`.......TW59..+.....yj..l}......g3..O.{.as..........VZl=kX....rnqz=.......0:.....H.Xjn.......}...q}......L%OY.Dw..............pa..#$q{5a$-................ 97$..af..FF.....~m..^V#<......;x~~~..tsF|.....S......RO......w5..ad....{n....6-..CR...hhrr..YRUF..N_CX..$.......NRvg'8!o..........h$.R_..................@....'....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{64
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\570__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.3654347926701105
                                  Encrypted:false
                                  SSDEEP:24:iZhbSBNpoioy9/LsT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMBBpFUBQ+JgW5I:i3QoydQYAd4M9/xJfAXxufBpFUBvfS
                                  MD5:9F1921D648A8CD0EF1CBA371F9B48FCB
                                  SHA1:E8BC1420CC170FA35192108145F47DCDA19ECABC
                                  SHA-256:16D37F1E75279749C2F6698C20C5B13C89043AD38EE17B9BD0FE5976B0E268C2
                                  SHA-512:8989F5399255933C99BFD3E48FD864D225427AEF00B7810C1A29F34DF5E622AEDE53312DDA4410CBE367245ABDFDA0B410F00DB4F091735693FA702C8D487AB5
                                  Malicious:false
                                  Preview: ......4x.................<1.......YCx+.........I4oK]GZ.#....t)..qh..............==.SleBQ.............XG....+"................::..}t..XO3$9#"?.............UH.^#^....xb...8/.LX.......BS....zz$$11.G.."1....ou\A.C....lsUt....ka..................@@fzTEyf....Wk.57HR..&...j|).-+HR..3;.................o+%0{nJC...cd(mt{..:.MM..< ..W^kx(?..f{{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\571__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1220
                                  Entropy (8bit):7.352737513102828
                                  Encrypted:false
                                  SSDEEP:24:knqNWHt7lbzUFOSUv84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9+BBpFUBQ+JgW5D:a7lbAFOcAd4M9/xJfAXxuU+BpFUBvfR
                                  MD5:32047200118B8A3E07938D190D55E8E8
                                  SHA1:CD4AA3CC501724B4F11BA26F0207A1CEAA8BE73E
                                  SHA-256:971DFFE935F47D4327E419B2CA806C25A89F93CA6E18E0643246F5DCC48328C0
                                  SHA-512:F6D038844B43DE41C9312CD999A0C4D7870E888C5CCCCFA2485AFF2B5425F2D725A151E7D5FCD50EBC98E44F8599356A81D35C8B4FB9F031603C650C56F741BF
                                  Malicious:false
                                  Preview: ......._.2%F\~....._M..AL.....F.ZH..?=PWo`......LPj;..kl=v........kq....JI'+.$.;:&>5*9..(9..%"PZ"vt}..g%7..CCwniz......./...........zx....CD..:n..+s....|FG...........;6..........HEb...|....&SS....0;s`....VM........4R..........LL}d..qmDC......77..0#....$,SL....-.........hW..............*5....lpix....6, 5!}............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\572__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.323403078065357
                                  Encrypted:false
                                  SSDEEP:24:eSllOsCINDg4Q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLc0BBpFUBQ+JgW57:eSlnCatAd4M9/xJfAXxuABpFUBvfp
                                  MD5:82DD5DCC6DFB4294D9C287A7754AE518
                                  SHA1:AEE90B4CF5D1C194A62724FCA1E545BD68C6D025
                                  SHA-256:5EA3047646CDF45754A6197C245BC6FCCEF95C2F6BC5904F4FD69F1573392F19
                                  SHA-512:57000128C8605B473D7BE953AAE8A42E1E36DEEFD98702A7090247D4F820F7C1186F9D3D5B8487DC68273A62D73F9F580EF90EC9F7DC0B0399C0739A9AE1793E
                                  Malicious:false
                                  Preview: ,x.4..._...CYUT..........................YFRN.R.....}lg:_B? ......HK..l_....ZQ...1 f}...$..._.*K_M....AX.."...dh7f..U........\^ud..........W........h`..+:O@{?.. 4M:4&.....WF.......>>..........,6..a"................#...7..?o...;HH..........A..T.L)..`h.'ww+=........NF..%2..n6/{....QF..Y.2v......_.H17..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\573__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.372495956175766
                                  Encrypted:false
                                  SSDEEP:24:sKeQdiA+JlhC84tFoze4ytP6qfHSgC0fNSZBzfteJTQRI3dBBpFUBQ+JgW5k:qKBiAd4M9/xJfAXxuB3fBpFUBvfe
                                  MD5:9ED923D17EC7E320974F9E1D5D1425EE
                                  SHA1:EF9A9F9A129D1C7B89664AD693B1B49B219269CE
                                  SHA-256:A002CCC494286E676E8B01B5AF51BE8EA22A37C418796766350E6F09388FEED9
                                  SHA-512:7418B58447D26BC7DE8100FABD74B024E488BC937EBA5B3635AB078B26741A92E7CB504F2135A5FA3F47EE6E4B9692F7DB507DC304469A9547303A9EC81EFE04
                                  Malicious:false
                                  Preview: .nj..K^.C..'&RTj9....../$..........w<...........U..C..kv<...h~.....qk......(u..::.......9...?"N.\Q.....^Bpy........&=..vj..AAqqq._V..<+..MWf{.O............RS...FJE_\Po..W ,tt...*C;-.q......dx........QJ..OE}).....iBQ..)/../%pV..tm........##BB..b.o|....ld..}j..}Z90y[......cd..`l.W...._O..........$&..ylNC....................?,29dw&$..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\574__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.36557522419752
                                  Encrypted:false
                                  SSDEEP:24:BS/ShuGO2L0enKLaAjFfrUiwo84tFoze4ytP6qfHSgC0fNSZBzfteJTQRo55rcef:B8UCeKLaANUfAd4M9/xJfAXxuT55rcef
                                  MD5:0696B0B856BC8EA1384E498B776E81F6
                                  SHA1:699360161029834ED3F86CD66CAB36FD8E50378C
                                  SHA-256:9D4243779CD3F81562990703D9097209F7789604F6FF4781DA3A559FA495E681
                                  SHA-512:15025CD46A9B6CA375489B5DA71D8528C4F4A143B9F3A1C25A42BB83A6A4F94938EFD091CD3D9F880712FB41CD62F7DF3D28407E2C2188214F342AEF7988C4FA
                                  Malicious:false
                                  Preview: 9..ba%0.V..UTMKa2 3..:8.........."#a*HR..J_..id..d<.4"DY~MQg..;f........+,#*..~#.........;,..VL..............Y@|q.......RN..ee....90yj........>3...E^..6...........!.A......[I...i.........;;..+tHA....0'..........lMiL........[R..94...Eo..PP..vj.n.....m51T......Dj..SE..Z\....`h......"z..3i7&CAKN..BO<)..ru..4=..=,af~~PP##..!*....YH..mjGM%.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\575__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.593944071206978
                                  Encrypted:false
                                  SSDEEP:24:gfSJthHj8h84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRUzfXF2tA63yrb+JgW5pT:gfSJtLAd4M9/xJfAXxu71EY6fTT
                                  MD5:73DC3D43F3BBC780BCC29E3677DFB3B7
                                  SHA1:E33971CFDB97400F89208C64FD5FA0FD3EBEFCDD
                                  SHA-256:2F7C07FAD1F2314F3C9BC7A9FC6DA803BCA08CE01202CF944F99426D6510B727
                                  SHA-512:E8BB1123B4DA72855CEDF4DD9129644FCE2CC5EF1CC7DDCF152173081E23B8E95F4CE08E06832A11A5A8956E94776622FAE579904B70859E5AA34D7E89AD2C28
                                  Malicious:false
                                  Preview: .CG.......,-.....`~[YT_...}t+4....(2.B......@A.i2..IT.0..{m..\^........haja..WPcc.B..>-)>..@Zexd'....EK,9....bb.._..............$)@U..tR....%6....PP..ff.........wm\Ak(..#6.....:15.&....9-.......{{..[.^W....YN5/NS<.3>@U3,..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..............$}{.}{461}{000053000055000053000095000095000067000101000108000108000117000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\576__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:DOS executable (COM, 0x8C-variant)
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.79924774485058
                                  Encrypted:false
                                  SSDEEP:24:BImMrYXgylA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRycsUzfXF2tDFvy8Bp+Jgc:OmkMxAd4M9/xJfAXxuhG158B0fF
                                  MD5:18059943E6D2FBFDC93974F51E10BE15
                                  SHA1:9783844CF98F7E2899928966043E5F80526DC351
                                  SHA-256:FFF651042876DFE5A646C61172145E4ACE00450AC11F26210EC8DC8BC03DE96B
                                  SHA-512:CBE1E9E4B8A7CF85F4AC09DCF6704DA6A6D2BF4EC168158895E655890E4B9BD4DD51827E6E40135DD18026A4D06BA79FB14575915F2E911415B9FC154AF27650
                                  Malicious:false
                                  Preview: ...\..............5p{v(#|{^..Las..tv%"..27....sl..C......GTE.E..C\....(/..`l1.fL/3....HJ........!u...l...a~1+[Z.)h-............ 1..#$...7>..~kk..f7.....$$....]N........mg....@....Iy+...$o....u'TQ.........D.$t..3c.....vv__TT........]LAZOH_U._EL.#.........[$@WuO......JC..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....\..6.{yPE.}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\577__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.708860766746835
                                  Encrypted:false
                                  SSDEEP:24:QX7ka4u9ezP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaZUzfXF2tDFvy8BXCL+J7:QCEAd4M9/xJfAXxuf4158B5ft
                                  MD5:21539FEA366A7F18327A91D3C74DB3E1
                                  SHA1:38A7CC206A8EFE300406505FC3076BC764E696AA
                                  SHA-256:E98D01305418BBD39F770C1777A7AF4374F01492A3F43DC4BAB6977FF4B259CF
                                  SHA-512:4C56EF29BFA426066B2DA1E7D02C7F39D4E238A48C9293218FACB89A357F786ED304DC53AD84849D1CA34AA19113A4D6A38B1CDE442BA047E7DA0018CC6B57EB
                                  Malicious:false
                                  Preview: 9mS.>y....L[ISrs..ez...E..92...-zBP.....,#......kt..},.......@..>!MW.......:.Ci..............{qD....D..GW......jvK@..fd..1*EBj`S......~wd}<1...)Oe............fw..>9:0..0hm.xoBxWi.............66..........@[.......Q....pf""......;.....JJ99..'6......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....|r.....R}{.}{522}{00005300005500005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\578__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.703104462731661
                                  Encrypted:false
                                  SSDEEP:24:HN0NU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRmmUzfXF2tDFvyv2+JgW59:HS1Ad4M9/xJfAXxuXB15vRfj
                                  MD5:E9E99B4B0492055D0FDC81730E9171CA
                                  SHA1:332F547E8FA42BA92DDB4CC3BFA0B60F4DCF643B
                                  SHA-256:B66EE421E3C75CEFB49E5E8EE8091F554A45DAA1AA925BD526ADDD69AAA4CD6D
                                  SHA-512:9C3332DAD4F8D47D2E15CE97CB1C72A546DD80BE1C0766E21BD45D8A5C51AFD1466BDF357DA81FA382F33E0CA01FEB7784B49E4BBE88F74FFB3208478E2AD784
                                  Malicious:false
                                  Preview: .y}..MX8twdQP..s KX..#!...#....`GFQ...&uLY39 -...Z....wj..*.......SJF\LJ........:=........L[YN.......n{........lk....j5...0'....b...XU..B]....................CJ......pj..2q....^A-.8...NNcdK_..X_....%%}"|u..?(..: {ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..x.....H..TC.j}{.}{436}{000053000055000056000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\579__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1252
                                  Entropy (8bit):7.403485124725602
                                  Encrypted:false
                                  SSDEEP:24:aJdH8qb8pYh7jW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZ/VBBpFUBQ+JgW5+g:aJCI8gLAd4M9/xJfAXxucvBpFUBvfx
                                  MD5:B082AC1EE5EFA8BAEB640AAF7512A1C7
                                  SHA1:F93E78E72769D3AA648AC5776AA8CACD06A531F3
                                  SHA-256:F6C3E77660DE87449D9A05548AC2BCB39B1AE27A4C44B20ACC8A8D586D7A74BE
                                  SHA-512:B6E0DFAE79AE815A93D0FDCA765EA5572434FC22200C9877D53A1A9889FC6DCBFB699FD2B025333C86D75E90F91374A6ABFBA6CB1B23537D90C32710442A6C45
                                  Malicious:false
                                  Preview: &rS.~9IHa7..is..'8.....EP]YR<;.Sw ..mx..34....56..`....P..BE............25.................:!....e1.. x..........@S..US...........hc................e?4..?>/jj.F[.&7)..X....uu..cn\5i...3........pcGEet`{............EC..IC....QH......99....--v:l.5x......mz.."....%PV......6.....A..............KN-$..q<........xu....KPpy..ix/(ww................fa..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0975
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\57__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1299
                                  Entropy (8bit):7.438340555912315
                                  Encrypted:false
                                  SSDEEP:24:Wu8N2AjjzKA6t84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrBBpFUBQ+JgW5xs:WhAA6eAd4M9/xJfAXxuSBpFUBvfTs
                                  MD5:74233C4A668B355E741A64130897FE99
                                  SHA1:0FAE89D13611C4DCF13B42E08E177AF2B6780245
                                  SHA-256:30EA18C0D32F47CB2630E4A80E683280446481D38FFADF8F0A927C65F0F7D312
                                  SHA-512:33C8C17AB370CB882F51C038497D7FEF32029B2CA9CD8A0CAE57575D47F9700FBE48BB223461AD75A50DDB715E44E9D1A25B6403F5AA1F0A96CDE751488C65D8
                                  Malicious:false
                                  Preview: ........fgUS..........YP........MX..- ...r)......BTq,......"%..lg..:=..q.i`.......DY..OBk~....EY.....)..WL...cG@....k4..?,2%..yc...P'*dq..-.nwdl'.LW..0Fy ....vm..~...t...xR.......KX$&..<'BE..a5......$..hgka......VE^B(/..GG.....U...R....poer.._x...&....vIvq.Ekg"e...IV......g~....Qn>..........T......_P..gM..>>.........._HZ@@]....33..22...5x....LSHe....&.B@YN......&$50........|{d...fdYH..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{649
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\580__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.343315974763099
                                  Encrypted:false
                                  SSDEEP:24:6R+EM68MG2KatT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmRawBBpFUBQ+JgW5b:Q3TTYAd4M9/xJfAXxuPkYBpFUBvfJ
                                  MD5:D032DEFF5BFAF7F2468515645DD91E05
                                  SHA1:77C7A9837760E87F61E7A1741E8C3C2B75294B05
                                  SHA-256:21FA4E392B0DEA822FCCA490D529342741AB0A05DD2A7E11A099209D8792C305
                                  SHA-512:83641F4175781CA4641FA22A0635F2A29C2AC53A7004F40DABF75372BEEEBFE3C1B37C4B1D7259544137263D051587988999F97545908C9777C3DE30DBA3EDA3
                                  Malicious:false
                                  Preview: ...r...............[I~;Q\.....4c..H]....vynk..|w..1-..}|....*;<a<!...............qm=6^M......eb.......Q5T..*.~~......60...UuF.1nn........<-.......'.Z.......yx......EH~..A6M_...l......9>kk11nnn1......k|......,9.....ep=7..uUXQ..*'..cP..iiBB77qm..c|.....NK.MOQKH@@nBB..^}..>$..$,..ds....8s..|ku~C.2v..#6T].._...61.....+.+||..g{.....=*8/*0':w*..CC..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\581__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.786500040332338
                                  Encrypted:false
                                  SSDEEP:24:UkYdo+5jVToRG9fY3aT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRnMnHUzfXF2tDy:qtdmAd4M9/xJfAXxuAF158B0fh
                                  MD5:65A3C0B23D2E0B18F895BB8F7F1A528B
                                  SHA1:DDA67E91E3439C651C18AD9EC43F5A042F4C180E
                                  SHA-256:F131B54339C9DBE8E0CAF56ACE4EE96D09763A13015E48902FBD4464E13D1A58
                                  SHA-512:070832DA4C219A9746122E9C893A5531BF754601252CDEEF7782D04136C552D8B119C2C66B704B3AD5416F8DA7C5261312B28D3F3EA73F65D0AD7D3B290FD721
                                  Malicious:false
                                  Preview: z.@."eGFA.4#e.QP...............CQRG13..[T....OD ?......c(..1l#>......).....Kx........VTQ@...."(.R........UJ......z?....JJey..n}..IX..HO......&~..9(.@...>MMVV....(;..{j............W.L..0a...../}..H.......c7R..R..a1..qB...........BQ/-~o=&+,`j..HA.....0.......`wg]..cr....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...PxJ......Y2%Y}{.}{562}{000053000056
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\582__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.695557685526458
                                  Encrypted:false
                                  SSDEEP:24:2IPWrVZWO1zt+RMy84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkXUzfXF2tDFvy8BN:aXt1p+RM3Ad4M9/xJfAXxuzW158B5fP
                                  MD5:882C1CA7259F0F6B649566DB325D1B08
                                  SHA1:CF3A2FD97B064461EF6B83DDF3EEC13478991FBF
                                  SHA-256:FB38E4D3A1DD4EA405CA9E0FF52B60FBC55558A4FE2231A1034A8289FCEC3670
                                  SHA-512:A20CD926BAC4E04EF8C0C17D8304CE64CCD730BE1C1995A1249ADF47C75AF700788E039199ADC9B04A5B96CE33BDBFD108E05D3DC9F4DEE810F5295E881EC30E
                                  Malicious:false
                                  Preview: .......2d....../0..TF.@|q....B.0g......af......,'..UIr#.........."=)3?>..>=..O|,.YE=6~mRPdu.........d<..3#>Zm^..rrYE........{`Y^...w~..........MdW..!!OOb~....~|vg-6..#)y-.......d^.........IIz..bb++..JV............OEm9i`O.DB...............^^.......$j{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......71..#....}{.}{518}{0000530000560000500000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\583__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.688466185075582
                                  Encrypted:false
                                  SSDEEP:24:Kyjv5OECjY6FV84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5UzfXF2tDFvyv2+JgWR:1bxNAd4M9/xJfAXxuT15vRfR
                                  MD5:F7ACD692F2F39BF3CE44FB7FAA143138
                                  SHA1:EE339C9A1A3DDA83EF322B0B6382532D0C55C5A4
                                  SHA-256:914A1B442E26DBF7CFDC8C954E5801E732CF3FFC0775E24523C96E242F73F4F8
                                  SHA-512:A89A23CFF2331C396BDD0A31E08ABB80F56D79F2D1098D32606A328B1A599B04053167D3D0E2F2B2E9F0C6C358193DB87108C47CAFDA1B5164C3A751653A0682
                                  Malicious:false
                                  Preview: Qfb.....</....E.@S\B.........fyDE....R)<FL^SQP0h.....,Pf.....,..........XS,q....(w..BQ..RE.....zw..........dc............1+....GJ'2......6/........^^.i`..........f%?2..MR....51/.AA.. 4..+,__..nn............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{z?.."i....e..v.\}{.}{432}{00005300005600005100009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\584__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.399053668822091
                                  Encrypted:false
                                  SSDEEP:24:UxuQvE92+la8KOepT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUBBpFUBQ+JgW5k:avE9NiO5Ad4M9/xJfAXxuDBpFUBvfe
                                  MD5:F1767F748E6CAA0F42C1CD2EBA691AA4
                                  SHA1:D22EC054607DBA62481CDC1E2AEBA912D3467D7B
                                  SHA-256:0E4122DA45D4AAE3378508ABEED720A5879C6816E50905D4DAA87AB54C057783
                                  SHA-512:797853D91D06B94C054975A431A3991AADC25121574967537D36F80387D61E5625C12575DD956C39158C4ECC52A528838BB795F91F8E333A6DD9970931A0EC00
                                  Malicious:false
                                  Preview: e....EP..DW]\..)z.........................NCHI........`V.........tr.......@(/..3l.'....5"4.....YT....]S....ax..`W.....ht..yy...qMDCP 7....{f.kfOZ..-...QY.....S....>Ias...kfq..4(....RRxx\.of</`w|k....(kid.....7_z....q~....!8............]A..hw......\^..,$..MM...-.....=......)0...S..........`uRG......~y.....!..88.............pmv+........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\585__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1208
                                  Entropy (8bit):7.332901177018975
                                  Encrypted:false
                                  SSDEEP:24:Q0vOwGsoEb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRN0KfZBBpFUBQ+JgW5H:+wGBAd4M9/xJfAXxuQL7BpFUBvfl
                                  MD5:A49EAB2D5517D61FA4360F7126C6F177
                                  SHA1:0A429C5BBD4F5BA31D57C7566C6255CFC9087522
                                  SHA-256:460E9B0E049A230C01DB98289C5C88509E55F86BF35D27A06F1F6FBCD21E2040
                                  SHA-512:1984306AB4638744AE3B513030DBDC2E8534027424ED4E538AADFD2F4C633A1321A0D26FADC8B9A657DC55380C23A11D1B312E078A4B9F453D7AD2A70EC31622
                                  Malicious:false
                                  Preview: (|..M...N.......7(gx....heYR>9..}o..eg......8;..!>B^......j!sbH.3...[A........(.......RAHJ}l....[Qy-.....f9+..==.....1@F7;...+..TT.................+v...f|.c[:....[-;b........Z3.....(......0,....JH..)2' LFD....O)ZIKh.................x....::...jyW.+$LD..sd:;...... &KKQn.......MZ.58..wh....KB'i....5 {r:b...#$..,#{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{U?
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\586__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.77187956085523
                                  Encrypted:false
                                  SSDEEP:24:yvX9zL/IMdxx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJ4csUzfXF2tDFvy8Bp+d:ylLQMLCAd4M9/xJfAXxuC4G158B0fF
                                  MD5:DBF395B8CDB65A67088C97E45AAB5B7F
                                  SHA1:66CB41E1D75D6A51779DEF00D9EE87688CA9CD98
                                  SHA-256:0FE6F14B1A1979D07394F0D3A0EC176F394F202028839D0116F60D233EF4CBD6
                                  SHA-512:8A2C47236FECC193CECAC02F18BF38D20BE99A7BEFFD758DCF7F98A0F55B2EE0753CEC145B55A1659031C7F2853D08BDEB3B7AAE2D2AE78FF1B0B793B7DBFFAD
                                  Malicious:false
                                  Preview: .HB.L..........&9/0..A._R...."xw ....`b..R]....92....(y<=..O.=,.........AF....eVv\........:+......[.v...R ti........S]n*.......+831..MV16..q%...N.....@...%...--pl..2!......OH!+..^W..L.1j.....E..<8=(..{~..1/u{./}..BL.M=b...3......TH......&7......q%U\..s~....1(:).e%2..........p,s.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.6.......B.8L.G(}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\587__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.706562272694932
                                  Encrypted:false
                                  SSDEEP:24:x/cna4a84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvxPUzfXF2tDFvy8BXCL+JgW5v:Kn5/Ad4M9/xJfAXxuU+158B5ft
                                  MD5:32C5D666FB72D21EEF6C223865C428B6
                                  SHA1:6F3B40C51014580126F7007A6810A580DC69AB49
                                  SHA-256:CD555D56D095AF836EA88916EEFB820671D0D26E7A0668796AD93E0C279A3B75
                                  SHA-512:EA34D32FD55D09103176AD846FCAAEDD8E90C8B71E7F64BE228D3ECB18FDECEDC2319CBF7286FB2CC3A2383A9CF0EBD75101BDE37DE34024CB820F479A18FBF4
                                  Malicious:false
                                  Preview: .........3$......&9..........D.....34..x}......>"\...CD.....2/2-..........s@..V]{h............w/@/WG..........PC....~e.....D.....I@cz....*.......dx38..fw......~*......,Vhcr..@I6g-.....eeaa........8).................id...*.....==....sb.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{L<.Uy....u../l}{.}{522}{00005300005600005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\588__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.713319148190225
                                  Encrypted:false
                                  SSDEEP:24:XWu9mo+UWieJRbcW84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8yUzfXF2tDFvyv29:XHB+bBJREAd4M9/xJfAXxu1d15vRfQ
                                  MD5:F37C745FBDFAEFBF08A0B554F764B4A4
                                  SHA1:AC0814A2A88293521DB5CFF6E47A373C832ABC90
                                  SHA-256:5536472A08E6A3B163C1BED3E19DF82CBE2201559AF5A276124D9E013C0992D7
                                  SHA-512:BADDCE2342CA50386FFA31DDD41FA600D886F0ACCB6BB7C35EF434CC1E37C6F9200537674FABFAF790701329E37DBA872FF7FAC8940BBD5D0F0E7E526DD1CE85
                                  Malicious:false
                                  Preview: x,.4.BXYG.`w....IV..M_....neTS..h?...;..WP../*..W\..2.._wv..L.*;K........st..p|....YE..wd..^Ovm....x,sz2j.....................(/..g3..s+...........u_00........xzwf..^Y...M..k3v.ds......KV...<.cI..KK..YE......\M..^Y{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{2.&;..!....tq[.F}{.}{438}{00005300005600005600009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\589__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.378361726053205
                                  Encrypted:false
                                  SSDEEP:24:2dvf/98a8Bfgv0/3hKzKVt84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2/VBBpFUBV:0z8BfgviYzlAd4M9/xJfAXxuLvBpFUBV
                                  MD5:9E99D0FAA5EBB2D46E1D97871A22519E
                                  SHA1:A2A7917AAD35626373DC5DB6C53B86DF2D4D200E
                                  SHA-256:BDE1EFA0FAC2CB67D40C2EB7B3BD2868874FE3DC047CF3B9E9FD964CAB2D3904
                                  SHA-512:F6FBA98A6138AAD121B7ADF3192B7B64E13884778038E3DB11FAB8E642E15BF3C5FBE59F66825E34990E9274E3D18586430D7B2D1FA8E7B1CB1E8041099B1EE9
                                  Malicious:false
                                  Preview: ...on)...0'....opb}..].!,zq..>d^.........p.....ch.............7*.....16.....;............un.._U.U..x 5T...........-su.....3.....$/..tvvgHS#$|v..R[.x...U]..C.....3(..............p)............~.>............>/.......el......pS..YVDN...........DD]]EE............|k....V_....rM"%3."...|*[V{k..ETDF...N..]Hwb6?..@.06vq.........]]......+8...../2......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\58__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1220
                                  Entropy (8bit):7.369800919255389
                                  Encrypted:false
                                  SSDEEP:24:4JrGAym1JOd84tFoze4ytP6qfHSgC0fNSZBzfteJTQREwTBBpFUBQ+JgW5Z:iGAy8EOAd4M9/xJfAXxu/wtBpFUBvfr
                                  MD5:6C54B1C72DBD758C29A9327B0D2D36BC
                                  SHA1:BA18C840275742A5DCAF60FE4E9BEB986030E70D
                                  SHA-256:6E02E39D7B3AA52C2A0D4D52FED5F083D00CD102F1F1B80ADE5A4A5783E47E06
                                  SHA-512:6E945EB7A9504CB81C9143DF88F1A059790D2F152BCA7ECCDB9CCFFD57DB1339859838F3E4CCF199DFF9850D755C9FA38EA3365628512C0465B1AC553A259CD8
                                  Malicious:false
                                  Preview: +...)nyx.....................R@.ft..|~..hg.........E.()...VG\...FYa{.........0.........TE....)#.......j...KKnw..........Zp....w|..sq....eb\V.UKB&~..4(..y...}{VM8yvT....R79<....P[..v~f.V.=1....WZ.b..8JBq?.....}a!*M^/-..f}.......0h,J....IO..........soniBB......S......IA..w`..Jm..;.IO..)........I.........q`vjj{g...(?...75..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\590__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.785836140647875
                                  Encrypted:false
                                  SSDEEP:24:OG5Q/M81FsJQ9dI8Pv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkpB/ZUzfXF2tD+:i/M8tvcAd4M9/xJfAXxu5Bw158B0fF
                                  MD5:D24707DB34E2858C210B1D2B83CE8537
                                  SHA1:5756B1B57CBEEC1015A221F25BE1562B333C28B4
                                  SHA-256:62AD52DB4EFC9FD8F65B1C9146661B7E6406330DF736110582517A15C3CA04EA
                                  SHA-512:B7750A63EC0DE581F92570825E67D7F46942FE8A224B37D093904B4A8549328DEA01544AE324F2105B729854CDA0DD347AF5D95B74BBF24E9C725F653FBC600D
                                  Malicious:false
                                  Preview: ..4......l{..bc....FT......f<.F....ik.........ls...._Xq:..T......*+.......t^^BLG......)2......ngj2.iXE.....).#f'.eO>>...3 ......VQ....q)......H{j@..3/..O\..]L@[..w}Y.*#.Y....j8MI.......O...7x_^......|..^P.^o0........MMMQ......^O....GM...w/......js.......]c..ro..S.?3{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....e.G$.....}{.}{570}{00005300
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\591__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.707874888238
                                  Encrypted:false
                                  SSDEEP:24:1G6pZAVHxg84tFoze4ytP6qfHSgC0fNSZBzfteJTQRXU/KUzfXF2tDFvy8BXCL+V:1GSMxRAd4M9/xJfAXxuWUd158B5ft
                                  MD5:6B2E628A187E6D4C226A6296990AF16A
                                  SHA1:29D1C4113B0C00B1AD41D9CDAB5677C775D4E19C
                                  SHA-256:792BB7F0D5C1AB48E1F38E4A075F604FB9970A647D2E5249ECBB40B4B83BDC43
                                  SHA-512:1C825C27267D0B5DEC61133B691722DCF0FC9188E5D2DF195B74841A9A5C4A091D3B1E722ED26FD77394654F31063381DBCCCA0F04449E0EFE8C7A1D6CDC9F48
                                  Malicious:false
                                  Preview: v"..z=ON.GP......MRWE.T.......~)../:..XW#&ij...........o$..$yJWb}......OL....W}..+ ..y{.........=4...8(.O|8.........ca`q\G..EO.B'...`.......C....<!!>>......DF......%/..|u.U..pg...xi..t}..]n3.33......`k....XI........fo@.......TT...............RC..F...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x...S.?7.J/..k..}{.}{522}{00005300005700004900009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\592__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.694463091997127
                                  Encrypted:false
                                  SSDEEP:24:qHAstr8W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRbV/AUzfXF2tDFvyv2+JgW5O:qHAeYAd4M9/xJfAXxuAD15vRfQ
                                  MD5:6B1EDF37AB8967CADEC47E1E81F35EF7
                                  SHA1:9135BAB922951DFD2D486D6F777935F9F32CB490
                                  SHA-256:25CEE1D7CEBDBDB25FC79A257F8FDAEE1374653D7FF0B4C52A2C9709AF25972D
                                  SHA-512:AD9A0FF122CFDA225573722FF032AD739866CCC86402357A5824D34CC9E3E2CE82D8740B7781DA4A429CF2CD77291C0E165CB9A27A7C647426CBD40EE1836C5E
                                  Malicious:false
                                  Preview: ..3..................F!,..Y^..S...DQ..............vj......%n.?...\C.."#....ie.6..c.....egfw..be...W^W..A...N*.1..}}....XK........7=)}-$....w~)0.#.wDkAooTT..(#o|........a5,%..FQ8.......v.........................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.,..f..).~.8..4.}{.}{439}{00005300005700005000009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\593__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1243
                                  Entropy (8bit):7.377119406694892
                                  Encrypted:false
                                  SSDEEP:24:qkcglv484tFoze4ytP6qfHSgC0fNSZBzfteJTQRUcMX//BBpFUBQ+JgW5k:qkcglvJAd4M9/xJfAXxuf3RBpFUBvfe
                                  MD5:99041C238D7233F37C5A9FCE6A5D634F
                                  SHA1:F39AF75149BA3192E22018187B4109EA56557A4E
                                  SHA-256:3DD4573C3A11F1D4726277CE5B2B03AC536C38CE11A17B459E3E156CC7E36963
                                  SHA-512:BE4F57C618EB42D7BBEEE42B7A8D35DA3AE48FD19ACDFA323A78BBDFE5E4B6AA22FEC415AABC691ACE3D3110A922D6C8B2D4CA39E5A4C8F30BCE19032D8CD5A9
                                  Malicious:false
                                  Preview: ........,?........WU...........l'tn*y....cn..h0..DR.....;m{w*WU......`gAHu~L.be....*9..`w.....)$..@_......=$nc..lvlw.......^..........QLH...[N.........o.c.g.'-80C58auy......l..............YR..?=$5....IC0d..8`....vUAGlc\V....voKXkwho\\...ll:v..<q'(..JUL[=<..ah..24............n81<..gx........MD.V............ii....i%..%6........A.vq::..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\594__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1274
                                  Entropy (8bit):7.415264986375449
                                  Encrypted:false
                                  SSDEEP:24:0jXrOQiYu8D86toG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRq+p/+BBpFUBQ+Jgy:0jXy3Bgo7Ad4M9/xJfAXxuKpmBpFUBvD
                                  MD5:2F4875E9DF1BEB405DDB5A44E59D0891
                                  SHA1:1CB12852894B568C1DB095417161562D43BFA59C
                                  SHA-256:17E139819F4368D80D3E3C7E44BE86033BFEC6381B35C7D54CC2DEE19C61EE95
                                  SHA-512:1D28842A7ECCA582F2C8777A0D12E6C9EC205190F84D8CA7D2A26FD57B08CF058D3FBC743BCA9ABBA272768CA127BFF5FB3677A9FDAC64A0FD74222FAA6502DE
                                  Malicious:false
                                  Preview: .........`wCY_^........................%*................~5#2n3......_^..KHCO....a}")tg......ni.....0h.....)22......& hd.....2''lp/$............\....w....c.......px\*........y....GtsYrr....MFl................'X>....*,..........bq!=hovv....BB~2....!rz...............'.....;7d#........................CJ......??..YY!2>5>-..gv..vq,&...+......L]`.n ..H./L..ZB..a-p&s~2"...={ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A133
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\595__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.377915389807056
                                  Encrypted:false
                                  SSDEEP:24:AAQjmU+3AJFaP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRD/9BBpFUBQ+JgW5t:7s+WgEAd4M9/xJfAXxuOnBpFUBvfv
                                  MD5:30A7EB69525E71F0FE0608302102F4CB
                                  SHA1:584365D04DEAB9317A9D4BDE7E5DF4260A2806F5
                                  SHA-256:DC737B31E91CD66226C1CB1B6D2A8C894548A1F472BA8634341EA7EB6DA6E8A9
                                  SHA-512:87E6BA6BB9428BA79DEEBFA754409EB532AF6CCA8E281E09E3C6492DEA5BD186F6562B0DFE726E5E0939F4C65B18400BC82B21D3983E07EF22E2C1F95F8B33EE
                                  Malicious:false
                                  Preview: .|...rs.......9&hw.... -..;<....._J..ho............,}....6}..+v......67.......Sy..ry"1..8).........N....Lj.............QM~pZ..:&ODVE......FA0:F........."...DO|f>v.....YK.."O........oo....,s..xk....YC..:yehGR...tQyl....Cc.'`y..............';.....GKo7.......Cm.."4Dg.y....*"..gp....k>..)n....YLd$.....N...@U..9a3bwq.........aayydx..T]QB4#gp....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\596__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1279
                                  Entropy (8bit):7.4237267084740335
                                  Encrypted:false
                                  SSDEEP:24:4Uv1sBE7JDPeZia84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4XG/acsBBpFUBQ+JE:4EOYDPAd4M9/xJfAXxuFGChBpFUBvfy
                                  MD5:105F2B84D6F04CCA810D88D38D1B8590
                                  SHA1:D0A2E55B2FB25DA730962B42BC040B0E0D15F5BB
                                  SHA-256:09F5012BC8FEF69AD7919C59DC7CB63D313343A48DAA016AE2333F556724A2E7
                                  SHA-512:7FFCADDE043E81132A9F298DC4C9A2FEDCCB954330D740E5FBCAC28EF66113448D555C3E235CE3353E5F1F2E3474A138EA7FC95F9109D4552705AF237CE734A6
                                  Malicious:false
                                  Preview: ...21ZO\.jyPQ...J..HVHJDO....\UIV..T...G.......^_E.........gq.....f..mk...........u*....*=.......^Svczeig..ELWN...(..G\....niNN..\...8+J],;.....Y..#6b}%...RP)!zIxpY^.......b..%:.k....xdG@..aaOO...........= w4..]H..........bB..SJ...iZFl....^^:&.....O...:_....RZ6...........eJ~v.......6}......2dn*....2;D........Z.....++.......iz.......$y>9....**......( C\.)%3...5..QF......zx{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\597__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1664
                                  Entropy (8bit):7.575833384161731
                                  Encrypted:false
                                  SSDEEP:48:THTSIqFz1WKfa0xr1dAgjmqqAd4M9/xJfAXxuAtBpFUBvf8:/S9Fz1W41xrIgjv1pBAXQg9
                                  MD5:63BF3546C6F12865F5B9C51EC942EC44
                                  SHA1:41010F3E536643730F95242BBBA455D6B0020F0F
                                  SHA-256:EEB5683E3965847520493535FF9FA6B887581CF93352E994AB5D707D35B6884C
                                  SHA-512:B548ED54331696A95E6405D5FDC9C751D5E1B8A3871A6FD89DE36B929E815F0C07D5336A48ACF72E82DCEBA3B5EA8F6D217554A78629E15545B7197734002486
                                  Malicious:false
                                  Preview: ..c`..L.->ML....H[=#................u&..,&`medE............_02..mw......ry.M..........>)..8"......... .ey......j]/56-H^..z}..VV....4'......1,.V....hw. ......oi._.......K.0?06..[......"/A(=+..qB..tt..vj}v....O^......z...J....[x...{q1...&?........MM??...I\Os>..T\....~.........||....Hr+'.........mp..64........JQ~h......fk......QJbk@B..........5&..=.....mv{|...!V|44....dumr..ie..g.......k'.ty..1.....(=......G...16D....yS....KW/>..n ..H..\J.Y.r.........[Y..NT...CYW..;..AT"+Z.....t1.......BB.......48..`.QUszE..........L(h....DQ..SFA^......crqviiDD;;..):3~..|tez7.00........AXG...~m_VM..WB..?6.@T.USho.0?Kx.6..........M.ma.H:+,HWOYTa|f....<+....O^x(ML........AF...IH.....hk8:.............8>25.C%*..hB......kz...jf...$2Ye..o(..FK....vk..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\598__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.403190606225206
                                  Encrypted:false
                                  SSDEEP:24:uT94FZfKxuaNA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9/43BBpFUBQ+JgW5M:uyFZo/xAd4M9/xJfAXxuoCBpFUBvfm
                                  MD5:968F50463A3BF3B22EEDA58E51F7917A
                                  SHA1:47EB6A6076E9F1BE0CE2E9A44439601F2733373C
                                  SHA-256:3FE338AE687F8FEC5211293D42C5AC779F6B625DCDA14374645001097FE0A403
                                  SHA-512:964ECEA5E3326B57BBDF452151BB30998170C25366A6AAA007E0754CFEA910736E7B0F278839692C2BE23BA34FDD2C3559F20E1CBE4FD9482786251215060D13
                                  Malicious:false
                                  Preview: .qu..=(D...SR>8K...........al......\.....,9....;:..........i_xnK.ZX....hn.......(/..y&%,..$3......=~id............1.: ..oy..lkGGiiV...yj}j6!......#..OP.............@..)=.6$MR.....?#..ll..nn...zi...!;..)j........y\j..........id.UN}.1..mm......uj1.....*(........TB.......XZ........_E3$1:.........<xvcMX..O.....<;.O@...$nn..>"..........'=a|8e..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\599__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1310
                                  Entropy (8bit):7.395902949532207
                                  Encrypted:false
                                  SSDEEP:24:OFQimsIiEL3UE8KZtnOg8Db84tFoze4ytP6qfHSgC0fNSZBzfteJTQRxC/L/VBBK:himA6Z5OfDgAd4M9/xJfAXxuuCDvBpFa
                                  MD5:4421E6C663FACED52D2B110D789DDBFC
                                  SHA1:476AC90357DECA6533B3ECAF9A5A9532291E2923
                                  SHA-256:D80349D4B5F0AEFD696519DA47E988839EE118A3EADBA18E470FB6D0A48F7569
                                  SHA-512:CACC2821C8EAB0786753A330E8B2971BD2BB5B3FA56C2EE67CD5E6BA781551A4673606317BFC1D018F12E50096CA3140B90B526AF4496D8C96EB8D9B3201C438
                                  Malicious:false
                                  Preview: ..p.......pj....NQ......xs '.............>;..do......UT&!....].........|.....fLye.........LK...H....pjx.............s...........LN...y~q{.....W.....P.jTE....>2...........1.0........%......5.....N..G.&@...;Z\~qBHAg.....9%..JJKK...........]B..ML......`f..........*m._R]MMR....................43..BK....WP]]==..fu1:jy...?....ZP....TTffkw.........Y:..9!...B....=-...v2]H4!4=.....|{._...'..LL..RN..)6{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\59__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1381
                                  Entropy (8bit):6.8001993317151
                                  Encrypted:false
                                  SSDEEP:24:YJmSCMA2xsj2NJ0b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHr/VUzfXF2tDFvy4:ZSCMA2xsSNRAd4M9/xJfAXxuOrs158B5
                                  MD5:B7254B2E46761AD2D670902F0885CCD1
                                  SHA1:CC8D6B15F810C20FBDDEB4C968F6DE44FF24E2D9
                                  SHA-256:FF52E9993D13EF709F00C33088E32597CB3E81306D57C73C7851C1183E20B541
                                  SHA-512:CA70B82D8291460F718D5F90C9F9D27A32850ACAA15CF6A0B3BD66706D2518B24C7C45ACC9E681031250EEC3CD6DBE2530398FD5A5C879F02B8E1B4AE0EC3B25
                                  Malicious:false
                                  Preview: .{.ba...>-ed..)z3 > EG.....ha../....H.=(J@>3....o4....dW!.7!..nlg~<&IO..FO~u...~~.GU\iz..~i....s0.....;.pi='vp................@W..]GNS..r>+...!9/ '....BB.......'......+1zg.B^SI\.......B...1b&/QH~).........w#.....HT....jjMM.....9...e.......j.D[y........#.&....:....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.>.Q...5.....P.}{.}{561}{0000530000570
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\5__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.439269306569427
                                  Encrypted:false
                                  SSDEEP:24:KeAvHtl7Us+h1qO4Nqw+vdcJ/NP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRv7BB5:K9fW1qdNHacJFEAd4M9/xJfAXxuiBpFJ
                                  MD5:36112A6D57D3BAA7296A37CD15D4B673
                                  SHA1:0DD36ECCA16621DA2FA34BFF225CF06B677DB853
                                  SHA-256:F3BB551E9A534609A241E32AF86B3A1F11BE6465306FBD1A7F034E54803BC127
                                  SHA-512:E9550D966FF72E06AA78FEF5679CCEED31094FFD53074F44C9247A8A9AF67188665C558605EEE69BBBA50BAA6876231AE89730BA4A75A5616DC6E06AF7995638
                                  Malicious:false
                                  Preview: :qu..ta`,):QP....^M,2RP................E<)......c;P.....?.bTOYH.75......ts..*!-p........O\........3p......................H^.............?(..:'..`u#<~G..-$.......dlT\."# .....au*].....k..........**''.ZS..pgmz....%f....a~..Nk........yp..BO........ii....\MzeQ.....OM|f......OY....IS<.......NWQ..{p....vd.............#$..I@sq..........RA.........16...<{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\600__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.372758696194694
                                  Encrypted:false
                                  SSDEEP:24:+vHrEzAVlxl1+r14PvS4A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRe48XBBpFUBs:KLEKlbFAd4M9/xJfAXxuFjxBpFUBvfs
                                  MD5:6DFCB93F526DFCC1697849AD5A39D045
                                  SHA1:6ABF8D3E83A307798C0D5AA208046D36023C1A43
                                  SHA-256:6ACC669E31A1826C9EAAC36201031EC4BB6562BFA357544D38CA8BCED925E2CB
                                  SHA-512:75ACEF2F6D76797157DC8BA274E23919B4B832185805FF0E88F45915B197092B2EF9ACF853598F8B24C9A13026C2BCA54A53FF85E0448777F1CEB8CF5FB4E250
                                  Malicious:false
                                  Preview: ........K..~....5+'%',..#........0*..gm.....A.....<.0...J...?&;!9?.).........7h........|a..<1AT....?#%,..}p.3 :.......DD../p.."1..................jh....G@..('w.7n'+.......LZ....Ci....JV)" 3GE<-9"...........Ol....GMf@[[e|....{|KKzz..>>)e...JE........hO...........<..L.g1*'....Z]ud.....>..*#|7w{.O..:~`u........%"y<........LLxd.......{l.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\601__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1313
                                  Entropy (8bit):7.4235429735097975
                                  Encrypted:false
                                  SSDEEP:24:1aLUKNI9g3pJnv2spJb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7hr4BBpFUBQ+Q:1aN7e4JgAd4M9/xJfAXxuyBwBpFUBvfo
                                  MD5:BBB176CB548E8A5D41647EBD5D59D444
                                  SHA1:BF1D3C6B1ADF7B4A80ED8E42D597DDDB7B819A9D
                                  SHA-256:C21DB60E4849952D98EC077502989F83CC265DDA36079926A82C2D21416E7978
                                  SHA-512:B34666DE38D8D25D7C7D9118DC0D202582161C768B47E744D312911723B62F99B030710EF1D3019B1BF1823F99436364028166A3B396798BCD7191594CEED0D4
                                  Malicious:false
                                  Preview: O....>+.4'..z|j9......ieuxpyNQHI....-~..{q.......)4.L......QS+2.........\.mj..E.....bu|kD^.............,5OB........kw.......T.......bx...G..eppo..............a.NByyCX..,EUC.d..hBMM''..XS8+....5.......t,....sP..:5..(.ssCZ......GG....))......../0.......wU<:TTqN(/..oc..E.....-2)4-".........qt........@G..jc....niyy66..?,bi..pa../(...8..NN))......%k..n6I*RI..N...FKM].....]....81.\5d.......<.....wwJV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\602__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.36329508876994
                                  Encrypted:false
                                  SSDEEP:24:Cm7+kU7xYLgIrp84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfeBBpFUBQ+JgW5G:Cu9U7xYM0aAd4M9/xJfAXxu0eBpFUBvk
                                  MD5:BECA40701F9D3BFA277937959662637A
                                  SHA1:4A51D3F3CEE1AD5946B34CE4D762A4AEE14A1E28
                                  SHA-256:B2D7576F0744B5FA35181E48754C4492D1F37C3E050E32E2C39195436F011D98
                                  SHA-512:3745848776A26D0510AF9F25590C2FE30AD6C4F7FA9175E97A43B27484729FAF30F43E325D3ED365D9367927D8E4722E837FD19B6F3442E8C4997EE80C26E9C1
                                  Malicious:false
                                  Preview: ...;8...H..}|..({........ZVGJU\..`a)b-7b1....S^....[M..Jy..@V..?=1(..TR..jc.......r-.'.............D[..PL......aV...........aay&..]N0'..vl...KF.... ....!)......$.....1.(...ZTYSX.....ee......}k..O|,...YY......;9ud..........2j..\OBa....93..AA#:zi............P......PX..ER\]..@b..zz....;.......7'..xe..57..FP4f.........ga.........5..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\603__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.40052226814852
                                  Encrypted:false
                                  SSDEEP:24:2ffWX4FuIACrBNDHXExDnk84tFoze4ytP6qfHSgC0fNSZBzfteJTQRT8dBBpFUBs:afVFumNAvAd4M9/xJfAXxu7fBpFUBvfs
                                  MD5:4CB8A7262BDF37C984162A1B09BE1226
                                  SHA1:691688659778AD016B00D8A00321178056ED08DF
                                  SHA-256:84C06DAE4420E581DD0C90017AF5B95A5500EA4DB27D8137BE3C3F3C05664268
                                  SHA-512:B058B570BF31B1DFD4A920A6F278C556F9342308AB2BEEA299187ED17981A6B9959D9FA54B05766FDC39ECB74E448FAE169C5E6E6B51D5A4C73AE0092F9B5D59
                                  Malicious:false
                                  Preview: .....DQ...10.........{p..!,......a* :.B&3.......Ft/..........mo\E..Z\....mfH...PP..6?{h..........qdqnbl[G{r.7....rhf}..;'}z..<<.....:-........$1...5..<>IA....[\,./asD50..aky......... -..yoi.yJ.1WW..;'&-..=?*;...........ZI........4...G^$7........xx....xw.....MLdCV_!......?.......^'qla....(5EJ..7<.......MOfc............v....UU88......+8......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\604__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1657
                                  Entropy (8bit):7.568677195400815
                                  Encrypted:false
                                  SSDEEP:48:lOwA04aQAnuQAd4M9/xJfAXxuSTIBpFUBvfrU:lOaEpBAXQST8l
                                  MD5:B2EBE87ECFE53F70DD3754DAE15DF0B6
                                  SHA1:7258696027E5A040D45C18AFFC51B713B2C6C959
                                  SHA-256:CEC93E919EFF6D5BAE68622BD73447766D31D5414CAFE3DFFF3C3349D0FBBEB0
                                  SHA-512:A7D77E5819863CB4CF2ACD2EECBC01093EEF3A1C52AA37A4FC11FF84230EB1A5E5562D26E0ABDB9144870714EF68851E4FADCCECE9AF7635212AA806C33B53B8
                                  Malicious:false
                                  Preview: .7.S.......ut...!3.F{v~u.....m..........vudo..htP.<=....{&yd]B..KJ....uy#...1-@K..pr..{|bh._....#1Y.....pcfMagxt......++..........hsy~..1eZSf>3^..3v#NZ^..KV...N]ots..8NJ...NN...!H\J{.......NN:&....prWFg|be....n6.o......syIo..d}BQ!=......vv++.[..I.....'8ZM..X.EL..rt....af.EJF.......'8....vtMFafep....j.R[.......}8*%...1..##1-..$7h.NY..PM..cd::==..-aBQ...p....Id|jRX........'...up......OP..6-.........................wg..TC......EL.R.*xi......72+>......lk3(JC........zzii"n..k&fi=5....Q|...~i.....<.K....R:/n{..9a...... e............;*8'....c;J8^L..roi/.K....^U..........[N....b3..16.......22....1 tk....Z....nq=+..`zqr....sj^.2#..-,.............0`..8&y,.LO............0aIO...[T%.."....OS..EZ......e...#_S.....IY....).pe{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\605__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.392699912441642
                                  Encrypted:false
                                  SSDEEP:24:HV0WcS/LogYi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgOfBBpFUBQ+JgW5I:HVBcM3YnAd4M9/xJfAXxuyJBpFUBvfS
                                  MD5:7C1C347E253ECECABB1DD0E9C98DE489
                                  SHA1:2AED99E5520ED6BFBFDC7850F954A183E63DBEFA
                                  SHA-256:8B467319D2D2870467FD975159B5900B38EE86FF57B3DACBC3014784B15F97A0
                                  SHA-512:D79C968247EE37DB7953F12B39AC35479570EEBFCA69E5B41E385A8086D6FF0D1D5A5F763356EDB930DD5ACC4B60DC535B7E136B347B35630D79E26C8ADD9731
                                  Malicious:false
                                  Preview: .'#................?4........ihz1g}.VCLF..-,....a|0..2..|!........rur{4?C.......v.~mox..cyvka"..GRrm.....'";..~I......SO....99...'4..9.....D.........................to..........^t.......O\ln....FA........t......an........"1...................ldPOub..+...nL......(....@...yi..-*...........................VY+.......%9P.......UB....f;....\\{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\606__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.363031079783614
                                  Encrypted:false
                                  SSDEEP:24:cR+4DdaEg6Fgx/ZWcd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRvYcsBBpFUBQ+J1:mnFg7WcOAd4M9/xJfAXxucYhBpFUBvfD
                                  MD5:C0BADBE14FA269486E4291E5670D0C9C
                                  SHA1:B5DC96A8BDADFD96CD2A5716A078E8715048D640
                                  SHA-256:AA98AA638CD16FC34C88481C2C4F01B4F2364FC932D2EBC5072F1485629DE9A3
                                  SHA-512:B8F86460152A3ADDCAD84293BA0CF9B00AE945D1D843100D7601304F5C3AB78C3D1786DACA3AC9EE642AFA0574ED8DFD9CE96872B1D41FC73EB12B58A4125AA1
                                  Malicious:false
                                  Preview: ...GD...v 3$%?98ezivhzx=diencdm7.......)<39<12................(uwjslvl.........52...[Pzizxo~ir........G.............71....m^........5&75.........dm.E.....L...9%p{...ww_K?I.D*&00..fk..wa.x..,.....ht..->GE..9".........R.c..x[BD..{q3...!8\O..UR......%%[...U.5:..........4=..qw..GxvquO..u2...3#.......4%kcT.h,i|..ELB.........wD........Z..|ofqbu..+6.H..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\607__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2331
                                  Entropy (8bit):7.736363577596414
                                  Encrypted:false
                                  SSDEEP:48:m352OuOYW+cioHHQDAUZyKtuC6d+bWoGcAd4M9/xJfAXxuv7BpFUBvfX:m35IOYWfNQEUZNtuC6dVlpBAXQv1C
                                  MD5:5772E609765E2666139A894C8F336FEC
                                  SHA1:3FF29164BF37A28C3275B4179DC684C7C513D6D7
                                  SHA-256:6523C1003F9CC3637F99B7BC8DF4234E87367AC408CEB66C4CB857F870DE80EE
                                  SHA-512:FE6EBE7823ED5E2FD3090E30871CEFA0179B90A6C56E5FBCFE3F8EB40DF60A447D2A9367E4D93185C98E36340BFE25445EFEC77572F25FE35DEF2A346D1EF664
                                  Malicious:false
                                  Preview: W.x..A..G.*=rh....qn..+n}p5>...B..QCta$&..ej\Y....$;.....43Q.....ti..........]QZi-.]A..........g`...I..7o...hN^^:#:)?...nbZ.......:&>5....;*........k3......h-a.......L..d..KP.."..X/'5ju..\K....-*..%%...DW..............Pq.-......}]mdmt'*.5.T~oo..==..ZK......T............................*31i..8+..|z....p3.....90...(/....Tg..%%.................._.........ra@.=2H@...H^`jkJ#!....1i....]X..<1......]F[R....Y^..MM..B..............y{;,..r*.......A......caGB8-]P}ha~.....!#5$....ddYY9u.......VI3*+.|i..h.`y....2.._K&b..(=....71..~;..h[t^&&....ix%:..............}+Q\..../*..<>IL......&9INlw..FD0!\[66.....3..t9VY80%:..)5....TQ.]R.cn@P...aa..._..OM............=j.{ZX"&..............3(MDnl....||....V.bqw:....yf,.`w...........G].mx.>zmx....!y....oh..if......c...qxVE5"..ou^C....ww.............>}DI.....9..y{...=w.......Wh....6@8`2>ss......NXh.kX.8....fz....@B....qv\V.M..1i...............G^..VQmmOO77.......A........jM*#hJnh//....$bn.8....1!D[jw.........IZ...mx..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\608__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.366739093975164
                                  Encrypted:false
                                  SSDEEP:24:eAv8LFLtv1ZNJFm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRasE8BBpFUBQ+JgW5y:eAvEFxNTzbAd4M9/xJfAXxu8EUBpFUBo
                                  MD5:A2AE75700F27457ADA69A176FFB6C2E6
                                  SHA1:F3395EF89EA6E0E7637207929F24C1DAB9BAF823
                                  SHA-256:7102420B68963331E962CCEC7E5285201C7AE68581945A824D49F9CD827755AA
                                  SHA-512:51E4387ADFB21226B5A5E9A4848533E47B3E497EA011DB5B105DF11732CBED6DF25FF4AC98A2B6DB83C1AABAD0FF1B0DA5CA69CDA9F3DF793AAC4B83673BFE7A
                                  Malicious:false
                                  Preview: OBF....../<....`3........{w..fo!>...Q/5f5....^SED.....)4&.h^_Ig:....`z.......R..''.Qv.H[....&<...94..!>`n.......!.........&!.....M) ..l{.....a"!,rg..{F....ia..mz.^qG...........N_..ST..SS......M^av..ns....OZOP....hb........94......pp((..KWO^ju..IE..X=..RH..........ce...*......Y@&~....]..fo...0uF.........a9.......H....!.22..C_*f..[H..w`'=..e8....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\609__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1248
                                  Entropy (8bit):7.389451377882504
                                  Encrypted:false
                                  SSDEEP:24:vGOxb/NsOqSK8FElJB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHx/VBBpFUBQ+Jb:v1vTqSK8FqAAd4M9/xJfAXxu0xvBpFUP
                                  MD5:C6D076E5C67AD5415D30BEF6FC29233D
                                  SHA1:A57A7F2C6A4B451A983521F5F29943A834FF2494
                                  SHA-256:062379741386D7D0A7B1F9DD8C4F3641A6D178400AABEFC2572BA68A3DE3BCC5
                                  SHA-512:872E34235EA73D599911E5E7EF4BF08A38C9005E0DDCD93CE11A429D4C4DD54EBEC27AAC2FC4E8C615B40C11E3E5D85C4EAED56A8F51610EBD5F6F6AF07014A4
                                  Malicious:false
                                  Preview: ..).....CI^VL..............JM....U@rp....|y #.......Y^...8e..............*JVyr...."9..v|......sajL........EC ,3b..Ci..PL_TTGHJ/>..)....V<5z"S>.....N6S.....................yh....||uu...B..........&e.......~[....:54.zs..id..."......[G...]....S.l\^4...kEww...&..BX....57........YP1:%4....[N......{|......[J......``........\M.........,..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\60__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.710071378488097
                                  Encrypted:false
                                  SSDEEP:24:lUyGSm2+6uyw/W84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5Is7UzfXF2tDFvy8BN:l4L6uFLAd4M9/xJfAXxu8K158B5fP
                                  MD5:648EED5FD44CCD4081CCDEF9FD5EAB5E
                                  SHA1:A61E4E0C41E2F5D5B9425948BB28C1A7FF286598
                                  SHA-256:A8411D468AD4E3E768B424436BBF26A826CAF1DE6FB579BCB7B3D37DDD20AAF5
                                  SHA-512:FD91B6ECBABB1622A50AAD8E3A4BC2C9E53F567E1E50FCA0258554E676D581227BBF4154ED56588497FB284E87D24FEB3865AAF5E82E42D2591E157CF2385B61
                                  Malicious:false
                                  Preview: g3.2..../yER{agf..xgR@B.]P..fah2a6}o....../ ....;0.........v=+:?b......WV/(PSXT....................n:7>b:......pZ.............be...}t.....IP.#.IUfkAxx..............VQ..P....VK9...........e4*..6......XD..AR........})i`.....6 .......*}}II..<<.....1.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...!..,.;.).d.i2}{.}{518}{0000540000480000950000950000670001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\610__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1637
                                  Entropy (8bit):7.561031252138122
                                  Encrypted:false
                                  SSDEEP:24:ltsNl3iwVYv2JhDjByury84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzIBBpFUBQ+8:4Nl32YhXvAd4M9/xJfAXxu6ABpFUBvfE
                                  MD5:DD64F284C8720906779E25B7840C4C10
                                  SHA1:9C781C56E13AEAFF00D9B9246C68D053EB06BF26
                                  SHA-256:BDC5A6CC1C9DBD5F765CBCB21A10C877AB57C5B845F375662E0DA14325916DC3
                                  SHA-512:A0FE3737B412132D10179067BA4D06ED5EC46844B0E4E12B9E845FC1EE565CB6379AB5D34E1B8B1185896D9D448D631ACF1976513E324931BF2101D74B3EA67C
                                  Malicious:false
                                  Preview: .B...ut.....45......Y.......j0......|~..3<....<7"=... !........c|....).....~M......TV..(3FA"(O....vz.*8..44..~m....\P.2.?...KW[P..^\J[YBLK;1n:..7o.dwT]...............&1zk..8?..........ve......NS................XQ... p...1rr??^^..o~...........d~../.....3...A[Q~....[L..P.i"..../*,9..7"ez..6-......' VV....YR..^\..nuLK;1....rr..">......FJ..........bo$4.....[..TA.........."g..............I.....4Ryo..r$....opPm..B@?V....[P..._J....%}q ..)............ET...[W.G,.....G..>.....A.5u.........*5..LWyp..M\{|....ee....d)..PX4+Q`PP..seKI..ax.T._r`64RW..:7..........TV..fa....rr....?rif....Wr.................W.....s%....'w4o..nf....9ny,......B@.........PW{`"+_]l}....GGuu.ra..yvs{..Ce....~v....;"d<.HZ.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\611__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.365652879738109
                                  Encrypted:false
                                  SSDEEP:24:p0i9qjugb/77+HmQU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcBSQX3BBpFUBQ+3:r9qCgbFQ1Ad4M9/xJfAXxu9SQXRBpFUt
                                  MD5:AE78B01C0459146E7BF60118B9FC3A52
                                  SHA1:64BC62D1D11A93171324142D6576F2442E8B5550
                                  SHA-256:4C9188A6320ED005C048A156EAA9BC6649942964E4BFE9DE3628C9FF276F58EF
                                  SHA-512:38F8C7C2FC5DAF8B895CC23B3FF7C1507DC4CB4978BF10A90C4A8BFDD9D0F4D04E2579021EF6157C67D56115618A306F92EE97B37C56A9833E96D03B098DD4DF
                                  Malicious:false
                                  Preview: :nY....x.......d{}b............accd......7<....M._^..u>RC.^C..Z@..pw^]...Ka......FD......DNV...8`..#1.;VV.....ECL@...(4.bb..yr..b`....9>........b......(<...........@@1*...c~h....!..}}....tv)8..........H..uV...!..Y.nn|e0#*6............jy..r}....ub..=.FOoM..XX..cd.,......_O/0........fc......2-Y^CX..ca..]Zpp....8+gl......nu..u...$.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\612__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1315
                                  Entropy (8bit):7.3942459706090675
                                  Encrypted:false
                                  SSDEEP:24:9oRkSHMUdaqDYHTZYeSSt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtvNehBBpFUM:90HMUda4YHODAd4M9/xJfAXxuEvcTBpR
                                  MD5:EA132ADEE9EDA1BF32AB6AE815FE0DAB
                                  SHA1:16EA80C58C75135C3CCE6F9994CB8FC878900856
                                  SHA-256:998CFE1C13E7F7CE022415E4408C530980BF014010120564EE0E7EE93BD19496
                                  SHA-512:BBD65A5D7AA06D34CAAB25668638A758A921691317BA377258EE86856D807ADF0C028B707FE4FDB354DBBC61179C5F5B420A502CC3A731BE01C514CC0A582DA2
                                  Malicious:false
                                  Preview: .+/zy....IZ01NH..........7;p}....lm'l.........#"n6......5.ZL...]DJPQW.......WP..3lof....ox....O.EH........%,.....%...."4FZRU44....MD..k|..OU......wbYF.,,!....~....w{..n7..RR&=........6...66.............QVAK.. )4l.x....BDdk.u..@@.........<<``...........ez8/+*..6?Hj....>.16Tn=1o(.................@Hv{..P.....gb.... 5..z}..ha..#2AF..''........;97&......?.6.11gg..te..y7.......`x..P..zw.......Q..XM.....K....3v..Cp3.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\613__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1245
                                  Entropy (8bit):7.361598278377712
                                  Encrypted:false
                                  SSDEEP:24:iXAofAOESODEQ/nLb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRElSBBpFUBQ+JgWE:iPIvjJ/8Ad4M9/xJfAXxuflSBpFUBvfE
                                  MD5:9BE4813B81E673F5B60D044E44353874
                                  SHA1:7EC938B2512017B16591EA6E8D013482BAAA4336
                                  SHA-256:620E66771A5949A39F699AC9241583B63F70F8A8245062157AFBA2719A57C48D
                                  SHA-512:79FFE0C876D8FA351F6EC5CEF0F05D52D06D8C67CB392D92565BAF9B4A1DE910684FAA7E24B571B78D54FBFE225C495387DAD7585FA9FEEB840219F232A99A4A
                                  Malicious:false
                                  Preview: I.........#%.^FU..9;;0......~a....PJ.N....,!....)r..YD....8....ULhr..IN....L.jm...F..*9....4...F.........)5..rk..(2f}m{%9.........ER....{f3p....+4..mb.......X.k]my6A......1&;*..=:$$..GG.IYP\O..5"....=~..EP......CV....vV.'3*@Mt$+...RR............?g.r..XB......OYVutr........ul..K..."+.M....y|YL>3....wp..................tv..UN....`S..ee\\{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\614__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.372060425671425
                                  Encrypted:false
                                  SSDEEP:24:swV9v9tqi5u+i3raIMcP3Oa84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBmU8jBBpj:su9FtHI5b27/Ad4M9/xJfAXxuFP9BpFJ
                                  MD5:403737A0776A0244A60117E5E90686CA
                                  SHA1:D499526FB47E49CD0A50DB56BD1135CDD0176E49
                                  SHA-256:7714C7CFC22D83AC941C854BB723579383453CBCA7AAA3556AE312F6E3F279E0
                                  SHA-512:2EA38680C3BD583BE243096C9DFA3CEC12F664FBD84F7158777AC6DBDA74756B0107F887E386601B67EB622116037C769469162AD5CEF9B3C5AACBDD04FFA830
                                  Malicious:false
                                  Preview: =CG...........j9..~`}...q}<1'.TK....tn.R(=........tb......?)&{-/VOCY......T_....HH.S..@S..YN..............~w6/..".....h~LP....UU.K.'!2........FTY)<..pp.._3......T..2...........6....cU.:K<ewKTw.%2.......aa++...kx..8/A[6+.94..ls..Z...28.....sjHE..jY9.FF..%%..L][D....']8.,.....'hh...EC...."*GE0'JSm5.%2._..57..?2dq.......-/........\O#(QB..(9{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\615__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1655
                                  Entropy (8bit):7.535032274855324
                                  Encrypted:false
                                  SSDEEP:48:RySAjTfd7/u8pMKYAd4M9/xJfAXxuREMBpFUBvfi:ASAffJzpBAXQREYn
                                  MD5:2AD959CA364B6B8C4F9E10CC7D83B630
                                  SHA1:2284A405659D00E3F3DE8E551CE771DDE99CE710
                                  SHA-256:F6B5EB2249CAF636D3DF62CFF6AE58167D741E7EEB5242B94A4435CDDCD7C2FD
                                  SHA-512:71B987284E990EF9396CABA12CCE06E7F274E75B38EB06E5E07233518C7E6EF0FD2C30E00F5CDACAB977264DAE120068B1F0FD95FB5AD9632531708FA7AB6922
                                  Malicious:false
                                  Preview: g3N....X.....*+..tk@R.E..ODTS.0g..........36.........A..ni.Z..[...tk......kh<0..Ys..,'...,.........JC...p............17...{H;.eePLCH5&ACIX.......@....%6.......,!J<D......KF....2.Ys..ss..,'...,....\[...JCv..w.=..............g{/(eePP.....P\O.|s......;:..18.............H.......? .....bx6!..'q..;..6?._............9.kk.........&1....1,R.HOPP..tt.P\O.............9.......ARom..YL......qv......#2^Y..ss..s?.."o............er_F.v............geFC1$..PE..STOT..02..9>..II..k'...C...^A..7.]H......g?....:.s7..2'..*rI.;=................;*........$6....!g.G$)....78EF.T......@......'.......Amb]n'.__....rc....i1....#<..mX..?<@B..CZ.....K&'.Wyfee.....'2.G...4a..spGE....D\I..7>..........|V.....IX......V.d...oS/#p7.6;......FE....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\616__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2632
                                  Entropy (8bit):7.768947821820998
                                  Encrypted:false
                                  SSDEEP:48:B67Xt4YcKG5ePdWhi+PgzKxRB45igfxvrCEAd4M9/xJfAXxuAlhBpFUBvfT:B6wKG5RfPgqRB45rFIpBAXQAlT+
                                  MD5:7FE909EA108E4B6B8F7967B10CAD25E7
                                  SHA1:F4FB63036C0811D276536C65B618005D9E41B07B
                                  SHA-256:560C881E97A41C54E4E03728F572DE2FBEDBF959BD51A0EE102BBFAF623D5DDB
                                  SHA-512:496D404AE684E22D2D57B2DAE89515BE3F50D86F35C93CFCF702380EAD55EEB733CDBE53048FB1F35BC7D0CBAA47E8489492CC3F72B747663B88C2E409930C21
                                  Malicious:false
                                  Preview: .04..XM.]@S! {}..{ha.......KB.........RX..KJz".......!....,q....rh......ry:gNI....`i</..#41+yd....0%..FH..'......=........oh.....A............TY.....!s|..yq.:.........t...............??......^M....5/...ob....`E)< *....md";..4dfU.-...``..ud9&b,....Z?8:..........ZyMK..............i..SD=6f<..<+68.......QD_R...........).??......OD....(9....6<..eODD11!=..ujH....{...ow.....M.............6?...-+...@...$..........>!..]Q<d..........GX8...}a..U0#0.......*n..ly..@...}z=x..Qb..NNjjxd......{#.|..5<......-=..0)`"V.;9.+J_............UW......00s?..1|......X}..JV..sn..........UJ1g.......CA3)C....zr..ii.J..................hsw~[Y..NI..##..',TG....E^....".........BQ...........LEP.L!......C?..cyem.F.....G\2?1XH^..Ar&.cc..ey..2!-/..d........>f%C....*,q~93......~m..z}cc......\...S......xo....qx.......5..|F..\.8n..WG)6.......rg..!(.G.J...\S.:W}.......YPGT.............dd.JY..R]+#..eH......{y..VO..l...GB.....:%y~$?..............`,...!...A^Ed........z" Kwm....=
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\617__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.366514497916958
                                  Encrypted:false
                                  SSDEEP:24:BtyU5FZXyYc5QD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJQGBBpFUBQ+JgW5t:3yU5CJBAd4M9/xJfAXxuCQ2BpFUBvfv
                                  MD5:24E2AD8DB7E6BBC75C1D720154A5522C
                                  SHA1:D70D4BD1CD2F4125404866502C6BD58163A334A9
                                  SHA-256:6C751F1CD00ECEF6D17027547202A0DF252851269CC159F3BB35F70399D3F149
                                  SHA-512:3E2692C9F5306A369990A9F1EE6A8BFEE6F8F4B8585A89D19EA5F543DDAAA5327E2CBE5C1EA5BD58109C2F52B8B61A5086EA169ECFA1761821C8DB8E960C1534
                                  Malicious:false
                                  Preview: ..mQ.....j}PJ..-2..@R..s~..JM1k.O..0%-/..;4...........|}...F..5h..^A..,-....vzyJ..;'92GT%'....CD..:n..L......5.....8.Y_...P...U....4?7$..[J..lk* -y..P.....#^..........K<bp........a}....rr........}gyd......WHVw.......Tt..6/ob..).=.......~bm|....MA&~W231...... ..$...: ..7?.......B.CPcjX...,...$1..yl5*!&...........11TGIBTG....AZ..|v.9......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\618__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.798979146996978
                                  Encrypted:false
                                  SSDEEP:24:UOKWIygw/b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRikPHUzfXF2tDFvy8Bp+JgK:6sgwYAd4M9/xJfAXxu7kPG158B0fz
                                  MD5:9D5676E40DE70E0D2E5082B23E22973D
                                  SHA1:D7D2ECED0C4B15D5508197112216B83463AFF80A
                                  SHA-256:C1338D32BCB28C50ABB81120A400D9498C05928CE170BF535A55E70EC6C7D2DD
                                  SHA-512:8B06BAF87494260BDF6A802C574187BA5F802C7EF812B33C89AA27E65668907776FB6D717C0DFC0B4D50387D6A4803AF4DDF3FF3C220AB2FA5968420A9B0464F
                                  Malicious:false
                                  Preview: ...V.Z[...%?z{.......[VZQ..y#.JKY;.`b....."!.........~5..!|~c....bcdc..GK+..5< ......`q..INSY..bk..............R....II.2......>/......Z.........."sfU....~~nr.._Lpr......ND.zsL.,u........VTPqd0b..D........P,~.HF)y3lkX........&-....hy....'-y-..\.TY(....zi.AV-.\b,=MP{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.......ZZ.i+..Z}{.}{558}{00005400004900
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\619__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.7123049133029085
                                  Encrypted:false
                                  SSDEEP:24:m86WR4pwC844fK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRd+Ey/VUzfXF2tDFvyv:LfR44HAd4M9/xJfAXxuE+Eys158B5fk
                                  MD5:0CB2CF8C4965D6C655FABB8013F63551
                                  SHA1:B803D974A487ADD54E9B826600DD5CE1B5BA1E4B
                                  SHA-256:090644F27D728BA21D962F1CAFAFCFCA7C89EF285324661A4CA83AC7D87C1F75
                                  SHA-512:E1E7DE109EB2A5B2C60F2640A9EBF99C006D0501FFB015E3C79FF0AEA665C109AC9BFB287473FCF6254C24E84A38C62F8B788378374EB791FF2887A71085841A
                                  Malicious:false
                                  Preview: &..# ....iz............................ak..vwj2.$~h..cPcU..j7.....AG..u|.......W............]...............00....xqO\.h..TN..x;....D[..UU......dc@@$$..(wle..`w.............1....4.......ht..]]jj.......EV....^Dvk-n..rg..($EEaklf..."%....!!..W....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{].c...)....@.KOH}{.}{516}{00005400004900005700009500009500006
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\61__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1317
                                  Entropy (8bit):6.705183798826257
                                  Encrypted:false
                                  SSDEEP:24:QpONAQ3cPZ/bH84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4cUzfXF2tDFvyv2+JgE:qGchDcAd4M9/xJfAXxuTX15vRfR
                                  MD5:D2BEE61574130E960E4AD4E614C899F9
                                  SHA1:AD3CE0A41C8475C0C5E117D4C5DB56C67FC1893A
                                  SHA-256:CDCCCDB3578B93E9E6E09EBF413CA0A72169424E028EA99002DD4A5811ADEBA0
                                  SHA-512:D223B244BEFDA0B694F8391EC78B02E7F769E1B342A900B85C8D95EEE4118B0605021A421F8E422E7F4EE88F68DEB4ABA9DA304E5D60E18DC7946C57EA58863C
                                  Malicious:false
                                  Preview: .15...........[H)7Y[....}p.......LV........V..O,:..N}1.............OH+"..8e....O.........PJkvX.2?..9&.............LE}n..3$.....AL......RR....b~....II....JCevl{`w..B_P.~sZO.._j..PToYnn..QE*6x.....**..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{J.=.......i....v}{.}{432}{00005400004900009500009500006700010100010800010800011700010800009700011400009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\620__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1329
                                  Entropy (8bit):6.738070484453916
                                  Encrypted:false
                                  SSDEEP:24:9BUFW+984tFoze4ytP6qfHSgC0fNSZBzfteJTQRw3nQ2UzfXF2tDFvyv2+JgW5BT:TG5uAd4M9/xJfAXxunnQR15vRf3
                                  MD5:88D75C2DFEB387FBD18FAD89353E4AA5
                                  SHA1:3D7552C3D48E6739130F84E4C4233BA9779878E3
                                  SHA-256:2BA35AE406634D95B0BF47BD064901464F845A5F9251CA2AB1986810BF546ACA
                                  SHA-512:F784122822CB3B3E578A5EB7EEAF7F03252EFBA63D9674112B8595540AB7AE1A0A1E35D3F11D9382EBA563E3B5D99892CDD9B6F933A9B33BDC73BA48532174F5
                                  Malicious:false
                                  Preview: ...MN...B..cbNH.X....CAv}..ZW........%?....`j.......rd....$...7jtv........yp........v)yp................. .....wp.......]N..........|q.......hqjy......QQ.py->w``wRH..............d`.).....k..MJPP..rr..%z[R....#4..ns.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.mmR.....U1..U.}{.}{445}{00005400005000004800009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\621__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):7.436820953949408
                                  Encrypted:false
                                  SSDEEP:24:FIpFfmPEsOo5Gp6kOgk84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWGyvThVEVBBp1:FQxo5MhFAd4M9/xJfAXxuXX3EnBpFUBa
                                  MD5:0B240034769FF5E818B6E2C3B2A3036A
                                  SHA1:DBAD871C8AB05B121E331180C2B4884EE841167D
                                  SHA-256:311545E3F4BD8037BBBFACAB53F8B30E5679CDCCDC4407AD25DE10E3DF6DEDDB
                                  SHA-512:70F71814FD8D5E14E88A55BE0CB96691C15E0CEBB297475CB69B517399DA3DB83B1D6E4BD4D994BD359902F8759576712302D4C2FD72E166B06BE8B5B9FE484C
                                  Malicious:false
                                  Preview: <....DQ;w2!.......oq?=....:7......0{..=n/:..7:....6m9/QL........+2...yru~wZQK...rr...................[D]S........0.....!7..WPHH__..~wKX.... :.........gQ....|M...v;w......PMdu..............l...9K-.v\..FF< ..............b6.....QB.1~x.....-BB..KX......__....o#0#............Ho...)....zE..Hr6:!f.......)1y|....3p....].=(epdm>f.E......<3......ssOS......`z................J..jb....xn........... "DA....>+poST..LEkiGVz}{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\622__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1313
                                  Entropy (8bit):7.41894760450379
                                  Encrypted:false
                                  SSDEEP:24:WRBtAMhpIURTq1+WFc1qsA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/afBBpFUBo:I8MhpFWLFETxAd4M9/xJfAXxuGaJBpFV
                                  MD5:8807D5328D24D6133425C732E91EC660
                                  SHA1:F1045B385AB55C4892281707629805CBFDA4E48A
                                  SHA-256:7B30EF284CEB7874D249054058E615A824713857857365034CA313FE6BD0055F
                                  SHA-512:6BD1512BDD155DC4FA0D40743F15AC93A6E3FB63CA29B50925CDD91F1A533652AFF42B3B816276FAD6B2468A5EE420238820748DEC56B7035EEEB3F81BF9C91D
                                  Malicious:false
                                  Preview: ...JI2'z6 3....w$......t.$(`m..>?.NG]......23@...9/...9..}kX.EG..yc`f07xq..f;(/....3:ve*=............u{....[V4.#9..6 +7....w(......*=6,.....j....9',...... m.:6ja.nNSkz............N'<*.......QQ..0;(;.,..be....'.ZK-h{......&,.....f..{g..88......5yVE<qQ^.........%md.]OI.............K..)9......p3nb..F...oz....S.....X....7.||....G........kq...?8.......M.............QF-4a9ra64..^K........ ;SZ....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\623__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1315
                                  Entropy (8bit):7.4118595906895
                                  Encrypted:false
                                  SSDEEP:24:7T23FtF0vAvngGDHla7584tFoze4ytP6qfHSgC0fNSZBzfteJTQRfgBBpFUBQ+JQ:7T21j0vAvngQGqAd4M9/xJfAXxuEIBpR
                                  MD5:574A37D964D755103F82BBAA0823D2AC
                                  SHA1:D25C5B193A9F5A975881D7A15D98357595C3727D
                                  SHA-256:A4F93BE23CADAB835720FD463413A3AFF357020C54E1F62EBE79A6679A9BC96C
                                  SHA-512:2E5703BA96D86D866E52AC80A568058DA93BD7F3C5E11AD2EE2756915D0CCD43F5A2DE8286E6686F7807D9F883D415CDE9FCDB5D5F3D1A9CA30864F8A89CD662
                                  Malicious:false
                                  Preview: .........zi,-...Y#0DZ..~u..2?......L...........h0......}K...\^..?%hn<;QX........cjAR..gp........EP.1....1<4...OTv`....mmCC.......I^3)..]...{n.....!b.,............IT..DC...NB....S^../9..............bq....,7.....R[...pzi......YS....js=.';CDSS..((.......3<....z{.&kb^|.......[a...=k..IYwh.L..T....8..S.Q]..w3#6_J...b3....D.....Xr..OO...@I..........-pTSqq...._....Tzu....#...4>...............[N.....be ;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\624__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.357857684854542
                                  Encrypted:false
                                  SSDEEP:24:jj2XofqJwlecc7s84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2yQdBBpFUBQ+JgW5R:jj0nw4ccRAd4M9/xJfAXxuXfBpFUBvfD
                                  MD5:F3A4DDEBB16A7C25D575656F671ABDF3
                                  SHA1:95290E711CB97C9231FDE2BA7BC6E15544708C3A
                                  SHA-256:53CA50E44A7E2A5798151AB086834E9261FB0987E67EDF6BB5DD723D9F806607
                                  SHA-512:6EACFCF01339B4A1F65E274DE0681D8668E181DCCEE17686654D072A96CD424F8C2A6B606010A70AE39FE84811648D1ECFBD58396BC4D36D7DD4670728AE26F1
                                  Malicious:false
                                  Preview: ......=k..........]O...gl,+.T..BPxm......DG....%9..cbY^{0!0....}bPJde..ol......=!....ik6'..,+...Z..m5..+9..FF..iz8.....(y...6\\..aj`s...?....EO.....i...T.3.T_......BM...q.L......LA......S`....jj....h{........?5.RQXd<.r....}{..... ..^G..^B....LL..nnz6......bjqn......R[gEUS...(ts.8..~9i?......x.pa..,=HJQTly94..7(<;...DF..AF..##..UFu~....5$.............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\625__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1967
                                  Entropy (8bit):7.6439211704718595
                                  Encrypted:false
                                  SSDEEP:48:J28QfeteG1tB6feydatzSF6Ad4M9/xJfAXxuzheBpFUBvfs:JufuXWeSaWpBAXQzhSF
                                  MD5:4C991359598EA090696D7CBBD77EDD93
                                  SHA1:62D4F22BF1E308D92DCF2C2D5344B2C329E1500B
                                  SHA-256:06FDB9D2DF4719EDA31409D2F29C15A0136A426940142CCB8413EC52DDB8D6D5
                                  SHA-512:F90FC1DDFB0E24FDB62650DD5DDFE27171505E80B48127790C40DED544BF4BEE1EABC545912FD01A970074B04AD8C460BC7F8513C7E6758FFC75AB148F974D55
                                  Malicious:false
                                  Preview: .Z.&(o! 0f..HR......&4v3..SX..A.Q.\N............HCa~..J.{z.........IV|f+*....^R. ............D_$#....V_.....X~..7.^M..LJ....-GmVV....&5FD..nuCD.....n6.....>Bp........._) y......94p.....yJ_u....WK.........LK@J...../I..1.....82....@Y..(4....ff........Q^.......................kg.T!w.................[....py.~/CEVQ..96..~T..../3=q..DW[L\K..-0+v......hh........fK........8/[B....fd.........LK}f*#....<;......V......[Sju9..........9X..,'\K.WZ....D,9......e4SU..{>........++......q}Z........V.(%......D/o...3&!,....................V...`-........#!....GZ..y(....3#.......................RP..?lTVe`....TA...........jm..))..?4VE^\..kp........//2...WDY[M\..*-!+.FO..j..........HJ......jfhh..p}m............/3',....ET_D....J......S@.'....FL......zi..OH..........AR m........ut..zsqS......be......q|JZ.....G....(=.......07....yJ_u....WK.........VL]@..g`..--..^....?0....tY..sy....0'.......K^....................GG..6z..l!..........2.....I^...+Y..~|SVK^..i|
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\626__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.3573630376062535
                                  Encrypted:false
                                  SSDEEP:24:Gu99OZeqYy0KQVuBb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQgYCbXcsBBpFUBg:FfuY4gAd4M9/xJfAXxuXgJrhBpFUBvfg
                                  MD5:E28394126D2084591AF7DC29A170B040
                                  SHA1:C36FA06D1D232119ABFF7F42EAA46C64BF9D73B6
                                  SHA-256:BFA9E66FC41A07B1E578E7EA8A76BF7C40E685FD4A64EE9AEB7CC50F7E14E6AB
                                  SHA-512:6E875C995CA437C3103E19B957DB76131CF654238D1416FEEB8767BD6E87FD8A2D1A7CAC0F0DAF9E4432E92DC047705426F63C9497F52867C006589B19CF9619
                                  Malicious:false
                                  Preview: ....-,91},?.....Cdw....V]..cn.."=;:.....\........{ ..kv.(.=ZL>c64..BX..<;....q,incc...h{ 7....KV.^..sl......LU1<..IS(3..0,......=b......nyIS':o,......N.og......q!I....DV...sd`q..OH....$$6iPY....W@.....id9,3,......XREJ...........3..99...._C.....3?...sq>$..ee....pv..#......3*.......+}Q.XM)<..@.f7..OHL......7.........7$.h....SN.....]]{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\627__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2048
                                  Entropy (8bit):7.674878362161391
                                  Encrypted:false
                                  SSDEEP:48:3p2XbbvJVmgBylr8+Ad4M9/xJfAXxukUBpFUBvfh:sXxar8RpBAXQkQw
                                  MD5:97239EAEA7B803FAAAECC5790EA2DC05
                                  SHA1:E2EC977186B8CAD0EE2084368DCA1EE433414D04
                                  SHA-256:A4737326D2D3CDE7E40AEF63426A1A0B429838C10525826D3DE07A8741FBF10E
                                  SHA-512:A62663F9DA9E85ECD3E22FA99E4840292C595E2F105A8CDDAA20D2875F9DF26D86F12F479E25E88F11726B83A9FA079FA7A78ADAD7092781BB18B67C4BAA918A
                                  Malicious:false
                                  Preview: ...;..8+..RT.....rp..fj"/....fgG............K..i.......v`z'....MW........E...... W^....!6../l....IV......;6...........dd...B..S@..[L..JW....H]..u`k..KX..w;.."6\+hz_@s.%2rc..>9..gg..{$....I^..BX..)j.."7....xm.....R[E\..[...................!yT1..`z..\r..Vu............RKi1.I}z....sf3&..7o..TR..G...Uf.9KK....0|W^..............%%OO|0..g*......0&...)46?(..,t..........)<..*-..../-....==..==...r?...........8/..+s..........ZM.\[..........A^BE..09DFn.kl.........o"..og..d}oB]H...........H\._......=e^.*,..............';....q?[W4l{.9>$;?)AtRH........q)IX.NVW..QN.........'&....]......._2v........*,..*o..7...ee....EL..NY.............TGN......PJ..$g...........QB`mF.Es....gu......dx....//.Y*#H[NY..$>...3>qdze...........2;.....M~..hh..bb..$5..5{....y..mw....pp..#.....?..............,.......^K}b..2)......>9.......;0..........BH............IVX.ZVA.2Q..qi.%.?i..jz.....I....6?._.60EB%`..?...!!..FZ............+j6`)$....RG.................ze..E^ah.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\628__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.7916151252959445
                                  Encrypted:false
                                  SSDEEP:24:UWMe4vsk84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNZUzfXF2tDFvy8Bp+JgW5p:vMoFAd4M9/xJfAXxu64158B0f7
                                  MD5:0F6512C3A791DBFA2C3CFD9DB7F3B7AC
                                  SHA1:B633748AAD15B210FBC90802617E497A07E59178
                                  SHA-256:7973D4B4DF1666A6EEAF3E84FDEF8B2CCEA11FED5C467D2DC2815E66830C13B9
                                  SHA-512:0987FFDA91FFFC9C05864CDB7611326D978F7E7DD0BAAC010037AFE66EC2C1C46F895BD0AC387A2B3B2BC6CBC3535372D395A4FA259B61B7F98671E5AB36A422
                                  Malicious:false
                                  Preview: ...W....W.......we....:1..k1.,>1$.........7<1./3.XY.......^..uj...}z_\....YsQM....LN........9mBK.x.......10..V..<..!!th....XZKZ..+,-'...-u.vv........EE........TV......W];o..<d..Y.....KO....{~c,#".....`2)y.... ...........83....yh......B....@ehqW......e.......IX.....C_SVV{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{;/|.C..%.q..;..<}{.}{574}{000054
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\629__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.705572322711376
                                  Encrypted:false
                                  SSDEEP:24:RIvK/zAW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRODS4/VUzfXF2tDFvy8BXCL+w:D/oAd4M9/xJfAXxuq4s158B5fI
                                  MD5:3BA61291198BD8AC0379DE36DE6407A0
                                  SHA1:F7BE2214D1D82EE966D6F41F6D28370B96EBCD8E
                                  SHA-256:E606FFB39D9571CD409AA7A12A17F69954BBE977008F1B83D5A2AA1C54861B18
                                  SHA-512:C1B121F7210BB5A3128D33D41D1EEAFD5FA364CB522D207E78D0DF3775C547DE089851BBD51E03F3B7C342D9D41BCEFD5426521C7C939A79C883EAE4289E0B8C
                                  Malicious:false
                                  Preview: .......].zia`...EV.......al.........I...rx>3.........`S..J\..WU........PY..@...ggy&..^M/8............_@=3......II............LV...@M..1.\z....KX.........d;..EVH_..rh......"7[D..tU..,......jv....vvGGhh.H.....)>........ep..!-..GM.....25....!!..UUn"YJ.@|s..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{WE..,...T.).a...}{.}{524}{0000540000500000570000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\62__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1238
                                  Entropy (8bit):7.349742938563275
                                  Encrypted:false
                                  SSDEEP:24:8vdkoOWBtB0OZYxMM84tFoze4ytP6qfHSgC0fNSZBzfteJTQREy0iBBpFUBQ+Jgo:8lkoOWF0OZnNAd4M9/xJfAXxu00iBpFs
                                  MD5:D38105A00ABE919465AB465DEC42639A
                                  SHA1:AD40EA79F181A552D5AB45792AF9511A558E8D23
                                  SHA-256:38CE3E8918C1A67B5011CCE34045FEA5DB0C8C1F1CA8DD198A6597020BA7E1BB
                                  SHA-512:FD5661ED265962C799D210C7E20665CC6EF73ED4DA39336A123E0361F9D2EEDC3F2CAC1FB15E67E392B24EDF5249ADF916BB0CF7D662BAE8D2EDC7F1AF269F45
                                  Malicious:false
                                  Preview: F.~...98j<~i....d{}b..#f......K.P.....=?......UV....xdE...70.{j........ED^Y.........]V..RPo~.......Y...IB#<...PP.........2c.....-1>5..%'et....5?C.@I6n:U.....ECSH].......|n6).....;'........,s.....fq.............5Z.at..dk....9 JGo?fUrX..22..NR4%opE......AC..u}Jd..rdpS..........MZ.......@.{l..x;.......8=..6;-8A^JM{`....xi......mm..p{pc;9..D_8?{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\630__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.694091560851086
                                  Encrypted:false
                                  SSDEEP:24:V9EADyRT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgqNTQtUzfXF2tDFvyv2+JgWQ:zjxAd4M9/xJfAXxunxs15vRfQ
                                  MD5:085B9B6AAA0856B9DBAAD94527599C23
                                  SHA1:ADDBFDBE65AF8EB20FE4D1C3DAF9A04528A47971
                                  SHA-256:7C0EEB0EC91E0651FA3AEFD1C3258832A000A11D9302BEAA6F9F72B61767230A
                                  SHA-512:DECC74AB0DE22C65A0C16974936281C77C1DC6F6E95ED928320211A95DF8E8467FEA1A9190DE888418E08ECF450A33707D72C4D0BD49816D62102A3F6A0F03B0
                                  Malicious:false
                                  Preview: ..,.B....Y..[AGF....DVT.q|..8?6l.%7....^Y.........iuc2.....A..G.....]G..G@....;..KW..bq..........z...#{....b....2..........ir..dn.]>7...XQsjhe%u^m0.yyIIG[......<-MVg`fl....s+>Ltc.... 1.....4.........ui~u........oh{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...-...c.m..@...}{.}{438}{00005400005100004800009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\631__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1522
                                  Entropy (8bit):7.523136522162715
                                  Encrypted:false
                                  SSDEEP:24:eMOm9PKRlgENNyeFlE85Crx84tFoze4ytP6qfHSgC0fNSZBzfteJTQR66uBBpFU7:eMOm9PGgEDDiCAd4M9/xJfAXxud6uBp2
                                  MD5:BF648609C7D8C283D776004FD1A59B29
                                  SHA1:19C386ADD0C7E6F7E3B4A3EA6E210EDB50E06DA6
                                  SHA-256:77A564F218D1A5EE310BDB37C3B0F16D8D5B20E78A9FE98B15B141F4CAD021BF
                                  SHA-512:4617E1FDB497241696449DC8B3E47C35AA2BD55039AA0CCE98929C158E446C5B3B6C06D7DA92A60E79F609C97767227A2F5A6ED6532955A4EC236CC8A71B3B0F
                                  Malicious:false
                                  Preview: ........</..Z\O...A_&$]Veiid%,....5~(2....?5..rs6n....-0.......FD...?9...................W@.....U...SL..so..NW%(.'..KP/9....))..h7....6!..]G.....qd...%.......b...5.............po.;,..iu25......v)..ARBU....pm[.r.}hvi...#6sy....4=..q|!q....//........D[...3k........p^.....!....|S.........L...I^..V.i-....@I/w.U..`g.t{Zi..uu....W.....bu..-7.....++..||......LD....QG..4...=*SJV......+..GJQD....vmV_$&"3FAcc.........uz..3,.=.........u..t{..[G..I:.......EP.......@B1 ..&&.....l...XW..EZLU........................#{:k.....X..tG~T..QQ_C)8...U6:.....UJ........FD;,......N.&'0a..xx..*3..$1.Zhi..F..}~-/..A.G.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\632__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.589871462567254
                                  Encrypted:false
                                  SSDEEP:24:dqa2wfWZSzkuK84tFoze4ytP6qfHSgC0fNSZBzfteJTQRbkUzfXF2tA63yrb+JgO:djLVz1vAd4M9/xJfAXxuQv1EY6fT
                                  MD5:BA3BE4D93E5F0153CF1709EEB5536DC7
                                  SHA1:AD8888044DA88FAEA3DCEDBB6CA2B90C17141DCE
                                  SHA-256:8115E51A0C0FCFEE616895E542E744DC09F717CD31E1BDBF3B0DD0F3D5349070
                                  SHA-512:2760ED64096D24FA29FC7621251276270BA2315895159957D125DFD86C61F9C1C11D4B7485C88B95F7F2D50CC3917E696CB13CCFC09A60E3A8496F222C6E1BB5
                                  Malicious:false
                                  Preview: ..........HN......LG-!..el!>......9j.....#"....UH0.3....[.. 9..?9........IN...jc{h@W"5..C^.'*..........eb....N........... =......................00..ng|o...h....X..+>..gRbC15.........-*..00....+t.....SD....E.......<0....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Q........C]....}{.}{469}{00005400005100005000009500009500006700010100010800010800011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\633__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.377288982038857
                                  Encrypted:false
                                  SSDEEP:24:NrJpv57e/9MtKA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIcjBBpFUBQ+JgW53:1J1YxAd4M9/xJfAXxuJc9BpFUBvfV
                                  MD5:A47F5DF6B6E216618321691CDB6E57F8
                                  SHA1:FA6F633A36D208892ADF5F5C4F4DB4046CB01ABC
                                  SHA-256:7223EA9748959DB56F928698D69EEF7DF1C58B4E5C46C24CC4055DFDA7E30E0E
                                  SHA-512:E3C773288DAA932384C4C8FA540603C9313EFC501F25AA9135D16AE350F32725306D0F6BB1131604651AC29D652BD289E89348CF6339E4C0F67891B0C0BCD78F
                                  Malicious:false
                                  Preview: B..o..XY7aPG?%..}b..........TS...]......wp..%&..tk.....................kh..[h........#2........le..7V....gg..........@.......4(.........,+..o;..9a....J....qs....R_......+9..x.....ZF-*XXbbcc)v+"..........+h..8-..On....Q[...%py...#1a..W}..--_C....^.."......7?......tWx~cy....><!6TM.i...@/GLXTy{.d........y=..TA......st.......hhos..=4..zm..E_KV..<;{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\634__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.637679686645413
                                  Encrypted:false
                                  SSDEEP:24:D8aSYYIQBcn6cuo84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWFSUzfXF2tA63yrbe:garPQhDAd4M9/xJfAXxu9F91EY6fT
                                  MD5:A4164EA541BCB6CFEC2DB85DD3D2DF1E
                                  SHA1:FDD2A3684110053F5C28EF1332438AF1B85D2CE3
                                  SHA-256:82C811481EA66CD30B9E3B597E0DB30CF6F3578918F1CC5C866AA3FD3BCEB476
                                  SHA-512:6659D9B5E723F4385ACFF5636B1E141ABA028F3AEF458182A605D486E64DF75010C61A8760AEBBA115A8E7A47A250528E59AF3DDB13DD559C4AD369A712FD5E2
                                  Malicious:false
                                  Preview: ...wtLY.C....N...JT....^R..gn..#"h#......&,`m....-;....+...f;....KQ........`=......W^.....................3/..!!))...JY..<+qk`}7t....3,uS44...HT..uutt........dstn.........(.hI.......CWWKOH.....==....ar'0....zgC...!4sl'+....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{G.AMF"....=.JE..}{.}{469}{00005400005100005200009500009500006700010100010800010800011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\635__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1529
                                  Entropy (8bit):7.533775717328029
                                  Encrypted:false
                                  SSDEEP:24:/VKl5ZyfJrNnrG162CHuO0qIrp84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6iQhBn:/ITZyBr5G1bssaAd4M9/xJfAXxu/TBpL
                                  MD5:C8DA315B53857FEF7182AE16866478F9
                                  SHA1:DC23A783B7425672F3ACC758F14BF3F9BCDA9185
                                  SHA-256:94892177632C06672D4DF85483DDD0F344B81B0F5DA10466841AC52F9EB686C4
                                  SHA-512:2080699F032C300CFF48F28473B798AF4B3C9CF3D0168ED5D79F3082EAA19C2AA070B1FFF04592FF756142484FB924F5E47773CAC3A1861876B8FF46EE202666
                                  Malicious:false
                                  Preview: .z.mR.............'5X...P[.....I\mo.........iv6*].ml..P.bs.8%....lm......bQ~T........ix~ey~..!u....%7......dw.,..yu....:@@\@%...........PZ..XQG.....=|gLGK......FK.............q`..TS..}}..=bof6%..mz...........On.......oOyp....e5.+...//))..FWivE.....A$..A[..Wy........?%...........N.....hlg...0W....U^K=..U@i|...5dLJ07.........&&....;2=.........w*....ttww`,n}^.........^T.9CA.......ZX.........../409eg..dczz........W[T..........DSRK.l.....BI..fdD-..j}...m.........Q...cd.......KK&&..$5="Y.....b...>7.AO.ID..FY...K.....u` -..8'g`........^Y.........I.('nf....om..}_.......L..jz..1g..pqG...LNOU.....xm==g0[...FB{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\636__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.592846228261576
                                  Encrypted:false
                                  SSDEEP:24:2Do0Q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSgOWcsUzfXF2tA63yrb+JgW5ns:IouAd4M9/xJfAXxunWG1EY6fi
                                  MD5:FADA5854E6311808B31538DB5767A1EA
                                  SHA1:715A5D71DA785E82995417814E85ACF88FF129E2
                                  SHA-256:607316893071AFD7AB41FA7B6B67A065A9CFF19DA2363A479F9E7CF1FD495D58
                                  SHA-512:5C3CCA2CE8C882CF4E85E98A022641CF882B29CF1AAFE8DA282DD627AC26F30594F23EBCFD5AB85945DA0D47BD25D5CAE759E2541CC4481EF8A41AE6C18D465C
                                  Malicious:false
                                  Preview: +.....`a.X..........)l(%..61..K.....PRVQR]...-......c2*+...q`c>........\[..>2...,0..!2eg....43LFs'....t...3WkX..nn..p{........~y....>7j2...9 - .E....ee......GT....0+.............+.*...;&..~/..Xr{{aa.......{y......]W8l..x ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..@...Z*|..{.F..}{.}{459}{0000540000510000540000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\637__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1283
                                  Entropy (8bit):7.415406360062894
                                  Encrypted:false
                                  SSDEEP:24:weqfSmqi/VVGG6L2l84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWHBBpFUBQ+JgW5s:wBfxR/fG5L22Ad4M9/xJfAXxuJhBpFUs
                                  MD5:73B4574518D52D6F6FC4CBF810BCD1E7
                                  SHA1:B589327F9D581785FB8CEFE3C973F0390DD8794F
                                  SHA-256:2F227C500CE2562053E00E8E09DF306E6DC5499993165CDE43B19023E3662E1E
                                  SHA-512:A92BBDAB8F2B2372447FA0C6D70F30C2B4123159C7079B580790677A738849DA6B88D7A1C04BD4519D8FE34340ECD9255C95323FA730958C1DCEAF14E8BB524E
                                  Malicious:false
                                  Preview: ........&5A@..c0/<.................}....kfJKk3.^..3..#<......B[.........;f..FF,s}t.......xe....WB.........GJ..........]Z..zz..CP..zm.....CN..... ......u}..iu8/..pz... W...........x....ww..zs:)~i....MP.........Mh......-.....1<.A...(..ii.........L..-u>[....,.++se.....3.....j}..f>.H......A...0.........,tJ.....j/........oo..S.{r...DS :...EB.......[....4;..UJ........ac....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\638__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.599626096023746
                                  Encrypted:false
                                  SSDEEP:24:zvEcj1H7X7IAB84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8GUzfXF2tA63yrb+JgH:Xj1HIASAd4M9/xJfAXxurh1EY6fi
                                  MD5:5EAE6D7C197F957F41EDC4E152211614
                                  SHA1:B0CA2C4731E3F31FE83566E6768AB74FD9DF8772
                                  SHA-256:4D8632FC03390FFAA5B79890E253A394FE4AFFC8A55DFFFB8EFBA915D2A36237
                                  SHA-512:D4078058DCB2B7099EE13CE81E4ED938ABF18670FB13984EEA6FAEE96BCB0D96EA0E0BBB4AEA0F3928E98671FAE495EAFDECBB34852BD9113BC98D3D91C4B663
                                  Malicious:false
                                  Preview: ..y.X...N....89..a~..i,......"x..GU....NIuz..yz..GX..r#..LK..du...EZ.....wt....mG....,?..%4......j>~w.!N.>3W.....SO........HO........i`....m=N}......P[RA.,XI....hb..A...............].@s..``......yr....sb..8?.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Y..A..F._.l.81G}{.}{459}{0000540000510000560000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\639__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1284
                                  Entropy (8bit):7.417965199668141
                                  Encrypted:false
                                  SSDEEP:24:R+/UXghbrFekzAZ384tFoze4ytP6qfHSgC0fNSZBzfteJTQRZf/VBBpFUBQ+JgWR:8/ig1FepMAd4M9/xJfAXxuyfvBpFUBvJ
                                  MD5:D3547BF2038FABA41D42C55FB1A013CF
                                  SHA1:FA8D5432F19FEC99E875F99DE754238630AE26C2
                                  SHA-256:5D279CACA97565B626A02FFC718C470B6CD46C9F72409A8E1A3FC67F30BF0B8E
                                  SHA-512:ABA39E946226B427AF9196E208A9E9FC722BFE711C7988C3EE1BC1990017FD5C05BCD2C35A1F59B7B1F7BB3DE0C4E2D8493BABB922CE6F1AF49742F0749C6A7E
                                  Malicious:false
                                  Preview: .\../h..R.ox....qn........?4CD.#t..............os.."#..........HR........rA....sx......7,ru...^/&.......CZ..fMio]Q*{.....!=......YH..?8ak.....1G!&..no..`......SUw09...."65Bwe.......2...RR**MM..$-.......$9I...qd....Nk.........zw..#..!.........IVR............Q...../*,ou..GOtv.......7/..F.~r.y=.....d<Q...@GJ...rA.........@;2..bu]J..sn.' ....%%...[.|s..D[Jg$2........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\63__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.393166555700022
                                  Encrypted:false
                                  SSDEEP:24:Bep7oq12IObVCb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRebxBBpFUBQ+JgW5R:Bep7HabkgAd4M9/xJfAXxu/jBpFUBvfD
                                  MD5:658DD5E837C40EC8EDE5DCC510FC8EC5
                                  SHA1:04B9AB4B352A8B7CD0DD440ED03D6570BD0ADDAB
                                  SHA-256:D163E90DE0B9A7A341CFD2154AFCC91BE14F193A62A826B9884B38CC90C183F0
                                  SHA-512:DE4B3145BA7271433DC41FE7C8A233F01A49EB49F41D2B6BE70CB41FB6B36C7F23BF2B51F02C4BE41D953B06F8F64F70A5E57B6909F00A250A26236E1DD0DA90
                                  Malicious:false
                                  Preview: .H......V1&SI.........NNC..INd>.;)..LNST..DA....iv..|-..PW.W...$9....ON..GDjf.. .....AR..TE.....:3E.!@m.......-.TR..S.........*!AR..TE....v|.+"E.'SIV....( ....AR....=d..%%.....`..p...;.....QM........un..nd1eOF1i.r...9.. /GMQw..g~........--..1}JY..q~..A^....cD......pp'...........?2aq..wp....ET.......@..T$`..2'........X_..Bq..KK.........w`... ={ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\640__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.593984562275536
                                  Encrypted:false
                                  SSDEEP:24:ercE6CyLVT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUoQUzfXF2tA63yrb+JgW5s:8R6CPAd4M9/xJfAXxuEr1EY6fi
                                  MD5:265F4B6E672F1C747F24EF529EC40F5F
                                  SHA1:0C56FF33CBF85B0DA827167799DFB7D6DC83DAB7
                                  SHA-256:4F61D23990242BDC5AE6D7C6A3CFD6EB962984F4A4174A295BB297ADC3600082
                                  SHA-512:0400C6780E879F44F3ADF70096239B1F1435D477DC9E4CABF29C8B8374D48840A61A06782F384E101FE87AD4CB661ACE1E959217E06F474B4444F92F10472CF4
                                  Malicious:false
                                  Preview: ...vu2ut8n}jkq%$wh{dzh8}GJw|qv-w..>,gr:8&!yv|y&%..wh3/k:)(..$o+:..8%<#kqKJqv.|%)&.@jjv{p5&y{l}8#Z]#)j>ah..:U[K.h..@jjj8$..yjy{........I.....K*..PI...Z........2..FUom......=75a..H.#QXO"...PA}`+"....7......$8@K......NU.....T6?..x~{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{]`..k`.L.H....}{.}{459}{0000540000520000480000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\641__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1284
                                  Entropy (8bit):7.384932470527522
                                  Encrypted:false
                                  SSDEEP:24:d4e2RUsSezjAPoTf+G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWszwEPBBpFUBQg:mjRPLzjVf+7Ad4M9/xJfAXxuZ7E5BpFk
                                  MD5:86B41DB607F8CF91EAB11A8F21738022
                                  SHA1:555FD21026885DF3C887FEFFE181CED2714C05DE
                                  SHA-256:E7F35F2AF04A02AF12EB170FC35727876B1FCE8577A1BCBF317BE859CC4AEDB3
                                  SHA-512:4F633BB64A3E1322BEC41D2E2EC0A2DFFA8974B66AF93249A89E602C1DA4D6ABE940765BFD55AF822EC2E45A3C6502C90841822C74B3E57FBC7F3C64F70AA15B
                                  Malicious:false
                                  Preview: ...Q....%s........c|R@k.[V4?...Q.%7..WU..4;.................M..2o..ju......LO}qbQ.#..K@..y{..OT..oe\......0"!.@@xa....p|..~M.....0;</..ud..WP..<hOF..W!07 8....<;...$........P..kk..HE.k}~..7v\..KK....WD75ix..........b:[=....!'hg..vP....=......!!..dd.[...A....$;..SR....vT..''=.=:QkMAL..Z,!L\..mk..cd/$.T..jhAD%0....'8..QJxqY[......((..%6.........$#_U..........gx......oHSIQ....xu{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\642__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.6236692346509045
                                  Encrypted:false
                                  SSDEEP:24:1vaJiHwKzhOWPtX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRtO53UzfXF2tA63yrT:1Hw0hrPtsAd4M9/xJfAXxuyOY1EY6fi
                                  MD5:4D030624275D0813DE97198D91E0655A
                                  SHA1:4C75E3B08BE7D2C9EF71CFAB9EDD4EA97CFD763A
                                  SHA-256:BAC85072AF1D135692435462E38D6777453C294FE52D3FCD88E20D61D6AA4A4D
                                  SHA-512:41568D17922C65709ABB864F7934690417F6F100A4F8927B3D22F3CE5B77452CBAC016894AC07C0DC41287BA3999381588D05038BB01DFF015FDB6987C0F2084
                                  Malicious:false
                                  Preview: &r.U.i...Rct..FGSL....>{......A.X.....NL....9<..ZQ....z+....w<.....3,....IN........OS../<............EL}%.UE...\v....zq....CR..*-....R[......d}...Ve.........^M..(93(8?..a5>7............. )T.bQ....;;......9*..yh..9>...ofY...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{q._..>p,.....q}{.}{459}{0000540000520000500000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\643__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1282
                                  Entropy (8bit):7.399575831581445
                                  Encrypted:false
                                  SSDEEP:24:gkr0GPxRIE2KTn84tFoze4ytP6qfHSgC0fNSZBzfteJTQREqBBpFUBQ+JgW5x:DXIEF8Ad4M9/xJfAXxuDaBpFUBvfj
                                  MD5:E7D25645C18BB25E4BEB4824019359C4
                                  SHA1:FCDF558B1D474A0CAA6042D95EC39EE4A7AC8E5C
                                  SHA-256:93CE851542F3C329569332F6386E1589CF6BDCDAEB276E6A2AD7F1CF3122329C
                                  SHA-512:114E87B1D601C2994027860A4C58F9A9DEB2C88D0191AA56F8410843B78D2FEAB03BE35A80BA8E4428CCF211309372150FCB418DA67B0DE7F84F5E0F168A0E41
                                  Malicious:false
                                  Preview: e17.8............iv.....\W....h?bp..........tw#(....N.....9r^O....VIis...................521;......p.....cz........................:!..........PW...../F..........|p....&+.s...tG.6....HT....y{9(....T^....`8.{....ECs|...............CC]]...'45x.....tc......Wu...........T.O....d{....ohod..WU........9,c|..qxge..ni......9*..........kl%/..+.....4(.......5m.....Jvy5...cs{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\644__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.605642995935891
                                  Encrypted:false
                                  SSDEEP:24:T3VUuYF684tFoze4ytP6qfHSgC0fNSZBzfteJTQR8lzX7UzfXF2tA63yrb+JgW5s:TCAd4M9/xJfAXxu5lzXK1EY6fi
                                  MD5:0893C42D1181F3A4B067318C679C5E69
                                  SHA1:A16D15B4BBA9E9606FE9C9858DE49DBDE27521F6
                                  SHA-256:5623EDBE35AEAC7E61793B9D63EB06D852F4A508735FFD76478BE798699BFE61
                                  SHA-512:BCE2D0E7E18D36B9CC77718E2321212CF089A8D79718E5548734C780B0DC9AA48BC742F3ADE22D27F37BA41780CF09F3A74E3B224BDA4B16C2614418263059F2
                                  Malicious:false
                                  Preview: ....R..!w..xb[Z..\C..;~..k`...%...ep.......")c|........0{...W....uo......q}M~..0,..?,...........[bk.D.z....DwNd))..ZQjy......y~..4`py..........w'..ySSS..^Bw|..FD..XC.........._H...0!': )K.aR............</TVZK......U.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{~..m...[Q....}{.}{459}{0000540000520000520000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\645__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1284
                                  Entropy (8bit):7.411146719892695
                                  Encrypted:false
                                  SSDEEP:24:ex8lBUpVLgwHoH284tFoze4ytP6qfHSgC0fNSZBzfteJTQRTEcBBpFUBQ+JgW5D:ZBm2ZHrAd4M9/xJfAXxuoE0BpFUBvfR
                                  MD5:625845B9836A0DE9EB4E303A4226F078
                                  SHA1:18BF5F004F41EE897BF36584E33A089638BC2ED3
                                  SHA-256:3359DA6D5220BF17F3E7ACAAA6D46804AB0D842E89EC3F43CB7E97F41C5B0220
                                  SHA-512:1DC8D00EC977ED036A926F5CD687D080A525D5A8868B664207A94287208BCC0A617A02D5F45BB513C91A3BFE2E9D6C33AA0AF64EF715D3D53CB7D90F47048DF9
                                  Malicious:false
                                  Preview: ..w.....T.....~........3>..........IK_X..|y...hw`|.gf..._M\..`}RM......]^..{H..?#/$..........B.sz..[:GU.;AAzc|o......._..........N].............G.0F]Z........&a[........h.BN&&....S:..:HbQGmZZ..!=`k....et_D......i1...._|CE.... .FF....ht...........P..z7........"#Cd=4..qw.. .]Z.....i.......[]......W...%'{~..r.....}z)2....AP.....22........1 IR....vE,.......%4..._..G........i%m;TY{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\646__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.625304090307276
                                  Encrypted:false
                                  SSDEEP:24:2vYtYGY7oB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRPbtcsUzfXF2tA63yrb+JgH:2xn8SAd4M9/xJfAXxuUtG1EY6fi
                                  MD5:4ECB6B1AFEFADF032E46D1B3DF44350C
                                  SHA1:6166955E8994F5851FF577534582032E5026636A
                                  SHA-256:56207FE1BB0B6DBA8EA2F6C9FD85D52C4C81EAF80C3D56EEF121006BDB4311BE
                                  SHA-512:94BCF09D92031BB34D95A0F03D3BA2E9C1779973B07592A00605A469356811425D595A4540C55FC542B8872AB8E2E586045FC6A39F09139EDB0A9B6F106BF1C1
                                  Malicious:false
                                  Preview: A.[....S.^I..23..YF..c&di......."0|i........T_....K..JM.I....ZG...e....vu..%...zf-&......YB.......[.E*...m.>.$**..%.............18.K.``iG^.....oEqq.......75....(/..8l!(...k|..|B....t}D...0........./$.............w~2jF@{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..o.zg..^.H.....}{.}{459}{0000540000520000540000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\647__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1281
                                  Entropy (8bit):7.400545673155708
                                  Encrypted:false
                                  SSDEEP:24:pVbBpFNsNmkQ33HNB4dj84tFoze4ytP6qfHSgC0fNSZBzfteJTQRF+BBpFUBQ+Je:XbB3mNm3NBWoAd4M9/xJfAXxu6+BpFUS
                                  MD5:F03156CFB6021A8507713BCDE3059ED6
                                  SHA1:49243FC3EB7BEF572438062CA5FC5438164E39FF
                                  SHA-256:88425F6E9EF73999400B0DD949FD49B476682A1D152098081C1C8035AE3B38DC
                                  SHA-512:644125A6EF475DCE51BE5C2FD7AA495039A376A9DE1B643FD98F540060FDFEACA05062C3C65F2791BF8895A3470DD0A118B66061593E60C49EAE28C12D70FADF
                                  Malicious:false
                                  Preview: ~....OZ.O....../|............ez.._...N........-v..dy.?LzES0mTV/6MW.......`g..Q..v..bu..&<................_F/"AvA[..UC..:=.....Q..`s..w`......*?..cE..in.tJBVt..........n..........vj|{ww..ww.Q..^M....PJ= Z...]H..iH....EO............iZ6.ww...........K..@.K...f|..p^..aw....si..pxDFw`..d<+}<;&>! Q...~1.YL..4=...)/..:...6..*((..:&..r{h{l{........<;??..uuX.,?....ME....4"...........N{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\648__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.594244955296768
                                  Encrypted:false
                                  SSDEEP:24:+TtDvnnqeuDcgh84tFoze4ytP6qfHSgC0fNSZBzfteJTQRul/UzfXF2tA63yrb+K:ktzqe2yAd4M9/xJfAXxupu1EY6fi
                                  MD5:4AA28930C07436A77185E8F9A9DF2FB3
                                  SHA1:48C40F99747CB5BC367338767F9E4331D50E1EC5
                                  SHA-256:8EA623B91A3D53240BCE52BA7DC333140F8F1AD69BB44DFE7DC93CF3D46EF0D8
                                  SHA-512:81DDF6D7CEC83A4E2DCE9E2E3C35CDEBD1E2560FCAF11286B65C8C8F24F07A0750F9EB0C065DA3EE7A63EE2BA91B84393997A90DCC1D6F4FE02235D623FB9C53
                                  Malicious:false
                                  Preview: ......YX.A..\F*+....>,........L.hz*?...........GX9%>o.....N_!|8%..%?CBIN=>vzo\....}v...}?.UN..ND?k3:)q...<X....\\..gl........%/..) 9a........9ikXYs00....mf.. "......mgs'...C.......0 1|aT]S...\v$$....}vFU.....5.....N...24{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.{..I.[m./.<...9}{.}{459}{0000540000520000560000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\649__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1280
                                  Entropy (8bit):7.409591968012403
                                  Encrypted:false
                                  SSDEEP:24:6BNryBC3kHx1iuT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR124q/VBBpFUBQ+Jgk:+0RCAd4M9/xJfAXxu14qvBpFUBvft
                                  MD5:435753F219BD21833DC33F93E11870B5
                                  SHA1:8D43C301F42F1C82B628BA6ED47E459AA0F73F5D
                                  SHA-256:8271F95AB7619EF87415CF89D27B03423927682E7FCA08353139D275930DA33E
                                  SHA-512:94026B916BBDD2A84B413690DDF7902C24AA26102D3B3650420B830FE1C9254D52D120D7688825E7CEC19918006EF2D447E01C613D15D29ECEF3F9CC6303DA62
                                  Malicious:false
                                  Preview: ...#d.....yc........R.....z}..............%&',tkg{p!<=..X.gv+vti................ENGTGE..F]G@]W.X.....yk..............k:...............mvlkv|~*dmx ?I........o..............i~hy..........sxqbnl..za{|IC.........+>8UZ.....<%>-..LK....PPEE.......]UB]PG....bk..06``..PW.6..n).Qnc...JLli...a,/-......,!.................ss..........&7..61....Q{11FF.......K...G*I6-%=..v:!whe....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\64__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1236
                                  Entropy (8bit):7.3873386035678275
                                  Encrypted:false
                                  SSDEEP:24:lTIAT+I3wb37xm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUIZ8Z0BBpFUBQ+JgW7:BIkgb3tbAd4M9/xJfAXxuO8cBpFUBvf7
                                  MD5:7B94E40D951FE2123F9630D6EB996902
                                  SHA1:BD8E2E7028A7E1584704A5A47EE9685D5F51C506
                                  SHA-256:BA8C99365E442DE44008D4D891CEB27886AAD6DFBC1A0FBA9A99E3F3752883D0
                                  SHA-512:2C2DE7BC432E80AAD19A99328309A6BF91B4731057AF2853A2F491D4AFB5F41DE456490C13EAB4F2FD1965DD1DA4C29812FBF12B540329A0B5A03B5BD69B582E
                                  Malicious:false
                                  Preview: ._....{zr$..hr'&..qn....q|....\.e2...........mn......R...JMF.etj7......_^..vu..o\..=!..l...fw..y~..........^xaa....`Kiokg..9../......9*.....................-%`}....6o.....S^..n.....66AA.................R....c..Rqz|GH..]{..cz.. <..}}..aa...X...s{)6....qVV_=.....[d..;...w0<j..............qti|../:..........J[......cc........0!\G9>}w3..!ZZ{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\650__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.622945035095814
                                  Encrypted:false
                                  SSDEEP:24:oNZpMc/E584tFoze4ytP6qfHSgC0fNSZBzfteJTQRVdddUzfXF2tA63yrb+JgW5s:CZukEqAd4M9/xJfAXxukO1EY6fi
                                  MD5:CEAD0DC93BAF20D4F81B32A0AFB6F3D1
                                  SHA1:A8018983485AFC96BF7924062BA6D6CF0D8E1AF0
                                  SHA-256:7BD3C40096794F710E4AA6976CA4CD15D82DAE7496F433DBE630DB33AED824DA
                                  SHA-512:31A4BC19AAD4A77024934F534E2F31774118DA6F04C68229DF8960D346E790F2B88C04421228CDDA079822127B0FB0371FABBEB9CF1606AF49CFBB570153E27B
                                  Malicious:false
                                  Preview: ...a.AFG/y7 ....mrnq.......ho..o}..b`............]A...]Z(c'6..OR..pj..~y..DH.%.:....AR..........m9>76n.iP@....;.........jh..YB.........gnWN{vH....(GG......+8...LW..i=..t,z...tNdZ..0-...'.......@@..@K......^E....~*......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{6p....."Cw...q..}{.}{459}{0000540000530000480000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\651__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1280
                                  Entropy (8bit):7.406567895426058
                                  Encrypted:false
                                  SSDEEP:24:+ESSDkrWaYs84tFoze4ytP6qfHSgC0fNSZBzfteJTQRe3deBBpFUBQ+JgW5v:5SSDkrqAd4M9/xJfAXxuv3IBpFUBvft
                                  MD5:4BD2542D687B0A49B24C8A891A6630DD
                                  SHA1:7139A34DE32F3812E967312D35931D3CDB54256E
                                  SHA-256:F4103E3DC99A9B9DFD6AC892CA2AFAB63A0FD473ED9A09A3374A1FBAECF754E6
                                  SHA-512:04CD21861DE66192A4E9A6EB85A3F03148B36707BC84C90B420AF800DC651D73115F46B9AEF8F49C326CF84BD4CCF3C8012A8A3C6497F3BF317EB76B755CEE75
                                  Malicious:false
                                  Preview: .Q........UT..2-........`g...n|......^QSV21.... <h9........F........*-..]Q...2:&5>................y!.ug............"s`S..""MQ....}.YH&=......+".Y?I....ed+n}.....Q......p.....TC..LK....??0o5<...........r..........PZ......sj....O|......~~....c|W.`l...a..LV..........71...._Wfd{lQH...fa.......R.L........\..:=.A"-...8....@\..7>........HU(u.....zzz6.."oWX&... .....Z{><tc..G.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\652__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1380
                                  Entropy (8bit):6.588916788866661
                                  Encrypted:false
                                  SSDEEP:24:tPcu7D2KXs4+xA84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6EPV2UzfXF2tA63yrn:tPfQ1LAd4M9/xJfAXxumR1EY6fu
                                  MD5:CA6FC0C3313FCBA70C3C53DA0E582FA5
                                  SHA1:7068D419096AD92F0037B125DA10A8E0D03A271D
                                  SHA-256:AAE80E4F75A586C0DE6687B9E59CDCE44E41A023CE38F668B64DAD5D961A5D49
                                  SHA-512:685AC48674F46707EEDE48DE350313E9114A9D968DEC190A6D43BDD13A4A66DCDE1DDEA69E6CC10265C713132EE79374D3471D350730A5383AA84908A71AD3D2
                                  Malicious:false
                                  Preview: ..3.CB.~i..+*~a,3....OB..x.=g.T..<)y{........en..JV.........R.VK~aisNOPW.....w]so.....^O.....Y....Jx.)9...);.....bi/<.......t~s'.'.W........[...JJ66..AJ......ir....7c...JP"]J...0\MDYLE.........__........BS......'sr{{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Zk.....F...0pU.}{.}{450}{00005400005300005000009500009500006700010100010800010800011700010800
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\653__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.353437654380657
                                  Encrypted:false
                                  SSDEEP:24:lM8pxAaOa4BoIRabT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsVBBpFUBQ+JgW5I:ljxAy8QYAd4M9/xJfAXxuLnBpFUBvfS
                                  MD5:96F9BF1E5D406AADEEE75AC1027B1404
                                  SHA1:9637A83C5C49A24F3D001B74A9EE01248E931652
                                  SHA-256:3C8BEC8EB99E897A4F0D75734503A19A7288B44A65130C92136B4D6624660B63
                                  SHA-512:EA14138BBB9DB6ADD8ABCE7E2D11ED3DB5A023F6E6AE403AC3003E579AED5298BFDD0D2F32BB5A13EBF8BECAF7160711DAF56D8DAADD61AB27277E07DDC8C5D3
                                  Malicious:false
                                  Preview: .VR.... l..z{us.QVEiw....2>~s....NO.........qp\...8....?....rp..../)OH....+v..rr....JY..J]3).b.Tla..6)..g{90..gP..$?....#$WW..%z...........i*xu........p$.~w~..AY.y ......OB;R......OO......qb......x...h<.....]NHkdb..T^....`y..jv..HH..##.....l!YV......&'....;...""Mr*-.>ma{<.T7:..........~9....{pc9klIK$!.."/..1..........?..$$......V]->.....5..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\654__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1505
                                  Entropy (8bit):7.517331072058528
                                  Encrypted:false
                                  SSDEEP:24:osPWYjFTE4h2DirTbkqw2BW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVRYBBpFUu:Zu4Fwi2irTbkqwiAd4M9/xJfAXxuwRQv
                                  MD5:23D78A21BA3D6D17800411E46266FB2A
                                  SHA1:B7CB7C7467178C3CAE9BA5CAEDC5DD6154AFF4A3
                                  SHA-256:CB7483C7C8EBB6EC418992A95B4606C6BCF872204D738DA3024CE7E86A53333E
                                  SHA-512:514F5D2609FC5BC4F5FB8324A68309156DFFE208D47D73257AC0E0F8E6E7E7FF7803D8118762B618811B5C41DE2EBB07016C073DB019B0393ECB294506645A6A
                                  Malicious:false
                                  Preview: ,x|.Y.@A....LV..\CPO../j....Z].......VT.............1`23.........uj..rsts..CO....fz........BYhorx...`8'F..jL....JY.......@\o.;;;EYt.l.lnq`........:3.RM-`i........K}$0..qc...o..;*ZFur....xxd;...........3`#wz..^A........2=7............))))..KWGVEZ..59.A^;`bHR,$-....?...e."..MOsdf..@_...........JHpu`u..5 .....YP....EB??....o|.....................;*ZE.F............QS.CN.......~k....6n..:<' W.}r"..<OO.......`........AC.......x_dd!#....^S(=xg61...v|~q`8?aa.....;(...;3....Jg..{yk|+2...............M...Y^.WX.0....77WK..,3....L....`....`z..nlgp..<d...Klm..~a..mi......P..........." ..E.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\655__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1509
                                  Entropy (8bit):7.519104633430445
                                  Encrypted:false
                                  SSDEEP:24:YghWCQZRr9IWQMjsj9IPYpeKeFIgy9z7vY84tFoze4ytP6qfHSgC0fNSZBzfteJZ:pOLrCXKPYpeKeip7xAd4M9/xJfAXxuvN
                                  MD5:445E1D8145983DFA01ADA04339D61D63
                                  SHA1:0E6034D459F21978BA6CD87E4BAF712AD38DEA86
                                  SHA-256:46982AAA8081EAF8B708F57D06970BF7DF91DE5B1B546A99D42507C4336D76C1
                                  SHA-512:729DF8358D9D610D6E7F73B23708D6415C68856930861B744E811B78BBFCE12D627917F0238E909A30227491929F661114A038E89B6B66B3B1ABDE6238AE3321
                                  Malicious:false
                                  Preview: .......P.AVE_.........P].....s$DV....uz....xs........D]L...........JF..1...........sh....r&-$g?.....@@....iB..UY..zP..UI....LN=,jq9>...*#d<.if}...B..fi...uC...i..JU.C..7&.........r-.......Z@MP.....HW...:......)..........J`........|m]B...B....OU..{U...i.......DL..ZMD]?g../*.U...}.46...........}f.....25..BBDD+8#(..........U_..;......./>? .BN..\?8#......V.id....l..@H]....L.P.\Z...DKzI................3ULZ'fD............VT..7"$)..+4?8....DF..CD...... l...../'.................Qw........VCbk.......[...h[..))''jv..<#f($(...70....fSa{..EG....R.....$%....99.....rg....A_...@....QU.@.H]{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\656__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.377224755869897
                                  Encrypted:false
                                  SSDEEP:24:pOgPUozi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUPgcsBBpFUBQ+JgW5xs:3UKAd4M9/xJfAXxunghBpFUBvfTs
                                  MD5:6F1B68610A0817277768CB9D59CC2717
                                  SHA1:BB40AE536AFD61754B251BE99CBA800B9EB0E32F
                                  SHA-256:D3B1970AB3AC421007A67100C342AE6C671D1445346122FF38ACC44402FB9334
                                  SHA-512:77AB3810A9C64B824C46197C34CE2B8BF23C28FCFCA1CBB21E5FFD72B24400FE0A883709C294D948A116E25616F6D402C6EBDE71B6EB9E0AB8D39AAEAADFB429
                                  Malicious:false
                                  Preview: .$ )*..C.!2..>8....:$..RY......................-v.../..3fp.. "..9#....le....+,...Eqx..gp..OU............"+e|*'{L....[M....55..)vSZ|o..k|...*i..=(......'.S\..T"..^R..0+.....h.Ra..LL......[H..............vYJ.!Y_uz........ 3uiLK............4<..PG...DM:.AG..hW..$...H.i?........}hvaJY..t7%aly.......$"^Y....jY......XD.@i`wd..J]..1,..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\657__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.3598254706837185
                                  Encrypted:false
                                  SSDEEP:24:dsl0HMkcJ/+184tFoze4ytP6qfHSgC0fNSZBzfteJTQRCVkRBBpFUBQ+JgW5t:O0HMka/fAd4M9/xJfAXxu3kDBpFUBvfv
                                  MD5:FD6FE25FEC0FC410D6A91C598E19D6A6
                                  SHA1:676AB1EC2DD7E24BF72641E31318EB50C7FBF52D
                                  SHA-256:8ADBC8CBC9B6C435B9B542382C804D9BBD9693102A4C7B2D92F0CE34AFFE7BB4
                                  SHA-512:FED13DEDE2C45CBD07430B5824D6D26554932D36B9A4BFD6F6F838EEB65F40BD1852268646F17C7274677DBAA3CD91316015D141F4618AB84B11122F9B35151D
                                  Malicious:false
                                  Preview: .e........$%......E.;6....@..`r!4..=:..|yyz....< ..^_..k ...M..c|..........U.....FURP......BH9m..B......6..KR..#..../~,.Zp............[\)#9m.....6U.7......xZ.....f.......^S.w..+Y...+....9%......~o]F..../{u|...8+....1>NDy_..\E}n?#ts..yyvv..'k........'8....;...lN~x...........D&p....GX >..5 ../<t9.m)xm.....Y....34.................qb......}`..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\658__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.621375377066749
                                  Encrypted:false
                                  SSDEEP:24:tukZc//284tFoze4ytP6qfHSgC0fNSZBzfteJTQRBUUzfXF2tA63yrb+JgW5ns:tukZc3rAd4M9/xJfAXxu6f1EY6fi
                                  MD5:E15976E10F5547454F1F89054E0E1539
                                  SHA1:93B2C32269F9AF53AF48CBDDAD5F53F55396A73B
                                  SHA-256:F7989F7398421FD9C265E2BA3A15CA15B52FB604C3A062F1650EF044F9A95686
                                  SHA-512:FD4238D5757AC639986AA13118CF251F0726276A8025BB95223B2828DBD5535F59CBDE78530D69FDD11FF994F7DDC615D8735CBCBC906AF00A4839921BC71C08
                                  Malicious:false
                                  Preview: ...u..vw;m)>..]\..:%...MFK....&|c4..n{...P_.........."sno..s8|m0mmp'8....RU......0......... 1....|v....3\M]..Kx..WW..WDtv......@J.....7V18........`J..kkpl..fu%'..7,..7=.....D6K\Tn..duhu..!p@s.!....MM..MF....cr^E}z* 8l.._.QW{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....AQ...c.Y2J>}{.}{459}{0000540000530000560000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\659__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.770292430730326
                                  Encrypted:false
                                  SSDEEP:24:/JEjUFoIDlKNb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7VEp/VUzfXF2tDFvy8p:/JRZKSAd4M9/xJfAXxu6Eps158B0fY
                                  MD5:D1CEC4D7C832F282A5721BAAB586F926
                                  SHA1:EE7A7EFE263F610D049A883F392E55CA6C0A8A95
                                  SHA-256:0E21836BA31ADD6A77720CD3BB5AEB6DA375FBDF741B74197838AC72C73F357D
                                  SHA-512:C56F6F5CE66368284CA6F355062774D4DA2036AB8D917027BD503F0EE6E3DA4A9F5E664AE10FAD3FD4E79BA284E226E08498B578EF6EE73F71A62A1EA0E22451
                                  Malicious:false
                                  Preview: .....,9..pc..[]b1..E[....59kf09..-,..E_.H]..CNa`..../2.).....|~....*,..MDSX.FA..`?..]N........B......qS:#........th......R...9*......{f......Hz*<wp..;<''..dd......l{_H..RO......yf..............r%...\[wc.H....V.TV....OH66........:)UB`w{a2/k(.#}h.....:#......6$ ^hyy{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.*..p.2./......}{.}{556}{000054000053000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\65__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1206
                                  Entropy (8bit):7.362484196999808
                                  Encrypted:false
                                  SSDEEP:24:mGGoWg4dK684tFoze4ytP6qfHSgC0fNSZBzfteJTQRa4xJ0zBBpFUBQ+JgW57:mGGocdKfAd4M9/xJfAXxuox+NBpFUBvx
                                  MD5:47629B61DB1B504DE73C5EBB31B6114F
                                  SHA1:752E910ABBEE99BBB932A602EC1B5408254CF0C9
                                  SHA-256:9FB2D335B49FCE904BF6AD189AF75EA945F1D587F253F9189C9BCAC1BAD9BA8B
                                  SHA-512:6C9B1A882EB8F754F41A912B7EC426A6D09DB395A2568BE7E33D95A77688A124F46213B74F475BAB5F0D8B28732FE1FF7F28F13A3D2C19EA86AADC73DA78E72D
                                  Malicious:false
                                  Preview: |($....f0....$;juCQy<)${pfa...#1....).\SQT......a}.[..g`..=,0m..C\..)(..twnb.3.;..~uracaCR....5?._-$.....vP......~x......%%*6....tv....inFL&r........me.......c3j....BY]P|.......22..................J..._+M........<6tR.........((......(d..p=ifGO..:-on....Pr.....EB......r$\Q..d{.........YL@4{..[N|i..../~....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\660__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.711858837932992
                                  Encrypted:false
                                  SSDEEP:24:+DH0LRt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFE7UzfXF2tDFvy8BXCL+JgW57:+DUL0Ad4M9/xJfAXxuGEK158B5fcg
                                  MD5:D9BDE771654101FE27FAF2C5C62DCEF4
                                  SHA1:B553AF94DED7965F5F0C08BC9FB699F3137DAADE
                                  SHA-256:126E30A18F2EE214EE945C6B6E52902961B7F6C815EB35345EE0D64E0EAAEF80
                                  SHA-512:F10F441278CFA2E6CEB3AFE4A64E8E96D3D2DBCDB5B0872226E4754D1A759C828AE51809532577F899C86A6149E5BB4ED1243B5CDCA70D363629B31E840E306D
                                  Malicious:false
                                  Preview: .......P.........<#=/....1:70..I~l'2..(/lcilij...........,gJ[.............JF.?............qj.....FO..r|l..%u___RN......UD..AF[Q......md..KFU.yJNd........zizx...........(po......0.......fU.)nn``........KI0!nu....^.*#.........aj....gg....uuQM...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..(....&..~vD...}{.}{515}{000054000054000048000095000095000067
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\661__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.687505167415607
                                  Encrypted:false
                                  SSDEEP:24:LO7tXibY984tFoze4ytP6qfHSgC0fNSZBzfteJTQRSBEEcUzfXF2tDFvyv2+JgWj:LefuAd4M9/xJfAXxufBEEX15vRfj
                                  MD5:2B8C90CF63F171604B986124F3EFC022
                                  SHA1:40620072E4EA9DC3CD81645CF06DBD26ABF2EFF2
                                  SHA-256:FB0A6852CD122D75A8FE1F88FB2CFDCABC148357B02A04587076819F389CCB57
                                  SHA-512:B80FA0F56498D4996368D84FB390A6B98F1727B510DC93A51A9AB8F8E6B0605AE203776E23697DD2446E25EEF4DE781A783D06D53012C49D58178153963911C9
                                  Malicious:false
                                  Preview: .qu..........................&m..5fXMoe....]..)?......7!l1`b........!(YR..;<//.......e....P..2'..$*J_....DDMM.Lmd.._H..=';&....BW......XKNR16..[[..w(ah..2%..?%...C......(.......))....EY........11......&1...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{).&MF......q.b.}{.}{436}{000054000054000049000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\662__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.351063097120891
                                  Encrypted:false
                                  SSDEEP:24:sBkAKL+ao3MMY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRjOHZEiBBpFUBQ+JgW5p:s7KL+v5Ad4M9/xJfAXxuMiEiBpFUBvf7
                                  MD5:0FAEE333E59692E0F06633C824DF2A66
                                  SHA1:B5B4CFAC026CF2CCCDB7ABE00C7A4108CDD693E5
                                  SHA-256:C7A899390E011F5D59C02F2000CE5387260884075DD37E08031E35D9777BC92A
                                  SHA-512:C67055008BA11BD08888802114220B5ABA569AE5E3B7C2E0691BEC0DDBE474D7AE0AB58BFE5CB368781C756C29BEC865F521D15C1F631BC8F36F8A82F0EB6BC3
                                  Malicious:false
                                  Preview: .L&......_h.....D[......#U^......>,......FIQT.......G..`g...b?.._@UOde...MA:.....&5......y~q{..LE...`r....:#......y(.7..55.2SX......_DNI+!.........Xc....E.34@C...H.nb&&..gj....,^"..1..DD....&5..ap..ni....i`......!...`j&......./3..........8t_L....|tnq......-$..}{//Qn61....k,.Q^S9)..T...w`_T.X..h}dq..h0Q.^X...r}=...mm..{g..AHQB.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\663__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1520
                                  Entropy (8bit):7.514863674529859
                                  Encrypted:false
                                  SSDEEP:24:LXNkdqtJNGfxrwBy9r2065ZafJLDLm84tFoze4ytP6qfHSgC0fNSZBzfteJTQRZU:LXPjiCy9rOwJLDnAd4M9/xJfAXxus/Ej
                                  MD5:9BE13664425DA0C8619711AD2974FF79
                                  SHA1:35B348B2DE9DCF46AFFABA342123D85A329DD7BD
                                  SHA-256:C5E1C6D22F2D6B6F5F0BFD5A2ACE4584EFB97F11B31228C2F259B60C2F225E86
                                  SHA-512:C423D14D8E6DDE9F80C45834ACC9A95C1D3EDF683ED2E7DC0FEA79B0FC7113A6BD3D00B2765566BBDEA6DE367856B42AE54A6A5FE0C4CC5F9892B2EFB6276AEA
                                  Malicious:false
                                  Preview: .*...QD.X..,-..k8......`k..r.......k d~....~s...O.H#5....qG.....lu....[\09...FA..A.FO.........\.7:....2<....:#....g}..oy....OO.......ny..@Z..@...<).......UX..*"<... !.%"47...............i!7....V|mm........HJ....ST...W...~.WD..JL..u..=....&5....UUVV00TT*f..3~..7?..........Fd....Yf..(...c$....../0#y;!AVk`........&~.J..43k.69tG....BB..O.....fq......B.[\.........1|......Ty............JY....>+...;]B..YB......34..@@........^V...1..OM....$|*E..^..d#g<)......z+.......Flss<<c......J84[.........<1..SL....j*LN......+>3,!&..sz......NN...........#+UJ....{g.(.....L....>!.P..ON..#?TV..i9.T.%-LY[[.G.8:.....=8..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\664__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2054
                                  Entropy (8bit):7.704457707427708
                                  Encrypted:false
                                  SSDEEP:48:TziQJb6N09/QkEkPqFIrxofT8Xs4McAd4M9/xJfAXxuVSEcBpFUBvff:TziQxKeIeBGfTV4WpBAXQVSEoe
                                  MD5:3922AFE80A36431B19228CA84EFD0C0C
                                  SHA1:AD1DDEB35A714B1D7993FA6A1CC01AE71BC8E179
                                  SHA-256:E85576F3BA6770769BDD29251BC4AF6C6079A28AA4D1A926A8F76A828DD68C56
                                  SHA-512:192DE63A9EE19659C4C49CD185CEA43BEFBE2B5F2CD29A6FC57705B0A29A598AB82EB648159E84E46F7475C8C9C4C1AAFF092D7BEECD2ACCE4AB93C15BDAA2CB
                                  Malicious:false
                                  Preview: ...........wq..</1/..zq........W....B..mgtylmp(i2..it......1l..y`....v.zq.....X&/..h...{a....}pRG%:BL....wn..........7+.....%z............2q%(......YT.........K......y=...vd....xo#2fzIN..rr....../<budsVL.........'4........-.......jY.#....TT..%4'8$j|p]...ge..GOFh.....!....3.jb%'..d}...5j..,(q)....=13|..H]......H....`%na......qq........<+:-HRJW....UU..VVJ.gt-`-".&...#........0'*3.R.......3>..................>>..0#<qAN]U........'0=$......................;*..........U...)!yf...+....1(d<#HoI.........;2'.......L........tt#?....T...0hw.qvmrK].JXB...._H....SB.D_^H.5*66..%<....f6..hvv#...ikok..M....^.\...ni)l......qq........<+:-HRJW....UU..J...tg#4&1*0..,o.......o.fkf\O......I.......V............_N..\[qq............4#8".......IV..............xu..............6)d*..7o....4.3;n@bbZL.........`b4#....L.\........vtgb........&!'<jc?=..52....................nd9...((....wf..e+$(...2)?'..G.........O\^.fs/:....%#....^Q_lU...........U....KT2cu#bc5"/..rm.....
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\665__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1535
                                  Entropy (8bit):7.540650400685673
                                  Encrypted:false
                                  SSDEEP:24:2xzbAulZhf2oiF+kv9ayn5YUB1FoTPL6ig/U7j84tFoze4ytP6qfHSgC0fNSZBz1:anhkog+I9askH6i8Ad4M9/xJfAXxuKEo
                                  MD5:27A1EAE569357F1E73213478CFF5BEE8
                                  SHA1:FFE9E83A10A870ECC1284A01A6D5BA518A75763D
                                  SHA-256:8A4CFAE98C4F61674DD9E63E633D229FE35F2379600BCF37A11ECD38151579B3
                                  SHA-512:965AD259BEAE55153CC2F2294ADC60A35DA5FB9DADC83188F6EFC88D6DD554F24CF9F46E9670709AD77C4DE2E7F7F8A7D5D4FA3270A1606EF098C4AFFA86D4BA
                                  Malicious:false
                                  Preview: ....U....XO..FGHW..9+..(%JAHOd>.C..SF..|{.........g{t%..8?.F...s..:%........Q]..bH...BQ....ot<;~t.QMD...7%.,44tmwd..jl..&w.,.=....hc........PW.........w.......U -......VG........=y..*>......er....>9ee..??...[H.h....{f..s~..<#....9,ZPXW...vovp}.......ww..|`..............og......5........~|,;..^.k$.................e`...4!..ebPK&/@B....<<........*9..*;UN..v|..,.ZZ.....?.........QJ..Zf.W..he..{d...EbwWB...C..{}..........>>''..ETC\..bn.n............2G.!..{~..b`AD..|q..........57yh..//....._>-..ANogqnTM..4!....................U............&FF..WF..>p....pw;$...(..rqxz.....ix.Z[.._@jj..=$..EP..@A....Y.../-..k/....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.B
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\666__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1528
                                  Entropy (8bit):7.524922423220224
                                  Encrypted:false
                                  SSDEEP:24:2D7n6fuMMHMQN26RWFdCzb6AtqPnEOM84tFoze4ytP6qfHSgC0fNSZBzfteJTQRt:2ntMMHhWFdCzb6AtqPnE2Ad4M9/xJfAD
                                  MD5:7F5DB7D32B8382BC069120478B42AE1B
                                  SHA1:2AF648E748B4BA4AC61C9AC0C6F3ABC8BE7DF7CE
                                  SHA-256:117A5E21B532E70289A60EC10212A4BEB001AA03ADE293196A87276E25BADB45
                                  SHA-512:260E7161EE5E67EC4269B95FE1A09F656B4F37909B4476CAC5852765DE75A92551CE0ACDDB169D188264965D7D1D20F40769C77BE4E3A5EB0B063F97484F8162
                                  Malicious:false
                                  Preview: ...C@..+g.._^F@`3CP..UW..&*1<3:]B.....d7....."#U..:,|aS`..2$..B@....#%....P[..y~..I.^W..........Y.........|`EL...........&:......~!....k|vag}...~s..ez..qz......~E..-,$O.......||%P\::..F/...d.=..cc...................7>.FW1........}w..{{......' ..jj.... l..7z..^V.1\Kyx....<........{A.....A58..(7....|6...t....SZuw......xm...:!....N_....SS.......=WU=,....ci.9.,........a/....}...2*.......{k....Z....W^H...........Bh..kk">................C..r........II..G.....r{..k:@F.......xR......1 !>t:..].a...#*.Y.AS^CS&9.........u`(%....KL....,.du....kk......V........6....4.9$..H......TK..99..:l6*....{+.1}..pell..I....u&....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\667__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1524
                                  Entropy (8bit):7.5475979221751235
                                  Encrypted:false
                                  SSDEEP:24:RYkAGzOGo0zQ46IwgAPUUnRHzq2sg884tFoze4ytP6qfHSgC0fNSZBzfteJTQRF+:RYGI0zQjIAP5hzUMAd4M9/xJfAXxuhAW
                                  MD5:46B46880D285021D1FF22A3AB2F337BE
                                  SHA1:B34C009E33E325C5C554A3FA65739CB5E93997DE
                                  SHA-256:CBF4371FC8664403458E592AB4EF4304E24E3D3218A6F7FCFB1FFC61F7EF2A81
                                  SHA-512:8A5C4758E68581A063272E5FBD3EE8407F925F807B41AD837A6D111CE54CF69B0534D66BD93DCD26D21210A783D956148BA0C0991C8C66CED9FDA591300BA791
                                  Malicious:false
                                  Preview: ]mi..........y..XK&8eg......"+.....4XB......GJON...I_..\o...'z.........LE~u.}zwwy&....8/zm..uhh+....4+..#?......9.....(>]Abe..........i~gp`z...<.............M^7?.;.....zG@..$&.m..>2((......{".fL....pl..O\eg..AZni........?,1..............G[dc..ff..VV_...?rS\..a~..#"{\>7wU......QV..59......EZ..w;\E....Q%4......Q\u`B]....PR..fa......qb..[H`b..azST.......||..l}..d*....`..2*...N.....6)9*............pw.@..UfoE.........X.....w2$.........tM"*..~|36......fy....ah)+........._....Qej...............0[Z|S.?+..}h............RMB-._u==\\..^O..k%yu..............><ct:#.Zrc...m<........pw...\JK...^..# ..73X.Z...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\668__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1527
                                  Entropy (8bit):7.5466622255214
                                  Encrypted:false
                                  SSDEEP:24:uvdRwPea8aAu7NewllIOLNKFWOkPY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRznt:uFRaquNRIu8oPpAd4M9/xJfAXxu2nEwl
                                  MD5:F937DE4F330D409B6784A268322F8B40
                                  SHA1:5710FEB7ED8089ABC0A3099975C92B6E40F78AF6
                                  SHA-256:E88B4F98C51695892EE92A03BCCE38DE1E8C9929C51ACFA79062315FE4C9C7FD
                                  SHA-512:69291923D97EEA25A02C9A9D4585E2B5817A1E56FD252487792B9AA29219222AB4D93B720014AAF894FAF2B170FF15A673E078C7023165E07B67209286317839
                                  Malicious:false
                                  Preview: .u.p7..t"..........HZ7r....eb.....PE....li....[D.."s32.....W...!>bx........Bq......n}geFW..........d.bp..GGb{..xS....\.....rn..........urj`.L )..94ZY......*"$.WJ..z...hk]_.....*1..@)...iZ,.........QB|~PA~e....k?]Tm5?Y...1.....-...........**33..t8..Q...^V....lm...'.....wH....oc g.x..FV...../4}z...M(#..G...................).....G[.sz....ubsi3...&!77...c/..F.....iv./}k?5.*....";.M..RP............E^....ix]Z$$..........YQ..dE..^\.....P.n....KB....|i..[N'8..OT......#$aa..qq...o"..-%..?&....... 9..O$..........;V_.....25.3<........pl....q?.........gq....=>#!........!q...9&..........Q.897).....vt..S...ZO{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\669__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1510
                                  Entropy (8bit):7.517679355799465
                                  Encrypted:false
                                  SSDEEP:24:m8Rn1WaTlyztq10uriCRwoU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrmEE1/VBm:m8R1WausLdnAd4M9/xJfAXxu2mEE1vBc
                                  MD5:D0C9860FAFBECE7B480A7E4DE3987164
                                  SHA1:35EC4B00E4EF1BF3496498C29D920128DC43ACE4
                                  SHA-256:21D821445F39E99AD806657D6F7DAEF6419F023278BF7C9722C25AE0F410CD71
                                  SHA-512:36D7EA56A0E7CB12425CA6225B338925919E9126ABFA633B68B1D0E3A1611AA7763A0E67F5712D15BB285B75D21C7A75226476BEA8A341822E3EA60C32E93A4B
                                  Malicious:false
                                  Preview: .~zWT...QB...........}vfj....b}.....M.\I........O.....6........[].................?(...... c58..LS..OS<5ip..............{{.(!....l{....E..........,...t{......."0nq...#2...??oo..S..v....l{g}_Bf%..............[T...........>.................(p.pom....Ig...'........vt..Y@v...z}..?#....(-[N0=....ru..\U<>...............hjJ[.5CD..Cp."UU((..udUJ.Q...W..$?9!pL.1g......&5..0%?*..u-......O@cP..ss..`|......^RP.*L..S...........Yb..&).G.....ha.O.N....{>T[.....ww..SBpo.COR.D/.{...|*s~....";...F..>;....DQ..DCYB............XX.KPC....tk.-..............dtRM{-....C.......c3g<.A..ly...&s....w$B@..bw{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\66__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1503
                                  Entropy (8bit):7.542622838653638
                                  Encrypted:false
                                  SSDEEP:24:97jx9RT2G5ECj1K3HAQpMWGZXrwQjX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIF:5dD2V53HA4MWGxrwnAd4M9/xJfAXxuwm
                                  MD5:1DE3B235F2D5107A32621CEB6D045EBC
                                  SHA1:C79B3E60608AAE6062AEB772341E39434EC35E93
                                  SHA-256:648990952D5CEE5F3641D929E175C36B28AEEDC59BFEF07E22A0DD2766883249
                                  SHA-512:5ADEC869019351ABE4B56844193EC908A96C212FE1C48F5959286B0C9A8E13946C78ED143B9F6558BE0D5A3F7138DB340C582A0B77D58A506D3528E25DA55172
                                  Malicious:false
                                  Preview: ..E..854n8..]\.......Q..~u......'5..34FI.._\......`1.....9(...wh[Ahi....3?Bq....;0..Y[....$#.............@@....=.....5dH{iC....0;..HJ^O..dc.......>3ci& ....)...OJ..Vp|gg..;6...........}a..O\qs3"..QV;1..FO..q.............WW.........BB....(d`s................;9?....\[.., g.\Q..NQ.."/o ....,)..gj+>..%"....-/..x...((.....xkvt..+0"%..?...77.........N...vV5SH..rNi%.Qv{VF..0#....oz...\......kdgT.$........ez.Z....r.i...fk..........G....... x.O..cda$..Wd.......vg......B^5&"...[........X..<9....]H......?6..fw...kk..-a:)..p.NF..Kn......<!8=...*'AQ...KTTML.4(......x#...sfBB>iG.qs'#*y....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\670__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1529
                                  Entropy (8bit):7.534442742828902
                                  Encrypted:false
                                  SSDEEP:24:OSQaT8HEK/bAXOY+naee6CgWAXJDOg/b+84tFoze4ytP6qfHSgC0fNSZBzfteJT1:tQaTgEKOWUxA5DLjTAd4M9/xJfAXxuW8
                                  MD5:1547ECD438D6822EFC3524073CD860CF
                                  SHA1:F78922961C4DDC9DA7244D9D433B6D5A5586B482
                                  SHA-256:D99A37025BFECEC69BA7582655955A766C8A3BB1AE57B521CFB70A0BED923CDE
                                  SHA-512:1A96FFC9EA8984D6A10C29A3AD8A24927548E8465A6C8F6FE8880A79D811EF138900A58BD3C3C37FEAA19EED6095D199DA654A9646869DBE7062139323DDBC2B
                                  Malicious:false
                                  Preview: <hi......+*7(....5p..DO..w-B...<)=?ni..Y\........`a..Z...i48%PO2(32..YZ..`S.....%6..9(....sy.S7>R.b.....dd..#0....KG..YjOejj..........irvq.....r*..G'..........t*......mb...Z-....r.fq..zf.x..66JJ...JY............+4......}w........KF].`S..zz((FF..wf......'.p.hjlv............?fn......t,L.pp.Vcn..ro..`l.....................?8..WW..):..VE......#$+!+.....66jv.....?3...e.....C)e.......tg..J_EP.....'!......gM..WW..vg...I..%}............P%..SXil..SQhm/:...ez........*;....RR....IFYQ..TM.(~k....}d.R7\...=AUv2wb..U\<d;j....2w..tG......YE......."z..ni...........gppi}%.....'v<#}}....`u.M.."<a4.c`....5q.MLY{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\671__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.80951964118948
                                  Encrypted:false
                                  SSDEEP:24:pi5EN9lphzl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkZqUzfXF2tDFvy8Bp+JgF:2KlpAAd4M9/xJfAXxulZl158B0fc
                                  MD5:E6681D31D8ED5C51AFD233530F6C59F4
                                  SHA1:4D10BE4E5FFD5200AECE4B436651D31AA4DF56A9
                                  SHA-256:A002E0DBC0966FC26D5E8657F22B3482851FA290B4534F0D85AC6E8B2C1EAAE3
                                  SHA-512:BFE9127E636A59F57A3F22599609895E696EE152C0217D3DAE9911F5523A12648B1EAEE671B612A5D5369A049D6DBA18E34B9E9EC53FDC64B1B20693E82A42C2
                                  Malicious:false
                                  Preview: Q.........jk..t'....WUne..kfbk..CBJ.....at.......^........=....-/..]G9?......A......W^YJ....{a..<...xmSL......ec....7+..99..K.'...........R.'*i|....ucniNR..dd..zz.....8/..KQ...M......ayO.....8!.gn....g~r%eb....L....rj(4ts^^..;;.......VA............%:.q....s~....9...3...$#sg{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.C.c.....&....f.}{.}{564}{00005400005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\672__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.719567321161262
                                  Encrypted:false
                                  SSDEEP:24:Qad3aHKjMbOF84tFoze4ytP6qfHSgC0fNSZBzfteJTQRrNgUzfXF2tDFvy8BXCLO:P0j5Ad4M9/xJfAXxuIN7158B5fP
                                  MD5:0D8B12CD5FB1CD8CD3E5590A12D94BA9
                                  SHA1:CD9F74344F063BDCC315593344838670537E5DB1
                                  SHA-256:2BC4F2E9C4324A267DED35784D7CBF55476EEC5846E4ADB579E1372A26077A2F
                                  SHA-512:1570A82DC09436E3A5D5EFA718D5872CC0C6FDD84658A5B6F2A214D1899A6D536077EAE679955E570D6940EDD08AA26CBDE80369C3392247344E36C583BAF86C
                                  Malicious:false
                                  Preview: .Mt.Y....A..e.....!>...`m.....#t......x.P_...........E.........\A........dg..Gt........M\shTS..W.*#g?.r.....-..OOsoQZ..........%/.J.. x8YHA...D...0..CC..gl..wu......v|.......@z..udQL...Ra[q......eyHCm~......pw......Y.(..++<1..........11??eyBS...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{JKtL...~.v.q.z.}{.}{519}{0000540000550000500000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\673__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1324
                                  Entropy (8bit):6.696112342451407
                                  Encrypted:false
                                  SSDEEP:24:d3JMGHN8A84tFoze4ytP6qfHSgC0fNSZBzfteJTQRqfUzfXF2tDFvyv2+JgW5Y:d3JFHKxAd4M9/xJfAXxuVO15vRfG
                                  MD5:29E03093ADD3607ED1130E4FB1408118
                                  SHA1:FAA06FEA02A9476A3FF925FD2DB23E04D23D6ED3
                                  SHA-256:76B84A5B3221B44474F2F50FCD9DA5BECEE20B1BE936E314971D3D6CB295E40B
                                  SHA-512:C78A4F3F8F25E584202A1D995508E97035D9D3F9725AADDD71B03CEAC19828A9C1010BCB4CE530D3BBAEA7086AAC7038F7F395F2E79CA18E6A5A670C0A02BCC6
                                  Malicious:false
                                  Preview: ...T...H...KQ....0/...obryMJ..?h|nI\..{|..+.......xd q...C......WH..jk......tG.4^BmfJY.........R.......zj#Gm^lF....+8b`xi..NI..x,...H........t$kX~T.....sx..fdM\..}z..y-.....y..@z..:+NS......ll00..RY.....n..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{e..;.F[.....,.`}{.}{434}{0000540000550000510000950000950000670001010001080001080001170001080000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\674__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1239
                                  Entropy (8bit):7.35764305070706
                                  Encrypted:false
                                  SSDEEP:24:oaO2935T9EzHopRbRb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBrHCBOEc3BBpFf:Ff9EboprgAd4M9/xJfAXxu+iBOEcRBpl
                                  MD5:3EA348A5DD9047D184C978DFD5748630
                                  SHA1:1C60E17FA614ABADCAAA6F5ACF9CD88A7711E07A
                                  SHA-256:0A88841528BDD674C40AA5078ED3A736601411C41B90A2E7FB4E7BC739ED5916
                                  SHA-512:B92E92471A27F9D4D5A97588BCF9ED7CAFB9C9FAD94BA6A03337C5186E4ECF1CDC1E46C9EA7B6DFB4455ACDFA9CF2383CA4BECF0D942A135304A65CB4D475595
                                  Malicious:false
                                  Preview: ...;8.................aj......WH........q{id..'...........cu...xa-7MK..-$MF%x.... ...]N..}j....J.TYQD....LPof..HE1...>%J\MQkl..~~..t}..j}..pj..-nS^..d{...`e.......6{..I]...5*...h........BB...............j)+&....Ed..?*xrt{..........hB....mm.......M..o7....9#~v..LL....=;OUfI....MZ1(~&q.vlUB..m;....8-......\[.]..).........[.*#..9.........jm{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\675__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1517
                                  Entropy (8bit):7.479672666104682
                                  Encrypted:false
                                  SSDEEP:24:F+nRNajDIiZR4gOAwtFmqnt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRATdBBpFUS:wnRMjDI8mZNsqeAd4M9/xJfAXxuDTfBp
                                  MD5:A77776C6FD9C348348071F2C3B89006B
                                  SHA1:818EA51AAF2AFDE17E2547A298E3AAD757D73DEE
                                  SHA-256:89B0CFE2015868A3E95234CE2A698B6EFA61C50FDAADF54B47A24DD28B7FA912
                                  SHA-512:D04998FA78DB2F3A6A3567A08FE3E4349946BCC79F9A8765BA77D5DA79B8DF1D89B7A2642BB04CC547768282FD4D1AE1C38EDA00214BE4E941A1E18A3A06D1DE
                                  Malicious:false
                                  Preview: &r.TW...3eYNOUSR..KTJXZ....%(/&|n9......;<...............................~M.......l.............C........JS^MzQ\ZS_I..7..........9;,=*1....R.....u.>38w.3<363{.:YMA66$..,A(?)81-16......F.......$3(25(/l.......-.....................LLLLLP.......%}......px.....................W.SKZRPJAV_.[JT..........ez+,*1..PR]L.x..wwwwkx..3 31&7!:....Wd..HHHHHTcrNQ.R]Q.X;....../ca7 -9).....)<...................LP.........%3.....k{..............\........Z..L& AF]...........c...*5x6...P;"&LE.w!6;......6t}=...lybo....................}n.MB..9&.......]..E@v'....WG2-..<<..i?..ik....%iIA.........EAO.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\676__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.385163223230416
                                  Encrypted:false
                                  SSDEEP:24:bR1ASV1UGb/1G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRE6csBBpFUBQ+JgW5t:t7Vhp7Ad4M9/xJfAXxuz6hBpFUBvfv
                                  MD5:5CAF19A93C69FB9DE827CAB5A5BE8748
                                  SHA1:AF067065450E57D9EBF584AE5DB6822158E170D0
                                  SHA-256:0E9EC265276D2FCDE5E9BD0BEC3EB4DE7114C0CF4BCCC3A8A3C6007AAD397E90
                                  SHA-512:55573666B09D1DE690B983F88351FA78D88CE6596AC8AF4952E2BF8D26219474B5704603FC2DA55716B071BA1F3C1A62BCB275F2CBB3AA6509AF646CC9508D86
                                  Malicious:false
                                  Preview: |(.r1v..........%:....N........SsaZO................=l....R....8%..vlde*-..?3cPrXeyHC..moVG..lk.."vjc..g7%'.........?9...<...33/3(#..df.....rxI.3:.N/..LJpx........bn....v{.v`a.rAZp..........mo2#......2fszA...........%...&?..8$DC..yy!!..V.#0.Sp..........|u..F@......*......@M!1........KH?p..#!....v{................BB..FU..........mj..pC..TT{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\677__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1246
                                  Entropy (8bit):7.37746027475677
                                  Encrypted:false
                                  SSDEEP:24:pcwoDqdtYJJylER3F7IFWb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQTTbBBpFUt:pcdDqdmmiRCFFAd4M9/xJfAXxuDTlBpI
                                  MD5:130915D7AAFC7C5AA26CFFDA64B1E0CA
                                  SHA1:39D63E6944F34A16A9C3C55D2FF7FA1DCB44B624
                                  SHA-256:0758DCDA3B7E349EF8F11BCB6BAB2A710733AB5EC72114B2C8B48E92CEE6DCC4
                                  SHA-512:18F3F1CFDB713D2AF96734742897797BA0E78CCA7E61AB1E9610A346BBBC5C11E356CA83AB6C6DD2AD396A7628333AE7EB03F0A17E3FD34BFB7738FDFFCD1488
                                  Malicious:false
                                  Preview: `4..M....*=8"$%gx..............m......................M....$9;$>$~...................^OXC........9a.3!=.......-...,}aR..77....cp......$#.......V.a......"g.l...........n|................EL..H_..{a#>z9he.;.....-....FI..XQ..ehL...@jCC..mm..........:_..`z....88LZ..ce....XP.....c-..[\3"....a...57......sf.... ;HAuw...........DO..'%....|{..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\678__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.6172107065057375
                                  Encrypted:false
                                  SSDEEP:24:nFt5KXgicE8J84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQ0KUzfXF2tA63yrb+JgO:35KwicmAd4M9/xJfAXxu4F1EY6fT
                                  MD5:150D84F9E2520CFF5AED87F5E9CC3955
                                  SHA1:672B89495B54A56A8F61407FD577A341773E2F65
                                  SHA-256:6495F87237B789D2F13173FA2F1EF3CC37BFC22E71726E860B4BB9C1A3FFD8E0
                                  SHA-512:E06AA342D6A8C336593794B8BBB9B81AB8092A5AD8EE856787B3F676867A76852051327109E2C8F5EA87CE403524C88CE76E4F87F705BD9EBEC77FE245B2D416
                                  Malicious:false
                                  Preview: /:>..XM.F......g4]N......am,!....|}L.E_x+..u.....[.....ns..Xn......)0......?6........S....+<RE.......VC....XMJV........,%.........2?....Bd........ni....]]Z.:3~m.....eNS......\CQdkJ....xxEB........++..NN.......^I..........c|......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.. ..;.B..uH...}{.}{468}{00005400005500005600009500009500006700010100010800010800011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\679__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.80296404845625
                                  Encrypted:false
                                  SSDEEP:24:jRFQnAAjYsCXs/wgm2AKMa84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKFr/VUzfX5:jR2nR8s+s/DzSAd4M9/xJfAXxurrs151
                                  MD5:87FC8D90B62055F4B59B282924E0CC7C
                                  SHA1:055ABC74E816FB91C31ECD8565CB1D17C352E2DF
                                  SHA-256:8537AF18A35314E60D8727FE54BD0D90E45C5FF71AB4C09B9A2E514D1CA59878
                                  SHA-512:B93D2CDF9E16A7D851DF3854C16C4CA388699D95C0D25195FABD259496C5F94644FCFA96184C8B370A3022340F337CDD3ADE292236B881746F4425A3B0E7552E
                                  Malicious:false
                                  Preview: ..u..J..y/....fgtk3,we......[\.n92 ..tv......sp1:.......HO~5....kv....#".x...S`..`|..XK....sh_X..A....h.dyPO........}N..........b`..TO..93I......++CR..L....**......zx..#8' ...el|$..r)...2c.N.."7......UT..jd...H.V .7g.V......nn.......l.................:. zc..f.sd.E....or...HD\\{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{........v..)/}{.}{574}{000054
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\67__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.419583002158609
                                  Encrypted:false
                                  SSDEEP:24:HxawWbeDxmY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRs+SyU1BBpFUBQ+JgW50:YwWbeDxsAd4M9/xJfAXxufVHBpFUBvfu
                                  MD5:126108383AD45C856DFEBC6564AA61E3
                                  SHA1:927A8ACF1E257DBC2789D0FDE1A5C359CFC9C147
                                  SHA-256:E55B5C711DDABAF04CDA6CC0A92EBC32DB0A780497933DA355D1B26F934ADBB5
                                  SHA-512:9D7EE4FA742B32F6EBD9E10208DD2D83F78E02BC1FDD4EB74EE7156ECDADB7A46692EB799F3BD48361EF15CB441B6EC37623A46F15A73643D232232AF446B74F
                                  Malicious:false
                                  Preview: .....M.....-+...3-kilg..58..b}...D='.XTA.............bQ..|j........oh.......kk.......AV..hu..`mLY....1-QX..^S....NU.. <....VV6i....;,]J)3,1.........:<..5N..34^_.s.kb......HG.........]F..u....).{Q..........+)..SH..lf........c@%#..t~....tm..so....==.....U..q<....+4....hO..7......%........fv......ah..*=YXR.....VS..>3OZ..x.TO........##..............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\680__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.690495574292023
                                  Encrypted:false
                                  SSDEEP:24:y9LegAVsqHnKc84tFoze4ytP6qfHSgC0fNSZBzfteJTQRn/SOMUzfXF2tDFvy8BS:h/CqHnKdAd4M9/xJfAXxu8H158B5fI
                                  MD5:CCD46AACA257B4504F3A4AEAEA55DBBF
                                  SHA1:0BFD3B1633AF027CDE6D0F957E4D2A9AC57F1DC2
                                  SHA-256:907DC16A546A2F1A8B3657FB854D9F9434D700A653A375B4EE129E2A295BA1C8
                                  SHA-512:49F04E2481EDF992D5AC2590F9BD4AD918E4988AAC6330DD62C37B5186F48888457AEB820FF648BE5BA465B52E05462387F7A572B32FE280D2B4C71A25C36BDC
                                  Malicious:false
                                  Preview: ...ij...P.........(6....VZ(%}t.........D.... -...........E.9;6/.....................7 H_.....)$..sl{u..........\U..reny}g,1b!..I\....RRCZ&5plfa..^^iif96?..)>..........\I9&.......ff..-9os70..yyGG..i6.........."?.M...............%9....kkOO........}0..LD{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Q\^....^...|z}{.}{524}{0000540000560000480000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\681__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.689933494026494
                                  Encrypted:false
                                  SSDEEP:24:wn1Ftnb+tAXnUS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRadPrUzfXF2tDFvyv29:O1L+yXUXAd4M9/xJfAXxuBP615vRfQ
                                  MD5:E8939757AE6C1A9E6BD81B49236D0A30
                                  SHA1:A1F97C780138742D79B857A9799A4C4B5C6B9F91
                                  SHA-256:5C4200CAE5EC87579371D693C08E1356D26B534EEA0213D7B36B05544551EB17
                                  SHA-512:1058911112AD07A2AED749F32D89E32F89E53D262F8C9C670D4BFE8B2EE4BC601C38097A1543C562DB1098333DCD0B2C8743106331758D6D1E163DC0C057C9CF
                                  Malicious:false
                                  Preview: ..K.I.....ct....OPLS...]JG.......TF"7..NI............tu........NS....+*?8hkR^9.Gm..38...........b6..(p.ntdu.gTaK||.................Xel.P..,%..ID..........}v}n]_..........#{.....@Q..<5^.9..,SS..........20......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{v.....8PQ=....P.}{.}{439}{00005400005600004900009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\682__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1259
                                  Entropy (8bit):7.393415919026343
                                  Encrypted:false
                                  SSDEEP:24:bN5OCADTbDwCfZBDxtPRS5a84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9lIFBBpFT:h5OCALECxBlS5/Ad4M9/xJfAXxuKIXBj
                                  MD5:44CB6515CA3079EABAF2A0715D342D35
                                  SHA1:0C8F637CAD43432F102C1F016F61D1BD98EF619C
                                  SHA-256:E39F345D17B3C2D0245CB663339F065A8BBF8E43CC73325FD59884136275BD06
                                  SHA-512:06744A1152DB2E3FAC4A802A636C19670714ABD636E13D95101E65647106E6E006949B24FA10EC35C7B4147789E54B57F589DD4B7DD9D385BF6AA93D28C1BD5B
                                  Malicious:false
                                  Preview: L..SP...........\Bnl&-XT....XG..}6#9[.........:b@.?)4)..Aw>(.G....wm..cd~wJA.P.......bqtc.............N@LP....he....+=(4........CJyj....*0..f%r.i|............%X...|8........./#..1*...*<.{..66xx....BQ.............'...\...2=`j.=....%6...........,?....=5.1yn...;i`sQ..CC....jP..#d.......]I,h.........PP.......U.........+>....ot.......ii@@22ar....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\683__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.623078764805782
                                  Encrypted:false
                                  SSDEEP:24:pjY0ciEjt+aG6z784tFoze4ytP6qfHSgC0fNSZBzfteJTQRb0mUzfXF2tA63yrbe:hZcltW6cAd4M9/xJfAXxuTB1EY6fT
                                  MD5:7F778D42A033B7BBCAFE4DD15DAB394F
                                  SHA1:686DA975219A99D61434E6B8A059377A2093EC1A
                                  SHA-256:304F2443F5713050EEED41844C09AA2A8AD0AAB74DF9BDD26457536F17CB4CF7
                                  SHA-512:A62C68EE4738A396B071BD01A1C131D3D14EE0AAB9143D023F446C23EE810D1D3CA97459B321138D55A1F620AF764B1FEC7D751FBAE9E5C7D4C1BF69D5257EE3
                                  Malicious:false
                                  Preview: RCG`c..<p....!'..`s....LG*&m`......Z...E.../%7:{z.O.@....@s....n3 "y`..........9djm..h7....[L....M...#6,3.......ffUU......L[....sn..ux)<.........NR..--DDVV..CP..........1<......."ok....}z..9%..$$XXccEE.\..tg..........+>....DD..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..y`.......Gw+.b}{.}{468}{00005400005600005100009500009500006700010100010800010800011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\684__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.770763811092225
                                  Encrypted:false
                                  SSDEEP:24:vNupDLSEY484tFoze4ytP6qfHSgC0fNSZBzfteJTQRvUqnUzfXF2tDFvy8Bp+JgS:otOJJAd4M9/xJfAXxu+Uqm158B0f7
                                  MD5:B2E76951BC05E041171D7A39791C81F0
                                  SHA1:824F60A7C2FB7906818DCA6836E2B895C1B37DE5
                                  SHA-256:0BAC9769B687602262F694B592F1DC8784DAC74BEB45D5B0D8E631E22C9DD8B0
                                  SHA-512:702C873BB1D8B75F7B4B3D0AA349BEF02E2FC0F7AFFAC3AD169CCDDDDBB4BFD756F6CC10E7186290E5DCABFE090D6777FDE10ECF411EA0CE24909F74F5F5E90D
                                  Malicious:false
                                  Preview: _......y/..xbz{....GU..=0gl.....?*{y....ad30..8'...01..V.....snYF!;....SP..Wd]w... 3eg...TS=7..-$.4F..`.3)..KL^.7...~~PL....&$......\V.D...@r.88(9....kA.....aj......2)`g......|$E..H.......CV7e..@........\.MO....];d............")..zx....16...) ...Oi.......g0'F|....ex.....pp{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.f.[..qr@..n...}{.}{574}{000054
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\685__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.688498552154375
                                  Encrypted:false
                                  SSDEEP:24:ZEr0ccuKzu84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9zW1IUzfXF2tDFvy8BXCL5:ZEp9KXAd4M9/xJfAXxu3z158B5fI
                                  MD5:90A5D9ACE480F7560DFFBA21192EE495
                                  SHA1:7576CA81A9F313959FCF83C75043D08EFE67A410
                                  SHA-256:D1C43FC2530504A006DFA7B6D293799545C3C9216BDF507F0DA1C4A4F3920493
                                  SHA-512:207E70F52217395D59B878F50DC203E8C3FA2EDAFE47D3B5A29CE138BF5EC68460F12B1F7522ECEBF78BC79DAC9AD7ADA5CC3CDE4E4D5B19F74BCA905BD35064
                                  Malicious:false
                                  Preview: ...wt..m!|oGF.......AC|w, FK3:......D^v%<).............bQ.0zl#~..0)....{|..........A...ZIj}OXF\..]........TA....NN...E:3jy)>....0-.TY.....-....#0......gg.......ub......D...fsNQ?.Kj..yO...._Kkw...xx..>>+t....W@.....2q....NQ%)..........ll......==.....FI..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..w.0K$..Q.y...}{.}{524}{0000540000560000530000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\686__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.694073545612704
                                  Encrypted:false
                                  SSDEEP:24:lqW03Qg8TeZTP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwgvhcsUzfXF2tDFvyvG:ld7eeAd4M9/xJfAXxuCvhG15vRfQ
                                  MD5:F269E634A126051B5B8840538EC716EE
                                  SHA1:B56DAFAB8F2328278364FCC3A5A97C074F3DA73D
                                  SHA-256:BF64A9EEC6E57CC761F6F65DE4E6D2B6311A517F3178F85706F1B6E10691F315
                                  SHA-512:9FA1BED85A12A1D477AF2A433C6F74F8D421BAFFACF9BB8A5B9F9F78B41FA876AA9C59151E038D4A93B08B3092702C6400ED75095AC23D1B811383B788C8400D
                                  Malicious:false
                                  Preview: w#....ed.ynD^........?z.....*p.[............|.&-..B^[...faC..............RQ...#.-B^....8:.......$p6?.....k..Ak........)+..SH..<6Y...A...^W....-}............WD`bhy..niys..OFQ..{1&!............Mg..{{HH=!..@S........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......z....].u..}{.}{439}{00005400005600005400009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\687__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1260
                                  Entropy (8bit):7.4094041111316375
                                  Encrypted:false
                                  SSDEEP:24:gL4cW2lRSHvlpA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkR2yBBpFUBQ+JgW5r:gEcW4opxAd4M9/xJfAXxuZR2yBpFUBvh
                                  MD5:5B6E8775D4E4CC363FD13F7B4D360A7B
                                  SHA1:6A181B27DA311C834D932B404C426829B135558B
                                  SHA-256:34681664B89EEDA4756827413EB7FAB11BEA4185E0E22588B984B28E796138D9
                                  SHA-512:391C1E0A67CFA79B6EC872AEB0F1A997EF97D9D19F204913D97C6D2AB127C232E87DCE600F34536C71090C4D497E55A1906E11D58D3C25C65DD8EA206A218514
                                  Malicious:false
                                  Preview: ......._...yc......;)8}...dc..T.......%"GH........."s.....^..3n......WVhoIJKG..........om..RI..W]....B..GU1.....jy]v...~/..|V.....7$GE.....ZP..(!Z..y.&.j.(...KCmVhuKJ.o.........*&--mv0=.~..2@Ar..**RR....jyy{...~y..V.....3 uV.....pV..$=^M..$#BB>>XX..W.YJl!@OIA......... ........$....W._xuHX........NT.....5<.........R~|.,.........>9nu.........ssO\....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEAB
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\688__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1389
                                  Entropy (8bit):6.620493885803834
                                  Encrypted:false
                                  SSDEEP:24:OpS10sO7g6o84tFoze4ytP6qfHSgC0fNSZBzfteJTQRf/9h0DUzfXF2tA63yrb+r:OpSG7g65Ad4M9/xJfAXxuG92C1EY6fT
                                  MD5:C08E3525B9BEEC1ACBC150BA8D4B25C0
                                  SHA1:FE3C693A6B52AA9B759632B04A62BD8497381950
                                  SHA-256:FAB01143C582FEC36C6B1528D86630D4FA605229AD57FDB77FEF694651B08572
                                  SHA-512:25489121328EE2D1E5B37B44A267500572F50103CB5EA3879820B0D2AE086518F9BB7F598769D5CD5196C79D011753EFE5CBC30E49E22BE555DEF5D7BDB4EE18
                                  Malicious:false
                                  Preview: .Y]...........)z............of..ML..e.....ci_Rsr..B........9/...F_F\....ah...@..11........ntXE................yyGGW.......w`....m...taB]......DWXD!&>>......qb..6!..OR.%(3&..Rs..7.bbqv...2..TT.......[..bq}j...............BB..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.`.:.9.B...@.P.Y}{.}{468}{00005400005600005600009500009500006700010100010800010800011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\689__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1394
                                  Entropy (8bit):6.8059467968851175
                                  Encrypted:false
                                  SSDEEP:24:gRbjFbgV884tFoze4ytP6qfHSgC0fNSZBzfteJTQRVGWm/VUzfXF2tDFvy8Bp+Jt:CyAd4M9/xJfAXxugGWms158B0f7
                                  MD5:48C1C3D5AC33BC111182CEEF01196457
                                  SHA1:58A5A2806CE82BC36A99399FC7F5899B92A9D0A4
                                  SHA-256:7A39B69439EBA7E4B001FF15E9F56F7DCF49B4177DA03CF34620DB5F09BF0D60
                                  SHA-512:5F5C303062217269996371339BEE54D190D6478B3B373AAE162C0A55FDA450DCF669580B8BAAFDED7FF4F4160DDC39BE189ABE49099591AB216508170E82EB41
                                  Malicious:false
                                  Preview: -y.{t3qp:l..BX....mr1#L.......8b...MX..g`:5..[X..UJ..!p/...............).RQie...%..xs.=SQ..^E..4>z.....a|.......T]n...b~......@Q.....(|....vv.....................Z]..k?2;'.......f7....1$.KN......IG..C.DJ.v)..Eo..55....QZ........~y...4=7o.......`s\#.......XEcj....nn{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.}..F<.}.T.h..b}{.}{574}{000054
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\68__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1264
                                  Entropy (8bit):7.407135397655018
                                  Encrypted:false
                                  SSDEEP:24:J8kY3dhY2U4wEBORBUWa7H7BuC84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgC4BBy:Krt6EBFWa7bUHAd4M9/xJfAXxu0wBpFi
                                  MD5:BBE391B17FB62047EDEC9BADB90A49B1
                                  SHA1:A7211E33DA35948F12E9492A8B177ADE5A7E330E
                                  SHA-256:6A379DD0CA314B5C8913F71843C13001BE6B5FB50D4325192D220AA5599DA0AF
                                  SHA-512:C0D67A3594F6453DA402207685188E7A488F5AC43F9F817F3DC51A33671FE1225697E5459CF338343D325294F5A6646BD83F92477E4B140D37ED8B21D67CCD2B
                                  Malicious:false
                                  Preview: 's'.[....UB_E..FY..............P.*8........#&....iv..1`..JM..`q..<#~d&'.......)!.......-/..2)[\KA_.-$.AT5[IjL....AR).............9%w|..gehyxc.)....V_.0Q49..!)......pdY.YKwh.XOn...MJ..??GG..........\F..b!cnAT..nO.:........CJ....................K."..................bx.2......ul...e*...E..U@....6n.R..fa........FF.....b..1"bu............rr....'4.............+ge....M.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\690__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.70252874043013
                                  Encrypted:false
                                  SSDEEP:24:Sezj3KcVUMsEjek84tFoze4ytP6qfHSgC0fNSZBzfteJTQRk7w1/ZUzfXF2tDFvA:bjJh3j+Ad4M9/xJfAXxu5U1w158B5fI
                                  MD5:9B9AAFF701BA982AB6A0D5C7F5CE7570
                                  SHA1:2D420A0F478FF13E9B4683DE2A452130FC5F24A2
                                  SHA-256:B32C8118BCC27AA01F7EE0AB929D463A8DF4C1064F55A843B7712C6E36125BEA
                                  SHA-512:E479B7BC1CFDB2B8FB3A27469130FB860B28BB86E6A3F26FB50C67BF75B0AD4FD758F2A5D7D063871D0E06C7A136079CA136FEE5A298C18CEBC60ED7A8175A9E
                                  Malicious:false
                                  Preview: N62GD...B....}{.O..2,..ch..$).......XBr!....(%....k0...................G@6?...............k|..JWv51<........rn&!...."}.......WMvk}>....9&).......-1lk....I.....tc....1,....}h...4............eb....==...t}..mz....#>F...PE..6:++....t...?8....::||,`...B?0..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.!A...~...H....o}{.}{524}{0000540000570000480000950000950
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\691__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1326
                                  Entropy (8bit):6.718745021828798
                                  Encrypted:false
                                  SSDEEP:24:kneUN0uv9MG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfN1/KUzfXF2tDFvyv2+Ja:Gfu7Ad4M9/xJfAXxuC1d15vRfQ
                                  MD5:D841293442596A70F3281BE5C230B620
                                  SHA1:56106102B744463472AE0FC9C5B3D435B0D46587
                                  SHA-256:506804B16CF838F3B3EB0BF4A16FF0805A74BCABCFC86407FE4D5A91091AB59F
                                  SHA-512:AD55B49549199216FC6234D1D809F20C6395C7A747DE3ACC3F6D089DAD20AB16A0BF42BA63E99BB6AA20F6D5978C351CEC19722E08CDDD98A04A27C93E672015
                                  Malicious:false
                                  Preview: .X...............S.......O..]..1$..OH}rcf..ch:%ui...........$;tn./;<WTW[..:...?4.lIKAP....\VH.ZS.J%..........0,......DU0+.....LE....'>......*....uixs.....HSho.....J..ct....[J.........@@gg....~u..$&(9...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..../......*..l?}{.}{439}{00005400005700004900009500009500006700010100010800010800011700010800009700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\692__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1256
                                  Entropy (8bit):7.375638818875685
                                  Encrypted:false
                                  SSDEEP:24:MxaliZxQj/Uei/94h93lOPb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRC1/ABBpFo:GtxQHYu1OYAd4M9/xJfAXxuh1QBpFUBV
                                  MD5:86BB50013F628AE00BE1CB77558F91F4
                                  SHA1:BCF9BD59E0BF9F662D38F900E60C6E5AFC89E6BA
                                  SHA-256:846A5D67E24B3FCE1956A5BE8ABB238208E1892987CBF9A8F71260FD8A5429F3
                                  SHA-512:046458230CC3FE54641F5A91C9CC2B082D1C3ECA639B4E65D5C0D0F05E607430ACC184EE0641E3CE4E89EA8F783874B33BCB06B9633F3091E4A6E61037CC3084
                                  Malicious:false
                                  Preview: ....#d...M....sr....YKf#....>d...._JPR......!"U^..a}`1Z[..z1..j7..kt)3..........t^..RA......' J@..'...b...f@..........HD1`..1.II..7<EV...............p..PuDQ....5=........h1....UN.....v...Q{........75GV..61..s'..\..u...(71..1;............<<LL~~!!.`s.F......fq..oHDM......Ze......K.(~...`...h|j........PV_ll....jc......il|i..PE..be..<5TV#2..UUggcccp......ET{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\693__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.7846544113090905
                                  Encrypted:false
                                  SSDEEP:24:VSVbrQE0WHRczA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLq1//UzfXF2tDFvy8M:AfQE0WHGzxAd4M9/xJfAXxu4q12158BC
                                  MD5:F75E9017D9FBB12F3BC992D3AB98C730
                                  SHA1:F967ED55573DE665EAFA193256681B39B5B65EB3
                                  SHA-256:6ED3048B692226F6DCB8EC461EFF1099A88B6B396892A84C23FA6ECE202B4B51
                                  SHA-512:78D4393EC848B7802A7F8469E16C4473567A53748CB06BF1E4624EAB1455693589A6E0658B587E5D87C5AA038701363728A0D24554FCB03CF485D6C8D072E761
                                  Malicious:false
                                  Preview: .\i........kq....c|...'*....I.C.?-N[57..1>^[gd....0,..! ...@&7].....PJ......\PXk................dn.....J8b.......8?..}NmG..............G@eo.@%,......$u..<.::..=!.......9"PW<6..F....S....d5B.....W.../`01.....X..N ...L.$.........gt.....34...S....yt"...D]%6.n[L..Jt.. =...%){ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{%...)..1....x..}{.}{570}{00005400
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\694__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.71477785254772
                                  Encrypted:false
                                  SSDEEP:24:vw5D/VA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQ1/+UzfXF2tDFvy8BXCL+JgWt:YvAd4M9/xJfAXxub1R158B5ft
                                  MD5:EE4CC673AF2BC19B78EADB7AC3BED117
                                  SHA1:7C45B89E6C1CCA0B2F9F6B7F269AA8A91E484705
                                  SHA-256:C2760D9D5664FE7A98767BA528B1876CB98E358C18F0DF64044A571E805E2C5D
                                  SHA-512:EE8C0A56A052BD9FD1B64D3168B2EE1A4F3E4E18D0EA15378C8A7BD0FC583CC9A23B441692B031DE8868284AE04935A1157783F8C4353D22D6F3F1D1E9FFE1B2
                                  Malicious:false
                                  Preview: w#W.a&vw.QF..ED....KY.F......D.......beifNK..(#..ht.M..MJ!j..S.;&IV..z{.......<.JV........IR....i=09.K..]M,H........ +....CR1*...........&/....Q..4....!!....QB....(3.xak.+...H....6.7.}l.....).kA........jy.}{j?$...............>3..Uf..44YYgg..]A-<.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....@~.....s..H.}{.}{522}{00005400005700005200009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\695__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.716559451365517
                                  Encrypted:false
                                  SSDEEP:24:bkbRrXFyQpcu84tFoze4ytP6qfHSgC0fNSZBzfteJTQRV1/9UzfXF2tDFvyv2+JX:bktrXQQmDAd4M9/xJfAXxu61k15vRf1
                                  MD5:711B52D4E0387EE06E641559243E47E0
                                  SHA1:B0C365305F66EDBAEDC3D0654E3F4FC8615CE7BC
                                  SHA-256:8BEE05AD16E1E935E9067333EA2CF19A0796FE320FC9B7E682E6A3901B3C8CA5
                                  SHA-512:5AB128A3014A1F1745401EC93041C56792FDE452595C78176162790B83E83EDE1517FA7892F64D450B8EFA4769D95F5BE48653100BBA42E899060688D1684790
                                  Malicious:false
                                  Preview: >..U@..cp....O.../1)+....(%..? )(U.|f.\cvOE.#..t,'|lzSN.+6...U.....5/..<;.....@Gmm..le.................`..%0....{{ii~!..!2!6......(kv{..d{..VVPI`s...........Pyp....k|...8{....nq.....................ww..${....UBK\RHQL{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{4.........@.U3s.}{.}{441}{0000540000570000530000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\696__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.393250296258425
                                  Encrypted:false
                                  SSDEEP:24:a2dkQQK7EcGIuDjE84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQ1/acsBBpFUBQ+J1:a2dkliE3IuDBAd4M9/xJfAXxuL1ChBpM
                                  MD5:401F7C5EE74380AED60D54069201F2EA
                                  SHA1:C122EEA110D1120883DE3D3FCAA3C1764573991E
                                  SHA-256:10887D16678F6144487527DF0E204F14F796E2246D5B19B73C59238E9E4FCF0E
                                  SHA-512:813D1812709BA707D3391A5353C6778F10C68028AF52705113E74A4680D4D55A11339D43D1AB8E07E9222A1978881BC74C791FF0FDB89C3F5C4422169E66552D
                                  Malicious:false
                                  Preview: . .\...DSf|....9&.......25T....xm........yz....dx..TU..[.CR.....ntxyRU..............L]_DEB5?..PYa94U..hN..->9.......).............SHfaXR.....V0...J.....l........... I.....:hB..........bsQJMJ...SZU...gt.$)/....bD!!JS....ruWW......{7..f+('ld}b.....9...km..................T[.....SX.............;."=Z]sh........qq..........vt{je~.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\697__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.811071725773965
                                  Encrypted:false
                                  SSDEEP:24:jI1eU5gdCbb584tFoze4ytP6qfHSgC0fNSZBzfteJTQRHU1/7UzfXF2tDFvy8BpM:jI1eDCyAd4M9/xJfAXxuH1S158B0fF
                                  MD5:209FC52095EF662B2C6684856768DA80
                                  SHA1:EF311F3FC5E96B2D72F33D65DC74E373B72BB9F7
                                  SHA-256:A9A110C14AB21ED294DF9E4B3FBD832EBD912F6F4FA6B97463E9A7C8AB4423AA
                                  SHA-512:16AA365C7D5C1B64144BEEA75DEEB1B17527CC29FB2AAEC7600C1ED5CF3CF7ACF8290BBDD335C8560A9DD8E1321CFCBB9C282D34FC8174E30FCE5BFF2692B768
                                  Malicious:false
                                  Preview: .Q.'e"......wmSR..op`r,i......Z..[....}...,#...........JK..`+3"p-........x.lo..eV@j............dc................(/.U......VJ..^MTV..cx..q{....F]>......&""..jv..yj..8)QJ....9mQX..N.G..............SR....2f..6f0>..|##../..........TGRPzk..]Z]Wr&}t..ALy_..zc...ub./..8)c~QXn2kg{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......*L......}{.}{570}{00005400
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\698__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.710743575565406
                                  Encrypted:false
                                  SSDEEP:24:/mA8rpzvVA3LLjV/tkH084tFoze4ytP6qfHSgC0fNSZBzfteJTQR71/43UzfXF29:/mRzaLXVlk1Ad4M9/xJfAXxuE1t158Bv
                                  MD5:2F38E9855CF896DA9FCAABFE324D7962
                                  SHA1:4AED1C5891ACA5E0632C1F4A0C5F22FD314ACE75
                                  SHA-256:0DBFC0E0F2785E523A5CFE53E2745C25E2C057BEFBADBAB44D17BC258341D750
                                  SHA-512:0CEA9E11AB3FC0B9136DDF062548F3170F88F169F37C437E91F34A5A27365F64EC00A962C3C4D8A1CBED46C593181BED7353C08DEBB47F259135C266AD82BDBD
                                  Malicious:false
                                  Preview: ..u.n)...K.....}b........................^]...........N.......qkEDkl..................."%...T..\...gw<X1.pZjj..AJ6%..PA....T^.........:#NCU.3...]]......0#b`..QJ....H...{#.q....[eIXlqdm....-.[[....PL...vt#2....."+....v......LG......''00......]B....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...c.R.....i...O}{.}{522}{00005400005700005600009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\699__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.7019548400929665
                                  Encrypted:false
                                  SSDEEP:24:HvvUELVj0vA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRH1/L/VUzfXF2tDFvyv2+N:PcUVoxAd4M9/xJfAXxuY1Ds15vRf1
                                  MD5:F66FF6EEB4921C0A859FBF64B2A46DDA
                                  SHA1:5F2EE8378F0CF678D7943550713F120447D732E1
                                  SHA-256:8581F8694F5FFD784F7F1DA01CB07F01F153018F5190945FF215A0E7D145581A
                                  SHA-512:14D6CA1C42D47A8AA91C4B8C31484E1ABAE7E922844E347B89315E27E1F96F26618925C4AB44A648EE51695EA358F739C9A3A43EA48F431937F7F037E0F4C264
                                  Malicious:false
                                  Preview: .!%zy2'&j..89........eg")..#......G]_.\I..................[.hj)0...._X.....WP)).qjc..0'......1<..ls.....be....8g@I......z`........ZE3...MT....ts....HH..JC....L[~d:'#`JG..vi]hEd..fP..%"~j..{|.........t}7$....yc..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Q.:.`..0axZ....}{.}{441}{0000540000570000570000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\69__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:DOS executable (COM, 0x8C-variant)
                                  Category:dropped
                                  Size (bytes):1309
                                  Entropy (8bit):7.408485081890231
                                  Encrypted:false
                                  SSDEEP:24:lvNWNlugcs+hEzRtmtnfVXZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgd1/VBBpR:lQqhhEdtm3XKAd4M9/xJfAXxuZ1vBpF7
                                  MD5:7FD2810AAD535C5E4C38A45E75BEF310
                                  SHA1:F420CB28793ACA317A13953325C6A345790BF9E2
                                  SHA-256:8C6DFCA253D42371FDDC16ECD0540D9F9A7A5012FD8A0F574755EF79C9F73291
                                  SHA-512:F9A27B9ED785DFD9614233BACFBEEB38E9AB065B30CDEF227A4B03DFF8FB92035E9DEC65868F2B0E5375B134751D44E3C146C56AB2250C2DDD41A3294F1962B1
                                  Malicious:false
                                  Preview: .{...bw......RTj9..IW..........,-........(%\].LR...ex..............in....ni..${90........ql..Q\.............8"....#?........s`......+6$g]P..........M^....ED@I@6P..........OYk..3..oo..QM......mvCD^T?k<5.P6..qR35O@syZ|....6%\@52....BB..1}..2.......-:../.el.......16 .....{-....QN...........fuG.....FC...[Nb}g`....Y[pats..............RC#8(/<6..Bh......kz....UYj2......5..s%..|l....X...+>r{T.S.x~...V.....$..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\6__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1236
                                  Entropy (8bit):7.395661439620676
                                  Encrypted:false
                                  SSDEEP:24:Hf1SG8ne84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsccsBBpFUBQ+JgW5P:H9SG+Ad4M9/xJfAXxu6hBpFUBvfN
                                  MD5:3E0BBAB23B68355DD197F3C18586D0BC
                                  SHA1:FB9A684BE5C6E3991278926C3D064FA412DCF12D
                                  SHA-256:F5F00AFB5AB3C89B0051316E3813DF53FE348E72720CA1D0B13EB05EEA44FF01
                                  SHA-512:6192CE675B6F2639A8A5E1C686EB83A0BE5D6BB433442C914D9C18002FFED8DA6EDC9E7DEF8F47A68D0BB22E8ADE05AC1C636646C50866884B01913A1728AC95
                                  Malicious:false
                                  Preview: ...".....YN='....TK5'.F..............vy.....'8.....\[..'6O...fy%?45....HDeV..........ZK1*..5?....Z......._F......TX...RxYY.....FD......LF.md.X.BM..V.....ds..i......=&}p.s'1Q#............*9GE..az8?HB.OF...`s.!..3<=7..lu........``...r>..l!....<#`wvw.....=.(......2.....).cn......WHqrK.6,..92......fs..Y..WQ-*A.gh..1.^^.....sz8+....qk8%...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\700__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.375656033527932
                                  Encrypted:false
                                  SSDEEP:24:3F+LNwsrg4xi84tFoze4ytP6qfHSgC0fNSZBzfteJTQRm/lBBpFUBQ+JgW51:3INwsrgknAd4M9/xJfAXxuZ/3BpFUBvP
                                  MD5:99A9229525CBF82E4D40224FE767F8B2
                                  SHA1:D2244D36AFA51850490E7B3592DD0DF5C1A04243
                                  SHA-256:4811C1AF0015AB4412370D6E245DC57C13A8276E3AA21FBF52FFCCAE5981FF71
                                  SHA-512:3968E0B73AB223B0635E09446452F45E2C7C2E6E07BFBDC88FA040026CCD794047FA06BF132B2CE30AB2D8881A8C3D2D25C6E160730971FD1CC012CDA3B2D6F5
                                  Malicious:false
                                  Preview: ...e.............\C....bo6=#$-w......16........NQ.......UCRo2..qntnml......m^....YR..:8yh.d43...........>YY......;=....u_.........pavm.......S......Aq.)....[y..xsq5+....nn|6).........))))JJG.......]J|fa|.I......Ml+.......Gg.......pCDn..................HJ......zz%3....vl..OG..|kSJ......?..2?..`'................{>.......................c~D.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\701__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.799520063664279
                                  Encrypted:false
                                  SSDEEP:24:EDiwk3IkI784tFoze4ytP6qfHSgC0fNSZBzfteJTQRbUzfXF2tDFvy8Bp+JgW5yT:EDi9IEAd4M9/xJfAXxuF158B0f4T
                                  MD5:3898C8229A03565856D100AB6A2944E5
                                  SHA1:1AB57708E15ABD80BDCE221DAA4678EAB41C9048
                                  SHA-256:9992D1FB5D0C1F19FD2F372E25A34C65ED8CC03F3D791F568FD0DF39802D5F53
                                  SHA-512:50400C7F28171BE1CC03561E7AD66E0297B530E6CDD4CCDF2AD3A79EF3BE0F3AAFD71B7C6A06A280B24742EB4ECAA823C72AF789C5B0E078523B1AFBB1B6ABAA
                                  Malicious:false
                                  Preview: .....6#Z........h{.........%:edi"rh.L..YS.....|'....5................:1s.WPPPU......)>..~c\.]P..]BcA..............ss.. ...w`2%,6)4h+_R+>? ......wk..ff..,,......]J..............S.VW......IP.D...z}.....4`....X@..y~}}..cc..S.le..zm....*7.....#<x...;",!..h]..vr..;;..t.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..5.w..X)N$....}{.}{568}{000055000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\702__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.712103472701543
                                  Encrypted:false
                                  SSDEEP:24:QdKSsHkd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAUzfXF2tDFvy8BXCL+JgW5KT:Qd7sHkOAd4M9/xJfAXxuU158B5fy
                                  MD5:D2B1E20D0ECE339FCCEAA4069AC2CB54
                                  SHA1:379C1A90C5215A5678634211A984CCDAA19860F0
                                  SHA-256:DB255FA0394E1059A9217B30110A0E58DF1A9D79F100E5A843E3EC6EFC0DFA66
                                  SHA-512:B326B616D2EF69E0C758C84E233286D59630591E97E6AE3B0BCD91DEFF738F95D8E9A97C2D71041DA15C2ADFD1B2A836EDBF17CD26148AA3EBC8FF70E125BA92
                                  Malicious:false
                                  Preview: ...9:.....32..b15&ZD..',..WZDM....*a..>m..T^s~..\.K.....o\.....U....GAmjBK....z}99S...|o......hu...........j....\\...SZ.......P....4+ .............!!........xo....C.....D[.'.7..gg........RR..$$..L.....{l....@]'d..7"......~tQ[....fa......!!.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..x..=|..y..W.3n}{.}{521}{000055000048000050000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\703__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.725735231051627
                                  Encrypted:false
                                  SSDEEP:24:neIXneMa3+84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4UzfXF2tDFvyv2+JgW5f:Het3TAd4M9/xJfAXxu015vRfR
                                  MD5:2A17467B5F718714C16736C3691E66FB
                                  SHA1:1054639B36522952EC37173F8B392031EB82A201
                                  SHA-256:1C1D82810A7D799B9A64CCDCEF0F84DDD0DFC37978C337313E1BFBE62F9AFDA1
                                  SHA-512:BAC354B03A6B1BFCA6CB0F0E9011862502361CD2B3FD8C0D04E0EDA008C4F2F431C0C919B6097555FD8A6535BA9E47870050A4E90BA722B7CFA931B073EF8A3D
                                  Malicious:false
                                  Preview: .ko....K.....hn.S....46.............Rlv=nDQka?2......_B.(....L.ik......!&.....BB.szqb..........Q\.........[\....g8..........RO.<...!>."LL:#..a}......xx:eah............%:...7.........G[..SS..JJ..T.2;....GP{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{v*....}..xS..G.}{.}{433}{00005500004800005100009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\704__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1521
                                  Entropy (8bit):7.531162600958413
                                  Encrypted:false
                                  SSDEEP:24:oHhS6+ZAE+1K95JTu2Ei5UsO36oNVyc5B84tFoze4ytP6qfHSgC0fNSZBzfteJTR:ge41KJEaROXMAd4M9/xJfAXxuhBpFUBA
                                  MD5:E4446DBAF6715AED526F5E5FEB8B032D
                                  SHA1:33B685C8CB2968465C7E2A56F7904F90ADC74F8D
                                  SHA-256:E3D467567468F85D0E468EC4BBA8402B691C012CA584319BE26D799833C40581
                                  SHA-512:81740DAA52952580534B6DE0DD5F2BC6C7E6228B107E0DD8219A8BA930139309B07E90159C11003DDE42DF6B8276D5A58C87CB2616133B16EBA0CABBCA160078
                                  Malicious:false
                                  Preview: .$.n)......RH76;$....w2p}..-*.%$s........%*x}....rm..(y..RUI.J[...iv)3...............CP......QV39.....Ko.......b{QB..qw..]....................RX..Y.]3+L..\T.)tc..#...[I.......0,..kkRR..x'#*..av7 ..jw........oNbG..ic..{[....LA...mGCC..DD..0!wh....J......OG......Rq.....:..zm1(g?.rh..^U......e|.TP\...............J....P.+$..Xr44KK.....%6fq..PJ...J....--.....b/r}............-/ub^Gd<.........XMqn........Q@....||..S.3 ...........ip..9W4S`.ki.+....ep..7,........--__...Hgto"....ktipUx.._]..VO&~..".l...8|..5 ...SF.#%....1>&...oo..YE.....M..c;.e>9......vl..........6f......>>-)..Z]`ui9..C]2gu'......2v>zI\OZjc{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\705__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.386323241321772
                                  Encrypted:false
                                  SSDEEP:24:0KKn7+JW/qsayjDc6wY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMBBpFUBQ+JgWD:0KK6I9ayjA62Ad4M9/xJfAXxujBpFUBD
                                  MD5:134AAD07052987234E1CCDF42D3E7EAC
                                  SHA1:8C94391B650753EA870476BDC064EC223F432072
                                  SHA-256:6593CFD70217C587C57E2D9E307AFF8763E3F969C07A6992EA050AAA5E8A42A6
                                  SHA-512:C25CEC3BFBF2CAA139D7841E25DD604CF8D4EAA75D80BDDE7D881A1433D61B9BBBF1F3EFDDEE4C90FE9FBD5CDB236DFCA46D91504B696C6B3364C279D223CEE8
                                  Malicious:false
                                  Preview: .%........./5....$;]O...........O..VC57...$!nm....pl].FG............kj....'+...........,=8#......|$.yug....LU......q}........................#w2;a9...z....2H_g/eS..C4bpopQ<.......UU....c<^W......PJ.....*5a@lI..ak..!...B[..Y..,....BB......:%.)%t,........<WW/9....BX..........a9......IN..K@....m0TX...Y........?9%"..... .ppbb@\.SKB...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\706__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.786154875387363
                                  Encrypted:false
                                  SSDEEP:24:71Lda+VRkdVl84tFoze4ytP6qfHSgC0fNSZBzfteJTQRwEJXucsUzfXF2tDFvy8G:71Ra+3UQAd4M9/xJfAXxuaJXuG158B0/
                                  MD5:356B25FAAA595F4A9635C2784B9C1908
                                  SHA1:A8658F126B7BA91A85EA5B45E92316020D3C0C7C
                                  SHA-256:3DAF0E66F9BA8AE568ABA30CFAC1242D7FDED141B4F8C32FC784980336D84228
                                  SHA-512:6D260DD4C831DA734BCAFB413763A01040F46CD9B34EF8A92C9E7AEFCA82E803C830202E78666E53EDDA4CD25473AC3AF93CFB83D322CE238E2CC6BF28DAD0E7
                                  Malicious:false
                                  Preview: v"...R..m;OX...........A..P[..K.e2ug......2=.........V..25c(..B.~c..\F...MN.....9mqsx.............V_d<...._@.......Ev..mm..}n..?.irKL....\U....kz...:..........FD............=e...E.37.......U.|y........=i.A.`n{+B...dN88..XXuiNE..;9..e~VQ=7E."+a9...=....BQ.i#4.8B|du......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.U..*.6S.l.....}{.}{566}{0000550000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\707__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.690715437929363
                                  Encrypted:false
                                  SSDEEP:24:l44+xa3C84tFoze4ytP6qfHSgC0fNSZBzfteJTQRGC116/UzfXF2tDFvy8BXCL+a:lX+A3HAd4M9/xJfAXxu+1N158B5fy
                                  MD5:C242501322EFC030B5C8945A1E688BA9
                                  SHA1:804ED29A8FC7F16CFEDDAD87F0DFE428B0FB99EC
                                  SHA-256:757FB746420C5A080D30C4FD9AD1F053E17BFB5474BD3966005EB4FC65F7B950
                                  SHA-512:9EA351B0C46BF1261F4D2C970643A9C8D40C2AFD04E89075E8254F3171E00FDD6DC7689F26CF1B62E67710804F5AD190F98C7531E222257BE46BDED318723397
                                  Malicious:false
                                  Preview: .~zC@+>....9?....46.......&9...Vcy)z6#CI.....L.U..dy.......57..*0..G@.....I......bu..&<ro.................7h..l.,;..='..4w.....1....{bDW...........A..xo....dy...'8.9;.{.............ll..qq..G............b........S_....gm..fz......oo...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....Q.H10..?J...}{.}{520}{000055000048000055000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\708__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1331
                                  Entropy (8bit):6.702801858870046
                                  Encrypted:false
                                  SSDEEP:24:djCMsGoCap+UA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQeUzfXF2tDFvyv2+Jgc:ynTxAd4M9/xJfAXxuDJ15vRfZ
                                  MD5:92964467E76732D8AB6342A3AD55678A
                                  SHA1:08C144C58C18FD72AB6EBD0068A0A61C86D523CF
                                  SHA-256:01584E52BA807CBD79230920B37024EFAA7C30A1D81FF2AE8B1A887F23B094E9
                                  SHA-512:74616F608DA59451151DF0B0B3F70B7E7DA38929B04D28633FFF6AC93C11F11CD9F19512F037A99A4C90A99577F2B8109C84DF21F731E55A7F5B45201EE1CC0E
                                  Malicious:false
                                  Preview: .Z^WT......PQ..r!..qo........py.../.!;.ly....RS.Hm6..B_....|jL...CZ!;..ho[R..D..........VASD....n-ux)<op...iu...........1&......XU....*......KW........(w........;!.3%f..TALS....04aW........jj...33.....]J..3)wj..S^{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{ma.H....'...Y.3}{.}{448}{000055000048000056000095000095000067000101000108000108000117000108000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\709__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1251
                                  Entropy (8bit):7.395447356961307
                                  Encrypted:false
                                  SSDEEP:24:FyIJyaZMKRstaqTnW9fW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCGT/VBBpFUBm:BJyaKFYuYAd4M9/xJfAXxuPGTvBpFUBm
                                  MD5:E71DB6050B36B86AFDE57C600C65F033
                                  SHA1:DE3E99E50F728CB7373EE7E86912FB53366A6E98
                                  SHA-256:B94188E1616C62DA7EDF8A8FAF0BD37C67342473395942065021B281D4D1D543
                                  SHA-512:5C5F4FE3D371480FBD6554528241A1C16ECA3E30239827B715AD9C381F32FF65B51719F748E6AA0A3A220A5CFB69AFF8D6133C5D967AD4BCFD44C30F7A077F5D
                                  Malicious:false
                                  Preview: .51.....Z.......A..[E.................Z...............[h...._...]D......xq...B.......i~..F\..R...................LV..........vv.LSZve..av..ITg$IDwb&9).utzcgo..5*...E..\HJ=..6)..j}..........((.J..............._J..Z{....pzejpP................XD....L.[W...}uw..px..........qk..~v..`wF_.....;*I...58..l+.. m.Kyl....~&.G......\S.&.........J..'4....LV..>c..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\70__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1239
                                  Entropy (8bit):7.392036467012617
                                  Encrypted:false
                                  SSDEEP:24:oQQfOPVS8rw1wLh7UME84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0ehBBpFUBQ+Jy:08rAsNlAd4M9/xJfAXxuEBpFUBvfE
                                  MD5:F02E73AE46BF76312841B1B7B078818D
                                  SHA1:3CCB6E2C8D1CB13B6BE7B0D032E3EE9E789582B6
                                  SHA-256:71DBD72689E2B22A4DCC46672D03B84EF297DA5EC8A8ACB6ADDF385DF1042D33
                                  SHA-512:1F47BB1066939B6A1A2CD0F0FFFF6F61FD346CB08D7B32C33A11DF2F82DCD8B15A848BFB024569830F57E7636CBF63104DCAE713CBA639F42423488B5C724B0B
                                  Malicious:false
                                  Preview: ^..........76...............bk...1z....at-'...........@s.....8:tm.......hc..RU''....(;h.....jw...u`....;'../6OB......XN.2KL..!!..........OU_B.....a~..................9;/............DCaaiixx.............8{..(=....gB..|v..Ppsz....KkX..FFxx......5*P.gkg?....JP....xxXN..........$3....cd..75..=.......U@&+....Z]CX...PA....................{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{5
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\710__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.762032891190133
                                  Encrypted:false
                                  SSDEEP:24:JA/Fyozc0J4684tFoze4ytP6qfHSgC0fNSZBzfteJTQRpXuUzfXF2tDFvy8Bp+JB:J88ozz6Ad4M9/xJfAXxuCXZ158B0fH
                                  MD5:711ADEB98CA4984DA8FCAA84C4D3D654
                                  SHA1:EAAE9FD2D99EAE904611C910024E5481DF29341F
                                  SHA-256:DD0B8ABFC184347C85525F0500F6F1134C0D4237EEC2345C2F42F0E8546D2251
                                  SHA-512:5AE80FDF1B2F08A94C2F81CD9C8BB677751936A8AAF3E97277672ECF9F53694729F262694E25B63F60B82ABD04A5382DC4AE38EEE247CD2A8D7C1475A00AB976
                                  Malicious:false
                                  Preview: .WX.d#..........op.........a6]O..=?..T[............#"....vgY.7*..CY\]..c`..uF..|`7<........]Z...<5..0-@_..........th...!#..2)....`4!(u-...ET*{.4.300ee.....,...'<....*~..6nj3g<.......62..V.72.....YW.......S.LzI4...nn..]Alg........HO..H...|$P]Lj......1N...Wi9(JWBK..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{?_!V,zE2.h.....}{.}{566}{0000550000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\711__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.696822296331484
                                  Encrypted:false
                                  SSDEEP:24:XXLfrLASjd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHd3UzfXF2tDFvy8BXCL+JE:DJKAd4M9/xJfAXxuC2158B5fy
                                  MD5:7C01D3EB25F75850861525D55B46DFBC
                                  SHA1:5CF659FD423862B4058002B627C89F4DEDA3C626
                                  SHA-256:9E0B220FAAAD12E20065E39A1B570FB9595661FBF60B0635A60D481A3E37CA91
                                  SHA-512:1FB6F9BB305DEBC11565487C19848FB9B1ACACD57ACF9DD2D0E241E65FFB75943125AC748F822CA51A5CE79E27979D241CC5F075ABAC135D5D5ADA1A79FD5DED
                                  Malicious:false
                                  Preview: .....<).3......_.bqxf........le..WVQ.!;I.wbfl......f=../2.(.>-;..OMwncy.........C.......DW...........[N........pw\\...LAH........&;..........>>....1-......[[..of.................(...1..."%9-....!!++.......n}....A[..)j..........eo...rA]..........CC...j'..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.i_C.vwW_......}{.}{520}{000055000049000049000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\712__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1331
                                  Entropy (8bit):6.685502875039669
                                  Encrypted:false
                                  SSDEEP:24:ejoSMiUiwjylJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRJNMUzfXF2tDFvyv2+Jr:uwjy0Ad4M9/xJfAXxuKNH15vRfZ
                                  MD5:EC622F2FDCC1EE940E608152E6BA061A
                                  SHA1:CBE3B615A628F59B2C32AF7C71FA0C8EE9A4E1C9
                                  SHA-256:5EE59FEB951AAA69AB36BD6F1975042162021709E2792F14706FAC06A598E5A1
                                  SHA-512:BC5BBF088578508F7C4FA2BDC14102C75E8748B83F5794DA08E95A653DA4E0B3368AC74311004694543838EF5CBD4CC18262CB5D92C9D71724E62B8CE1232ADE
                                  Malicious:false
                                  Preview: >..VU..C.4'./..>m....W\......98..TN....S^.....K}k-0...._Iq,........G@R[ne^........GT7 ..A[(5C.$)$1..FH.....rr..s,.........QL+h.. 5D[..{{[B..................I^......- MX.`1.....).ll70cw........33vv,s........wmkvd'p}{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.D..P/+\V...,.*.}{.}{448}{000055000049000050000095000095000067000101000108000108000117000108000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\713__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1255
                                  Entropy (8bit):7.378777630078614
                                  Encrypted:false
                                  SSDEEP:24:YdY9axdnGuXstPf284tFoze4ytP6qfHSgC0fNSZBzfteJTQR+mdmBBpFUBQ+JgWa:YGUHzX0PTAd4M9/xJfAXxu4wBpFUBvfa
                                  MD5:C56F675F31EEA4FB5DC17894B2EDCAAB
                                  SHA1:457407AABE98F85460047D445DDBCA9E53797ACA
                                  SHA-256:35E8F270DC5B0BE12731C775141CEFCE69E9C00F583D24CF460288B084F8C067
                                  SHA-512:BC959D53CD7C6A89AF71E4AB0D32F2AA4621711BDD3D8C946AFC48658F232EB42F39F1A1260B762E1905C246450A37AB16017AA89C52BB62E235AD88FBB6F877
                                  Malicious:false
                                  Preview: :nj^]GR.M...........uw.............'==n.........e>.......#..S.FD^G........*!._.....ypXK....,61,Z.:7....^B....p}..MW..,:..............JPWJ.FKvc;$....:2oT........`c............'N......^^^^|`..PCRP....|{28...c;%C...........=jjsj........nnBB))R...R.............py$...>>.......%sty..HWje..p:..........r{\^..#6......SH,%........................../%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\714__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.325090768449435
                                  Encrypted:false
                                  SSDEEP:24:IYpHXx5ENr+vw584tFoze4ytP6qfHSgC0fNSZBzfteJTQRclBBpFUBQ+JgW5xs:IYpBSxqAd4M9/xJfAXxuN3BpFUBvfTs
                                  MD5:601284429D90404FBD9414D56896C077
                                  SHA1:8AC310423E8652926D292A3219E14C62AD78CA93
                                  SHA-256:19146FBAC7A25CC82783F5C98225A695D0C46FAC4A2A16C18FF6AAD8E096294E
                                  SHA-512:8EEB3D5964D5D14ACC55AD41D8372B53A902D53B1E0CBB95F3A003006AF30886DC435C8AEA2425B9662DF5479FF5281C779D7B81B928E91E5AA7A9F429496887
                                  Malicious:false
                                  Preview: .......F.........#0..b`0;..#...VW,g...DI\..........!...6k....)3& BEI@..q,61BB..............._....LS&(+7......2.............EE....3 .9....zgw4......T\..3{.)..O8XJ.....zk..........\.......%25/...T..DQTK.%....T^...,..PI......3...ee\\......7y}q.I...'=.&Wy......RT..cL..}.ct..J.G....X..XF.........]H49?*{d......CA....@@xx00RA......ud.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\715__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.807033561547119
                                  Encrypted:false
                                  SSDEEP:24:0r28dHBTy8b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBUzfXF2tDFvy8Bp+JgW5A:pABTgAd4M9/xJfAXxuH158B0f4T
                                  MD5:40621577F48319C5D2824C6AD6AEA2BA
                                  SHA1:1DF19A33C1DB116A3FB192C3539E000ADC89832B
                                  SHA-256:36B339BE6456383AFEB03B78502414674F89742780D19EB299193B4E2C3FB7BA
                                  SHA-512:AC8EE48A1A4BA81638C2A6E433C242F33BA6A6FD3FD525077BCB5F02665402D25E8435570906EB6FEA2E9C5933E6B639873A7B55522C5E1495CB56202F1A0474
                                  Malicious:false
                                  Preview: w=9+(...]</()PV't......5>......UJQP.\..2a..Q[......`v........?bTV..........4?..MJ....!(..ER..\F......MX...........................l......$9.N..ylYF.....:&..qq....U.MD...............ph>g......I.....+2...h|%s...H....6..z}........F.........~dex.\.#LY(7..09....j7/...,(....NI.._T{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{<.,.h..9........}{.}{568}{000055000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\716__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.72482773194876
                                  Encrypted:false
                                  SSDEEP:24:dueat9+7G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNjcsUzfXF2tDFvy8BXCL+JE:drFAd4M9/xJfAXxuIjG158B5fy
                                  MD5:B994F60249011FBC926A605AA7BEBBDD
                                  SHA1:FB12441236FA55FB2F605C79AE24212F91767B24
                                  SHA-256:8A665FB6FEF2E71794919875AD3440A59F7ED7B6D41996EDF96D317423F936CE
                                  SHA-512:FFE5ECB3BC5766702DD73DEBAF7DEE8C72279C50DC08DE490B0F9066037A537CD686A62966DA37DC28CC34E3D02AC3A8568365AE969461E98C42CFFB3ED0D03F
                                  Malicious:false
                                  Preview: ...`c..(d.....,........ ,...!>..V.|fT............K..LQ..LzYO..........>7..........XKyn/8.......oz[D.....kl..GG..\U..ynJ]%?..=~........EEHQ..@\......BBw(MD................a@MIyO....H\....``ii++o0W^..8/.....z9....B]......OE........<<..II....BQ....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...ZI...V....'..}{.}{521}{000055000049000054000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\717__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1325
                                  Entropy (8bit):6.720390624984759
                                  Encrypted:false
                                  SSDEEP:24:PbKS6M84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsK+oEUzfXF2tDFvyv2+JgW59:J2Ad4M9/xJfAXxu7aP15vRfj
                                  MD5:BB2E36A3A007B4195D3DF5867161D121
                                  SHA1:0C66F2282CD1582D67BC9B19DA59AF2A140DB0A0
                                  SHA-256:BF6E81824769A3CFEEAF0914A8D1BCE3DD5FC649AC57E51AEAC32423608B0692
                                  SHA-512:94ACE2BD351C396A097B2AC763B0C086F7ABF14EA8D676A3B4064E7A3DB2C26D6DD204F921A4D79ACDE9FF1353D42A0F5864CED2E2E6106F43500C8A81C459EF
                                  Malicious:false
                                  Preview: ...fe@U...MLIOR.XK.........py..@A^.SI...PZ/"...\.@V........} !#IP.............<<e:........OU........op(&>+..61..==..............<........RK..3/....44..k4>7..fq....!<...5 ..oZ....Bt..TS..ye...........Y........WM{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...P.@......iMM}{.}{436}{000055000049000055000095000095000067000101000108000108000117000108000097000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\718__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1338
                                  Entropy (8bit):7.447180257092067
                                  Encrypted:false
                                  SSDEEP:24:8+Ecrfx5tTo/P9EI6kj1ojP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAeBBpFUBb:8+5fr0VhxjGjEAd4M9/xJfAXxuiBpFUJ
                                  MD5:A26CDEE6BA30D6C798E9E12EF59145C7
                                  SHA1:AF8E9EB41501DA8E55AE8147D089AD1CC7B29467
                                  SHA-256:976577B483FF94BE611ADDECDC2742DEDE97ACA692D112915337B928F689581C
                                  SHA-512:6093D1D4A2827F919D442139DAD09BB9C650A983EE149E76086EE6D8B823188EA12B33986644870A3999885D848BD2EF8C3F2F5F3F7AC5FC78274F6141C29B51
                                  Malicious:false
                                  Preview: ...Z.......LV....$;...J..>5CD..b5..0%..klVYsv........\..........B_POTN..AF..........BQ75....ohND..HA..a....,,.....>8...C..)...!=......vg:!..BH..%,.Y.w......uz..U.....'<|q....uF..00..RN.t....VM..$.....J....~]:<........5,..6*.......[[.B...Q....-:..9.....42....CD[a...Y"t........F@..............6g..dc...9.GmUU....!mv...$3k|..} ......HH.........%:..+=%/......)0n6RA........YL........?=?...<<........CK........#6....[BH.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....].
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\719__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1393
                                  Entropy (8bit):6.810920680112636
                                  Encrypted:false
                                  SSDEEP:24:BUkNHblmhEN4884tFoze4ytP6qfHSgC0fNSZBzfteJTQR0rT/VUzfXF2tDFvy8Bf:Bf4hENSAd4M9/xJfAXxuXvs158B0fTs
                                  MD5:89D13FE3DD82462C62BC77CEC1B2373C
                                  SHA1:18E21BD60C25DBDD5DB6A6B4A028FA7FF2FB2E0B
                                  SHA-256:123CC4D03FAFFB7B93B0DDF9827AD561FBBD4263B6F4EF66F3BA6EB2B37DB1C3
                                  SHA-512:212B0AC468930AF834C09FDCAC49DDB12A38E38C5B10C88606DAB9C8FBAFCE78B43731B113B18F3FBD8334BDBEDE082B2AB8C07EFAB8BA3A62E301F27FE91DCC
                                  Malicious:false
                                  Preview: .NJ......1"tu.....NP..v}OC..ha(7..[....rgAK....W..........1'P...;"......lebi.Q.....Pah............xu....eG....x~.......................5v.......4yolk....$$~~.......[L..E_...S........]........HACZ..H.......sq................DD@@..................6Z........Ontp..JJ..MY=6]*{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{ ....k.>4G...#tU}{.}{572}{0000550
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\71__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.629742481799404
                                  Encrypted:false
                                  SSDEEP:24:VU9V76+NHqT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRTUzfXF2tA63yrb+JgW5vs:VI1HXAd4M9/xJfAXxuJ1EY6fxs
                                  MD5:7B0714158848F58E71BD6E67302CCD59
                                  SHA1:6D8CE9A2455D2F50EFB03B710DCDFEB07533E9B0
                                  SHA-256:A96BE48DE4A8224A7E73165E9B841D9C570073B7D418BFE4E4153F2092F3E220
                                  SHA-512:CAA291673A87A2A0D04A5474C8B86DCF17D7B3775AE0DF8B0297FF596D87F5F7303136B915AB58D1B2C550AAE531865F38718DF2DA44A04E7B4C892ADF6536EC
                                  Malicious:false
                                  Preview: ..=..........EZezn|....[P...........Z]`o{~%&....ey......#h..H.......67..'$jf.......................l4V9...xKXr................w}.[+"..``i\E...}N.*..KK@\qz..NLPANU..flA...+s.sdIs..........Iz..QQ......FM..NL..MVdc..[...{#...`vddp}{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{m%.{.a...lX.i.d0}{.}{475}{00005500004900009500009500006700010100010800010800011700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\720__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.699665689162231
                                  Encrypted:false
                                  SSDEEP:24:YfxgTmmKp4T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRiUzfXF2tDFvy8BXCL+Jgk:YpgT5KpAd4M9/xJfAXxuu158B5ft
                                  MD5:C9DEE768A1868B95363FAF2BB7D4D717
                                  SHA1:81EE2116BDA5CB8E71432A387FC3BE76B546CD1C
                                  SHA-256:9E8355BF6C82D40FECD5691A14812377B54E579ABC795E5FEAFE03A6A15FD631
                                  SHA-512:26A3C17664F59C799E0505659E58136C2B3B56A102593C7186A32114F44E989D976185111954E84186AF2DFA20FE6EF7CD847B7D685C43FC1B932D22CA6B8E0E
                                  Malicious:false
                                  Preview: ...y.....ERcywvvi..GU..LA.....S...,9......z..............#h..........@A!&|...."..8$...............I..`8?P......@j==..ODfu:8L]...................8?...>>0,sx......RI.......P.v.5"..9.......J....kk..CC........L]\G.........C..<Kj|..|q#(bQCi||......#?9(..x6..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{\Cj..Lp.V......}{.}{523}{00005500005000004800009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\721__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.715006111102641
                                  Encrypted:false
                                  SSDEEP:24:SYCplX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaB4UzfXF2tDFvyv2+JgW5C:L/Ad4M9/xJfAXxuh15vRfM
                                  MD5:E4B338441AC8644A4BA2BCF79F0856C4
                                  SHA1:855F592BD24C18B20FB7DA2CEE3B65331B24E064
                                  SHA-256:6B9759DA10E8E6466967173AE82EEE0B38AE05B4CF1C9CA21F44C17096D2A328
                                  SHA-512:00A4F6AB511210AC40783BFACBB56BB1956E8871EAF8D6C41AF1FF2C1316EB88B12250E031E100F433F48C569D53E6672640B51F9FBF80B707665BE60AE3CE7A
                                  Malicious:false
                                  Preview: 7c.wd#........~....................-"........ui.\..............edpw.. ,.../< ...........oe..-u......kX...th..h{......PWBHw#V_.Ru.SZULM@O.Tg.8EE@@b~..S@Y[..XChoci.L\U...o.h.."...LQ..L....=..''.......;*{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.S..:..P...K.u/}{.}{431}{000055000050000049000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\722__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1223
                                  Entropy (8bit):7.34447302187856
                                  Encrypted:false
                                  SSDEEP:24:VufRzf4x80zl7jW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWBBpFUBQ+JgW5iT:4fRzI8KZLAd4M9/xJfAXxuFBpFUBvfoT
                                  MD5:B8CE9E5ED70281CD670D19F8F69C4659
                                  SHA1:68A8A85D44D9E52D1354DCBC518995D8DBAEA1C8
                                  SHA-256:B701AA418C66F46270FD79C87F56C30296F8FA6D5583ADDF90697647DEC036CF
                                  SHA-512:A77A4D38F873891E81B763BD5F4B777A1642780399167AB4B387BE645CC99DD3DAE7C13794018500F25153D54F296DDEB96D0CF4A3D66FD051CBFB7AA673AF0F
                                  Malicious:false
                                  Preview: .QULO2'........G..4*.........A@..#9..zo..JG.....[F..GqPF..^\..'=....`iU^3n.....Q..........a"...JU..fz..XA....2(|g........88+t......AV..ZG c........2Fu|....*F....s...Y].Z.S_..:!.....d.S`..FF....ib...........2fu|"z.j=.Ps......**....YE;<..<<~~...~mu8......|k..@g....GAuu..RUmW...J.............G[..9d.........*(}.ojPE{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\723__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1308
                                  Entropy (8bit):7.422058498218198
                                  Encrypted:false
                                  SSDEEP:24:zJMBSc4ilZeMPLktaUBalkjZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmBBpFUBJ:9M3lI6LktajgKAd4M9/xJfAXxuRBpFUb
                                  MD5:0C1D75C89D5D62BD5E85CEEACF3C13F7
                                  SHA1:3153DB69A3F657CB82E1A9AD7191A69FF72025EC
                                  SHA-256:B42B1576F2329996DC642EA8BF6220E99936C04A6B1D48678B8A669CBB22E9D0
                                  SHA-512:F9018346436095BC752EB4FB9E8093C17DB1A0F23E390D00EA60CED8402C31ED0A380BD06092A8229F3F4155DAAE1084973232AF705398355875034D2BE1B86C
                                  Malicious:false
                                  Preview: .W.x...........nq.....GLebk1.ygu.....s|),!"#(.............6+..............U......IKxi~e.xzp.....0Q...(!!........nb......dd............6<......k`m~c,$Qa.....{"ie...........9.......dx..............+.............CI........9%..;;..&&&&:v->f+ejfn.........HjjlzztK.........MZWN^6).....M@......r>..$1....F.l=....P.....rX.......,%..tc.......G..??hh......('IA....%3..vW..BUnwU._L..................AP..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\724__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.790524327878589
                                  Encrypted:false
                                  SSDEEP:24:6vc1LeELY84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVoXUzfXF2tDFvy8Bp+JgW5T:1thAd4M9/xJfAXxuU158B0fh
                                  MD5:E2FB6526727586E8BD9BD797555269BA
                                  SHA1:720E075CD48D488B5AD8C5205119B16852B0AA5E
                                  SHA-256:4F01127DC4CB2BC89AC0B086CEA227B2C72E7EAE9FDBCBD5E704A80EE937B501
                                  SHA-512:86ADB565D10B626477B114FFF160080A3092E4B9E8B715AFAAEE098D39E6C47C036B5EF8F1DD5ED4982F342EA792CC79B7C8E93069E8533BFB67AE673448B929
                                  Malicious:false
                                  Preview: ..l.....Tj}...........Rid.....Y.UWEYL....na8=...2-...........WJ..CY.........?Pz..u~bq....@[...H.jc.S..ti..%?..{|...9.\\............%q..7o.....R..Bh....4(P[iz.,..za..^T..........S.A.=9..i;723|.."<...-...p~ p;d.L4.......1-......ET....OEU.zs....;...kr5&K4W@....<-....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..[.O.YH.. .9..+}{.}{562}{000055000050
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\725__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.684613248593141
                                  Encrypted:false
                                  SSDEEP:24:+0dbLZg4dbx84tFoze4ytP6qfHSgC0fNSZBzfteJTQR68UzfXF2tDFvy8BXCL+JJ:+8ZgkCAd4M9/xJfAXxu/158B5fP
                                  MD5:36E2553C681F6A2FAB28C3A04528864C
                                  SHA1:05D04AE7C306402824D2423A0BF8CF2C0A32A54C
                                  SHA-256:41E2F192C66C9E93DE9C810A5C47CE38BEECA6C478CC0076775CAC9AAD78FB03
                                  SHA-512:294B0B5833A85112515450E91279C8E7EFEC494C7081210B8BB1E6D1F0AB2FFBF5BBB447EA3D2478EFD144F5BF8DB902A71C4365C763B67AB70EF0907E431026
                                  Malicious:false
                                  Preview: ..6...<=W.....b}/0...^YT..dcu/G...!4...........NQ...kj.......f{ezuo..' ..zv.....*9LN.........X..p(.AGW.b..mG....`kVE..hykpg`mg.09...3:..].~M..%%//........l}BYURZP.R.v.q....-........._..(.......!=.......RI..ys....-Z........_l....AA<<..^B..EZc-{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x..J.stx.|.{.c.}{.}{518}{0000550000500000530000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\726__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.699948556817108
                                  Encrypted:false
                                  SSDEEP:24:IV0RnXAoumH/sh84tFoze4ytP6qfHSgC0fNSZBzfteJTQRFXcsUzfXF2tDFvyv25:IwAoumH/syAd4M9/xJfAXxuWG15vRfM
                                  MD5:D8D792C193AD5CCA94F32F02B4F993AD
                                  SHA1:B5F9DE4A2B183DF698BBCB87FFE6FF6E51217551
                                  SHA-256:3879269F11153C4C66E5AD43016445FFFB18E52FDABDBF500F8EF5D5F490F4D5
                                  SHA-512:0E8BB404AC1B71B4340B0C82CEEE7D23C013ADB580149A638E94A6F8D7BBCEAB46EBBC91684805EFFE8A5342298F7E1C089DC87F6965C84A4A5AB5AA81E58E56
                                  Malicious:false
                                  Preview: ....S.......98(7....P.JG....d>K.\N......BM................~o%x+6.........."......7<..=?..\G.......?g%JRB..s@....{g......ap......f2....*3...pC.....................V_.......+....= ^Wv''......LL.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{i../.R1F....\?.}{.}{430}{000055000050000054000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\727__Cellular_PerSimSettings_$(__ICCID)_UseBrandingNameOnRoaming.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1400
                                  Entropy (8bit):6.547149461000052
                                  Encrypted:false
                                  SSDEEP:24:tQRnvbi1A84tFoze4ytP6qfHSgC0fNSZBzfteJTQR34um+UzfXF2vFvyvNSwJ+Jw:kvmnAd4M9/xJfAXxu061jvNSwUfBs
                                  MD5:3B5BB1CC1CE38E05AEC4A0DC2A4BFC7D
                                  SHA1:58D4F5B5005899CEF99C5AF30B3344C2EE70DAB3
                                  SHA-256:8D5C3881B8DF9CA4CDDCF17D22C2FA84D80622E43A119053BB4250C58FE001AF
                                  SHA-512:173D39402BB8427997937E01891400923B22D4A694A11C430C02F33692D4EE73749DC5AF3B6E7D0E6647B67FD8D143A349E73A4D2E85DB95FC2CE8F58DDEB5F8
                                  Malicious:false
                                  Preview: .Q.Z.[Z.@....*+.....0u..lg..)s..#6><qvCL......~a7+....<;>u...@9$..MWBC?8..48.3....+ ..qs..............}m....*++[G..iz........\V..HA...18......{H...........?=..xcin..n:v.|$..7 .....n......-...XX..44......TV......"({ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.j.c..t|....)f}{.}{442}{000055000050000055000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\728__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1355
                                  Entropy (8bit):7.448761586835809
                                  Encrypted:false
                                  SSDEEP:24:3Jzu1ryNVYUE584tFoze4ytP6qfHSgC0fNSZBzfteJTQRQBBpFUBQ+JgW5U:3cryMPqAd4M9/xJfAXxunBpFUBvfO
                                  MD5:2AECAD485FF83817C18490C9F773236A
                                  SHA1:F5557185071F23D085C91EA5F7E4CD7D2A86E70B
                                  SHA-256:807BA1C20C099E276732C2488328958F28DBD11AC5C389FAB4D3FD99EC0261B3
                                  SHA-512:AA02D49F31538735FFC38737D516FB5E3A2A226AD819F8E83B875B16E483C686ADD9B9E2B5CB4BACEA10EFCE1814F0AD296D90C3D34B52595E4F5E55406DC37E
                                  Malicious:false
                                  Preview: |....fs{7ar/...4g..'9......ty..+4..>u...M....he@An6.N@Vb...h^..~#..ZCf|.........CD}},s[Rdw......b..I....3,................TB..eessk4...................S^..XE....\A....aJ....]k..b...SL.s..cr....EE....0oMDRA......UH.Z..fsnq!.|Yat("/ ..#*....M.....DD$$..3/[J..:t...........<..gq..42......xz.............M....ki......bw......RP4%............,?..O^..AF-'Fu5...........:t............U.e3...o..&5.................#..hh@@..........I.?\...,%q6i?..br<#.tud{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\729__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.777881645977699
                                  Encrypted:false
                                  SSDEEP:24:aZRoDmDCB5ZDr484tFoze4ytP6qfHSgC0fNSZBzfteJTQRIoW/VUzfXF2tDFvy8Q:CiDJBXhAd4M9/xJfAXxu9Hs158B0fh
                                  MD5:30D2A430BBFCB381B0E2856E6C2221BD
                                  SHA1:A04BD2EC1820F64125A093C278AA6F5991CCD8C8
                                  SHA-256:0474A61FDB36707DA42BFD09DEC23120D3490592000AF6EA90C781C9C73D86C1
                                  SHA-512:CF19C90E0B28F33693E328C4A80CC7DD528315BA5689C78FDF4376A4972CC0B4217CB56AD189C03AC0488AC473864150DE9AE85E9ABFF8DE61C8E65DF260811A
                                  Malicious:false
                                  Preview: ..u.....{l..QP...............%78-..oh.....HCWH..o>BC07........QN6,..lk......*.os}v............I....U.kv+4......J.Jy?.<<';83</gegv...........*I.."3S.[h[q........9*02..VM+,...\U\.S..#x.T.....X\wb...........`4j8......F....JJ....3/.%..MO......mg....^...qWyysjRA...@z%.^O...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{...xZ..J.cf.y.}{.}{562}{000055000050
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\72__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1381
                                  Entropy (8bit):6.779341676841147
                                  Encrypted:false
                                  SSDEEP:24:5qsxlimVryRcvjm84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7CUzfXF2tDFvy8Bp3:8sxHTLbAd4M9/xJfAXxuq158B0fW
                                  MD5:3B4EEF2B17A2F6F2729079F1E2D15C04
                                  SHA1:8F8F1CB90EBF42D47FA19E09EF3172F2A835AA27
                                  SHA-256:9B9DD5CFA4461D185BF2F78691AE18AC99BF5BD1A16002ED35D8D5922EF0F80D
                                  SHA-512:0A158E51EB272AD37B81674BE8CC7433BD4E7339D8CF318559E3A188922D3AE195A9581EBB9EC732E3A51A8F89046592C8B4283ADAC27F2B2B02B733F60983C3
                                  Malicious:false
                                  Preview: :..PS..)e..............SX........yxK.'=F......{z.R.....wD.,....qs-4..60st*#...16.....L_@WYN....p3...........lj70..TH}zkk..>aahN]....._B.D%(.....*........FF.....U.....93$....\.LAYL:%.....d7]D.............@...V.........~~.......}t..;,'0....K.idYLWH"NXQ..948eQd....!.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{^.p...Z.IU...$..}{.}{561}{0000550000500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\730__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.718817676996189
                                  Encrypted:false
                                  SSDEEP:24:aV4DWVAA+XnT84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6FaUzfXF2tDFvy8BXCLO:au2dAd4M9/xJfAXxuHV158B5fP
                                  MD5:BE9CCC3DB70ABE256CC30DF9858F1B56
                                  SHA1:DB1F2A407A97D6A595C371124DB5B73CA05EF4C5
                                  SHA-256:6DD65E1D29F44B550E977BC7DFA149077ED5EE85F9F3FF237693D1FDB9E2ED43
                                  SHA-512:79217D28D6A2B74C05CFE4714E0A71772FD0F3CE2EB1841D2E547A4A21F1658946389B031AB3169371888E2290839E46898B4E136027280A8469072D0DECDFD5
                                  Malicious:false
                                  Preview: .....vw*|..............ZW....;a.E..............)"....Q...70.du6k0-poE_.......L.gM........2#..........}%b.....6...RNgl.....sh..$.:n...^.~w......Ic.....$/........^Y)#h<ha...tc..........H...1.22....}a.... "zk..dcAK!uqx....Z-J\++....H{9.....rr77...wh.Q{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{P.'.`.yH..h.9..}{.}{518}{0000550000510000480000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\731__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1322
                                  Entropy (8bit):6.7083794526979945
                                  Encrypted:false
                                  SSDEEP:24:N/PQgUAAxhn84tFoze4ytP6qfHSgC0fNSZBzfteJTQR8UzfXF2tDFvyv2+JgW5C:NPAAKh8Ad4M9/xJfAXxuw15vRfM
                                  MD5:092D5DACC3E67BC82E7096F3DE36780C
                                  SHA1:2AF7E05219814B6256EE03F2D2F499368903F1F7
                                  SHA-256:B994932169217C56957323F3956226876C01AAF89C7E53474C86F8C462731384
                                  SHA-512:02E9C581256AB156107091659AEB196FB20E61A6838677F32EE9746A5D46425157BBDC7550C973BE899A60332237A62995784FC4AFC79C78DDAA9A7C39D1DEFF
                                  Malicious:false
                                  Preview: ..X.^VWv .... !c|..QC..ID92)..Zw ..........CF......vj4e.....Pet.sn-24...LK.................kp]ZSY;o.......kX..33....EV.......\V..pyK.}...kr58......PP....qzev..gv..ru.....v\.....Bx\b........9.,,......ib.._]ap{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....U..P.e.u.*L/}{.}{430}{000055000051000049000095000095000067000101000108000108000117000108000097000114
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\732__Cellular_PerSimSettings_$(__ICCID)_UseBrandingNameOnRoaming.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1400
                                  Entropy (8bit):6.5219386192132
                                  Encrypted:false
                                  SSDEEP:24:LoNqNrFLDU84tFoze4ytP6qfHSgC0fNSZBzfteJTQRztCUzfXF2vFvyvNSwJ+Jgv:LoNq31Ad4M9/xJfAXxuMt1jvNSwUfBs
                                  MD5:195CEFE563EA39A1E7FBB875A12EC151
                                  SHA1:DD081055BD7F630C5E72DB22AADC25E723DBBEA4
                                  SHA-256:1D687327B305CEE9BD689D70D739EEC83E6C263014131289729DCC5BB22B54F2
                                  SHA-512:3520E9148E520A98850E00D1A400527C01B9D8F45827B08D89CF8840632D48204BA5D2340A95E89870121C8421680DE93FC7B94D479B99862941EDA69BFF786F
                                  Malicious:false
                                  Preview: .N4.A.yx~(....BCWH..$6......~y...\gu5 VT................+*x.[.2#8e........jm..s.......5>ra...........\U?g.....b...3..QMNERA..(9G\8?...P/&v..AH....?oH{U.....HT..,?....HS.._.5<.....~DPn..kv....Jy.,\\..EE......DF$5..NI..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{e.xg..K....|..}{.}{442}{000055000051000050000095000095000067000101000108000108000117000108000097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\733__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1355
                                  Entropy (8bit):7.437157211144681
                                  Encrypted:false
                                  SSDEEP:24:SJK1NG/N2TSS+n6yoO3l84tFoze4ytP6qfHSgC0fNSZBzfteJTQRdBBpFUBQ+Jgf:SJv/N2Tp+n6JAd4M9/xJfAXxucBpFUBO
                                  MD5:0C1A8FDB71C4F6BFC08C163F38D665CB
                                  SHA1:5572FA591960813345BECD871D7A90D0A8B1E122
                                  SHA-256:C8DE4E900CD2CF8DC2357E9D75FA400643AD4AF21CCCD55277E6FB271FB52AB9
                                  SHA-512:94BA81DC36BF1D4785FE23A2377762CF762D92A72ACEAADF899652A579C536B3C04D8807B9AF95B55CE0B5C201DC213B5C9FEE3A05A33AFF8BF57191144164AE
                                  Malicious:false
                                  Preview: .........zi....%vo|....OD ,,!....98..F.+>..3>..k3........t)-/E\..HN>9[R..9d..>>............$9.B..*?....[Gr{..heMz!;by}k.........*#....;,...............r.......01....;*......udv...........FF##..n1..5&............ta..nO..QDysS\..?6..r.N...u_........7&MRz4.....GE;!*"'.,,....ga......4#...U.....;x\M...?=GB....j^A.x]FI@..bs?8vv..cc....-/.....6<l_kAbb..........Q......Htw;.ux..+4ar.gr........+,..BM...%...';..POd*...q........t">3....od..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\734__DataMarketplace_PerSimSettings_$(__ICCID)_DataMarketplaceRoamingUIEnabled.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1491
                                  Entropy (8bit):6.382387563834717
                                  Encrypted:false
                                  SSDEEP:24:2VeKfkEforVYbG84tFoze4ytP6qfHSgC0fNSZBzfteJTQR5S/Vs1HJz2PXF2t1HT:5EoBcAd4M9/xJfAXxuZd/1qSwdfbp
                                  MD5:F854A9B1AD057060AB6B3882D886F6E4
                                  SHA1:C1F154C3FE49CF0670520F4BAF109B933F3E2F4B
                                  SHA-256:5744589965091F8ED8AF7D92B47D43CF8E48353AF8DB27B45FF0F377F4229C08
                                  SHA-512:59007E1A702984DA5DE0FEAA6C1B34FBC5487DE1E35BEAC1D469104820E518D41FCC7BA697E8CEB0B509E81D5D9006118506CE95637FE4B1F5CF851B8CD9CC6E
                                  Malicious:false
                                  Preview: ......XK67........)"..........Z.vl7dBW........t/XN|a...$..#~..NWLVwq.. )t.......i6..........wz..ls97...........]R[[H.. 7........xg.....=qhl}..HJ.X.....^^..LG............A....M?..."A.........Pc..uu....../$..|~..xcVQ..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x...`k..92..ze.}{.}{456}{00005500005100005200009500009500006800009700011600009700007700009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\735__DataMarketplace_PerSimSettings_$(__ICCID)_SupportDataMarketplace.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1432
                                  Entropy (8bit):6.506979695943622
                                  Encrypted:false
                                  SSDEEP:24:2ctAL8nCyV6U84tFoze4ytP6qfHSgC0fNSZBzfteJTQRyk71HJz2PXF2Qv/HJz29:2c2L8C661Ad4M9/xJfAXxuN15dfU
                                  MD5:FED6C74D7E95E6999554993A54CD1F45
                                  SHA1:69C2C24EB4F47C1B2B342E2E544B1DBDBCAA63BD
                                  SHA-256:4B3DADFEE1C15CFE7BAD71E75ACE154FE245EF631F645D1711292458BBAF8702
                                  SHA-512:B4F1D12FFCCE1E63EC0B0366B9C93D510B6857717F0504715CD1A888EDF69C8A15E40EAC502CFE9170C8227E2A8DCA90BAEDD767DF9E62ABBCBFCD00F3A79AF6
                                  Malicious:false
                                  Preview: ...p,kRSp&......ze.....Lty....O.!vTF....:=........<#...........)tuh....bc..SP....t^....pc..ud4/........S~..........ye..M^..^O`{^Y7=5a..R.........+%...CE........`?HA....e.......k~........Cu..........{{77>>..C...4'..TC{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.:...N....o..[V.}{.}{447}{0000550000510000530000950000950000680000970001160000970000770000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\736__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.794830317741347
                                  Encrypted:false
                                  SSDEEP:24:PlkxBm3O84tFoze4ytP6qfHSgC0fNSZBzfteJTQRoEcsUzfXF2tDFvy8Bp+JgW5T:uxBmzAd4M9/xJfAXxuwG158B0fh
                                  MD5:AA5BA946F3C8C0F4031DF3422664BF1F
                                  SHA1:8D0843C11B3291146B97A73AC3835A85D9B29444
                                  SHA-256:DC3280036B323E181FF814504707674AA4D0322A2E241DC5EAABEDED30898657
                                  SHA-512:8A491DF8AAA4D489F0B217114F514C0A7A3033CA7720CB54D846A8A1220ECC49917C1A237B5D7D9FAF8C781F85180A96505BCAAC3FC4E7E6B9F2F36B55D5BE82
                                  Malicious:false
                                  Preview: k?.....2d5"OULM......V[..16-w.....FD..mb..^]p{..b~..ML..._^O/rb.........@C.....%*6.. 3..~o......h<....5G^C..NT......S`#................(|..........U..eO....}a........CX..$..GN.\...o=!%.f->:..!s.......P^.*xY...b2.Ra............9;UD...)..H...........F_......3.c]......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.n`=.U..>..a.j..}{.}{562}{000055000051
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\737__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.695831638460996
                                  Encrypted:false
                                  SSDEEP:24:Z7eIG0h34iQOvP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQUzfXF2tDFvy8BXCLO:desh4rAd4M9/xJfAXxuo158B5fP
                                  MD5:1A5B75D2B2B4256366B9A76F6CF5DBE8
                                  SHA1:D2E2883E1A398E9C36CB9F5CBB59AD8205D9D5A5
                                  SHA-256:BB30C3D6304628736E74BBB966480A0D974080AAC70BF879E8845C9A2A931E48
                                  SHA-512:299A6F3C7A481F2120AA441C1CFDC7E5A9E4042CEE4B304EA1F4320FF34D71B8462C16B9EF7D6918DC991531ACBE7A228A1F77E8044DCB4E1A99F314A61E96CC
                                  Malicious:false
                                  Preview: .GD.3t...........17(...G..ib.......5 ...,#Y\8;GL........\[.]..i43.....$%..VU...6..?4^M.."3.......ENG@.#L..s.....rr..YR......e~..{q...'...7>.....VefLkk..iufm..ge..qjaf_UX...T.x.(?..7...UH....%.........;'..........82...t,& !V..22...Ve......&&#?..:%.Q{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{-.c`Q....w:..w..}{.}{518}{0000550000510000550000950000950000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\738__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1327
                                  Entropy (8bit):6.705816732383833
                                  Encrypted:false
                                  SSDEEP:24:sU9au36e84tFoze4ytP6qfHSgC0fNSZBzfteJTQRaGUzfXF2tDFvyv2+JgW5r:sU9auKzAd4M9/xJfAXxuR15vRf1
                                  MD5:408824C7F9791178A9A82F725AC25CAE
                                  SHA1:8DF58029ABF0DE968554B00DECEA375A6A712B2E
                                  SHA-256:A9D71204A9B6BAF17F4D92C5435289039D8217D85B00F190FD6C926030681300
                                  SHA-512:322279CAA66207A90390743083951BF5DAA8EBFDCC44311DB07520932C62893E5EF7472D4D607677A571D0323512FBAAD7E825EF0EF8413CAF345A88EC4F7967
                                  Malicious:false
                                  Preview: =cg..........35G.....pr..6:@MofXG67\....H............_luC...MO........]T=6>c...........re...?|..4!{dYW/:..$#22FFm2..........;xcn..? ..==....jmhh..\\V.../<J]3$.....58.......'...9DD....os......[[..\............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{!..k0..Dlm..I..}{.}{440}{0000550000510000560000950000950000670001010001080001080001170001080000970
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\739__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.352675573063193
                                  Encrypted:false
                                  SSDEEP:24:avkMF3vGhGT84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfAp/VBBpFUBQ+JgW5R:avkMh+hzAd4M9/xJfAXxupvBpFUBvfD
                                  MD5:D3BF813B021749D79AFA1297555C389D
                                  SHA1:B1D15AC52220AFD4BED19EE0410C19CB0A7B3321
                                  SHA-256:EA5BD21DC03393C3DF8C17974AEAFF947FAFB2AA966643DE2B1CAA6607507875
                                  SHA-512:7627B52762E764EDE953ED06C9D31E9CB9AC7A4A95BC45A2F33A8F231681F1C8C69025198580884C6F84EA53F64D03EE826CEC5A1C67CB84DBF5B26E802A11A2
                                  Malicious:false
                                  Preview: X.^.z=()......(7.....J..*!....=j?-:/57be........yf..........QL....LMFA8;0<...U:&yr,?.........LAH.N..tfz\QQ..#0.,....y(4.:.mm..QZ....TERIG@....x ..bkxk..........8>2..?.....-L39...."{.........uj|m..*..JJJJ....qbqs..........j2-K..>82=_Uz\..............~~.....W.......]J...........2fa..{w.Z..!1..}l......J_N[...T......m(\S[h..%%...U..ARbu{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\73__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.7379656920958055
                                  Encrypted:false
                                  SSDEEP:24:dLrEYDNqTsjqwAGAe84tFoze4ytP6qfHSgC0fNSZBzfteJTQRzLUzfXF2tDFvy8z:dMcQTsGHGAzAd4M9/xJfAXxuN158B5fP
                                  MD5:B14B4575540F470134F1DE8B8D284BAA
                                  SHA1:9ABA9BBEB7AE597B5332BD2FC0627DFC84BF3A97
                                  SHA-256:A66395961085F195A463D386863DDCF2F2981FAA1A4F7CE5CDC02B6DE05C7804
                                  SHA-512:6CF365305FED142C82F754B6FE268EB6DC84C0B06DB4E043A77EB841CF2DBB57CB487E76FC51CDB12D6E9A19B8D13D9E871D874792A4332F543A42661EE2513C
                                  Malicious:false
                                  Preview: ...R grs?izm........UGE.....[\U..GFT............}v..NR....:=..L]..._@MW..@G..nbTg.................]...m}.r..$.ee>"-&$7..ap...........-L....cn"r....pp.......................+..............::!!..........FA......B.#%...........,...qq....WK..RM.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{........O.i..}{.}{518}{0000550000510000950000950000670001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\740__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1250
                                  Entropy (8bit):7.381957799556954
                                  Encrypted:false
                                  SSDEEP:24:mZ8qe6SJvTeq+CzYRzWuG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRlrrBBpFUBQq:m+fJvTeq+LWu7Ad4M9/xJfAXxuW1BpFe
                                  MD5:7EFDA3B43675DEEF9C1BBB52629CAB9A
                                  SHA1:0A768D948339E6D641FD35085162E7E1A583B30D
                                  SHA-256:079F3DE011599506D437E3D39A526317E5732292C63A486F472CAD342CAB3A1B
                                  SHA-512:163143C53078ABE4720A9A134D518AA3351E38698199BF10D217E6C7992E6CE590C1F026040D357C0788660E312CD6D6A097EF86C38FEF8F2C76DF9A789A6746
                                  Malicious:false
                                  Preview: .^Z.......3)89....tf.....KL>d....><....@E..38`....M....3x.....UJ.......nb....3/.........<;&,(|..w/0Q..x^........-+0<1`.. .....FM......yb....B......{...........TkheMG.....//'<................< .t............Y.....7Q........LFf@..ULXK....YYzzzz..+g.....MEiv...~Ho................f!z,..+;..AF..EY......]H....? ....PYHJ....RRxx..o|t..............?....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\741__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1522
                                  Entropy (8bit):7.53596418484402
                                  Encrypted:false
                                  SSDEEP:24:HlLohwJEVNzTkUFAErIywCvKRNqBVO84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpZ:FM7zTGEEjKjBVjAd4M9/xJfAXxugvkBI
                                  MD5:1899EC9F12322AE9608DB8A9A8D3D811
                                  SHA1:30768BA026A1D0BF6452D58FAC2C6E0C3AEF504D
                                  SHA-256:3DB43255F560C6107ADF5D68C1DFA9DCDCD230E1DCE7DB4FAAE4AFBCE94132E0
                                  SHA-512:1F107D0F37377A0500D4208A3DE3B7E14DC8F4BAF951815252AA3A2A648702D8226C850F0F28B8883F36461FED21CF9A4EDD5FFD534DC57EF2F8509F30192959
                                  Malicious:false
                                  Preview: 5ae.....'&..j9&5....`kfjZW..}b54t?..+x.j..- ...4o........h~.T....;!VPQVxq......w([RAR..."8?".Q\~k3,. ......KF......!7..%"...........YNe.xe....bw/0Z}.'........%...fi...O[W.......................JH......J......................4'wk.......66..7$;v..S[....fg......su.......3GK?xz,......MJ..9%........#*?............))...........etcx..AKQbeO.......$;|2.....; ....:v.....3,..^...QD...IV.BDjmd!#,Pc..........7(e+...6Pqg.z,.......|#f.0I...@A-|{!5-....ZOkf..wh.."9yp..~o.........A..........WNlA....SD?&R.a...7u......PE...J.\Z..=x..S`-...,,(4?.WH...7o....qg........)0....a1...URM..............C.V.....gc...R..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\742__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1521
                                  Entropy (8bit):7.554358628187577
                                  Encrypted:false
                                  SSDEEP:24:LpyGmcWyuKTU+8poRFv9+qNKS84tFoze4ytP6qfHSgC0fNSZBzfteJTQRHGw3BBt:L5rTU+oonnSAd4M9/xJfAXxusGSBpFUe
                                  MD5:E47D24049AB16AAC4E029DFB92494446
                                  SHA1:2EC704C574B0490B3A56EF657309B6F8CBD5A8E2
                                  SHA-256:B253FA187CDA9C2FF85056B8664FD997134CF250EDAEFCB71C0B246AD76E32BE
                                  SHA-512:77240179C151E0021399AE6F14D01EE924B1EAC76CFD9ECC2FB817A2474487AD8EB03DB4DBEE30D269A06646DA7573E6F52E0199338B90739E2C4D45D9D8AB39
                                  Malicious:false
                                  Preview: K... gZ[......HI..dv].di.....O.......IN........$;...qp....rc.CKV......~y..48.(Ka....\O....ZA.....7o....kk....oD....},iZq[..RN.................^.)Myj....jk..........NZG0....J'..]L........,s..8+pg..nt:'......:.............kf..Gt.!.......wf......E ..\F....TT,:Nmnh..iF....gp@Y.E.........dq..OZ......u|...........\W......"9_X..M~V|..<<...?..)g....0S9"..Pl.../".........^K....oi...].....44..&:du......%}...W...&+..gx.d.R.!...K...........}hVI..RI....RClkxx..00...'j........_r....oxmt..v.Su.Z/;F.9,yl..B........NP_[h?.ww..yeo~1..^+'..9>%:...#&<..hjsd....YHm=...ktuu(,..WPep...........<8...oz..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\743__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1521
                                  Entropy (8bit):7.527848725838677
                                  Encrypted:false
                                  SSDEEP:24:fEc8gshfbiNvmTVGQ9J9oeYf3/TpedZXucq84tFoze4ytP6qfHSgC0fNSZBzftet:ON0vmRf9WfPTpedY4Ad4M9/xJfAXxu4u
                                  MD5:2524F71F611B599633461F368B2DAE87
                                  SHA1:87B7B54934D493F2A4C9EA76ACD0279B1393D743
                                  SHA-256:FE261D6A3E18C9299272DEA2D297929CA93C7D4900FAB1B9B355C5DBBFADD252
                                  SHA-512:B31BFB68F72F6E3D0A23300763F16F42E9F9BF4C64B657D1FF3FDEC2961B83233EAE584F3FC2FEEDF48B90BE41409AD9DF0CD23A546CC2815801D126C75E7600
                                  Malicious:false
                                  Preview: .....8.......SR......2w|q..{|.OP.vd_J.....olmfA^zf......6'z'..!>.............$......GE......MG..~wb:3RJX."++f.&5.+171=6g....CC......KI..........kbw/..s`.......W+..ZL.V.7nz....{di...l}........33/p..ar3$5"HR$9......@arWylgm...(QX............77.......F..d..pj^V_q..UCpSlj..Mb..NL........../$5cR. 5i|qx..*{............DD..........TCRE..C^.Wdc..II......^Q]U..q\......./85,..{hac'"..7:...PW.............YY.....if..c|.;..|~......|...G.........c...........(/&c...L........KZIV[.ZV...........=0................c|..,77>..........q=rat9..4<........}_.......N.......//...FDX....G.$...... ......,.13..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,.
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\744__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2346
                                  Entropy (8bit):7.697989738967392
                                  Encrypted:false
                                  SSDEEP:48:AZrM8ypeVJ7Yc/rzVCCy51qrdRYAd4M9/xJfAXxuZL/MBpFUBvfE:ZdknlwRCrLpBAXQpYh
                                  MD5:D690AD6B880DDB2B4B917476310B4A9B
                                  SHA1:F6117ED8547A3CC36C91225C88A899ED9D626081
                                  SHA-256:7298519691934601ECB111082BC8CE58FE84BC5B49B841E9A245DCF5EE9E8145
                                  SHA-512:D053F7741B9E742B37EB94D2F9F6FB79F28183E087E34DF52383527F57A32AA7E1F02323AA96277295C927DD9600DC7671F2B230981EB2653F8152F0AD50580C
                                  Malicious:false
                                  Preview: .62..........;h........+'M@GN..FGY......................k6.._FYC..%"T]^U.......V..VE.............'8........2?,............PPL.{rAR8/>)%?.3...U@ls......O\......ts.\*.....@RIVj.......33BBBBm27>........._....SL*..........5<....Y...U...vv.......Z=19a../5..cM..QGGdf`*0./#+'%%2QHX.-xjj.VU.....mj.l.Q..%'cf........\[........&!..TT..2!?4..#!rc..ho...2.1cc..';AP......R....6.Rn...kfiy....#g..^K.....z|...S\...dd....du..4z..r*I/rd..)...|l..^y..eyXI4D..du..57..cv..yl..z}..yp..8)0744..44..ve.Kyv..4+..]p..57..{bX.6].. b..7s..vc..l4.}{..p5..).7.44..4(..ezK.vz..+Y..yf..Pe..gd..bu..q)..r"^_"s..88..$=../:.../..'r.."!..&".I7s..h}..l4..ce..p5..*...44..8t..ev..l{..}`.....77.^|u..w`..~d..t7..yl..Bp..dc..7?hVfu..q=..&3C4HZ..M ..HY......77..(w..fu..re..c~..}p..4+..aD..t~[TwW..xa..e5Uf.7..))..)5..ez.vzX.6S..G]..xV..rd..f`..Gh..57..{bX.6c..:...ad..e9..}+.h}..ng..5dIO}z..4;...7KK77..&j..{h..re..c~^.....44..+g..z7..dl..He..nd..57K\xa..6%..sv..cn..4+..{`..57......44..(d...4;...\}BR:8...
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\745__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1382
                                  Entropy (8bit):6.6161835461233505
                                  Encrypted:false
                                  SSDEEP:24:gYy3Ten+Ja84tFoze4ytP6qfHSgC0fNSZBzfteJTQRm5jUzfXF2tA63yrb+JgW5m:7yDpJ/Ad4M9/xJfAXxuBi1EY6f4
                                  MD5:EC8AADFB996331FC1428AE2C9C1B747B
                                  SHA1:3740FB45FC43E8FC2FFF849013FC92BD547A81D9
                                  SHA-256:ED970CB94F11FEDA8530E0B047B922701F7B43ACA9C7133DB3FCD03785BF04C6
                                  SHA-512:93753AF371658C4E456ED1652410BC0E2FAE2A40F379862E80EFA9B90BF550B3079C969DE3361B37628D80801878B607C5C2BB9B489044BEAC7FB28338AE4F01
                                  Malicious:false
                                  Preview: ..)..B....RH....ez...6;sx..!{.@...20.....`cv}..........Y......C\`z...."!MA...:&.....l}...._U})bk..#L...cP..tt..-&....>/3(#$SY;o.. x..w~AX58.Wd!.&&...c..yj%'..WL.....NAH.M..J].........IbQxR....kk[GDO......d.70BH.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.Z.....@^.)`.b.}{.}{454}{000055000052000053000095000095000067000101000108000108000117000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\746__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.356265744805096
                                  Encrypted:false
                                  SSDEEP:24:CJMhquGFHvINa84tFoze4ytP6qfHSgC0fNSZBzfteJTQRi0csBBpFUBQ+JgW5n:aHv8Ad4M9/xJfAXxuJ0hBpFUBvfF
                                  MD5:2E311FD4B1DA9E52C1392B41BA5F802B
                                  SHA1:8012F3663ED343C10297D364B63CE9DCDDB51441
                                  SHA-256:7D2C1D7C031DC22C4381B28A30FFC1D893D1C5D75ECF1D126225A8C03074F81F
                                  SHA-512:77AC9509AF94C2B19340A93B1B585FA3284A7A1F83685B76D000FA771AF8D57D27701DF166D562A78368D8D4A86A0F9A87B698D38627A35199BA6CE335546C52
                                  Malicious:false
                                  Preview: ..30w|}.....wv.........<7:=.\.^....31..4;14tw.............[....bx......w{..>.............X_fl/{ha.....[}..[BO\....:6 q_l!.....BI..<>)8....)#`4...................NQ..tcudht..{{{{...H{rar..%2ouro...........<H][QEJ..V__F.. pIz}W....jjjv7&*5...s......&Q.ggaw^}SUqkQ~......................5*Z]+0OF......KK..hh....LN..2)z}.........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\747__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1382
                                  Entropy (8bit):6.614320642984019
                                  Encrypted:false
                                  SSDEEP:24:Q0vknY3PN9Al0P84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6lUzfXF2tA63yrb+JC:ia9REAd4M9/xJfAXxux01EY6f4
                                  MD5:88CB95AB6A9B6AA8B7B57AFBE88A461C
                                  SHA1:7191B28AFEBA04F870C3473406B10F8887AC35C9
                                  SHA-256:6ACAEE4ACE8BA085EB1D84EED102614188C1AB0E293E2C43D7FC05899E2FD708
                                  SHA-512:8D4A87DA9C95230EDC243C5263BCAFAF3AA2EC2597568D789BBB1F2B6B7B90FBE4127147A13461A9FD1A2D429095369ADF97FDF9BDC30710A41F107438623D83
                                  Malicious:false
                                  Preview: ...o#dqp.............@.....) z....<)31]ZO@..................DF[....01"%fenb|OGm.... "......:0<h/&Y.....#.*.....=6..rp...........m50Q..xa...rA....GG8$38........9>......p(d.....)...UH$-L.....KK......|o....JQLKhb[....]{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.>U.w=...(..B^}{.}{454}{000055000052000055000095000095000067000101000108000108000117000108
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\748__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.372106386378796
                                  Encrypted:false
                                  SSDEEP:24:4BXgAxSdrGv84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmZoBBpFUBQ+JgW5xs:4JgAxcrGkAd4M9/xJfAXxu3ZgBpFUBv4
                                  MD5:1708CE8392D2D3CBC45169B72CE86D87
                                  SHA1:9AA6EB0499CF6EE418AF63E9E82B91BC6983F166
                                  SHA-256:47A605715D188C1E247FEAC312C5E12BA99B53D1D8D53A532BC2C2865BC4A300
                                  SHA-512:074032D2CB433D7CF8974B9DE8667817568C3B04DBCADB5465749DF4D04033524DE17A8D5C7421717048FB45994DFF03E995482206063D500C974ED64938F0A7
                                  Malicious:false
                                  Preview: ^....rgA.......M...fx........>7yfML.4OU.-8/%.............yOfp..............y$.....DNG`s......QL c85`u..4:|`......;.NT:!.......................M@&3..EV....UTGQ...... ,...........Yj.9iiii@\sxjy-/WFto.....MBK|$.q->..HNt{.....LU....,+..uu//EE."1...4<VISDFGHoAH|^^X.......VZ..C............bwn{..........F...Gt...cc..s?....^I.......X+,......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\749__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1380
                                  Entropy (8bit):6.600879259718585
                                  Encrypted:false
                                  SSDEEP:24:O0LRnse1hT84tFoze4ytP6qfHSgC0fNSZBzfteJTQREl/VUzfXF2tA63yrb+JgWu:O0FnsXAd4M9/xJfAXxuzls1EY6fu
                                  MD5:12BD398C6F6C1D032011D07BF4A66063
                                  SHA1:C27AB3664EA89B5F8CF92F7E4B66FDA50C69342D
                                  SHA-256:FD980B24CE7EEF122A50914FFFC2624841D058BD0008997F21502A01EDBEFC5F
                                  SHA-512:4F15E0D1CD36ADBD28D03A220E60011C50E5B2B030DF571388B0285D26E4754D0272243729AE3B010EDD6FD15555220BB85CBF91E45E0BFB55F018809FF19513
                                  Malicious:false
                                  Preview: ..%._vw.Iubuo89.......Ucnw|"%.Xy.......~y<3mh..+ [D....QP...U..1l.....SR......Wd...38FU................|l..2.Lf......IZ..PARIURbh!u....8Y,%.....iZ....''@\29ve.. 1}fx....t}..........i`..Ar..wwww............qv.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......bx.Y......}{.}{451}{00005500005200005700009500009500006700010100010800010800011700010800
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\74__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1317
                                  Entropy (8bit):6.711375388061128
                                  Encrypted:false
                                  SSDEEP:24:fcxc5puIBBB084tFoze4ytP6qfHSgC0fNSZBzfteJTQRf3UzfXF2tDFvyv2+JgWR:zuIBPVAd4M9/xJfAXxu4215vRfR
                                  MD5:8DABA397DBF5F82F673D89D8BA6DF15E
                                  SHA1:B9E53CE29E793F0E55BA7CF8C8DEDAEFA2C11A10
                                  SHA-256:37E0D97310216F0EA096F9D8815D7526738F380077A91A4E66E13B92B19751AC
                                  SHA-512:9BD7789C9A8440A39808318AFB2CDAA2C10D4840A329249CC221E348A70D78D2D96AEEB70949D669952CE30A4E0CE9ECE5BD180C8389D6DB4476632E5A8EFCA8
                                  Malicious:false
                                  Preview: .JNKH.....A@..7dKX..SQ....GJ..hw......c0...$\Qih.@.H.......0..[...2+........NE.Rjm................k(....ju;5>+OS......t}....^I7-?".1<..tkOiddov..QM....IIKKS.....PG..^D...la...............FR=!....%%..::..ZS{hUB..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....k 6..G....}{.}{432}{00005500005200009500009500006700010100010800010800011700010800009700011400009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\750__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1390
                                  Entropy (8bit):6.788538004743448
                                  Encrypted:false
                                  SSDEEP:24:OyzU0vCfYI584tFoze4ytP6qfHSgC0fNSZBzfteJTQR2YXDdUzfXF2tDFvy8Bp+/:dzU+CQIqAd4M9/xJfAXxucXg158B0fH
                                  MD5:CA435D975038909D2CB45300314E5959
                                  SHA1:F2DD175B643258A4F13B74ADEC8A8113E568E646
                                  SHA-256:3589AD6CB461A5663BED6E6179711050D50DBDCF43106CE12FE4C8DC5A83AC59
                                  SHA-512:793450CF7ADD2D6682A6049C88938AA43864ACEF6A55A0FBFA31E6CB2E55969C672CDCB307058BE34C58F49DC23D57567F5A827EF52AED421BDE15AFBF32C2BB
                                  Malicious:false
                                  Preview: .X........WM10fy~a7%........9n........X]....8'KW....WP.L..a<}`|c^D..ts03...)..yeodxk....RI..]W7c...........,-)..........JA@S..4%lwY^..+....D...q`....9ssggOS..O\;9......H...6nr+........_..^K..z.....WI...._....&vn1..........jv..iz8:*;.....R.elz"..>.22d}S@......Ku..ns...I{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{z..D......2l..4d}{.}{566}{0000550000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\751__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1391
                                  Entropy (8bit):6.69295073858753
                                  Encrypted:false
                                  SSDEEP:24:MOiMkySM68+bBb84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIvNzeUzfXF2tDFvy8W:EMkySg+1gAd4M9/xJfAXxuBvH158B5fy
                                  MD5:D25C95D03C486C6FC20A7D92B3559C02
                                  SHA1:571B46A24EE6CFD712F6CA2A0FA70C924860AC64
                                  SHA-256:39F79A56121E95CD41FB275B0DF57B9C5825B162190FBAB01677781B4BB436E0
                                  SHA-512:62DD480921C5192907657E3020CE857A2FB27436E2F35608A419CD5D4682B5B846C7037E550BB6452F58659AC5BDA0BF7AA5F79A09E88FFEE73B6A2B48881091
                                  Malicious:false
                                  Preview: .../,...........HRA........AL.................45..............YCAG^Y.....\}zaa.q&/`s..`w]Gqlu6..|i...RG.........V.....k|.....A....... ..0)..VJURTT((::.r{...............4+9./...)...OH....af''LLyy.....s`..,;XB"?..r.[N..........SO..''..\\WW''.Y>-!l..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{~./$vF.7.|.....4}{.}{520}{000055000053000049000095000095000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\752__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1323
                                  Entropy (8bit):6.678374751464069
                                  Encrypted:false
                                  SSDEEP:24:T4SytGZr7L84tFoze4ytP6qfHSgC0fNSZBzfteJTQRSUzfXF2tDFvyv2+JgW5f:T4SytGZrMAd4M9/xJfAXxue15vRfR
                                  MD5:54D0C4AF693CB48645372765D0D58728
                                  SHA1:50109DB66ED1B6AA17A9AB48D3660DD89E4187A1
                                  SHA-256:5CE28465B3FEA5AE2854AA11B6D2FDF4527A63ABB8FAF8D79D41F23CCDBF40DD
                                  SHA-512:4BAA3B95F5200A2948DBFA6600BC96505F795EF3D4D6F29CA7B9D73932F704265054D84DF4157477FC4136C9BB35018EB4453708268FABCEB131A39AF9FCA457
                                  Malicious:false
                                  Preview: 8AE^]....):#"..,.....K@481<LE....w<5/4gu`.......p+se..YjPf...9;?&..........{&;<DD....M^..UB......;6..C\.....ho......?6......}g..<....#<..wwF_6%';LKoo.........sd=*..TI.jgqd..+......7DD..../3..TT....\\=b:3.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....... ...V4..}{.}{432}{00005500005300005000009500009500006700010100010800010800011700010800009700011
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\753__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1511
                                  Entropy (8bit):7.475819709583938
                                  Encrypted:false
                                  SSDEEP:24:F3+f/mF2AAeaXCgh4Cnq3Ra2VBVIEhHM984tFoze4ytP6qfHSgC0fNSZBzfteJTT:FOXmF2yaXCX73I2V9dMuAd4M9/xJfAXc
                                  MD5:BF0A5D5AF376A1B4E9D16F9EED9F374A
                                  SHA1:C8866D13EF5A408A90D6A56FD068DD68C682EFCB
                                  SHA-256:4A8A7CE2DD4168D289FFC902E7D16BD1C782B7E3BA41366CE164893068784CB4
                                  SHA-512:95A8F80C1037C493466E77163466428ED26A9188CDCC5203D9368E9D0A99EA5FEC9B871D370691611070ED6BD8DA346B3CAA00C8D5A44B13A61D4E25B65F4829
                                  Malicious:false
                                  Preview: .W.i...v ..]G......i{._7:U^....M.........P_fc..lg../3.Mihbe.Y...^../0IS67ST....Qb....RY..PRvg..qv..v"..3kM,cq..BB..8+.T-+S_.M..eO....RY..PRvg..qv..v"..3kM\....OB...0..q.ew9&../8....<;...."".jc..5"..?%..M...^K...<Li)<YS..........C...;.""..""..&7..v8..K..~|..7?U{::_I.?............]Dg?.pg."tO.7"..W^...]..07].yv.7eO..OO....YP..REgp..vk..[\OOvvOO.^..C...4<...5M[....MO....T.....fc......tk..\G..KI......jj...W.....ZE....ki............|=..B@..IK......Z_................n.....MMVV..........JU......><....9a7\......4!..PY.. q....!d..rAnD..............O.9>HW....uoSP/-..y`.vJ[...._............./SMG...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\754__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1515
                                  Entropy (8bit):7.527478084467052
                                  Encrypted:false
                                  SSDEEP:24:VY77JhgwCGqJ0FdMrP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRUpBBpFUBQ+JgW2:C7ViPGM0FCrEAd4M9/xJfAXxufBpFUB2
                                  MD5:26D2B3B06CCD1CE408208EDA04B43642
                                  SHA1:8C3994BC8128E8FCD526E6A3C3D05341C1390A97
                                  SHA-256:1565363D8134A9DB82E91DBA10A07BF5BBAAC25EFE31DF18219545913E0DBF35
                                  SHA-512:3EED35C2811CE0C2B27F92FD7C0924D5E15889C1A5F2220BBAA0374C4188FFA57343AC196FA430312B10780BA044E15B762F8A2B6924AA8A07A65181B841E980
                                  Malicious:false
                                  Preview: .D.........fg..hw..+nV[)"...E...4!..!&78y|X[%.....>o..%".J....A\....{z.......@j..yrwd..5$....* .E:3...e..eC....PC....y(.......K@....yh..../%v"...V....LO..91Sn...{M....IV..;,......RR&&.....................Lm8.xm..[T........7...yy..++..6'..X.....;^....80r\WW.8....#9eJEM......V.....uw........=/..sn46..5 ....~aBE1*......+,LL..........ki.........%..UU--FZ..4+v8...V....ya?.w;:l...........~k...F......P&)...........C......DR..n8id..>!.....5U..h}..AH..)x......XW..Oe99......op.Uiet,L'#'....K.........Y.`b...............<-lk..++...K..j'..:2HW..zx4(..,1..6g.J..K[..,zjj..N.........z!S......;ly,....F...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\755__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1516
                                  Entropy (8bit):7.520433943013637
                                  Encrypted:false
                                  SSDEEP:24:y+3H273I4xTXgIWc3lJ7My1ObjQZEFRG84tFoze4ytP6qfHSgC0fNSZBzfteJTQy:pEtXqc5gsZqR7Ad4M9/xJfAXxu58BpFu
                                  MD5:B2043341391ED11528FA44D3C17D3C89
                                  SHA1:F54570632F0C2204661FFE4048C90407BCB1662A
                                  SHA-256:F15A4519195A6B1F2ACE55F20F67727C31644BB34D97BAF913D2F158C534559E
                                  SHA-512:20C4ED47C30F2D8E6C6BF9ADB45A74FB1FFC08C15D662A88243AFBD44BDB6B33C7BAAC0AA034662113A2AF931F2008D5D3B07EDCFCB15DD565FBA497A8E32EAC
                                  Malicious:false
                                  Preview: ...BA...fu..db.....fdW\...........nt.7"....'&.......Yj......Y@..db....ZQ.]Z...]T......RO3p....B]]Sa}AH8!......by........i6ZS..........58..~a2...;).....DW....aW....i{`.I$......pp.....V......OU$9.....#<..Rw$1......u|......6......JJ..........&~...5/..'.....|_Y_..........ZC./`....SR..1r.W..TA...-|..OH7r....u_>>dd..{7......ub..yd.61..dd..V...........:..:0).ZX>)................EB..cj....34..pp...TG........bC#3......{#.SKF=8......0t......^...!'[\.H........a}..1.F...-u.....S.?i.........A..)+e`....K^_@ts'<....}laf//..ggu9.......RMHmb`......RW.............#?......].`,.......G.....TVSV..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e."
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\756__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1247
                                  Entropy (8bit):7.369959332898931
                                  Encrypted:false
                                  SSDEEP:24:wUHTyb4AUR84tFoze4ytP6qfHSgC0fNSZBzfteJTQRgcsBBpFUBQ+JgW5I:wi84BiAd4M9/xJfAXxuzhBpFUBvfS
                                  MD5:6F641FC81C96A9D13CCFC86BB1A5F830
                                  SHA1:A026DB945627F55473BE82A3DD5BA1185559208B
                                  SHA-256:0F646DE1FC4B84ECE8F1E7C78F323003500ED31ADD34C08AFC9A35AAA01A4CA7
                                  SHA-512:B5AD19F68BA769C94A61B71508106E4C37E93F0CD136D4EFFB98E1AB94C59E06638182660A494C6F931EA8464D34A8006F9E6084527F237A630976102249CFAD
                                  Malicious:false
                                  Preview: ...+(.......+-...hv{y....XU7>.........."/yx....UH..i_..~#..RK.."$g`.....dc.....&5...........vc..BLA]OF*3:7_h....,:..AF.....*#..[L%2......nc$1....[TJXrc......(6...f\.IE..AZ........1....((......TV.......c7..+s.UF..EC......WWrkH[VJ..uuaa..vv}1->].UZDL.......&..........0.vz.......|c..en^W|yfs..............`i02......EE..ve..XK$&....6<..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\757__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:PGP\011Secret Key -
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.394304645815117
                                  Encrypted:false
                                  SSDEEP:24:Gj7jLBdv9U3SIz4c84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKDBBpFUBQ+JgW5Cp:2jLBLUihdAd4M9/xJfAXxuldBpFUBvfo
                                  MD5:45916AFB4FE2889B0940A07B3FF01301
                                  SHA1:91D75B9434923D28D381645C970062A702D608EA
                                  SHA-256:F5D7ADD25031A9266BE9142C6A776B1D9B7E8372E3FC82F403F1F23700BD8FD1
                                  SHA-512:90A0ADDA74BE1AA8334B2EB02A8DCE0EAF3E16DAA7BE58C0015A01B2DFE965C7AC781F6A048C7EBAFF3A2F1B88F7986B1A3AB93402634547B08DDDB02B9A4CBE
                                  Malicious:false
                                  Preview: .nj........*+....(;........M@,%..;:.Cf|......xu..d<q*....cP.)FP.JH..?%}{....*!.A....A.......DSE_ql....sl..^B.v:#yt......pf..ho33!!Z.3:....|k..lq.F..........YH......Ma......\Z...........>()[.'.+nn..C_RYRA......ST_U...&~....Uv..]R..........b~.........?s\O*g....TK......ZS^|......y~.................n{,9.....[..WP.....dN..........#4YN.....^Y00{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\758__DataMarketplace_PerSimSettings_$(__ICCID)_DataMarketplaceRoamingUIEnabled.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1491
                                  Entropy (8bit):6.379400646222602
                                  Encrypted:false
                                  SSDEEP:24:UcMCDCOYAsrVG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRY/Vy1HJz2PXF2t1HJzh:zMCDDlotAd4M9/xJfAXxuFdp1qSwdfbp
                                  MD5:D64B548ADAC9A5EFE38280236AD5D2E5
                                  SHA1:118EEA1E08A6D5AD923072A4E899D62261FC3113
                                  SHA-256:6DF621FEC01FF6E42C3F0920012B02E09863D12E044B2BEE17CF2AA41C0CF867
                                  SHA-512:EC4DE67CECA0F3AE19916D13BB8E412E092ADD4E5BC0B3EE9314997B2FF2BF3A3E8DBA2D69CD26228565064C5535C047B2069BDAE7B770CC53BB1170CA058AAC
                                  Malicious:false
                                  Preview: '..9:....N]...q"..B\LN..................."/..@..E......Gq...^=?QH................'M^..W@'=KVa"....(7FH....WP}}ww...VE....ou...heH]7(Il....sb....U..............1 2)EBFL.....@U'l{....du....[.#...44CC........0!!:....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{x..z.._.?.C...}{.}{456}{00005500005300005600009500009500006800009700011600009700007700009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\759__DataMarketplace_PerSimSettings_$(__ICCID)_SupportDataMarketplace.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1432
                                  Entropy (8bit):6.502262143582317
                                  Encrypted:false
                                  SSDEEP:24:OBMInRQ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsj/V1HJz2PXF2Qv/HJz2z+Jgh:OtnRBAd4M9/xJfAXxujw15dfU
                                  MD5:7F6AEEAB9E94323CE911C8BFFEB00C1F
                                  SHA1:6A73CB8F2AD335FD91003531A9A4A69FE6729B6E
                                  SHA-256:4FF780511E60265A7B5AA2B9E381B790868E975845D720CD18BCC5653E1753C6
                                  SHA-512:756F46B2C3FEEA5E14837135B60B08C9430A94EDA4B0175ED73C430F92EA57EEF0D14CAAAF6C5316A4B74E67BE7768CB89EEF1DDDAFF523606D30B2A06B44FD7
                                  Malicious:false
                                  Preview: ._......Z.._ECBIV..DVT...HC...Y.D........&)............z{..y2$5.B..D[A[..ho.....9....W\..ln....URKA.R_V..u......ii..........!:....s'..R.............S^$"..25......[.dm........#`Q\................................jy]J..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{{{%..L..K..i..}{.}{447}{0000550000530000570000950000950000680000970001160000970000770000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\75__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1236
                                  Entropy (8bit):7.376390337521631
                                  Encrypted:false
                                  SSDEEP:24:0NGd4DTWSmAkWGLQXV9OA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmTABBpFUBQi:0wKEBtkXV9IAd4M9/xJfAXxuFToBpFUp
                                  MD5:F98DEDE5A93FEB7753D01FABCDB89BB1
                                  SHA1:893392D2097584788A9099128D76E0229BCB8DB9
                                  SHA-256:5B7F4AEAD1207D5F3E0BFBEEFC61EC31574A8151BE48F65156C48613948E4D88
                                  SHA-512:6EB0A6FC128FBDC4009CD02FB021F5C7472762CE2A150FD65973862C816058F187DBCFE7F0066A2F566463C6A89DD9A677314E72C11939B40D9F0303758693B6
                                  Malicious:false
                                  Preview: ..+ g...I^...~OP..);=xboLG.....(....NL....DA8;......Y......O....9$....kj....GK.<Nd..=6..57..kp..sy...w/*K.......9*.2ce@L../.oEff....QBfd+:..Y^.$.....Oe......o..e`......_...^^]F.......+.>.....nrsxzi......?5....d<....pS..:5....--..`sqm34....AA..%6_.........]\.. )..tr......<......jg5%....XS*|B.(=.....>o& ....KD*.@j..**...\..evK\0'a{...X&!{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\760__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1240
                                  Entropy (8bit):7.369529160116341
                                  Encrypted:false
                                  SSDEEP:24:D0r0UIfzondNjH84tFoze4ytP6qfHSgC0fNSZBzfteJTQRP7BBpFUBQ+JgW5n:hfzsNjcAd4M9/xJfAXxu8FBpFUBvfF
                                  MD5:46EBCBFED453A9B7B10A5F694D420E00
                                  SHA1:455BFBDE934137F352EB6CE99D888948C75224AA
                                  SHA-256:218782EC1DE93083BBE1D1B0F41A83F15DCDF1798A8F8F17F81AAAA4DD8608D2
                                  SHA-512:7A45583B22873CDC66FF203A2CF59792041C69BF4EEB7AC87C54FFD3655CA2A4765AA71C0D348E969932BF2CFCF552014FABB3741DAFC935031720A3067998EB
                                  Malicious:false
                                  Preview: ...m.lmy/<+..SR.......V........^_M..<>......LO.........Y......RM..QPWPWTq}...............MJW]{/..<d{....................;;;....EVEGdu.......F..H..n...e."#.......evn.....\\..FK&O..7EcPW}**mm..4'..-<+0VQ........bH[~]..KDSYy_.........ee....__..VEZ.MB..yf..`a.3ngIk.....352]gma&ac5r........TV>;.;R_~k..pkFO..&752GG''....%.}n...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\761__CellCore_PerIMSI_$(__IMSI)_SMS.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):7.003438498378233
                                  Encrypted:false
                                  SSDEEP:24:fdVTunp8k1giM+84tFoze4ytP6qfHSgC0fNSZBzfteJTQRNzIc4vPXj+JgW54:fzO1aAd4M9/xJfAXxuhRnifm
                                  MD5:D8F91AFF5C291E0A53BC0EEC9D1560C5
                                  SHA1:5DB7E3801C48B93ECA40863603A23649B455C5CB
                                  SHA-256:15D75054BD6EF7670BEEE81A8E829A2F0A417A6A51DD74D50A9BBB927EA0B307
                                  SHA-512:C576876F500C6FC8F38FE51F1A5DBED5E0E1EFB11473C88FC791BAA62E8DDEA35F736A7DB698F10F753F9326F5E1F0DD4CE4399FA038691ACE61A3E260B91FF2
                                  Malicious:false
                                  Preview: .M.3a&../yfq....>!.1....q|_T[\t..Eo}k~..ho.................j!#2....3,]G..<;12..kX.$....ev........gm.V(!k3.......#.....JA........34...90./NOF..B_.8..'...55DX............eo.....D69...........aa...............*i....a~.........(.-.LL...WW..en..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{... ........)..}{.}{498}{00005500005400004900009500009500006700010100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\762__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.765981145567503
                                  Encrypted:false
                                  SSDEEP:24:0cPAQHWZ82YGtBhd84tFoze4ytP6qfHSgC0fNSZBzfteJTQR7iUzfXF2tDFvy8BC:0cBFGtBhOAd4M9/xJfAXxuwN158B0fF
                                  MD5:28811DEBF99B668F5F65F88E781CA32B
                                  SHA1:DDDAA7E50344D8342BCF9ECC04C6520A6E2CAD00
                                  SHA-256:11DE2B5DCA3609853CB8DCAA02828F007FA48EB66E8A9A972F5C9B5A6512948A
                                  SHA-512:9495BAF1E104F7082721257B2500184FAE6839FB69448131618A81038674E8C922FB2B3EC3FB9012D25BDB9A1C5F336DCD75C5BFB2827F8F41A6D2D653858024
                                  Malicious:false
                                  Preview: {/r.e"..E...9#gf../0.."g...AF..ypb(=64wp....MNW\@_...S10...TRC.......ih.........*............kl..1e...^Y+....='..af.R..?.....XK........H.^W.........iZZppp..b~......et......9a9`.........X\sfD...'h..vh........~.\.zIu_......^B...y{......:0..<5.....7__.....sl{Rh..n.?"..W...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.T.K.{v..1bx.`..}{.}{570}{00005500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\763__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.713395093759894
                                  Encrypted:false
                                  SSDEEP:24:Kx3ugZVkrd84tFoze4ytP6qfHSgC0fNSZBzfteJTQRkxUzfXF2tDFvy8BXCL+Jgk:e+ZrOAd4M9/xJfAXxu7g158B5ft
                                  MD5:74860A027223F04637771075C96A6FC7
                                  SHA1:062E1E81B9CB096D868D51B55CF809450418FF0D
                                  SHA-256:B142D14734AC1E2308054D81A12B36635A1E2A9F914F4FF3CCAEDEB0336DA73B
                                  SHA-512:142F19EE756260CB03ABAA7947577AE712638398E7E6D5E5A99530B0108400DBA9F012EB2FCCE63FF235DF65B26D3F62A4DBB0B049936F9600164C32BD3BC0CC
                                  Malicious:false
                                  Preview: ..V..23}+%2....A^..HZ....,'..F...^L|i.....HM..1:..........O...G...'84.........[h*...k`......\Gjm..............Ys..5)..@S.........Q..y!..w~..:7........**^Bod....~oNU......<d...D~..............<<..}}..........D_....h<_V..e...^^..k`..Oe......??b~.....L2>{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.u6.{&.N.|.....}{.}{522}{00005500005400005100009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\764__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1350
                                  Entropy (8bit):7.4251933450401895
                                  Encrypted:false
                                  SSDEEP:24:GNDz8lYGoRifuAB/b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcS00BBpFUBQ+JgG:sDzAFaimAiAd4M9/xJfAXxup5cBpFUB3
                                  MD5:BF43C74FEDBA05428CDDDC621566DF24
                                  SHA1:B81992D845D5BC89D1270EF811924B8FA2289D1D
                                  SHA-256:DD078441C5F0C21CA35C517D0037E14C2E27B4CFC704E695AFD87324E0CA4BC7
                                  SHA-512:41D9B5E38757114B5186D7245DBA519114E8A26D0F996525481352D6EED45C9ADF5F1371A67A03E85E5E2607F2B2244D543B0742910DBBD90A903783A284DA5C
                                  Malicious:false
                                  Preview: .\..x?./..DS..JK..A^.......FA...as;.....('..........A.@A.......[F~af|BC#$.......?#SX..;9....?8_U9mu|..z.....}}....eNIO..,}.%..HH..;0....CR..oh..Q...?g..J|..`+..,=je..)%..*1nc..^HH:*........%..........39.....o.......('BHcE....../3.................YN..Ho.....FF..BE..3?..&p..)94+1:.K..#~.......]j.......W..........Tg................)3!<].jm......7{.......)6]p....Sr....=$..........+&....,+...'*(..OH..??......r?..H@...$..iD..|~..#:K...+Y{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >..
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\765__CellCore_PerIMSI_$(__IMSI)_SMS.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1254
                                  Entropy (8bit):6.99406744294842
                                  Encrypted:false
                                  SSDEEP:24:coCt8DUPUfqN84tFoze4ytP6qfHSgC0fNSZBzfteJTQR9rIz4vPXj+JgW54:cBt8NAd4M9/xJfAXxumcUnifm
                                  MD5:4ECF01DD34EBB9BBEA7B64D48179EC71
                                  SHA1:D2D2B6C788FF021B8527CF93D91A6AFEE53193DC
                                  SHA-256:A3B991A05D0BF410638D76278A593F8B7FF8DA0BB91917E87B3AD7F57461487E
                                  SHA-512:757DA0226F2E929AAB8F458C4AA4C717CA2FD881970517AF05A2D285AE1ED5533C022B4C642AB8A44B5F13FD6A87D2E9552FED1D38828720C615363D09E50229
                                  Malicious:false
                                  Preview: O.J.}:.........&9.....eh83ni........75........AJZE...P..16.O^].>#&9..sr......tG3......'%............c;R=...n(...VV........5$....../{py.......gzB.Xk^t,,99..v}......pk..ZP.XQj2.`....9#....??!!BBPP..HA{h..avXB...ID..gx..ff..XB..0.......TT..xd..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{B.7..9.E.%]....}{.}{498}{00005500005400005300009500009500006700010100
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\766__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.793813526584309
                                  Encrypted:false
                                  SSDEEP:24:WPedGK0kU6TvO984tFoze4ytP6qfHSgC0fNSZBzfteJTQRjcEcsUzfXF2tDFvy8M:WPqwSAd4M9/xJfAXxu6cEG158B0fF
                                  MD5:7B7C55F611D73BB81400356585B1DF31
                                  SHA1:22CF3398D070FBFD56FFA7C47723CA0CFC146E0A
                                  SHA-256:A3A290C9DD05037D2991EF5C1923CD9CBE4DFFA9D06B5010A3E60DB881127904
                                  SHA-512:66DD7CCC70101C6F82915C5FB3FA8AC022373F6CB4146B60ABDE63530C1C73BF7F63B854A323FF0648D2DC56033B1C0D4F62E4FC953167D6EBF34894F968D411
                                  Malicious:false
                                  Preview: ...W.CB........MR.....m`....^X.............<7........DC.@}l`=....+1UT......./....S@..4%..g`...W^.......GFX_..Zi....[Gaj....~o......u!JC.....PA..<...>>..TH;0H[..ud)2....c7........Z.....min{'u........DJx,p"Y...W.T........../3XS....!0......Z...m5......5,..P/..tN%.6'..SZ&z..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.3...u....$..}{.}{570}{00005500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\767__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1392
                                  Entropy (8bit):6.715107518756425
                                  Encrypted:false
                                  SSDEEP:24:Lljitb4vn84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMx1UzfXF2tDFvy8BXCL+Jgk:F6UkAd4M9/xJfAXxuHE158B5ft
                                  MD5:6EF2F4B163E8B494DAC938F885DA8BED
                                  SHA1:7B05BF518FF5060FAF021E26DFEE8834B57281F3
                                  SHA-256:0FF64B9AFCC1EAFA9F348DE4B4B5B1A8D95672FAC805786FE02105B5773C5FA3
                                  SHA-512:B9AD1EC69D2C56D0101A3B27E006D12933799D72A2854DE7332C0EC509A5C9A9A3CAAA788CFDA6C4DCBAF5C4F88F6D08ABC9AC4A0B4C4ED7830A9BE10DDA071B
                                  Malicious:false
                                  Preview: #w..R......[A......yk6s...._X.Bw ..at..ts..E@BAk`..YE.. !FA....V..iv.... '.....'....CH..=?....NI......@..%5m..,u_...2ne......cx.....fo.v!@ha......S`......yr....}lD_x....X....e..8..........O. .4..##..~b..{h....ST..............;;....vE....66......Q@"=.E..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..........7RF+c}{.}{522}{00005500005400005500009500009500
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\768__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1341
                                  Entropy (8bit):7.42807991871955
                                  Encrypted:false
                                  SSDEEP:24:NhtdRtorMS+Bjwkrq84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMf4BBpFUBQ+JgWk:NzGrGPAd4M9/xJfAXxuNwBpFUBvfk
                                  MD5:F1102AB87A11E0C9459DEEDAAA7AC592
                                  SHA1:279D492C6BF9B3256E831D52CA14DCDDDA1CC9A8
                                  SHA-256:04BC95EDB25E36C2B1B5E2863CF19570C20EB5833CDA21C322F63F23AD1EB182
                                  SHA-512:4BA18AF246B9BBFB7BA21B189AAC776976FC4FDB319F6793121389E91E746826FC194FA0F9F572B0246C58E24A8339865E20E8F141B3853C3608EFA917543504
                                  Malicious:false
                                  Preview: <........jy/...............YT..ze....,6j9I\.....~...qg.......Z... 9UO..Y^..P[R.G@ZZ.A.......pj^C`#......ig..18.....6='to8...{|UU**....UF....7-RO:y..|i...-...:CF.......[wA....dv...`|k.....zz..........pg............tU..mx........MT..a1.5....YY[[......l"{w.Dw...9#..".....Ba.._E............W]D.R..nlNKU@......61{`....?.....KK..............)..Ev..FF@@..APwh.N...P~...X@_c.....$4.....V.....L.T.}{..@.bm...ss..........%}..........\..td.....?Y[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|....
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\769__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1384
                                  Entropy (8bit):6.617232881859114
                                  Encrypted:false
                                  SSDEEP:24:oO/SKEN+0jU0KxJ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRV1/VUzfXF2tA63yrT:oSSKEN+Oa6Ad4M9/xJfAXxuC1s1EY6fi
                                  MD5:A39FA64E85B324218BDD2FDCB62AD70E
                                  SHA1:679B3C310F5FA5397E8FB54C1D03304A794990DF
                                  SHA-256:E181D942B132E8727414CE171B40B68EB8D584D6FBF260A1DE36FB712E194CAF
                                  SHA-512:77172FD3F9358941A80EC7C29DC1CD824A2E03E4A2D61E6743594EE7F2885A9A1D766AE39D273B7B6589F08A91C8F9ECBD85B0D199AFB6FB7AD0EBC38C929919
                                  Malicious:false
                                  Preview: .B.=.kjI............d!....KL......fdbe..gb....ls/3..,-.....D.}`..>$32..BN..nD....6%........PZ...G.O .....``......ca........W..s........Ak......K@.=~|..RIDC...cj...i..........?6............DOKX><rc..VQ......L...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.:.>3.7..5[....}{.}{458}{0000550000540000570000950000950000670001010001080001080001170001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\76__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1773
                                  Entropy (8bit):7.603513390404995
                                  Encrypted:false
                                  SSDEEP:48:IUR8QsWy0zNWFZc0Ad4M9/xJfAXxuf73hBpFUBvft:IU6LT0JwZapBAXQrTs
                                  MD5:39EED2E47297F2EE9C3A8EC004D62443
                                  SHA1:C1C10E3446DCFB585E880D1CBA9657C59C4F3154
                                  SHA-256:C31837898A13C824F7D64D2417AB5606122C86ECF115A8BB327847639338A46C
                                  SHA-512:AEA20455CCA5E3171856AFCFE35CD7B12AE4A0EB1FF74B1C8BD9E1BACF2FB7951321CA6C5253C8AE309390FD1A355CE87B27F1D5EC3752CAA9E042F82CD28823
                                  Malicious:false
                                  Preview: e1.DS....6!.efg..MR...M....oho5}*..bw........56w|.......?8S.+:.....CY..34KH......(4..%6..^O....$...v...vd.9..CZ..K`.."....q[....=6........]Z.$j>4="z\=BC.........08.....Tb...i......1&O^......dd...fo....CT..4)B......`..;.:0an.3.'9 ..g7Ar........)5..}b..IE...c..[A...%..J\....5/.8u}..:-..q){:../>..il6#DI..IV8?..]T......##........s`..rcza..@JbQ.......2..hw.[..p(.9"?'".........m)/:..I@....(...MNA..}W..;;....!>.C...N,JCUo...%(SC..@.9q[}.|...ikjoyl6;...mj+0XQ}.}lX_........2!...dlA^...>XM57....m5..Su...K..fs..<d........CpxRjj..1-*;B].nb......................Z..c3YX.="mm..8!..6#*z............okl(......le..C.9?.......`Jjj:&@........TN..N.^Y>>...fo?,....-78%.W....POyR..!`....0</b.t..2=p..A......\Q....Bq....))....IK}l..lkak.094l.k......0?....gg....HT...ggTTRRJ.TG/b>1...)>./..qxy[.....)...+XT.DM...wgIV..U.....N[CJ...]....H.}rdW...........GT.. 7..pm..in..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\770__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1253
                                  Entropy (8bit):7.373550751569907
                                  Encrypted:false
                                  SSDEEP:24:bsrNxKHCJd754m3G7Tcp12Fo84tFoze4ytP6qfHSgC0fNSZBzfteJTQRubPBBpFJ:iTJd7555p12PAd4M9/xJfAXxuLBpFUBs
                                  MD5:AF0CFA8FEA3D60A7318192B88922AA12
                                  SHA1:2D96DF03D6F6AF2C5F6918A58D528C0B805D1CAE
                                  SHA-256:47E707E0906C6B324735C47982D0F685602E228E397D4F5008A659978562E729
                                  SHA-512:9025913AEB00D41D114C40B1797CB969EB90EF8C2AE7D6A7DF33C8937CA0F39072D6AF658EF146237693850407C43F60F5E5D449E56EC866427C619A895008A8
                                  Malicious:false
                                  Preview: H..AB.._.......U...E[............ED0{...n{.........G..........`b...24..7>.. }....n1/&EV...z`.."a/"n{....W^4-..h_yc......mm...\............A...-8..Ml..- .2....LM..}3....mz.......8....*Y....N...QE>I.......=,{g34..II44V."+....$3RHQL.M@3&......zo..gh.+3:ul..........xxnrFW...GK....$>ck}S....rQ......px......vW......CX.........H...wp.....zP....=!V...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D097
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\771__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.37837751936912
                                  Encrypted:false
                                  SSDEEP:24:30cYpJK40WHmOx84tFoze4ytP6qfHSgC0fNSZBzfteJTQRmteIBBpFUBQ+JgW5b:EcYpJKkHmOCAd4M9/xJfAXxuN0ABpFUb
                                  MD5:318E8C82C8B642B131EAF73191B114A5
                                  SHA1:7B8A043E4BEFA36954A93906C95FA095EBFBDA26
                                  SHA-256:7CD77D0146512D524DDE698031BDC6560BD1693C3D4CE55A2642067EC60809FE
                                  SHA-512:C6935F1A608B6E001FBD134820A6CF4A3729F70F81B573DDA81125D9080A4B1124A1CE92BBFFDC6919446FF0E14CB2A8D82215A93289C9F4CAF3C175C6E00B2F
                                  Malicious:false
                                  Preview: ..&.lm[.........M_........7m...6#..%"`o.... +RMZF......._o~.........21..Pc........WU..8#....7ccj..n...@fggMT.. .Z\..K.S`j@BBui..;(..yb....>j3:.v$U..xGr{H@Xz............AZ.....3AqB............ZXcrd.....O.....o|.)#%ghFL.)....>-..........ll..WD.!.....+<VW.........}Bho.'ie.L.Wxu..&2I....DX@e(.D.\.........PV.....L.........GN..rect.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\772__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.600856382396464
                                  Encrypted:false
                                  SSDEEP:24:kzBcwCyro8f84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0WYZUzfXF2tA63yrb+Jgr:UBc4rcAd4M9/xJfAXxuRWY41EY6f2
                                  MD5:8CFBE06BF40DC737342D310ED8B59B93
                                  SHA1:5C07D1E1F17F0EE55A625A3D170308EC1ACB2843
                                  SHA-256:5E28024A2CF1489F27168A9899F478F20B7533DCA45CEE9AFD7C4FC851491E41
                                  SHA-512:7C6FEA5D9ED5244F7DFCC1B76E1F19CF1BDFD2432E937245688BE03A8020456254733A287277F80F9291941E72AD7B01C35F6A0E5DD9669932548E219C398784
                                  Malicious:false
                                  Preview: ...Q.jk*|....UT.......?2..............MB.....'86*C.........SN.........NBl_.$..OD;(JHbs|g43..q%~w.../?<X........T_....IX..AF...S2;....W^..HEG....!&&..pl....}.......HB.S...1C..oU.0......=l5.'.....II....ACWF[@.x....3:..oi....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.z.'..........}{.}{467}{000055000055000050000095000095000067000101000108000108000117
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\773__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.359946056761343
                                  Encrypted:false
                                  SSDEEP:24:tyTBZbPNla45tp8TNBP84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6tBBpFUBQ+Jgo:tsZe45tp06Ad4M9/xJfAXxuFvBpFUBvR
                                  MD5:76FB9D5CF25B0A462540148803E3DEE1
                                  SHA1:28C19C8231A2EE72016E06413E8E5970C22866DC
                                  SHA-256:6F38FF2C18E4C0200B765B1A5C3193AB1AFC6012CA9CDE7DE674A8150BA63F60
                                  SHA-512:C3DDC0D2E1CD29E0341A9377EBB36409698B83198E06F32CC3D8F6B87A5E5827890C8311736F60F5F6FEADAAC1D96A40CED047A25AB281373524D03B2B6EC347
                                  Malicious:false
                                  Preview: ...i.^..K.8/........QC...fm.xs)y...YL..07kdcf..JA+41-%t#"... 1.......KJ' LO=1,....................sz..4U...........ecr~R..9........9*..m|..EB..K...S.T1^P...f.....`s..[_.......ZZ6-...k...Gt..ee..RN=6..kisbsh..82..+"..:\..mN...j`..II......<;HH..WWPPs?..e(..GOEZ[LIH.....]53...@;<...........HWBL(<....IL.."/..........jh....88......83............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\774__DataMarketplace_PerSimSettings_$(__ICCID)_DataMarketplaceRoamingUIEnabled.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1491
                                  Entropy (8bit):6.373902632467738
                                  Encrypted:false
                                  SSDEEP:24:xZT7btG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRu3/V+31HJz2PXF2t1HJz2ASw3:xH7Ad4M9/xJfAXxuvd+W1qSwdfbp
                                  MD5:3C92792C44C800A001F0183D9C450CEA
                                  SHA1:6B797478817DBB647828A41BC989B02E267BF66F
                                  SHA-256:4F34D6E96EA4C2A127A244D5EFA9F794F9F3D996D6581535DEFDB1DD4B78131E
                                  SHA-512:40AEDA5D0AF1680FD6345F01B6EB71883C50077E33D2A1685A108AE69079DD78AB5650A3A1887E3FA036ADFBD10BF31A06F80345E888F3226CDDAF800EB358CC
                                  Malicious:false
                                  Preview: ...+(....,?0135*yraRLjh..zv..`irm..m&..C............YOKV....esD...1(..........#~AF...U..{h....rh...<1ZO......';.x....${XQUF...........^A(.......ap..ge......ll$$ZFT_.....xc..* ....A..BUZ`....3:..Ev.....KK..........+0#$KA{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..)].<...w3.KZ.}{.}{456}{00005500005500005200009500009500006800009700011600009700007700009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\775__DataMarketplace_PerSimSettings_$(__ICCID)_SupportDataMarketplace.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1432
                                  Entropy (8bit):6.4863069717720965
                                  Encrypted:false
                                  SSDEEP:24:gLfw+K9g+4C84tFoze4ytP6qfHSgC0fNSZBzfteJTQRCxPlv1HJz2PXF2Qv/HJzI:gRK9OAd4M9/xJfAXxuJ815dfU
                                  MD5:A4EBC4CACD9ACEF14737D209E367E978
                                  SHA1:F21C90F526F91EB87A1278AE9FF3F911611052BD
                                  SHA-256:03B3A62BBE211C273414511792D444A675518FE32068EE995A96251E5B6FA6E6
                                  SHA-512:86B735B66DB958A237AA983E20BFAC2B5145DC4A7779E1CFA49241B06ACB56BBD63E40B6474F907CCFF6F059E7942F053A6429FD681721D0501B3034847BE885
                                  Malicious:false
                                  Preview: .t.7pGF..xb....SL....yt-&.....%7`u..............%9..wv...H..Y.@]YF5/yx..AB..BqDnwk....57ap0+............fU......0;?,..pa.......@..w/.....8+..gc.._C....33....QX..@W......Q.#.[N..Zo..d`..$$Z]_K;'....\\88uul3/&......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{t.6..5.z5..kB...}{.}{447}{0000550000550000530000950000950000680000970001160000970000770000970001
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\77__Cellular_PerSimSettings_$(__ICCID)_AccountExperienceURL.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1377
                                  Entropy (8bit):6.6233016693774776
                                  Encrypted:false
                                  SSDEEP:24:X/8MO6m7r84tFoze4ytP6qfHSgC0fNSZBzfteJTQRh/VbUzfXF2tA63yrb+JgW5D:M7wAd4M9/xJfAXxukdq1EY6fbp
                                  MD5:6DE037C9D03F3D5F233FC33DBB13B484
                                  SHA1:9C626E76B3AE2ADDCBCB2333F2629E84F1A64137
                                  SHA-256:2273119D79E99DF3A49448B6AC36A49EA69E7FBA61E535887CDC6F7DA69426B0
                                  SHA-512:8132CFE653DB0EB1F6B858D75B6EEE7BD5CD0B79190683D292331DC51C62611441A5308A612010AA564D51C6FCB5C716F84D379CA9A36BC469707FA59C98D268
                                  Malicious:false
                                  Preview: .im.....U......T.zi..#!....7:.... !..)3E.......%$......HU..Zl...;9&? :........|!..""\.3:.........................MM..8g..cp........#`....rm....1(->FZbe22.....ZOF..........LAK^.._j....$.........+,..AA....%zypPC....+1GZ"a..SF..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.e*..j./r...#...}{.}{456}{00005500005500009500009500006700010100010800010800011700010800009
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\78__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1388
                                  Entropy (8bit):6.803077918076144
                                  Encrypted:false
                                  SSDEEP:24:LJ4FQ+7AhOb84tFoze4ytP6qfHSgC0fNSZBzfteJTQR0UzfXF2tDFvy8Bp+JgW5p:LyrAhOgAd4M9/xJfAXxuc158B0f7
                                  MD5:7EBB36AE31B5119E1D54CD91E03EF8C6
                                  SHA1:ACD2BE508BDC179597E3574D44D196697552E5E1
                                  SHA-256:4A3D80CB4E679EEE02A230FED59D10B3E094FF81DC56E4A1C6D4A693D43F4187
                                  SHA-512:C213F19914CCEAB10DEFAFE7B404125170073A8272F0DE203FDF81623800A5782EEE92EB9224E4C654FD7A9B371390B45280F74C253BEE3D4CDACD5212A39D00
                                  Malicious:false
                                  Preview: T.e..GRS..............id1:...YF.........@Oe`mnfm..%9/~NO;<.....L.............0......IZ....<'ur..W...7o..b.....z{.....eO....@K'4;9..lw\[DN.Tfo...b............`s....ZA......CJ(pv/..#q...c(........M...7)....T...._.%.$..........tg{y......&,r&....NC..~~.....%2....}l..ZS.C..++{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....Q.#.C......}{.}{575}{000055
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\79__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.7330134886290125
                                  Encrypted:false
                                  SSDEEP:24:wjud0VVE84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLMT/VUzfXF2tDFvy8BXCL+Je:Cud0VVlAd4M9/xJfAXxu8Ws158B5fI
                                  MD5:53E72A0297ED51A49FE208DFA50B7CB7
                                  SHA1:C9C7387F6AEF1FA1BF905AB614306441BC2E435B
                                  SHA-256:FF4CD39D2111464BD70E7F21410D5ED8C28DBB801B6B504BEF98E4303A5E5807
                                  SHA-512:240E5E9074BC9E699772B3756252F75D910366EF70F48149FA362AE526ABC65240F3D086D4FD92C23CA3EA62E5C484A4EBD715C4AC0C2C89363AB910ABED0A84
                                  Malicious:false
                                  Preview: ."&............\O.....6:OB....23O..e....$..ih%}q*.....+_i...R..,6aglk..IB............L[.....nc..VI%+......;;..>a;2..mz...e...N..qd......`s......WW!!${......bx..j)- EPnq1..............)..((....n1 )XKER2%='..!b..at..:6......q..............@.O\.uz..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..D.fM...Q......}{.}{525}{0000550000570000950000950000670
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\7__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1232
                                  Entropy (8bit):7.42902409997393
                                  Encrypted:false
                                  SSDEEP:24:hd9t+j9kHrAM+RVUZ84tFoze4ytP6qfHSgC0fNSZBzfteJTQRa0NlBBpFUBQ+Jgo:ht09kLykKAd4M9/xJfAXxua3BpFUBvfJ
                                  MD5:20B195BE4E14FDB9A8FE86162BC931E8
                                  SHA1:7870D6BC2179B4F0F061047646165FAF31579444
                                  SHA-256:08DE2E31F9C586D25F33F811AF353AC88521BDA3F665E2F8F88DCBB06882BF4A
                                  SHA-512:F6502115400C8E8A50483297D0C1AFC25E033F567A0DB00E1EE9D6F079744C0AEADAB5BC49AC489F8CCDD5F7970EBA17E365D236C0047F074769B05240C381F4
                                  Malicious:false
                                  Preview: ...#d.................P[..X..Jsaqd%'ts..qt............mj....M...........fe....?.SOV]TG......39].#*?g.....sj..Chrt...............64..%>$#..s'....!T..bmjz..c.....91..9`tx""=&49T=........%%**...wd.}....EBT^....-uX>........T^~X;;..wd4(ST......XX..+8'jS\..QN[L......Y{ec...........J......lk3"dx2#........]Hpo16; ..?=..ST............><........UfDn{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{59
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\80__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1321
                                  Entropy (8bit):6.74530596956419
                                  Encrypted:false
                                  SSDEEP:24:UrSIK5K3kIr+k84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIjUzfXF2tDFvyv2+Jgo:U+IK5akC+FAd4M9/xJfAXxubi15vRf1
                                  MD5:44B1002E3A166A1C979B3D246E7E10EC
                                  SHA1:EB6D0CA1ED42B7847857E24253AB51816271F333
                                  SHA-256:10831B3917E490F25793D129909B07C1DC872BE9EFDB2F0C9BA4EABEAF59EAEF
                                  SHA-512:CA7C89DF0867DFCBF0AE2388E22D2AF4DF692F1E8938ED9ADBAE936C2A560470B4E6E784C9194DC098DDA21D2C027CB0D199821041F9F89820B27E36DA20ADE8
                                  Malicious:false
                                  Preview: ~..zy.......:<.....\^.................G^K@J....f>.....vE..@VM.$&...oi............@ZSZI....`z...^....0/ig.....................H.[V*?fy................^5<.......%8........."....:..vq2&...........M...=:-..>$..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{01.+%..?.3e....}{.}{440}{0000560000480000950000950000670001010001080001080001170001080000970001140
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\81__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1241
                                  Entropy (8bit):7.365584342001079
                                  Encrypted:false
                                  SSDEEP:24:maAgtmFAroh7+W84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKxiBBpFUBQ+JgW5I:vPO7MAd4M9/xJfAXxuRiBpFUBvfS
                                  MD5:90B46C92F299C5B0F330189ADB7616D4
                                  SHA1:5A9C43B334FD2E8AB0EE54D8E3D9DA258A129757
                                  SHA-256:7DE17F345E1284FDCB2E01FE0CF22915B13113830F1B54332992209E7735A1EB
                                  SHA-512:3280334149F98F133D60E8CABAD70A5C738A72F78B3B0BAD573F9E384494DB1E4F23D2667822167EE1AC53ACD938D8A2021413C35339713AF7CD3A3B78854017
                                  Malicious:false
                                  Preview: ......_.EVA@..i:%6)7PR}v{w|qV_.............M@............................[P......D........5/(5?|.......................7+=:....=b{rarpg.. := *iKF........[.oTSYACt|.<=:R..I.........j....qm^Yss..bb~!..>)8/.....L.................@I_F7:)y........GG......'i0<_..a......{U11se........fd-:...VVGNG....`u'*atA^ts..81..5$..[[..00=.....31..KP8?..........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\82__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.3699617840960014
                                  Encrypted:false
                                  SSDEEP:24:wPwImj5yxSP2G84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLBBpFUBQ+JgW5x:SPYcAd4M9/xJfAXxuaBpFUBvfj
                                  MD5:2CE7B6ABEE24AD8E3057F79799FA1FDF
                                  SHA1:A55377408C1BC62ADEA6E67739EA5F8DFD8A00E6
                                  SHA-256:792197026835435A13683FAA7E4D72943F81C489F2B63E2701D0E79CF857CB03
                                  SHA-512:0355AAA3F9276504D753063481D0C373CACD5C885EA6CFB12F39382D5C190EAA3C042A39B794D615E679FA0CC6C2C28812334217978F732FB06D68C0348FCA7E
                                  Malicious:false
                                  Preview: ..Cy>...U......*5....._AL;0.... w,>oz|~..uz..+(t.....Z.98ru..XIf;..............rX..pc......16j`...............=;.......,,......rp....mjPZN.^W.....4)..{W..KD..J<....ssyb6;.}..l...........\W..QSj{....%/M...h0.......VY......D]gt......{{55..L.M^:whg-%......$...BD11eZ..Wm......dtgxDC....7&.N........X......LY*'AT..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\83__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.828812902774987
                                  Encrypted:false
                                  SSDEEP:24:vALUBbgbrflu7za84tFoze4ytP6qfHSgC0fNSZBzfteJTQR68IUzfXF2tDFvy8Bf:Y4erNuHAd4M9/xJfAXxux8z158B0fTs
                                  MD5:9CBAD31C2459D20469B54E44F239C0FD
                                  SHA1:D554B2BB8C57169E7A9952CB66C9627A121CAB73
                                  SHA-256:FE3F70EB8865D4459FBE3A4A7C5AD7651D169CDEF3E131B03925C64F9270AB78
                                  SHA-512:6381EAD119481E9F4C49112D8CE15E4CAF9654C98A5D16BBA57AD6825B521AF10FF028E5F47E55917DDDF28269849816B1E5D425CD58F5188E5D916338F2F84D
                                  Malicious:false
                                  Preview: ."&....9u..ML..z)..e{LN........\C...Q.....AK......e>aw....H~...........(/.....Q....0o......_H....b!..-8..Wu.........vj..::yy4k......`w6,....qd}b....@Ght....99..a>#*xk....)3........poYA.....CZ....G^[....UEB...I.Q..........II........:)bu......R..;.]B.m............X\.0kk..BV..r.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{r.o~,......^!...}{.}{573}{0000560
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\84__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1387
                                  Entropy (8bit):6.728505582203816
                                  Encrypted:false
                                  SSDEEP:24:KNt7kt9CFQ/84tFoze4ytP6qfHSgC0fNSZBzfteJTQRRUzfXF2tDFvy8BXCL+Jgp:S+Z0Ad4M9/xJfAXxu7158B5fI
                                  MD5:FB35DD3B0E43B28D5280609407E01956
                                  SHA1:6A1187D51C27AAFC1621A1E8751B3097CF92146C
                                  SHA-256:F4E47FF199206C033B087385ED5B486F4B331B2F9B56E6A354DE730B29160C94
                                  SHA-512:05E6B668572C4F4C8748F2551099ECBFCFE0E0FFD91FCB42462AF5C8810046BCDBA16C750B9E0AA648B051322643BA26193346AF1B66D97D2FC1665EC7BC84C3
                                  Malicious:false
                                  Preview: ...213&f*VE..!'..TG....ib....LE....*a...sf..r....A {..`}..GqES.........z}.........V.........}g..(k/"..>!..cv..25..ss^.pyfu.......X.cnVC....FF..........!!;;...N]`wgp....t7..<) ?....15.<ww....vj.....<<BB....pc..ox..EX....OZC\{w..ys..K&:&...........m!..=p..RZ{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.V.65..V..K.. .}{.}{524}{0000560000520000950000950000670
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\85__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1319
                                  Entropy (8bit):6.7012774544484826
                                  Encrypted:false
                                  SSDEEP:24:rCLOCgmMS7Q84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfgtIUzfXF2tDFvyv2+Jge:2LOVmr7BAd4M9/xJfAXxumgtz15vRfj
                                  MD5:D271B9FB071806F24CB5FEC34D74C92D
                                  SHA1:1622454B281F4763F34CE15691D9CAB87C8118F8
                                  SHA-256:418977B33ADA6DB658DD6C018EC51BA8C86A576262812232FC5D858D1601CFB8
                                  SHA-512:A009684DFE0967F6DBCDB488E2EBBBBE1CFF8CBBA5CF0993C5769870F4E3364559148A75CFDCB9B0CD57EAE2C175AC8C61BFDEE27B957B9BD0BB2BA090B8D04E
                                  Malicious:false
                                  Preview: \!%vuqd.....B.$7..+)W\........./@...;hj.=7;698.'h3se...!uC..:g..\E..........@.LK''.C..fu.........R.#....HFgr......RR.Rw~*9:-...............SS...=..................@WD^..i*....}b..Kj$ ....be9-..}zrr..==..i6....k|XO..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{m.x........v...}{.}{436}{000056000053000095000095000067000101000108000108000117000108000097000114000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\86__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1249
                                  Entropy (8bit):7.388049565388821
                                  Encrypted:false
                                  SSDEEP:24:9R12hh6Viql84tFoze4ytP6qfHSgC0fNSZBzfteJTQR+PvdjcsBBpFUBQ+JgW5Q:B2hhnAd4M9/xJfAXxuNRhBpFUBvfa
                                  MD5:58E05077BF548F57F5F91D8EE2D0DECF
                                  SHA1:2AFAD8F7645FDF9E2CA44A13A7EA3B86969B71EB
                                  SHA-256:BBC4834ACEE72C10E96D28B4167ACF181655C92E7554AE3AC82DAF18CB926757
                                  SHA-512:576B9DB4BA8564F04821AE2F18C9ADB8EFBA6DF95BD3BC2252A64D7376745C16434C0A9DC21F1AD9522C77E8F46D8C0A98AE7A2D67711B60ED03657BC1ECE190
                                  Malicious:false
                                  Preview: ...9,..98..+x..KU9;....94......b)4.?lu`..Q\ML%}S......#Qg...Z^\..lv......yrN.fa``...9*..>)OU.......gxcm........1+0+7!3/....HH..AH\O..2%....@.....9&..r{.v?8\^......NA/'.`<e.......b....g..oE;;....>5..GE..vm.xv|!u..U..f%6"...HGGM.>....O\....VV....==.]..-`..>6%:...aF..*.........+....x.....YF....}aXIH...5/..N...B........CNwb..:=......\M<;66**.............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\87__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.353764239277466
                                  Encrypted:false
                                  SSDEEP:24:Zsc9F30OA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRKmMBBpFUBQ+JgW5x:ZJvAd4M9/xJfAXxuGkBpFUBvfj
                                  MD5:1BB503EDA5F9E60CB04D54FB48F26C70
                                  SHA1:C4F673BB2F1331E24FC82FDD2115A40B9522C39B
                                  SHA-256:C89EF093FA97E40C1271869A0081002DF94433C5BBB7FE7F9765293F0D01B95B
                                  SHA-512:6921D8A7092D4E7BAF231B27ACEA63CE6B3188816443648E433B09F79B52AD1A14BD66E14F5A83A61218C5AE5544DAA6257BF12FD948F59995F6992E03CBB144
                                  Malicious:false
                                  Preview: |(o.)n.."t...........$/"%..O.jx3&ge=:..........a}.Az{[\.?.y$-0........;8NB.........[Ypa..-*..})gn.X.....'..tm->..hn..n?........K@wd....ir.....^...[.-#..s......."{o......5"^O....++..}}!~...w`YN..PMz9......)..4TA........js94................b}!o.....<>1+`h@n.....!}{#9..u}.........^...C......59G^RW..qsr?H.....'.C.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\88__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.78909552522466
                                  Encrypted:false
                                  SSDEEP:24:0LvuRtTN1kmtP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRapUzfXF2tDFvy8Bp+J8:Evu/Z15uAd4M9/xJfAXxuvI158B0f4T
                                  MD5:993EDD10E35B94538674127E33F9FBEC
                                  SHA1:9797F07EA6F7F1C961A4BBEB4F3A5BBCCFD5E48A
                                  SHA-256:F62A7A07FB9448261A6A185AB9A653AD21ECF762B745D0B6155890BD73F56A7F
                                  SHA-512:1FF96E169531D519C7B5D47CF67647E042ABA8369972D193AEF2747E2738AC443FCC5654123645B0620614F4B60D7EC5C71140101C7C5CA71088A941D623315A
                                  Malicious:false
                                  Preview: ./+gdU@.I.............kg....PO)(.@...^K...SR..EV@MPaReS)??b\^ 9.........RjmLLf9EL..NY.......L..wb..Wu+2..|z........B.......=*..,1..........DC../(]]99]]..........3)LQ9z.......o6..a2..0c..{b..b{.^.....ZX.............]]..}}....lH_..e.!<..~s....0\ )....2ou@..^Z........)"{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..'....w..B+v.}{.}{569}{000056000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\89__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1386
                                  Entropy (8bit):6.734999858063281
                                  Encrypted:false
                                  SSDEEP:24:IqaO9OWpTMNDVKt84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4d/VUzfXF2tDFvy8h:xppkAd4M9/xJfAXxuDds158B5ft
                                  MD5:F62D192FB483362369AA1F9943F6ED6B
                                  SHA1:2E1E3051768D9B790451986E9AC83073F0A5A5A3
                                  SHA-256:7ABE354D53EC671FE70CB53A63C34F292666C6008BF3923E5653E7162C1DA91E
                                  SHA-512:EBF61A93ADB5E722AD58404B4F33F9ABFCE55A1ED4DBB2D46E571867245FDDB4EDB6B3119C5CD083F279523F2B87F0A0FB66F5DB1CAB74EC0D67D089BF0987EE
                                  Malicious:false
                                  Preview: h<Y.....D...........l~.[..QZ.......8-..IN........SL.........bs,qqlWH..ON..........iu..l.GE:+VM.........5Z...8.@j\\..../<......cdPZ.A..^.M,NG_Fs~.....||>>.............DN*~(!4lt.....(.........eV...........]N.... ; '%/n:..*r.......AL..........HH....>p..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Q.S]L..1...d...1}{.}{522}{00005600005700009500009500006700
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\8__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1265
                                  Entropy (8bit):7.451157684480903
                                  Encrypted:false
                                  SSDEEP:24:w0mxjnSFo16WSuwmmW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRo8WBBpFUBQ+Jgt:ncL4RZAd4M9/xJfAXxuvBpFUBvfk
                                  MD5:EC758FD3AE6E2320B21A1A9E1F97D9BD
                                  SHA1:8C0FDFDD7CAEFA0BC0F4D4A62C7C7E25A0E38A1E
                                  SHA-256:CAF9DFCBBFC4B50E3A36B0601D329B6E8AA6AE3B51E0BBD02BC5249163E9CAA3
                                  SHA-512:468D8DADCFFF18A8AB0C5F86E14BB66DF4F8175836697923C393CE46546B3B69368052C0AC1D43D7E5C85A3884C747DFAD7978E9490AABB29B0E07781AF4DCCF
                                  Malicious:false
                                  Preview: ....{n.........n}..........bkls....lv.9,..ob..d<./9....fP..."....)3.. '..............`w...............MQ......bx!:..3/....::.......[L......fs.........3&......[-f?......:7l.RD"P.&..^^qq8$....wu...ho....ZS.......(........yjmqBE..&&.......R.....5*......U\0..........................~{..~s,9..._D<5..J[..oo//..........UN....Ar...........V...v?\..PH&...........{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\90__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1321
                                  Entropy (8bit):6.714477943005511
                                  Encrypted:false
                                  SSDEEP:24:n6HpFpFlD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRVai/ZUzfXF2tDFvyv2+JgW1:QpvIAd4M9/xJfAXxu/iw15vRf1
                                  MD5:EEE6354EFDAE358730D9A89117D53351
                                  SHA1:E2D7321CEFD392E5697B7159FF78E01DBFBBE2DC
                                  SHA-256:419BFAAB628E4B2BFB18459A0DCF7E9F5872AA7BB815E95F03ADE1AD8D267C90
                                  SHA-512:92F6CC531D16B08186B936DF58BF5F6C976EC15AD7FD4B981468265885E9EC5FFD7AD80CA2FEA8CFBE16DBB93244B361C25A9D893FBECCF0977735D708B62A62
                                  Malicious:false
                                  Preview: ........AR..y*......xtfkqxIVbch#..I.sf....76...@VHUwD....s....,6......FM..UR00........+1...'*..UJ..=(..77uu..iz....G]......N[..7.....*9....oo..%%=b/&?,SD..1+..^.....KT.,.3..8.......\@....))..RR..&/AR..|k..1,{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{e..4.^l.,@..}{.}{441}{0000570000480000950000950000670001010001080001080001170001080000970001140
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\91__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.373325004528943
                                  Encrypted:false
                                  SSDEEP:24:U13rOZldteObVJhYtxRFRM84tFoze4ytP6qfHSgC0fNSZBzfteJTQR77ZyZ/KBBO:U13KZldcOJufF3Ad4M9/xJfAXxu+Ziyg
                                  MD5:2BC1155704CB23E834C761171990AF99
                                  SHA1:F3E3994F9D41A3ED69F587F24F942C9DD57C397E
                                  SHA-256:7027B071330B26C6605392C7873ECB6F39EF0A3E0F2AFCAD3ACB49743FBAEF5E
                                  SHA-512:DAFB929FB99903C0A46AE4E169F0D282AA6ACCA2E7D5EC655E9E9D1080D7E697C1CBBC474049C5DC8A1DCF822E9A5597158F61D35C56EAFA8868160430EC3A53
                                  Malicious:false
                                  Preview: ..@...:;.}jkq..qn.....D..6=07.D..*8sf.....!+.QR......[.......................*.//3HCTG..........K....[:4&.........WQ...A..gM....!*JY..........$-........qs.mA@..]U.....)E...........ju."5#2...........Z....2%%2}g`}.........)<:0{t..DMMT..H..%"...........a~q?.....z..F\..\r...%.............w#..dk..`bZ_)<......:=.....kz.........XKhj....KL....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\92__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1210
                                  Entropy (8bit):7.365371613591727
                                  Encrypted:false
                                  SSDEEP:24:AulruXHMaKyYBs8hkW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRLeED/ABBpFUBQ0:thu9KyKOLAd4M9/xJfAXxueecQBpFUBt
                                  MD5:EC764A6579FC3D3B9A417510BA7CFE37
                                  SHA1:614C09B816DBC3EF4245A474A6DF01547DAC8F9F
                                  SHA-256:769DCB593012D513B237F667CB10C111A2FB1FE1A363524F850C0324532A5A3D
                                  SHA-512:F6AC75D557EE39B9952EDB9E6F4FAF878A50518678083D5B888F257FE3588EDB6AB147EA470FAA2F7941C3A896FAB0A55D12B62F1D757EAB737A6E85BD973B5E
                                  Malicious:false
                                  Preview: z..O...K..cy..qn...........x..j=ug:/ln..`oup....LS..[...mj.C...^5(VI..EDRU|.*&.....92>-........"(Q...i1z...F`...H[Hc.....O|..11............0:../&..#H.............=...?....q......; ....[M........:&..UF...............@y.fu[x{}+$..0...........44......8t..{6..2:....xy. GN....aa....jP, .a7..qa....,*................61{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FB
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\93__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1212
                                  Entropy (8bit):7.400663633125695
                                  Encrypted:false
                                  SSDEEP:24:ikAkDJDIXXdeGsP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRV//BBpFUBQ+JgW5x:ikB9DgsEAd4M9/xJfAXxuMRBpFUBvfj
                                  MD5:CD345ECE25FC3DD1EE7D9DD4C63BBD0F
                                  SHA1:637123A1D0BB9160C13248FC5649599088CA0D9A
                                  SHA-256:77E507A292C6B7AADE6573EE4B71CD41936565E2364DB501B6D82254E6A3D923
                                  SHA-512:F733B7A95EC5599DD9B275A898ACBC34885773DD3019C394BDB0701BE23BDF9ED662AA0DFD3634964BE606096F72043F5593A6DA34D73828D2A9A7FFD479D4D4
                                  Malicious:false
                                  Preview: ..u.B.z{.K..ouwv......F....................mh..k`....j;@A.................mn>2..Ka..MF...........L...&~.x..".....qbt_42KG...?.pp......@BN_G\............(.........K....Z-2 ..(E..~oDXni||...........-7.......:%wV..@U.....4DM7.=0M.......UU........].UY...}..RHdl....2$.....9........._.M`m..l`............KW....TQ....h}fy{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\94__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1207
                                  Entropy (8bit):7.352480913706354
                                  Encrypted:false
                                  SSDEEP:24:wbCoG3sTn2d84tFoze4ytP6qfHSgC0fNSZBzfteJTQRIQgL/+BBpFUBQ+JgW5e:CCpcT2OAd4M9/xJfAXxuPLmBpFUBvfk
                                  MD5:6B37B3933FB5A208CADFE3E216969A58
                                  SHA1:845B025D6AA732AE172483645CA1B6446AB6FC64
                                  SHA-256:A3B2E5F728149C03A414D6C71484EFCB3EEDB45F8E658ACADDF3E559CF30E1B1
                                  SHA-512:C87791740595D05C7F56C27826726E214B4BE76D46E589AF21C4D3A956FD34BE9E50B749F5477191F20E1B4B329F2D6410BC41367D09AB7C84117D4EB3BEB7A9
                                  Malicious:false
                                  Preview: .........tgGF...GEV`~.....\Q..KT*+<w...S........%}/t..gz.=......mt..ec..#*...ts....LE..BU....snI....%:}sui.......>......FZ....99.`i....!6..LQ.Nid..........;P....-%$R.!-ee4/...x..N<}N..oo..............)......J.....x[KM......WWvo....JM......DD.PQB.Hcl........_x..}_%#77oP..-.}q`'B.....>!....L...X....G.....SZ..3b....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\95__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1244
                                  Entropy (8bit):7.379225824422985
                                  Encrypted:false
                                  SSDEEP:24:oh2+Jze5NUyjEwo84tFoze4ytP6qfHSgC0fNSZBzfteJTQR4/9BBpFUBQ+JgW5R:oh2ya5iyj5Ad4M9/xJfAXxulnBpFUBvb
                                  MD5:7654DFD208D935EFBF08618F31CE4454
                                  SHA1:7D484E8A088A79CF2349329D40946213E0AD8480
                                  SHA-256:E11A8277A57F4EE2A1655A29F9E8DBCEA2A1266FAF4EEDFA2E6EE7462F04860A
                                  SHA-512:D084B6B4661BDA2F235FC9B242D2F1290D6C97D4221A372C3889F621F0090510F6233A8FFBCD1B8294180B8BADEB57577AEB415C5034F23AACBC1CBFC0D2EB6B
                                  Malicious:false
                                  Preview: ....Q....J..tn.........94EN........VThoWX..tw........8?l'........,6........gT\vMQ..cp........dn..=4K..}o............fj.....11..JAl.....qj34.........(=....Et..ok.6]kv.....`}$|p..\GP]...wEv..........IZsq8)nu..|vz...H.c.JYfE..5:dn..rrxa]N.....99..MMq=wd...FN..,;../.xq........9>..IE..].{v^N..g`..............+>..0%....$?..WUBS..FF..MMarP[....WF$?{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753E
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\96__Cellular_PerSimSettings_$(__ICCID)_BrandingIcon.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1383
                                  Entropy (8bit):6.8080994394514285
                                  Encrypted:false
                                  SSDEEP:24:ggT2IEKh84tFoze4ytP6qfHSgC0fNSZBzfteJTQRX/acsUzfXF2tDFvy8Bp+JgWc:ggSIETAd4M9/xJfAXxu+CG158B0fc
                                  MD5:D9A27F04300C35B389DDEFB59DEC0730
                                  SHA1:C070676079A2238123E7A4A1A16FAF29135B4330
                                  SHA-256:0C2DF10FBC29A3DB547F52BCEB2560199E2D7FF3A4A10F443F87112FE9248FA5
                                  SHA-512:05DBC24005AD4C80103BF33DB6D22D7A32C3E4EF6D21F00BD1B2ECA2B1F53750401CAE47C3D51D8454E02F42AD3EA96A29941D13E4605609A1FD585A4D42C7A4
                                  Malicious:false
                                  Preview: mJN..wb.HEV....9j..A_sq..."..........yc}..j.u?2.....V@.............4.ec......?b....2mxq....7 ..snK.......1.......be......vv .....8/.......X$).."=..............2mi`s`....^D..s0..GR....ON....X.LE..m:zc......GE~*...hp....66..jj...Sel..}jh.....x;..lyGX...g~P]`=......^h??..>*{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{t...e..x..g..v+}{.}{565}{00005700005
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\97__Cellular_PerSimSettings_$(__ICCID)_BrandingIconPath.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1385
                                  Entropy (8bit):6.720215461767049
                                  Encrypted:false
                                  SSDEEP:24:tP3QfAwl25T84tFoze4ytP6qfHSgC0fNSZBzfteJTQRMXel/7UzfXF2tDFvy8BXY:qfAM3Ad4M9/xJfAXxuLeS158B5fy
                                  MD5:C28A7092D135CDCC515767BCC29A82C5
                                  SHA1:DBBC1F3A510A012B8D9C0920244D4E654350B0CE
                                  SHA-256:0CA865F11FEF78526B4BF053FC023BAC872338C826DC9392DFBA23917A8EA30C
                                  SHA-512:B80DBD0754BEC54816D20FD00C0392B4A5357691B38B18E6B5C500DDB17B0B7D11FA4D307994CC19E1D671080893D0A228B2521339F4D94779AC9D152AAF91C2
                                  Malicious:false
                                  Preview: ..."!...l.YXhno<....$&ch...w~$;.......`u............|O.9?)8e....F\F@+,..;0<a....X............;6?*... -8\@.......>7xk......snt7cn.....<55...l....ss..!!=b...erctg}..z9m`......^Z6........_X..tt%%..t+......J]......+&....\\....`.:&....uu^^...c/n}....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....u2.`.ex..Q..}{.}{520}{000057000055000095000095000067000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\98__Cellular_PerSimSettings_$(__ICCID)_BrandingName.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1318
                                  Entropy (8bit):6.727465271024532
                                  Encrypted:false
                                  SSDEEP:24:GVSxpy8Zt2884tFoze4ytP6qfHSgC0fNSZBzfteJTQRs/43UzfXF2tDFvyv2+Jg7:YSxp3AAd4M9/xJfAXxupt15vRfG
                                  MD5:A514D4872BED553FCB9235DB1BE850E6
                                  SHA1:C2E13242AF80965200E1107F2B43EC1084220D50
                                  SHA-256:A0417C07937086902B09BEC2E0FFDEE0D3291EFA45E54AE298CBDDED5ED70B25
                                  SHA-512:9A0936CFF245B766E2FB5C990747A65A83656B46826361F80E60E17224D7B67CF4FFDAD3434E497AA42D292056E175F8B175C227F9762C71AE5E38A46F361F75
                                  Malicious:false
                                  Preview: W..|}:%$...QK.........[V$/|{k1.B....=?..,#..zy1:.....O..Y^=vDU.....<&..........hB..SXh{<>....' .....7o.....y....uu....../-8)..pw...mdz"@!..2+......................syD........Tj.....g6Zi..oo......YR....UDlw{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..0.u...f..]=L..}{.}{434}{0000570000560000950000950000670001010001080001080001170001080000970001140000
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\99__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:COM executable for DOS
                                  Category:dropped
                                  Size (bytes):1237
                                  Entropy (8bit):7.399351518299771
                                  Encrypted:false
                                  SSDEEP:24:upLOpUbgY3P84tFoze4ytP6qfHSgC0fNSZBzfteJTQRpY7K/L/VBBpFUBQ+JgW5k:uKUbUAd4M9/xJfAXxu3ODvBpFUBvfe
                                  MD5:4F6835547688452A8E9C87CEDDAFCCF3
                                  SHA1:796949091FE7EE0C3312AF2CC07EC83DFD859135
                                  SHA-256:61D1F4F9E30E162F23531E9FFA646CD41E74573EDDDD60BDD4AAAC65600A3908
                                  SHA-512:F5EBC5077638F0201835CDE6D70DEC63DC737E0C25F60AF41090B06C3E29C5C76A6CF65925086CC86485D2C51F6C280693A6FCBB695A744F1D157BF98B319E44
                                  Malicious:false
                                  Preview: .GC......TG....L.KX........3>.v....<w/5..flcn..........H~bt..`b..6,y.!&LE..,q..@@.i`.......................Q\.....A].......Q.............v{..sl.+oq+:..*.zt..9q....p.....3^..[J..::.................F.r...^A+.Wr.................iC....CC........ x...........LZLo..G]....EG..pi...}h.[..H...vt+... -.......6?om.?~y@@RR........rpwf..~y....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\Prov\RunTime\9__Connections.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1242
                                  Entropy (8bit):7.39783688399219
                                  Encrypted:false
                                  SSDEEP:24:KyPvosDcPH+cH7d84tFoze4ytP6qfHSgC0fNSZBzfteJTQRma/VBBpFUBQ+JgW51:b3osDMbOAd4M9/xJfAXxucvBpFUBvfX
                                  MD5:214035FFFDBEF64A875495FF9F36EDF6
                                  SHA1:9EA566892A5FCD48CA592B51A7A4F396322C49F5
                                  SHA-256:4F3E2375C7F4ECA7430A78B5C75C67697CA8EF04992B5F7CDC00101C619656F8
                                  SHA-512:61E7F7CD6287C928ADC84146D60FB9EFABD3C5AABEB3CD176B1CB64BC1E8A28200AFB2192D856249CDD3D0A57FC5AE0E4FDB4C54C931DEA03FE6AF3BD3DAC485
                                  Malicious:false
                                  Preview: u!...Q..2dTC....ze..bpc&..AJ..>d..CQ4!vt....]XYZ5>..KWY.....l'Q@....ju...........3.6.....MO......"(.Ycj.C.}.../$$RK........:k...&ll..fm..@Bap.......E{r..}...WQ.,...iu..p<....pC..F\34.....:.cq..*G..)8XD..~~==..z%QX->..TC#9}`.=0GRls...).......)....)$.Z...................W..w......Mc..m{."..|f.....}..ipB..A...................gryt..C\..`{R[tv......ggRR..aj</..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09
                                  C:\ProgramData\Microsoft\Provisioning\{c8a326e4-f518-4f14-b543-97a57e1a975e}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):337794
                                  Entropy (8bit):7.998198642774862
                                  Encrypted:true
                                  SSDEEP:6144:U7wvSnOcK5XFujCaao1uv1T+8gdwPLEPNCSYp9XNU8Pvtkyzx0Ip17QrlsNwtHl3:fqnhuE+o1CC8gmPO4SYLW+tbJpCrHhl3
                                  MD5:7C863FCC67C70FA189B0991245834D92
                                  SHA1:7C5567E8C6EB695F4100DA14B4E32326F7F7670F
                                  SHA-256:452AF734DED09D2E9CF52DC42B172862CCF5C2FA9A3BB825DB439749E1DACC82
                                  SHA-512:C105ABBA9E214215FB934E597521D02CBF85C6825C8D529351D7669B2BA7422C093E8BC00F20F8B37B82CE8B8EE10B54D344A1520195ACD53F93DD2FCC4A6B5E
                                  Malicious:true
                                  Preview: ........5&\].."q.lhv......85@I..yx....~.........51.7..-/............MQ..&.$".>*+ifh/J_ca....w|qyBP9Y.......................bh..........YE..####.xG=....<=..]D.\HAD].....Y..................................>9" ;(,9601c..>29bQV..||p.)>..#".......c......Kx<...)5yA....of.nJ@QthLEo'4T?&~i.90%..J`.............?SV3..-``-19....KX.....c......9...........$}NI88............F..~b6...ia............F....................S..........70+)..%0....}N..................xx..o.2!..'s........]]]]c~]],1,,ZZ1,...............rn]Z''pp((((mm4\O\IKjMZO>/tGgMjj..................[t.................]J.&"*(........``.....................ee........RG......eeee...$.......LLO..M....o3........6,."}~,.....................................................#{.<<}.tC3*.KTD}|TV.?....!!CCCCffCC.Q}|..f{~.1_..t,.iJG*(rE....I[.............................2..xg0,..( }..>VO:b+Hek1>`h<r.=..>7.s_]..^Y..........4........uu......Q[.......2-zf?"kj...jg.........4...MM.......^
                                  C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.253469085985404
                                  Encrypted:false
                                  SSDEEP:24:hfOf84tFoze4ytP6qfHSgC0fNSZBzfteJTQR6Y+rDPv4W5y:hfOUAd4M9/xJfAXxudhc
                                  MD5:4D02FE23B52951662F22294C8BE59944
                                  SHA1:EC2F7A49A0D6BD372F2CBA92C81DAC988DBC168B
                                  SHA-256:3D97A36BE81AA2C4A8C303EC2654D9651D24958E7C37C669227D3057DA50F2E3
                                  SHA-512:24041158FADA4F499A220FA7E3AE3C44C2020CDD0333CED97A050E5A846D299D172AD2DEF1432F6E0A8B37B80FDCB8419DA8DE760E8D5CBD3D61A0834E309D3F
                                  Malicious:false
                                  Preview: ...r/h...Vtc..~........E......b8.[..|i..QbAw......tanh1. :9(..d~.WzIXYx~)z...VJ..!!.tu......|}.!..EC.e`l..~vm......XiTH........A.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..067....o.F*.1}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1043
                                  Entropy (8bit):7.5093359854780015
                                  Encrypted:false
                                  SSDEEP:24:1ardS2a/rP84tFoze4ytP6qfHSgC0fNSZBzfteJTQR1f3W5pT:x2HAd4M9/xJfAXxummTT
                                  MD5:D244DE25BD7049B7661FA8EDCFA3EF22
                                  SHA1:6778B2C8C71E2D427AFA5AEC87666E01C31CFDBF
                                  SHA-256:DAAAFC7B2515F8AAB16A94A8250E5FA0F3C5C5902430D79FC3355070A5C90384
                                  SHA-512:9C6D38587E8BAC8102F5C85656925D6F001401C52C809B175752880CFDCCAE1C5FCDB662E7C2B83DCD47CE17652D0F673C01AAD9C84DC7D13787AB0ECAED7842
                                  Malicious:false
                                  Preview: .73..RG........A..4*......|q,%..n%..WV`g..VW......RO......oi.X........7(..H{......bj..9>5 ..oR......q#..................8"....P...........d/.....K@....V^^..w...g;GAQ&..mt........|E5ZZU......en.......fs..!............j${ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{bfP@z...kKX"...}{.}{460}{000082000117000110000084000105000109000101000046000120000109000
                                  C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\Prov\RunTime\0__Power_EnergyEstimationuser.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1505
                                  Entropy (8bit):7.261450343257683
                                  Encrypted:false
                                  SSDEEP:24:OEFBBQS/JdDAiZkd/4UcW84tFoze4ytP6qfHSgC0fNSZBzfteJTQR04RK2bKXO+N:OEFBBQ8bjpBLAd4M9/xJfAXxul4RKFxR
                                  MD5:482A804A310C706EE6408B46083F3178
                                  SHA1:B07793CEF2D7DEB4108C012790368C39CF4BCA19
                                  SHA-256:FE7E2F97A729BD589823549ABB0757904DE9410FA3DB413D1EBD94371A7FF27F
                                  SHA-512:BCE3215CF439F4A740AB87D36A9E8FD50B199396B9CD58CFB02B080BCFD6896E704EE0509BDCE58E2A0E74A9BAFD76DBB51A1BA28E432B451645EB6267933051
                                  Malicious:false
                                  Preview: ...>...........MRSL....P]t.........AT64.............v'QP...YH.orwh;!....wt^RL...*6..L_.........q%aha9.z......?...b~..4'....G\@G...lew/.....2...II.....Y..........YD....EP..!.w`PN...]Q_B=<..U[..........GG"".v.;(j}&1........wb../......C .Zpgg..BB~~nr5${dM...E..z............XW.....pZJJu%A.'*...."/uw63......YF....ln.A......<<..!!......UJ<r....G]JV....ZR..WX......2.$!`l..}j..X./<2 :~......{0z`'%........FF.......@...{t..A^.;YZ[VwL..ur............98cg....Gwz....~...AD+>..mx-2.........wDDn....$$..-1'6WH|2{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r
                                  C:\ProgramData\Microsoft\Provisioning\{ee4aac98-c174-4941-82b1-d121e493e4fb}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1777
                                  Entropy (8bit):7.687695677426351
                                  Encrypted:false
                                  SSDEEP:48:pZAXX9wJaKQwGpnmAd4M9/xJfAXxuqWR1UB86g:ng9wXSppBAXQl1Z
                                  MD5:A2786370BD3B42E245E6625DB584B5E6
                                  SHA1:547BC89DBAF30F9FD4A7C665219887D867932943
                                  SHA-256:B38D5E71A8A303F39EE8250C0E31FEF9BC142B228755530F1C0C453CD50D16F6
                                  SHA-512:678813E589CC95BEA93F5058D02C9937779D3DA1BE9D91EB7F3AAF5F886C8A79D80ED36F7F7BA46BE5A1E296E15AE9912F432718C21AE879F3AA0DC7612AC7CE
                                  Malicious:false
                                  Preview: ...U.J........sl..*8.K..?48?....m 5...(XnZd39WO..............vq..J&..1;..Bn}u..t,..`}.....[..kf...kO..B^..h1>2,{."T^...!..c.5...vp...........cq.:4.VV......2g!#ON.60Y@&+,)...ui.OL....>o.....y.KL....M?*&................7;.3..DotzIB7]..........Ar....dx..A@hn.H0/...6!........``......5...x#..-<....8pB"..:-."(=tG.#......bgVX..&.....iC......UD=p_L&...c........&u}..tR..MB(q.....c}l..$-t'......C.......l~.........1$&{6..p{..5h....CYWV..P...(.......oh....9,*,....j@...........}0&!..{{....D,.l....D[(.........j.=.....uF.#......nn..@u..}l..`u.......((..yyMM..58...*D..^...TLXO..ta....yD}tzxDs.....~|..Z]..kk....--..^k....sT........AA....rrA)....1....+.*..............82WJGA.P.&...d[..b@bo....fYZY.;M..3#...+$..5....::..rnf.....BeVCo~....{{....~b-V..*(..IN...........*;/b..KK..\6......>^t..cc..>".........?.>.%%00cc...........(._..........Ns..)<-...paE.87....""..$$...p.....".............{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS...
                                  C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.285772551646306
                                  Encrypted:false
                                  SSDEEP:24:U/HZ4Nq84tFoze4ytP6qfHSgC0fNSZBzfteJTQRcglsY+rDPv4W5y:U/HZ4NPAd4M9/xJfAXxu7glshc
                                  MD5:0C27345A0325FDED1FC4BF22CFC2D93C
                                  SHA1:403400AB084E87BE14E5B6B95FAF8A27624FE26E
                                  SHA-256:C9E71359212680DDD44E539458A958E127FFCCEE445E92DD0957EA9571EEA224
                                  SHA-512:E01339A6C01120B1DABF5538059472F094E383F37BDA8AA865A399329665B35BDD57FA5EA29C462C2A8126B315F4C4E354CF3FDCAB503BA8DF4B1D7788DC1A0C
                                  Malicious:false
                                  Preview: o;6.o(vw.....54..$;.<.....Q.........Xn.... ..........L]....^..gfz|.....DXjm............YD...Cfa[].vz...E^......FY;7Hg..y&{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.......6@Y..e|f=}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):938
                                  Entropy (8bit):7.396990496854668
                                  Encrypted:false
                                  SSDEEP:24:AZbF1CKX96m+hPG84tFoze4ytP6qfHSgC0fNSZBzfteJTQRw3W5/s:Az9ohP7Ad4M9/xJfAXxuzmhs
                                  MD5:08C3D327F7398331F8E9B13EA8AC014E
                                  SHA1:98F1E9ECE1F7994D17B5DA4B0A529AC5FC659CAD
                                  SHA-256:D832E1F8C949E57151458F33FAB2942195334C0A965BDE44BEEEA269C52BDFE2
                                  SHA-512:1E426B6CBFE95CBF48490BDDC3B38C73369D5790F449400800C1C66781B4AE9E42BA779A30F477FB39335BBD683663260AA6B3522BCE7D3A000F40D6F609C842
                                  Malicious:false
                                  Preview: I.<..K.....f|....]B..m(eh....~$^....;.....I......?8...........gT..HNl?..yg..*-ll\#......FUroih...[v4!{d....U@.^......{rcWex{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.JE.c.s.q...K...}{.}{251}{000082000117000110000084000105000109000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}...~{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1807
                                  Entropy (8bit):7.589793304146797
                                  Encrypted:false
                                  SSDEEP:48:DnEN1769a1pj2Ad4M9/xJfAXxumHKPhf6g:zcDpjZpBAXQ0Q
                                  MD5:75FEFB16A970AD64FF03B3F9BF370674
                                  SHA1:6D7502B32E33DF4A5067C7F1CEA679923EBEF56C
                                  SHA-256:F42044474A8163DDEEAD756F545B9228A465ED0AB8849165B353122B95A28B6A
                                  SHA-512:A68648560DE3A8DCD64B04ED7F6A30B561A8BA66E0966AEB7C3EACE5B54C21E89A360C0CE868D43495221BA8FE75EA16FC90F0718F6DBFB8D30B44C4A5144730
                                  Malicious:false
                                  Preview: :n.{....A......3,..cq~;#..... z...@U..DC......T_.....01%"..`q....A^LV..)......4 ...{p..>/CX....Y.u|...JZ.. 2.QQ...............'s...L>..^I..stKKSS......BQ..j}....Z.>36#ez.............ttwwm2..1"mzmz...t7.........BV+7X_BBQQ..FF??..XQ}n..$3JP...T1<"7WH..eR..36>5....[\..QQ....RR.....ub......k(2?..c|......@u..hiidQLX.o\Oe..gg........B^..o|..'6,7>9...>7....U\......R.........7:.N.cc....Q.Z...J`..YY......88....)"PC.......x....py...~]L..............LL''ZZ..NN.SZ.............@UVIF@....\J)#(!.1.......7......ttwwqq..cc..((....ez..........P@+)#4...L..VD?{..QDv...c(MW....ge}lg`..........{{...vv..M...Z...........zc.....}m{d..|~......`uIVni|m_]S.q~{H..gg........BBMM....|06??,.....4...`g......DD..........lgIZ..ud..^T.2..``..........*f..8+.........N....))......QQoo.....>)......U.....SL.I=m..............S:"#tP..Xe>{~_................ww...fo|o......c~l/...........{>?.....mmdd22vv....YY..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS...
                                  C:\ProgramData\Microsoft\Provisioning\{f11899f2-71ec-4621-9997-e17ae2f6eb26}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1964
                                  Entropy (8bit):7.6976397782818555
                                  Encrypted:false
                                  SSDEEP:48:nP7VMXuEihlr6jIMd6oiaMzMAd4M9/xJfAXxu3v8WR1UB8R:nP72e7jXMWrpBAXQ3vz1j
                                  MD5:590BA6D21AA100B188C81498B5F77DF6
                                  SHA1:FCE15136E411745DED22B126D9ECD5080454B378
                                  SHA-256:BE7B340B3B3E01D210E9EBAB8E9E6EF3F6FF8AC4BDECA1A8A0AADEB977EA24D8
                                  SHA-512:C154453E827799C384390BF437DCD8740D4A374994EAD8849A7AF9A3997002FB7C71AAA588EAE8456E5ABA7FFB6AD07FE08EA40FD3DE3F4F99E96C9438BB8A4E
                                  Malicious:false
                                  Preview: h)-..<)1}../.......omGLtx -....67~5....34M&..........}...4!..IT-.'.htIx............&$3}._,0..bi....J*}w......b,GE......gc(LVQ......hj...{t..B.......EEuu....KV%%...............pp/!....TPa5..x(..=.?2uF....dx7.....jr...t.......Zw.....405~usi..Vy..h[......"......po..=D....qp............Y..q*..-<..ha..u............YYVJ....}sziaRx}^m......nO.."o'4.......884'....(..Y..q~..Z]....`q....^.H]/-....8$C.=6....q1fl..OS....PR.O..}y.B............Bq.................cPGm....,0......H....QQ;;RR=U"1...3.....`Bu_..}u*6....TT...33........~k....*.HH......ccso........3}..U]7(3..:{y@wmt............@@......h]...........LL__....GT.....gT..55.......31qv|O..XX]]..7.............>>..(;nl.6)*.=:!!............Km.......Xv........{H........PL........<?$i..UU..DD....YH....*g.............~..../.sY....44..55........uF.......&&..>>rnxN..............ZZ...UU..)5q\..1...05=6+1....QQ......ZZGG......BO......gf.....kl........gg....__.........W$..Pt..............VQ....))..++LL..hh$$??...
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\MasterDatastore.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):996
                                  Entropy (8bit):7.256058895003086
                                  Encrypted:false
                                  SSDEEP:24:Y+yP8PM84tFoze4ytP6qfHSgC0fNSZBzfteJTQRBY+rDPv4W5y:Y+yQAd4M9/xJfAXxu4hc
                                  MD5:4D0B45F402E91238028DA83B710308AD
                                  SHA1:7A9C6C0172404F50D3FA6E45CAF782EE659D1BB0
                                  SHA-256:947BB31EAC3FDB6566CED4E751E7DD4465FF490FA56512B462B907C6E551F339
                                  SHA-512:4E0C034A49759E50B3B479E0522578EB9D53D6B3030144C77C557E6001CF56813E95D2795C557655EE1D2A0D0ABC8245AA4E81AAC8CA6B60453648EDC9030D0D
                                  Malicious:false
                                  Preview: /{.~h/Z[h>..OU.....o}.......I......WJ........&(..ZO..a\....=.5/..Ar.....K...................)445[g`g....<0..YB.$~v/-......-!An....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Ar.....h._xR...}{.}{271}{000077000097000115000116000101000114000068000097000116000097000115000116000111000114000101000046000120000109000108}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4125
                                  Entropy (8bit):7.914939817788636
                                  Encrypted:false
                                  SSDEEP:96:P3BZbNCMgcWnepHyo8V5UdRgiGpJMRwZwxst4pBAXQs:P3LNPgFnepHAcXgiUMRg/
                                  MD5:4BAB02E3995F86D61B47A4305B00E6E6
                                  SHA1:E068C8F6016D5C4442916FBE5EC5C81B326B276C
                                  SHA-256:F89221C52080E9A662375859C8F11CC5CD78E0F1F114EE3F214788A70383B1CD
                                  SHA-512:1A810AA71B008591EC0748F70F583A57E1B68A18AE95558F11BDB5CEA1A1ECFA3F2BA2FB1DEDC2FD5C53E073F39AC4228F0F92D267294645FE420C64A634840B
                                  Malicious:false
                                  Preview: .U.f!Z[....f|....6)pb!d`m....;a...........gi<;..hn...........+-s ....iu...............nopF._`M..........Z.....}`..!.....GX.L...\....y{.....fshl....G...PW.^.02......UYp_.. .tz.......55Ezhz...#..yc....=3.......9....ZU..........%+.."7..Sn....kbH.<n2/p~'&...LL.......C...FF....B.......ch..ju....jo8hLO..%Adq.....,......Jp..d].EJ..AV..~}SY...&?....u..............pl......VC....-<..md.c1|a..on..M{..RU....z7l|....Y_...................jk..h8..z.....U@.vp;L64..2G%........u..c{...ba.$.....~ka/.~f'0.."7...+............36....vt......`.:;-"......PQZlK...<)yf....~k....+6..".......E.....TVnq^..........Z.....I......."7......... ..#8.':2c.**....v[Nq..3)I...u{.........5.....o I....LP....JA-1%..)...F.......b~.$ZR%+....tr........b:.....23_]Nx...............^X..6b............c|..=<+..%&../>.............Qv..|x....iq-:...........ZO8v.h..X^11..,.....8)99..0d...........CJ.........\Nql.......!#pa..{{.~...L^"1...............G^....1 ..........
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\0__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1752
                                  Entropy (8bit):7.637618124725596
                                  Encrypted:false
                                  SSDEEP:48:VxJW5qXJsvFPB9znVE2Ad4M9/xJfAXxusKPhfap:oqI9B6pBAXQsbp
                                  MD5:D0F2AC242268155090BC49E5C75F703B
                                  SHA1:14F5297B2760A1A726471F4086A52C0E2952B0D3
                                  SHA-256:7D14A227123F3678DDDE55C45DEB1D0D8CD307D8564171D013272A663CDB6F06
                                  SHA-512:B58ECBEE72173249515F714B3900E7D0054267F8877A7703643352E2DED71495F559FB204AC7172BE2F08ACAA2E664E9D3ADB51899D92177728A6C13C7BC0FD4
                                  Malicious:false
                                  Preview: ...56n{...@A...........($|qJCZE..Q.pj.O..?5.....=f..wj....v`.F..xa....34........55U.........nt..i*UX....LB..G[....II.fo..:->)]G...X.........../.;..........GEet....W]....,t3A.....Wd....""..............{q....g...,1LE..............iu83..TV....OH..........HN..= ....::....HH....\.............cv..Gw....^k....{vTI....T~....99......so%.@S..zkazni..)}..X.q`#*.......>'..yvcnk D.}}"&3g.C......EE**....))............toAF...............ZE..RUKR..B.(s...........<no}..).::00..>>pp........GLH[...................&......L}f|ES[\........cc...rr.........#0g*..AI\C.......!w{vP@........JG....70....$t..Yj.$..22........zzllcc.........d<`...................)<ah....e..|k..IX..uu]]....QQ--..''ss......du......Ar`J..xx<<__00......ZFbi.......ni......I..^I..........[X{l.....:...~~......EE........,=9&.......^S.........JZ.9=y;.....l4.P..,.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{.
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\10__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2733
                                  Entropy (8bit):7.776496906050794
                                  Encrypted:false
                                  SSDEEP:48:Wjq2+3ByuiYIheszJZllvPQwZy//B9/NB/mRjB15EAd4M9/xJfAXxukuLPhfz:KX4yuiYmekXllbM/Z9FFmbpBAXQkuF
                                  MD5:6567191B36AA1DA7F6CC63B50BC34738
                                  SHA1:CF06FA160FB0679F7951D44CD9086391390B80BA
                                  SHA-256:852D2ED97EF16F9DE889828ADEECD3AB6ED6D56EFFC86CE766E56D542E4E2784
                                  SHA-512:21E9880D593470FEF823B8846F1334EF0AC682657BA4F4B51078A1AAF7C85820C15A9481964698EBB802D822335AA1268660EE40C872AAB0EB3ED882912B478B
                                  Malicious:false
                                  Preview: ......wv:lgp#9..\Crm........_Xv,3dugqd...........FY..r#>?......L...;$<& !....{w*...KW......................c.L............@QF])......"z..............##G.............ehI\........EY..//;;;;....2;(;..?(....#`=0....}}..............GG......m~....TN..~=idep..].bn..........7777..$$........RCTO....Q...c;..=6;3..ZM....................++............(2...\............^^...zc*/........CC.Gw'db......' ....11..""""hh.......................q~"q98..pu"j....6yxz..Xi<ol*y..K._C....KKKKOO00....!!ww....................._L......;,...Ra..{{{{..........xxxd..sl...........IK.................].."8................))))........aaG.........<....A.^jgIY~a!$64....,!GR_@.......O.....8hh..2244OO..RR}}iu.....l<+QF.....FA...&&....JJ..>>...R[|o}j;,......|q........*;....hU..A]....JJ........qq..nn//a-"1........!1..7Y...- ....+8..{n.....G.......HJ........mm..EE....DD))DD..0}........d}..+}..)9ez..x<..j...n6.../-..^\fwZ]ii..22''22mm..%%..........}lVM..MG2...pp....mm..mm..%%MQfm..om..|g
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\11__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1932
                                  Entropy (8bit):7.644002795045823
                                  Encrypted:false
                                  SSDEEP:48:FajLYBPc6nyXo3g+hR+CFXpQCJ2+Ad4M9/xJfAXxumZ8Phf1:FfBPvnvw+b+C9N2RpBAXQmZg
                                  MD5:2A07883FC9439FABBC4D25FCAFC6F91E
                                  SHA1:061877A89F24CD746AFB78AB118C2535C6712B36
                                  SHA-256:5EC18C865DAF1BBD8C70D4939D89FBE1B824722DACBFCB585AFD237B1834875D
                                  SHA-512:A88C47B51AFFC8A11025E69810213CBB181CCF659777F9906E22FAB71EB9AD66F0662DAF82AD9EB532EC38637B3DD90861BF7D1FDC008C8B772672981285F5E2
                                  Malicious:false
                                  Preview: .PT..AT....y..Y......ja."WZu|....G.siw$........_..NX.....(....UW............XX.N )....ds-7...X..U@..jd1$....ll!!......L[CT"8..^.YTAT....0"..L.-........6%...XC '* .fo...y# .$......nn........dfYH....q{....G6...........$$....}}....%'bs....f2.....ql..DD..c.....NN....XX...Qpy....I^.....p}*?....(%..rG.._^.....B...4gg......................E.....xqR.....F...Y@.UWJ..=0...ff40.....V-.Pz..[[!!55....;;KW...[Y*;hs..[Q.........:>rv.N..`d......jng6......]U..o?...2(.........jj......B^....9;.?@[>9CI.TdmB.s.~m....^^MF..wk......gg..hhqq..XX..NN.....4;..@_pW..>'..W....YF......K^CN....ru.....U'(]nMg..OO..\\..xx.........k|!6..7*w*..gg....UU....CCzz.....9*..gp....p3......BQ.. 1..,:]`...PW....rrtt..ssii..WW..!m?,.. /........";._F...SC..]NX.......'...PJ...........aa--..WW.........XSgt......AF~t.................VVMQ....(*VG..G@ak#w...0Q:".......^m.=......**....--00^^2.....Q.ie.P..bW..p`..NY..M...@Rr6ly../&.]....,....m|..@@**((......""............vm........dd..JJ..//.
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\12__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3703
                                  Entropy (8bit):7.8275948181281105
                                  Encrypted:false
                                  SSDEEP:48:ZDL9S5VAdy1nD853hbAlN9FlhYJEZOvzKbxmG80s+vK4PcEmEsXAd4M9/xJfAXx2:Z9S5V6K93hYJOsKgG8rlWrpBAXQ7/
                                  MD5:05C8DE90A52817828B003C0806C506EB
                                  SHA1:583E973CAB5C06BFEB1D0B58E53EFCCCD2E9F8D2
                                  SHA-256:1729636559E7CA522426774AAFFA0B2620EFED0813101CFC65A0122A162340F6
                                  SHA-512:1B9DD7D4F29CC81DA125565CBF669D5049384AA9F034D1BE94BF0F678AF22B1DF7F730D376A183971A6D01DC1A239889F075FADF5CC38C943B200F8CBF788F50
                                  Malicious:false
                                  Preview: 5a.Q<{...fq..........h-obFMho...Oug....{|..@E..5>.....U..........HW}g..WPmn.....*....uf..{j....fl....'.....>Z.............BS.......ha.........DC..llii&y&/..ynBU....D.GJ-8..c\mh;!!=......hh...Pfo..PG.......M....#<..IIg`/;........??....K.......)>..lq.idh}..........[....##..##''_C..fu....PK.........O......ZM....SV............UU..AAbb...........\A.]^SXM..........I...........jr...=mECpr@.QM.........88ee..cc7h..1"..ny....s0....-2......,9...5b.......:f?nd6`a~r.^B^JM....EE................bu....w4....)6cGrL..HA@_p.....Z]ll..ww..;;......^^....h{F._Pdl........l+4b]P|l.............v...............{{..OO!!..44........JYB...ai....J}\E.:l/".o..]\..R.CVH]...J|7kq "........>>......WW............`b....vq* .........[[..nnoo..PL..L_uwWF......e1...H.[LhJkmct..........og!=...............eeUUI...S.`ock,3(........bovf....}.;>..........1 ...W...3....11II......####....-2.1........0 WU....[.,<>,1u.........mwfd....paRU........eeUUUU..^MQZS@....g|fa!+n] .......nnnn..ww..
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\13__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):8779
                                  Entropy (8bit):7.957046184724903
                                  Encrypted:false
                                  SSDEEP:192:2wKZMx0FS7OtjOaw0n4MAMbXwirikPTAdDMUY1AoNe8S:N+a0QOtjOaRuJixPp/Ne8S
                                  MD5:80A4811F82182BE4A307D009FDCD9139
                                  SHA1:61383C62C59AB3B8EAEBAA5ECAD34A5948D07143
                                  SHA-256:275858D59B295A8622FA402438656F0A0D3605D4C6C113F852F303A4C060FE8B
                                  SHA-512:F2B7DACC1F1AEE4EEA1C5F898415A372660497C625CD89D55CB81F0063C459FDDBAE73080C2570B090392DC7311D5E76D00544CD66B5725CEDE1F06B4C59E373
                                  Malicious:false
                                  Preview: ......;w.......YZI=#......]P....`+........he..u-..........>(..]_ul............AF...TBK..BU....5(........ .........q.....\KXO :...<@M5 ..+.!3_...=.......")....vg..UR,&)}...*Xef......v\......KW..->...n....Q...9a)O...........AF..::;;.....W^..MZ..jp.....U@..zX..wa....(2.99......ii..!*........ST........|..2%..,*..*8wFlvLZ..LDzf....cc.......R.}t...........-8tknK%"......''aa]]{{..xx**.....:-4#5/..._....D[...#....**....ee.......J[;$........5%DF....d<....Y].....`u.....T.....NY..hy......................N]....(3/(/%kX.<??..gg..::..........6!..c~Y.....~~..\\.....K@2!..AP.....u?...........@@........m|...ci......r.......sd.._n.."4..ck..9>........tt!!!!)v........lv...M..LY....52..~ytt......dd....LL,s.......Z@4).?2....xj.......................[D\.=1n6.....%'....N,?..\[......wr....0%.........U..!...............!!......NY....;&....::ddjjvv...........vg..16.....YY..........PY...7 ..0-%x......<<..99.......yh..oh..rX......A]a->7....4#JP..J.....--..vv.....`w.
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\14__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1529
                                  Entropy (8bit):7.533798316040648
                                  Encrypted:false
                                  SSDEEP:24:daUbinORqhOv8gXyT7orHklGOllOF84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAum:daTnORqh+WQg5rTAd4M9/xJfAXxuPuPO
                                  MD5:BAEEDDB88B75E98B322A2D1409FAA1C6
                                  SHA1:5545436BE52AD07F1E12F6E7AC1ECEBEE2667B45
                                  SHA-256:E92A5630644A19AD174623D32B3FBE4D620208475E95232D324589F7E96D945A
                                  SHA-512:63DB7DFDD46224C9A61C68D5BA4D345E6D282925843B66248309E1D00265A9F6AF113332FAD992F5B146858AF89C30F5E18E344334B5001BCE3C2F0EF07CA68F
                                  Malicious:false
                                  Preview: ..%....VA@Z............^UX_...EW..df..ZU_ZNM..nq*6C.@A..%n...c~gx....hofedh..2...u~ve....5......Q.....W3..............LW9>#).Sxq;c|.....*6..........=4..8/>)..)4.............< X_uu''**hht+09.........<.+&I\.......................H.i`s`7 ..ntsn....AT......gqqm....7.....44......ZIZX............7op.bi... .............xxxx{{............NY....-n......r 0ddd.../bxa3................jvEB........cc.....cj....4#.........kt.3..2+......>......"qh~h..' VVaa55....WW.......xq..........4w.......3.......vT-.%2..............**..RR^^99::...Zgt|1kdai..Kl....s45cwz..XG..GEPU..YT&3..QV..TV.vy....xx..............rn..qx....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\15__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2075
                                  Entropy (8bit):7.193906302433658
                                  Encrypted:false
                                  SSDEEP:48:vaFIQqM6XwP/EeTD1prfAd4M9/xJfAXxu8DPhfA:vaFfqzuJGpBAXQ8q
                                  MD5:F637BCDB808F789167788592032263D6
                                  SHA1:A87AA12834B84071030801647B93F48B29FCC918
                                  SHA-256:E47A67AF25481A7CE5C023C567072E1B38894453CDF3218BC0D61484D398646C
                                  SHA-512:B16190C9B6C70621DBA4040FD2C25AD27B521E277BBF75422C10F572C4A7966D8C18780D2668E1A3CFA193552A35E2559E8317F3AF26D788A74548A09CA67498
                                  Malicious:false
                                  Preview: ....J..!w0'(2....D[..E.&+.....Rj=..~k-/......^]RY....H..~RU.(9...RM.4..<;QR3?..<.....]N......34..4`....g....t.3:.......</...........K..-u.e}..os..........1" 7&1*0...H....9&Tkhmg}JVebHHHHcccc. +"........pmg$p}taUJ;.....$0a}NIccHHHHHHHH8glevegp.......H7:3&~a.1.......J:..$$$$$HHHHHHHT +"1" 7&......H.}ta9&Wgl...8....-"/*7:a}ebHHHHHH$$$$$$$$T.......&1*07* c....UJ[P5f0666)b^Q\E\Y.Xnzu{vn%%]..Z^X..6a&:..$$HHHHHHHHcccccc. ........mwpmg$p}..UJ,...6/7.,4&1;.....>.hqaw&:..HHHHHHHHccccccccHHT.....gpavmwpm.H....UJ.&1%.& 1....<...&:..$$$$HHHHHHHHccccccccT....H..ia9&EgRe...JH...6&~arsac........9&mjpaca.JHGVebHccccccccHHHHHHHH$$$8teviH....UJ, ."/6&ac.....UJY4&$`epep...UJ...&$&1acl}ebHHHHHH$$$$$$$$HHHHTG.."1" 7&1*....VebH$$$$$$$$HHHHHHHHc. +"1" ........$p}ta9&T...!...."0&.*.&aVebHHHHH$$$$$$$$HHHHHHHT3"1.c-"..UJ).>..qa&$rehq.UJ[JH..7"7:3&~a.......J$+:..$$$HHHHHHHHccccccccHT....H.eia9&@gR....JH../6&~apace`u`uxqd.._XBSQS................kkkkkkkkG[H.............i4..****xxxxxxxx0000,?sx</<>)8/4.......
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\16__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1333
                                  Entropy (8bit):7.42594287151479
                                  Encrypted:false
                                  SSDEEP:24:BJNnRyUJWHJ3aS3K/XG8hDvoD84tFoze4ytP6qfHSgC0fNSZBzfteJTQRQq3cl25:rNce8xaS3KOEAd4M9/xJfAXxuLq3MPh0
                                  MD5:978D42CD1C7024F174F0FC2345FF1BE4
                                  SHA1:079599AC6C2FF20416196AB5E0DC85985CCAE93E
                                  SHA-256:5E7751FB9B5F366B4BEBC59066D69716946BB75D746219C74FC875ED8411ED5C
                                  SHA-512:15339C1B31898C15518753694276316AD569CBC957C73F8C5AE410729E6AFEFB7846F236643FDE338C079DE5E15E8035CAEF61DD87DFFFDB701BF59151F52E12
                                  Malicious:false
                                  Preview: j......h$L_[Z......yg....:6..kbgx..C...3`....)$...F.....;.[m..b?..&?..!'.......S..zzJ......:-7-EX0s2?oz......wp..UUX.AH..(?.. :zg:y..k~....WE.S..+...oo........+:~e..HB@..........9........./3............W....y...c~....$.......00......:8.....6<j>...K........7*.............#|) 4'{l.........>+..vFs~/'........GZ..WdJ`..@@UU....++ey29..46.........cj.et..[...}b.K@M+2.U..JE...N......O.(okX....DDBBTT....++..ZQFU[Y..(3......t}.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{..
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\1__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1725
                                  Entropy (8bit):7.609156241790787
                                  Encrypted:false
                                  SSDEEP:48:0GYq+8SZjaV6W/s540laNAd4M9/xJfAXxujGPPhfd:01q+/dmA40JpBAXQ6f
                                  MD5:5E73B731BDF06BA296917A7019841CE4
                                  SHA1:CD2298FD41F7B920FA4E303ECE1ABFDFD5E5F8BF
                                  SHA-256:75BD01100CB16752316F5C6BB68C85B3E85C0654F985695ED6A2781E3844921A
                                  SHA-512:1735AA361BEA8AB70A07F5E99672F36533A29CADD6ED0497E9122650B5C67F03C8D47EF142DBC23A6B0A8C6DD9931C95FE222CEF4FA033892DD12D347740EE49
                                  Malicious:false
                                  Preview: ../.=z^_.0'........!3.....16..~):(..'%g`lc....hcju...............HI....w{..4.......MO..WPSYT.....}...t.{HiC..........GV..ST..7c=4{#T&..+<uiLK...................#...ls..PU...>9..((..................@.^S|i...#............{{............ub..8%.......|^....~b.........DD**[[........}l....dnc7..[...AJ..Gr.....gb........WW==NNaa........#0XO.. :..S.49........MK....................wuV.......]]...........@......`wg}..|?LA............+1}}*xFRE.SOz/;2V.A.h=V.........$$..ii........cj..W@......r1.................<:........77..gg00ffDD............(7..Ny...m;- ..|c....p4..>+.....>$:8............66||VV..TT........WDEG..........Nd...99........yynrk`yjCA..VM%".....L.....aCX^MZ...*is....$,nrkl......KK...oo==....G....fiXPOP..Zm...Z...&6d{..vt....NC..EZ....?=x(>1o\......yy..vv**..TH...^M..{l.....LK\\00....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\2__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1373
                                  Entropy (8bit):7.445428860380203
                                  Encrypted:false
                                  SSDEEP:24:CvEsJIjjSAWH016D27/hB84tFoze4ytP6qfHSgC0fNSZBzfteJTQRa72QG+JgW5M:CsP/SrH0Y6EAd4M9/xJfAXxuN7Phfm
                                  MD5:55B4F0DD5C6F24EED21605461B51B281
                                  SHA1:A7F7EE69035141FC7964E537194605D7B120B88A
                                  SHA-256:F26BE3AF4AD4BE20B6572ABDBCEA6B9DA1DA083F44FDD430324D1086081FD1A8
                                  SHA-512:06E158035581CC4886890DE160C6E9E687E16AAA3CBE02A076FDED3B45F7FE4F1894B98DF032E9270D282B20732AD81432F594E41654A92A99D3F782ED1A08A3
                                  Malicious:false
                                  Preview: ...|.........\O<"wu..Q]..JC....P.........fkCB..S............{b....`g....".ho...kb........TI.T58....)'......rr77.A..zi......ROH.`m.........WZi.;>>.....#0....CX....:n..W........"66..\\..t.....cr....q{m9t}.........r#.78...SS]]..........shJM...\U..i7*..ccdy`|..!!AA..............0'_Eex\...'2hw*...@H..10WV.....bQ`J........44....:1......QV\V.....U0!..T.NN..w'....g0....obr9.W..IM.p$.*.3............qq....BQXZ..g|@G..^...C..K........`c..J...............F.!g......%%{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ...
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\3__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2068
                                  Entropy (8bit):7.68679127073774
                                  Encrypted:false
                                  SSDEEP:48:3ZoUsVZLXlmJTAfdDeUHHcDXxRNRHMUAd4M9/xJfAXxuGQ1WPhfb:3ZvsVdIuQIUXrMPpBAXQO
                                  MD5:D6CAFF765450BC60837262F36E43A7BE
                                  SHA1:20631277A51FDBADE49698FB09DADC9497AB6FA0
                                  SHA-256:94062EB84D544DB573E4CD6F9AE7F1BD1FB819634AED4D4C7C6A0FE81AFAAA1D
                                  SHA-512:0801CC6080FC44F79403748757C58A628D01348F22169AA1221660E7E3759F757846362FE31B445724626F7058839E451E23353A5B3A49CD5E5E467CE583DF36
                                  Malicious:false
                                  Preview: ...wt..7{.. !..f5........*&.........6,0c..bh....q).W)?;&....NX....fhr-+..@Igl.HO...V....;,..A[..v5......ig..NR......s,..^M..RE....O.........hz.\...,......CHcp......xr....h.....M.{H....//..*6..........G@..I..........|u........YYGG............jm..............3>"........aaWW....cp....hr,1}>..yl...................UfEo........XXII..%.........y~..x,...B....Q.[[.....ZC...Q^....U...KOW.g3........99..HH&&..........5$....6<......U3..8,..A~......=5{H.......^t....CC............................p...cd..qf.Ar..kk..II..IIzzWW..ll........tx.DE&/...........|$..........CN....(/;*" -}..qB.,WW..''..11MM--..xx>"..vi....v......wg.......3 ......>+......,+....}-..4.......__......II..........qf.......=:YYGG......EE..99...............58ly...:....5.......utOS..!!xx>>..))....EEQQ.._........VI.,.............wd......o7..6,........>9II......WW....HH.....C...Y..ld......HQ.9o....;$.......$|...:8......z}..yy..11MM..AAxx>>...... 1.........................W.........&;......#
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\4__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1988
                                  Entropy (8bit):7.681821833526171
                                  Encrypted:false
                                  SSDEEP:48:+cb46Oy9acxrS214MWAd4M9/xJfAXxuPcPhfr:+M46OyIc5S+jpBAXQPe
                                  MD5:59B000ED683F2A9CF90431BB3902F49B
                                  SHA1:E5BA28407D78DD53479EBA2E5D5F00A4368EF391
                                  SHA-256:D0C7F47B523A2F31C65B53D3B4A245B7A660CA12D7AEC232B76495289A2FB39B
                                  SHA-512:573F52F250F2AAAC5F294FFB8CB1F6A5D9F140C9A25BDADA89A682B816E953CB24333EB30DF7E7EDD0FCB86FFBD61F6165BBFC978E035F322ADD703739048B17
                                  Malicious:false
                                  Preview: ;..uv....S@.....Lwd4*..zq..R_...........(=................I..S.zx?&IS..cd..ne..in..................vi..dqKW..VVM.:3......)3.....gr..,.qcx(..".mmss[G......ZKhs.....Sle...WT"(......~~33....bi}n....to.................#.1..''.....*!.......be....<5..4F..............00..qq..... /&'4..............K{..W_.(no....vkh3..bH<<.......................}w.J|uf>....W...PO.....f\...fi...@@......A..T......WW..gg@@%%....1"..)8,7..-'@........V..... 9m9....R..............OO..kkxx..II...VJ..3 ......34......r*.t..`Cdo..Qx?(56.......$.::......55......kk....~0r~....bW}p....pg..................@ZtvZM%'.....iiJJLL....11..yj..wd........PZ..+.00..qq....ccggui....................mm<<....??->....}.....STSY....GG........4(]Vdwb`....FA..B...J.pk[\..hh......F_......AB.........O.&e^m.%...pp..}}~~..dx................../I>=....4...............eO..kkxx..II...VVQM....sq..{`........v..BU^}do..\u..OLav=0.?..2....ff..::......\\UISB..r<...)O.........+2....#1I...rg..'.....V
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\5__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1596
                                  Entropy (8bit):7.582582575918077
                                  Encrypted:false
                                  SSDEEP:24:HVMNHYYv1K0L17+0npB3oY2a+jd5Z3ZwoYr/qa84tFoze4ytP6qfHSgC0fNSZBzX:HVsHR17+0n3zdSAd4M9/xJfAXxuwPhf1
                                  MD5:92E816867B16B8AB191C59B01B654EAF
                                  SHA1:48BC24FE88F1B2040CBC0E82065D9C29BCA04053
                                  SHA-256:8AEA6FBB0295450F567B0920486768851DBBBAD696D06BE8CBF99F71C0EA96A4
                                  SHA-512:7E46BF66350F3E755091FB65B30F6254D6567635069C77F162B92C1AEEC8B0853A8144FA666034D1D9F0BC5A4216073C3BC5EA884C5442B889AD709C797BB080
                                  Malicious:false
                                  Preview: ..........~...........0;ma..........}..YS....H...................y."%..@K"...GGk4ng@S.........LA*?........``((7hPY{h....Z@...$){n.................XS............].SZ........I..........$/............e1..6n.x2#ro..,}.'rX..............hy..dc...T...........wj..QVzzee66....``W.......*=..2/.D........{v......RS....M.+...ss..........*9wu....ts..m9......)(...`x76.Z....ju..'#....89}....KQ....\\66**....XX...T_........dcsy..+"...`c1%muB}...*HC.........@...:mm..cc....""......ib..UWq`jq.........H:........R@Et....vq;3..........YYtt..77//||\.....)&..WH.......\...6&..bcUWVS..v{........20%u....?.....''ee{{..//tt-1.^>7......VL...........<<....pp.....OX..bx%8y:id..zeBw[O+......4......+-..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.w
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\6__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1418
                                  Entropy (8bit):7.502023720273251
                                  Encrypted:false
                                  SSDEEP:24:uWwUBwSkPe1tKy6wCwYBv3fdMl84tFoze4ytP6qfHSgC0fNSZBzfteJTQR3cl2QB:zwYwc1tKrz3VPAd4M9/xJfAXxu2MPhfH
                                  MD5:908A0D59678B84B468B186556A249F40
                                  SHA1:A6048F3CA1ED4A5149AFE4910A22CD9E7D49BB54
                                  SHA-256:3DFF5B05B1A314785D281672504296F5603FEC369873C2FFAB8AE5C68B6D28F9
                                  SHA-512:790B7AB805B9EDFD0CBE960782657A91F4D93EE856DBD1064BBD6F6D73C314072A933671EEBAC53377ADF04774DF28306179FBBA0456A2707666643A7B6EFF39
                                  Malicious:false
                                  Preview: G....8-.........FU.....3?..HA.......d7.........l7YO;&...1...........']V....\\..R[..1&....+6..LAwb....RG+7..ii>>............!<.DOB1$UJ..../.[h....II.2.....$5..QV...[RI..gij...S..gM..........4'..n...70oe............b3O|~T..yy..........|m,7....C.....+Y............~~qq\\..RR..)vbk..1&.....S....kt...........a|.............[[....sxxk..APD_.....F..t,..rs...@hp32...q#..if.........O"x*+"8....hh....hhpprr....^M....cx..u...$-......]I..gX..hI..V^.......!.9.......CC..22..DX......"3......) ....$.........w0`S<.nn{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,.....
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\7__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2946
                                  Entropy (8bit):7.816220478654101
                                  Encrypted:false
                                  SSDEEP:48:Ss6mtO0VISac8tHZeDwjGvy0xTaNTMsNftdzwO/L5uYaHkuOxAd4M9/xJfAXxugV:SYtMi8LeVqAMTMs3pwOD54kZgpBAXQN8
                                  MD5:189F3EFBDD569A97C5E2743537F14E45
                                  SHA1:0753EF02084CCC1082473FE54A727E01FFDDB1A6
                                  SHA-256:79EF46B591B8799B31CB6EC00A5E87BEF0CF07EF48F0F123007CFEA7138B071F
                                  SHA-512:33B7081AACAA2AB26ACD6628D13950DEBA3D39E515E906F489F2FDFDC28306170AE3C2CFB399518CCF8E2A59ECD8B219127BE36C5CF62F834215CF28B4C4AB80
                                  Malicious:false
                                  Preview: .....<)...on.......uw....=0..,3.....1b..zp....^.....?.eS..." ..xb....I@..Q...EEQ.......@W................?8vv.........ER....Q.....PO.....[s@.$dd99_C.._L.}du<'PWW]0d..*rX*IJ....7rXDD......YR.............NR[...sb..<5 q.&zP..............sq....IN....NG9a.q..............**~~..uu..[.....zm...."?i*r.......3>....KJ......h3.3......--.....%.RAAC..vq...Z........%%...Os~.....P].S.W....].&rk,{H}W..........,,...... 3....5......GN......2&......cB.....$.....rA..cc......nn..gg//..}v..NL..%>Z]..^....N!<;..UA..L@al.D......DD....llOO..__..KWHYvi.R....r@u..td{y....u-..I[.?*.....G.1+..(?..........,,..))..88........Q.........dS..%b(~......ca....lyxucv_@.............NN..EErree..ww......=4....UB..........,,..((..QQ..o0...qf..F\......................#4}f............xx......iidd..wfnqH.NB....*'..uw..D]......i-......6}uo.........AA....vv..............~3uz (....l[..5r:l..td..xz..&#YL=0........46..na...>................g+..l.?(...@]x%ST....tt..55......11.F....avh...g
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\8__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4114
                                  Entropy (8bit):7.8579220716705285
                                  Encrypted:false
                                  SSDEEP:96:bmdeGAQ0xNbu2+4cc+RMyEYMH9tWRd7N3PlkyspBAXQcp:q8U0C2+k+R5E9G9PG4H
                                  MD5:6D93B7552CEB488684BEBCFDA9DBAFBD
                                  SHA1:4EC8F214668ABA9D0817DBBDF7E6B60D901FE436
                                  SHA-256:2E329D9014644364E9186951AFC682C314146FBB3265AF42153FA1F7C7029760
                                  SHA-512:C1FA90C31046EF6D3AC62DCFC495B66EF3E65C61283BDBE3EB410636C180EF43EDB3BB429430E76FF689408E66A9898459FEC69B9760F0D33E88F0E77D052F68
                                  Malicious:false
                                  Preview: ^......`s....@.............B]...VE_l?..XR.......M..-0?..%i...:8..wm/)9>..HCO.\[..8gleVE....uh]...MX........IN..99.....SD....%8.C -..9&.......sY....rn......+:........w~?g,^~}.......VV..VV................p$w~..,]..XE.._...+.rr..gg........|~..ot..ka..{rI..h..[]..XE..:=..oo..oo..}}.5<..........u6..fs.......U`[Z"#HE.......PPRR%%RR..II..............$...4=..........@_L.KF..........A.....Yl8X.Tg.4rr44..TT..TT....^U....duybcd...~w..ZL\_.._Y....K.............C....D68xxO.pCEo..AA....\\**\\........uw@Q..G@....sz... 3......HC..............AA..AA....[[.........tkVt..{b........1.sv.."'..*'..c|....ZX...DwU.ZZ..--..--....nn.........GK.....[V3#..0'..!y..tf:~sf..kbU.{0`z<>....]L..ll......dd..99..MM....M^^\n...in...._u...aa..aa..++44+7bi........^T.....C...:....CQ..D@.pC..vvXX..XX:://ff//..............Sf..IY..........X]..HE....UR....|s..oE..............ww....XI...R^..B$.+2?....0'..#{..75..at..}h..dc....~......?......!!MMCC....';........G]$9v+*-YY....HH.........@le....@WP
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\Prov\RunTime\9__Power_Policy.provxml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4114
                                  Entropy (8bit):7.874242829003467
                                  Encrypted:false
                                  SSDEEP:96:k1M6hwKsqUu4rcaY/q7eg5Hxfb/iKiOlF3/pBAXQap:QlhPnT4rS/qKwfTriOlF0R
                                  MD5:3CDA76A990516FA45A890C0D930F0C35
                                  SHA1:9AC62941844FA7FAAA916A9D9556A48B3BC772DD
                                  SHA-256:CC0789F7CD615EC3BFE3DCFABAEA06B0298F9F441C741B12B05057BEAB2D6776
                                  SHA-512:E00D1F16C1C91F6C18832DCFA18C05123241B871CDCF9B08F7EF399E3D508C94327D3B628AC082E299EC8915589130C0270892A72150D61AA4C064F53A4609AE
                                  Malicious:false
                                  Preview: .....~2.......%6....ZQFJ.#gn..SR..RH.....CNed...xnzg.:......om........OFqz9dbe..._;2]N..h.......BO 5vifh....tsuu>>.........]G.....{n/0|C..m=8...TT.......[Y....i=81..V$....3h..hB........en....pakp[\ciD........uh..)xaR.)yy.......AJ..-/<-G\..gm.....U.......LQ[G........@@..//..CPav?(F\.....h}/0......a`vw.....Bq....HH!!...ss.....-/..g|!&v|.......FO.$$...Mcn........bo.Gz)OO.......5.Sy..tt..GG....OO....ra........ci.....NM....`|.........ji..U.......>z.&..hh..wwpp..99..;;....^MOM......!+.Y.........%311..,6..........--......||$$.....k&CLqy`.6...=$.J.B.."2a~..SQ..YLwz2'......df.@..Izj@..))MM....**vv...8)IV..i1..sF....pr.....^........RG..U.E...9;{l....beYY....vv..!!..ll##......(*....pw....T~..MM....hh......EY..GT..WFF].....*#.G....tr)>WE....Y....<ss.......NNCCuu..zf....6x.....`..WZ........!ypc....<),!H][D....$&....:hB..~~..........nnkk..8)..u;..>f.]h'*WG[Y..\E.....tq....................~~,,..ww..%%.....bSZ.......ehu.JM.........??,,--ww...?,DS..
                                  C:\ProgramData\Microsoft\Provisioning\{fc01e91f-914c-45af-9d7c-0b2e5fbedf62}\customizations.xml
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):29106
                                  Entropy (8bit):7.987136767740447
                                  Encrypted:false
                                  SSDEEP:768:2JJYiBMbPMD38syidN+G0CRIHQXUC+GL6KLGbM2:2aUDMmdeC2wX9+vK6
                                  MD5:0F20EB13073B8DF970D29F201FBE2C36
                                  SHA1:DA0202D0EE157867660A786E513E69B5950845E2
                                  SHA-256:F7C1A08169DECD409A0A46BE3A2D5B6369A5F475152045E98B7278A7C686FCBD
                                  SHA-512:A16B67CCD01C2DEC0FA63BE2F6465B4C95D3D3806BBEF2706A4DF8E97AA6C18DD20D1E7495FE403110A007690EAA9C20DADAD34841C8888CA0C8AD8FCA3FAED7
                                  Malicious:false
                                  Preview: ..W..A....ny........;)../"..kl..S....ydTg>.`^CI1)..f`....:!1,..l!........t~...IA..(pED......T........M......ah.Hs...nP....T=7&O.#........>6gi..GXJX..4.......g"}x..6jB.H\x}.......F..O.......Y[%!.\..v...aa""?Muy....S.bTuuDCBV.....{{...6.}u......vj.-ONsu.T^^HV....VW+-....gg..{.3*....n{..V\..WK..IZ.....)U\..kl.....b..~+[W...Y.;<..;;...i.{y?^to..........ICdf....#-..">Yo......%}$%......f2....59...WF6*u|...A...t~WO.....PJMK..[R_C]Z..MM......BF..kvONk&;<....WW H#0'%NI..gM....]]....AP...y.{U....kz..........NN..........i|\......55.........r....r.....MWy*k'Q............Nd....uu&&.2Q*VE[Y....ET....ZZ.....y.....B......rr..+C\O~|N.V{a~..Je..........@j....??..DXAt..M\....k0|{..........%%W(..........}qJ..............qs|mBE.....==.."1..........t/..>>....hh...ATJ[..Gm??jj.....6.....l.Q....Zx...........2sy......PPeeSSLL;'zO2'...+SFj1..mm....66.............i.ie..Z(..^I......qn.2........Q.e7.. 1..]<.......&..400//....< h.EV....&3..$.....uuaa.......S..........a...
                                  C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.db
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):99174
                                  Entropy (8bit):7.988674511513006
                                  Encrypted:false
                                  SSDEEP:3072:N9RhHSqGiOt+uFNquO2kaxNxiegHsP9X8MRXbhr:1hBhi/O2kSNxbEsP17Z1r
                                  MD5:6BADC2C5C37BA467AA2C311415B5B36B
                                  SHA1:6857925CE1F8C2CFE87FEA41C4D63AAFAB9B3EF2
                                  SHA-256:3596C50EEB7E7EB36F834DF8F076E2F06997991EF36582E58139146F2372E9BF
                                  SHA-512:539E158938CAC6284167D774697AD0B16AC69642C7AB4636165CF7ABA1DF589DE24D114C4CBAE67AE7D7DDC3837E5FFBA9C57E6027F4C0AF4D10D470418B4F2A
                                  Malicious:false
                                  Preview: IWf@..c..trrrYYPv.........9sn+.&;MW6:LL..::::..........00........oooo..HfJta|.!........,,CCCCPPFF....##..```H.J;.\bwj....bbbb............eeee..............((GG....TT........]]]]....----ee........++++nn.....99bh.......P.BBB..........FFFF//aabbbb.................FFUUUU..<<rrrrYYPP........@@@B..==::::LL..::::..........00........oooO..H\zzzT..........,,CCCCPPFF....##..````....llll....bbbb............eeee..............((GG....TT........]]]]....----ee........++++nn.....99bb........BBBB..........}}...F//aabbbb.................FFUUUU..<<rrrrYYPP........@@@@..==::::LL.....-...z.....00........ooo..;NfJta|.!........,,CCCCPPFG....##..````....llll....bbcb............eeee..............((GG....TT........]]]]....----ee........++++nn.....99bb........BBBB..........FFFF//aabbbb...............xx..]]]]UU........ ..........GG....qq......WW......~~..66..~~......KKTT..ii~~..bb............JJ..........zz.....PP..RR""....==..KK..........EEFF..zz....aaKK..77.....ww....SS.....
                                  C:\ProgramData\Microsoft\SmsRouter\MessageStore\SmsInterceptStore.jfm
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9067
                                  Entropy (8bit):7.926422622220849
                                  Encrypted:false
                                  SSDEEP:192:XnNHJkOS9m4lVNtsCJjX1aQ/rtrNHzBdZZbX+w8+NxlDdO:3NK9z/sCN1aCZNXb+1cJO
                                  MD5:273CD19DD7C868C012EFB4EE43E5ABF8
                                  SHA1:C3A1CAE919268BD890CCD38083EC5CD09C968A0B
                                  SHA-256:62F81B7B10CC03ACA636CEEB8A616A5B675BFB4D485D07B5C29D24396F849931
                                  SHA-512:DB255F6B0CF34F3C88C8DDB1674343AEB4D1659BA805215075BED24E670ADBA42606CDFDE62D6F16F17289D42ED73891732049383FD06F2470F595AF7B61939E
                                  Malicious:false
                                  Preview: .............II..ff......zz..AA....''HHOa....XB...........,,..&'GG..$$........[y.........N...........88..]]......I.JE{jw..0>.............NN.... ..UU^^....99.........44..AA........;;..??~~....''..((nn..$$qq....BB||$$..ZZgg......{{--....CCJJ......22..TTpp::??......AAee........BBss.......wwkk.......55....AA....ZZ..((....................@@...rr..jj..........))....~~$$......((.......................vv......qq..........ff..gg......``........KKAANN.....cc.........[[kk....''....--....==.......99QQ....00ii..........JJ@@........nn....qq..\\jjLL....BB..SS............YY........,,....||@@......##}}....vv..11aa..............>>..,,.......UUtt............AA........++....{{..........iiaa..&&..~~....\\''kk55.........^^..kk..EE...........bb..66oo......NN....ZZ......""..00LL$$..nn..CC..rr..]]..))......^^......//......33''................xxvvXX....bb........MM........DD..iimm..yy..uu....OO....YYZZBB.......TTNNff$$....ii...xx.....{{..11..JJ....iiII++ ........AAjj..$$.
                                  C:\ProgramData\Microsoft\SmsRouter\MessageStore\edb.chk
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):4886
                                  Entropy (8bit):7.2718268923989005
                                  Encrypted:false
                                  SSDEEP:48:qhnQ2Q2V2Q338/3CDJQy802jjjjjoREH6Q4ZCCaCaCmaXx/9nddddddddddddddC:8f8uJfp9bVFxjDYpBAXQ0U
                                  MD5:25966D8B968396B0668DDBC2BB72DDA9
                                  SHA1:63EBECE87C7CBF6BA46CDFC9FAA6D63E36E7C115
                                  SHA-256:58824961894BB3A50E89224D72C89A3516900318DD761EE08BCFEB0C11825D8D
                                  SHA-512:9D05A0046608FCF9F9A5E554416F1B33F8CB338F0C9DD61D66FE546A1934BB65B600E93E44B7F2CC2868EE99E9E285C90D8D63D39EC9A1DBC1BE1D937BA8481E
                                  Malicious:false
                                  Preview: ."'*....EE....LM.......gVhmp..................x;........!..............a_*.6,...........6.....QYY....PP...............EE....LL......IIffvvvv................xx........ee.............22YYYYzz.......ee....QQYY....PP...............EE....LL......IIffvvvv................xx........ee.............22YYYYzz.............0-8...."?................ 6.....8......IIffvvvv................xx........ee.............22YYYYzz.......ee....QQYY....PP...............EE....LL......IIffvvvv................xx........ee.............22YYYYzz.......ee....QQYY....PP..{{{{..dd......./...""D.666....0.....mm.9......@@@@..YY.......... HH.......vvvv....qqqqYX..............AA...........66.......bb.............<<....::yy.......YYYYTT......ggkknnnn{{......44....BB....RR....FF....55....``TThh........**..........zz........==..dd++.................JJ......AA..oo..``....{{......ppee....XX......ii......MM ..##..//..oo.........[[..jj..TT..BB......##((............pp..kk....nn..........,,....YY55..ggB
                                  C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00001.jrs
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):33607
                                  Entropy (8bit):7.97555985858878
                                  Encrypted:false
                                  SSDEEP:768:SJbdVRxi0YcrLO7ve3wnK5mQjBMlWRvnxP6d+1U2u0NfrsBag/pf0:Sg07rLqeTmQjBPvxTu0NfrsB1s
                                  MD5:C292376825DD40172274A5B26D1BF139
                                  SHA1:0F7B8B40F3A78ACF76D1CAE514BBCAE71FEC34B5
                                  SHA-256:35821B16A92022F1AF523801E64F4B6297DDCA433D932ECE8D51B6CBA855B07F
                                  SHA-512:03AA896CC61280E953900164F526AB51E6A8D33616B3C14CDD196CB6D2D14E08AF593066CE1CB06AEC1E7DA9ECC6DFBC37596FFCF7791971C819D3395D527C29
                                  Malicious:false
                                  Preview: a....{{....tt''..........,,............RRii..mm..11....TT..88BB....""aa..llJJmm EE....yy..HH......xx....sstt..``ii ....^^..##cczz66kk..oo..{{..YY..>>..>>....iiaa..RR....jj,,\\....33......DD......``..ZZ..RR......((II..||..00.......66................ssKKJJCC??vvffUU$$.. .............aa..ssAA..HHMM....99....PP^^..44....>>..EE....hh..ll........llPP7711.......ZZ....ee!!....TT..PP[[......]]......SSYYbb....ii//........KKee....33xx......\\....ww..........JJrr........!!......xxyy..QQ....GG..``............33..HH....[[..............""SSll..??nn;;....HH......QQ.................??......nnqq....::....00**.. ..FF....CCXX..........::!!((..@@oo__ZZTT..ggbb...}}.............{{..ee..vv''rr!!..HH....ee**..............))..::...NN..??............ss##BB..__.........))DDRRUU............>>..TTvv......DDWW..==....MM....==....55...........33....FF..ff......dd......33...............??....||OO.................vv**..AA..TT..}}nn........vv..**..RR........11......HHTTaa................MM....V
                                  C:\ProgramData\Microsoft\SmsRouter\MessageStore\edbres00002.jrs
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):33607
                                  Entropy (8bit):7.941383942463983
                                  Encrypted:false
                                  SSDEEP:768:s5C0z5335d/Nxdj5j5j5jchwd+w+w+aPLSE7jb7vPhPW9DDRvvvwuLcG0:tgDV1lllZLLPSWjnHdUGuLcb
                                  MD5:B18A291F401DCD31F7A67B08B93A47C2
                                  SHA1:96FB7A43371FCA131074C297004082708F329CD8
                                  SHA-256:3CF4BB3D880AFD66348E1E8F9FC547ED9D79A89C50DFB1503EFDF01001550929
                                  SHA-512:2A4DBF0E753AF6FD5456A062862E444D10B84B5D92D5C699C1C23423D1438844B0523FED98D8B34D41622BDEFAB22461CE869D57B2DF2DBD29F7F09F1941EBED
                                  Malicious:false
                                  Preview: ...RRWW..**........hh77BB..XX....DD..\\hhZZ........FFkk................%%..PP..II55<<..hh%%..,,......ss==..TT...........QQ..>>..11ss..jj..DD}}..TT..oo......$$dd...II........aa................hh......hh..FFPPoo//....**.............ll....%%;;....%%..99........{{00 ..oo==.......ff........qq^^\\qq......II$$]]..FFHH....{{........EEaaII..SS........JJ....MM.............zzMM''..((..yyjj....VV[[..TT......ttCC....mm..>>vvrr::zz....kk...........ooDD............tt..pp..RRWW..**........hh77BB..XX....DD..\\hhZZ........FFkk................%%..PP..II55<<..hh%%..,,......ss==..TT...........QQ..>>..11ss..jj..DD}}..TT..oo......$$dd...II........aa................hh......hh..FFPPoo//....**.............ll....%%;;....%%..99........{{00 ..oo==.......ff........qq^^\\qq......II$$]]..FFHH....{{........EEaaII..SS........JJ....MM......bb........MM''....yyjj....VV[[........22""AA....TT88II..DD..\\++......BB..uuDD77--....ii.. ..........kkZZ@@..''......vvssjj""..RRBB..::\\//...
                                  C:\ProgramData\Microsoft\User Account Pictures\guest.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3502
                                  Entropy (8bit):7.915219571663754
                                  Encrypted:false
                                  SSDEEP:96:j7soDL9iKgC4b+K+jCFiCjyjhlBFahsGJpBAXQzU:8oH9ieKziCjyjHBFahsDIU
                                  MD5:AEAE4DE844E7B7BD590A26A2DABF59DE
                                  SHA1:D31B143DF75DBD4A67BEDF17C24E4E5A44CE6C27
                                  SHA-256:13E59022DF8B13F5B047F920522EAE056ED530A7A4F9686D1405F3D6A8C162AA
                                  SHA-512:0BAE03B0AB021A0A62328949256DF4D02B7960F71BF4B9C75EA2C6F2482DB1B1D2C3620F085BFD48A6CA78B1A7EDD676E399090C8D788CA2FBEE0F10986A95CA
                                  Malicious:false
                                  Preview: o=#;q?/ysKK..ei...._/.l...]].(.....sHE...1.7...5.+.4...4~T.~.q..C.o.....!J@.p..y.....jq......tS.|ft..i...5..;....U.b...=K..@G......0..N!hh..k...2....8:&B(C...*k..JJyh....54..q!..MMnk..:{....q!..M. $C.S.....X]....}=ed'2[.....oj.H.<,....s#@D.^..A.(i....<9]....jk..8h37....|(. 0<<......oz.Q...ojA..U......,|}ym-.......RWEQ............II..i=....tu...F......I...p`......f&.......!!HM..a ..kk.."rws]...mx}- 0....3g"c!a........!u..o::.....D.LM..;k........o..m:..n.....@.d7t..E.#.'W6...k..q``.).1sn.`...>...M..*`..4T.|.89huRO.......T....#.....b.....:....W...........e..}X..9.......q..R.he.6,D.;.;<S..:R.aw.K....U.W.....\t...s....$dl..3...Wx..^.;=5....4B..K1....\...@s...y.....NN...G.....i=.!j].9........=(N...R.l..km`.^^IJL8{A*...!.J....X.Pny.....);.....#..{.,(....... ...kRG.c..v...05...h...;......_.%y..q./I..-..#.=CU.H...~.?..'..l...f...n..3T]YV.FQi....Z,.).}.......@f.:.".hz...UKg]..S...6....UJ.:u....D..S;....ZZ:2.=. ........Y..............;@..
                                  C:\ProgramData\Microsoft\User Account Pictures\user-192.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2023
                                  Entropy (8bit):7.794624756756688
                                  Encrypted:false
                                  SSDEEP:48:/MBbAc3Z3WA3MpFPJUAd4M9/xJfAXxuqUGN:/IZ3pePhpBAXQqU2
                                  MD5:9B37D83553FC380AB3371A34BA814F3F
                                  SHA1:1651D7CFA90FFE6B4F3E6150F3620CF9D5EB0F7D
                                  SHA-256:F5E99DD3B7054281367A57A0B115F177DE99BB1B3CF415EA3662608A5860404F
                                  SHA-512:5D95109AB9931C3D6B22F9E8DE39DEFEBA6F86829F048F25BF76CBAACABDA436133570FD5C1020B6F4D45A4FC91EF0D2A1C13F5218CF5792855182429685526A
                                  Malicious:false
                                  Preview: .c....QQ....pf....LL.3.....c...."'...#...........f{...]L.\ka..!Z....[E..Jp.|am..d..SBq....7hk6r.1..>....q....KA..|yA.B,:.T...<....;.In. ...p.g......6.x".....GW....;#../....V.j7/....=%...!....y.]M..+3..LD\.7.....nv....qi.i........n*.>XA.......44..<.?(...Q._^..ff.....D ....B5..?...r..........I<...........q...o..u...|...&...[.]....y.._p"."./.C..l.....jF.oy....!}....<..............Zm...ZI."(.NC......ep.....-v......q...+....B...%m..XB.}.cww_;l.......9k.g.....9W.!j.....R.D.e>._......|..'..1.v..F..$$.[zS..}R..w..u......."X.5.3..AC:Z.."[..sg2?....aH.{`.....o..W.uA1.{I.:GD.@WB......k.r.s..{<..N...CH.W..k.H.../sD..pp......%%.........~:...}H.....B.&V....Vl.t...T.[....E=['P^:O..(G...............m.?.%s..EK...va.M)....Kh..PvIV<.=k...........:.8..+5.u.GS...H.......@*$....@.[....%..V.=TN.~,k..M.;UZ.]_+..,N5.`.u.A....)....:...V.22......T...G[. 6DL...#..2!.N.GG.....%..$.....Dgk.......B.....,R..:...W......;YQ..vz.7....h.....(....4'%[.G......;..).M.Z.....pu..1../.
                                  C:\ProgramData\Microsoft\User Account Pictures\user-32.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1020
                                  Entropy (8bit):7.445697683600116
                                  Encrypted:false
                                  SSDEEP:24:N2sV2b84tFoze4ytP6qfHSgC0fNSZBzfteJTQRb2k8ds:NRAd4M9/xJfAXxuwdf
                                  MD5:1A5D6EF7173209D2AFEF527B5E39506B
                                  SHA1:DAE013DA13378833A3B66B23F8EC8EF6807E1002
                                  SHA-256:C9B1669475DF23D3D492393494EDB0A955CB4939E2D7453F7526006994BE530F
                                  SHA-512:68EBF9F0E1F86118A02CD1B439DC69AE8108D64DE1435F62AD0BBE2CE8668C4926E6586AFB08E968F2CCC057628FBA99C83A6295BA1262814C486B871D94FE1C
                                  Malicious:false
                                  Preview: ..QX....CC........wW.......%..0..hi......Se.h<q...}..H..V...GI..C$s..-.M.#,.5.?...X1 ...........!X.@7.`(s.L..X..u.:.@.g.w.....slY...o.9t..g..<Qe.......t.26^.Z]Z.8./. ...{*....t..$..z...yu.#.a..,...>.U.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{....@..F.g+.eb.}{.}{415}{000117000115000101000114000045000051000050000046000112000110000103}{bNbWbPbRbWbNbNb0}{
                                  C:\ProgramData\Microsoft\User Account Pictures\user-40.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1029
                                  Entropy (8bit):7.4720187976113035
                                  Encrypted:false
                                  SSDEEP:24:rnE1c84tFoze4ytP6qfHSgC0fNSZBzfteJTQRWkBDJ:rnE1dAd4M9/xJfAXxuSd
                                  MD5:AB98AB7D256E39F28154233C5A00CBBA
                                  SHA1:FD59C61A75D1C92D5F327122611BFB038F285BEA
                                  SHA-256:CF7194984597F211BC55920BD9BF5B69BE9AF4836B658EC815F5544EF3F8FAD3
                                  SHA-512:04974B05FD97202558D4C85E1D961BC037AB4529AB921E0B0F97FED8335E131B568001B1DD695D6AEC349ADB23E56AD2C5471025E2CC5ACB035D1DD02284A0DB
                                  Malicious:false
                                  Preview: z..b(QA......zv........]}#!...W....v.......a#..(......G.....fQ.x..q.[%n.8....Y......y1.Z...rp.zT.W..CO..lW.2..2...D4.[.Ng.5...&.w.}...9B(...d....X..P4......k/...J .,..dpr...I......@mm..@....X...Qdzf.S..L)...B.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{..`6^\f0.+F\...T}{.}{433}{000117000115000101000114000045000052000048000046000112000110000103}{bNbWbPbRb
                                  C:\ProgramData\Microsoft\User Account Pictures\user-48.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1063
                                  Entropy (8bit):7.481845842819068
                                  Encrypted:false
                                  SSDEEP:24:LM3uo6KFfsk84tFoze4ytP6qfHSgC0fNSZBzfteJTQR3BQb:43wksFAd4M9/xJfAXxuSa
                                  MD5:0904A014FD3CBA092497310A95382393
                                  SHA1:610AFD545054B80D5237FB1ABA1B1B3D9F1AB2D7
                                  SHA-256:28CFA8A0473AE2AC6C776EED33993BB3480DAE4A9C5A797EF1CD76F31BCEC108
                                  SHA-512:4154801BC494018E041771740481A6A3FC36E7B6D709E9E3D851235A0F907BB9EF889F2568894BF7EC9286FFC4A1755A5390DCBFE3FB62110AC2FEF082742529
                                  Malicious:false
                                  Preview: .7)U..........P.......Qi.....g.6...9..pe..$P2.*..S....f[..r......^.0(R.Q..}....Q.SsC.j%.B.g4.A.0Pj..`....y..T..7.#$.Q.+..-.x:..b...z....%h.o...y..E..t..U.y['o.0u..+A3...i.*....M..q.\.@J...K.RsO..'..n....=.....2."...........X. .......A.~..=.{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.G|.Bb...H....X.}{.}{501}{0001170001150001010001140000450000520000560
                                  C:\ProgramData\Microsoft\User Account Pictures\user.png
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3496
                                  Entropy (8bit):7.9064648728889315
                                  Encrypted:false
                                  SSDEEP:96:eUByGxS+1QZmZu/le5T+QmRdv8ntB4xwpBAXQyU:e2gKQZmZ9YRWTopU
                                  MD5:3B4D0F24FD615926C68124CD7B7F71A1
                                  SHA1:F20B8A05A5C2101F8BA030EADB17DE7A892AF68F
                                  SHA-256:66F141743C8429BE21E96CA2A60907A645BF10548E31DA77EB416C276341B23D
                                  SHA-512:813183E4FB3DEC09C238B371E29D4481ED21D0A0F7115E19D1D4F2815602346AB3A1100B8422CC0A7CB0DDAC3DCC52612EEC1AEDB14107CBAE7560F414D41EB5
                                  Malicious:false
                                  Preview: .DZ.@iy..cc....Z.....Z[.QXZYY.ap{&&K....l.0.>..O....#.\.....n1-N.0.HR..3...,...._....!K.....|..f|.3.........J..../Hw.'.B.;...fx#.G..M.....x.,.#.>Z.......MI...}m..xi..Y].XY..}-..mm......$%N[t$JN.RV..S.......%!?.$%*?X...HH.............45..t5........_...`a..0`x|..x}.C.csCCfw...............V..R..........`p..e`EQFB..GF....SW..SVP...@P...\..L.! ..a ....TQ...T........>>..j>.Ihx..m|#s{.c#z{...V............CB...C..m-rvi=2s......d`d$ed...U.......L...G........d1..6..j...}.Z.#BUT1...z,,..............o...S2.`...,....9L.a...........7t#..=v...N..3*1....I2Wlq.fgg.+9..IH.1.....5[i.5.|q....;e.....l...r.G......R.*kd..^..Y.../G...o/..jT..*...Y.m%$"f.....L.....,...^....4..}..Aww5U.m.q.*.1.H.W.6.7cc.g....]a7Qyy..s...pv.O..=>S'...,....@.R...dZ..g...}oA.ss.......?qW...F.3E,..!l.?..n.!...f.....H.........p..._}.}....l9n.eXXY....v.H.MYH......N....-k..b.8<k...:.c...nQ.......1......#Mpn./......4....Pez.......l.P_7.B.)........H......tz5K......`.w|....liT
                                  C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1072
                                  Entropy (8bit):6.786236152903272
                                  Encrypted:false
                                  SSDEEP:24:Jbibs0uP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfNiDrnmy1/W/L/L/Y10:tiwVEAd4M9/xJfAXxukNiDrnV1ODDAO
                                  MD5:0F19191CBCBD90623E0BAA2CE5137DE9
                                  SHA1:61C4A4DA391DD07E5AEC824B9EC540D994237C61
                                  SHA-256:D3AC348938EF1313E99B363E6AAABC5E029AD22A558F4330456C566CBDA3484B
                                  SHA-512:DDC53FFE1372151C7DF89577D3069579D4BA668115CB981AD9601882F3BBADC3331DBAD9DC23C38744205CE61ACB28FCCAA3F21D104691096E6E6DCC5950B49C
                                  Malicious:false
                                  Preview: ..**c......@*..........KH"".Pff.(..w..v*E.oI:"......=X...Y0h.a.^~.W..9Z..Z?{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{Bj..,../.`.n..5}{.}{158}{0000490000530000520000690000500000510000680000480000450000670000540000520000520000450000520000690000540000700000450000560000670000690000540000450000530000480000540000570000500000550000500000700000570000570000570000
                                  C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\2F1A6504-0641-44CF-8BB5-3612D865F2E5.vsch
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1048
                                  Entropy (8bit):6.7115810777365335
                                  Encrypted:false
                                  SSDEEP:24:0eqWW84tFoze4ytP6qfHSgC0fNSZBzfteJTQRshoCdmfGBpxGr8:hrLAd4M9/xJfAXxuREfGvxz
                                  MD5:9DEFF6AD533D9887E4AD83865C80D5A7
                                  SHA1:CB57241B7E417B797F413EBB100197DBA57F65F1
                                  SHA-256:67596F1D0C8A414D9C2806648CE3E80E2A307715B33EC915071A2ADC1D663ACD
                                  SHA-512:63FE3FB07382252D89432D96B2E70D9191B494C1C8973C88EFAF0560121099158771279FF86E009A53A00C331056C56ADF61EED8179F1BD68D5AEED01B4A22FE
                                  Malicious:false
                                  Preview: }|BB..!..8.....:'0NOmm...w_..}*...F"....~. ..R7...{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{e.M<..._.....f.y}{.}{110}{0000500000700000490000650000540000530000480000520000450000480000540000520000490000450000520000520000670000700000450000560000660000660000530000450000510000540000490000500000680000560000540000530000700000500000690000530000460001180001150000
                                  C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\3CCD5499-87A8-4B10-A215-608888DD3B55.vsch
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1124
                                  Entropy (8bit):6.874775263105621
                                  Encrypted:false
                                  SSDEEP:24:Mi2Zb+h84tFoze4ytP6qfHSgC0fNSZBzfteJTQR/g6/L/oYM57DrL/U:Misb+yAd4M9/xJfAXxuf6DlkT/U
                                  MD5:921A1BC044B28E8279FF568156E0AAE9
                                  SHA1:10518931A880B94EB7F07CA86628B2FF5D7A3A2F
                                  SHA-256:E34FCBBC6837801D1549D9B038B4B754027BBD3EBFFA32C1238D1FB2E3754A06
                                  SHA-512:51A7EB0E1077469C480035E99A26529E60045ECE5C3D1D99D2CFE4ADF84DFCD528FF001FDA93215B17A4EC57520FE93313CEC4A141E6F04AA333AA914A4A1F99
                                  Malicious:false
                                  Preview: on??.G.[s\..J.o..P>......QQ.]]^..fz..v.$S.|sS...I+...V_>.j[(...tb.~.9.G....P4T1.a.>W.nv...........RV44))LL......:>mm......33{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.@.....3..7%.."}{.}{262}{000051000067000067000068000053000052000057000057000045000056000055000065000056000045000052000066000049000048000045000065000050000049000053000045000054000048000056
                                  C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\Policy.vpol
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1035
                                  Entropy (8bit):7.464423649584009
                                  Encrypted:false
                                  SSDEEP:24:B1AyQoP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRajVWyY6LT:zAUEAd4M9/xJfAXxuZWyYCT
                                  MD5:8CBB1B61185AFF4E2A4F4A68882B760C
                                  SHA1:3DC60829393508EA8E0D77BA2EB12EC34BAECBE4
                                  SHA-256:018EBEAA5C1B3EDA03D1447A02ED328F688089C9491BAFCB8B9866990A290C2B
                                  SHA-512:AA86A07C6C4639796B55910AD77A267CF527973B910A907B7DB6A0DB9BA65C51A2C77230802612CBA05A5E43444B8757A1EC06F2D02E55FEDA7AC61223AC8275
                                  Malicious:false
                                  Preview: ...O.Y.y..(..6p..Y........S .hR7L!.....y..>S..('q......II......ee........^.h6.K.s.%t.....;..v..^....n.H...#"...F......w..3..).]][.$..G~..1..l..h........1Wrr......0...b....y....e.O.`.@...X0h.;.}.....~..IKLl..{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{../..p..C.3.U.(}{.}{444}{000080000111000108000105000099000121000046000118000112000111000108}{bNb
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{293EA9BB-2A1E-4502-A513-7892F9AB9060}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6247
                                  Entropy (8bit):7.901542157216135
                                  Encrypted:false
                                  SSDEEP:192:rTKnKEAKSULahnQ0T6vBIOULSxsWsAz6ZhxjP:v/EAK7ynQ0eOOIiuW6ZhxjP
                                  MD5:6242D83C2C38B626B757D6C664EF3851
                                  SHA1:66C87687A2549B0F208F583CE01BFAB80291D7DB
                                  SHA-256:542F2367AF361B321DFF529FFDC04AE7B9D6354E2886F79E16A2D2267B2E8030
                                  SHA-512:600698D37F5B5E093134F6C42F2DB620E31752478C3A653CDCA9AF8E3D51A1747E1A3704CCAAA8C8413A1ACD4C3C298B28DCE8F248500A2A8CE3E22B16096314
                                  Malicious:false
                                  Preview: k.3.w..T...b$_Y.....+w@...........l.6\^.'..../..w.E......_.iJp.).....:Wj.r.wG.D.KT.Ft.;u;.I8.~R.%.g....W..~0..O.B...!...gh.JYn.,...2...C....H.".:....+.O\'..}.......79...V0.6.+..6@...S.-G.V..A...BJnh....R.w.k...*3..q.#..9.d..7.z...R....<..f.v..5F..AUu....8.K..0z..j2":..K..v`.T..x.C"...?....t.._...K?.Lw........:..,.A.m........=..J..I...!.j..D.&.......I...X}kx47...O..B?D...r<.]U..!..%.G.2.Ij..&..S.....,.).T...b .....u.oVBU4T.cx.a...&..]...3..z.;..1Q;.|F....K.c........o....'"}..UO...E.1.......q.,. .TjO\e..Wb+....(7.b.DL.D.s..0.T....Ml5^.....?.........1.E.:..j.=:..U.......8...6...1'....,.jv'.......H..k..8f..]...ka..p..`.N...$0.e.n.....wQ..Z.@..<.P.x&....t.^....'i....AF5...}..s..K.....2..8Y.F.. "..*..w....#....8.{.J-...U...A@P...&......-..%..'I.%.............5.#.r.4... .1A>N..e..G.)~...z.:....V.}..{8....U.....%.g..`..#......Iadz.'].....o..3..w+W...a.....(.....#..p.z..2.o..Wr..L.B."}...a..Dg....n......{....k..c.6..S..B........"...[.....
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{2C08BC2B-248C-43BA-BD0E-E1FF5D8E4E70}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6229
                                  Entropy (8bit):7.902157608962874
                                  Encrypted:false
                                  SSDEEP:96:Iyc9kzIjuW299QWwWEAxucwbsrfbIEhYR4WynCh+2up12e7e8/tRyyUPlrpBAXQK:ouIqvPQW3rTIEe+PCVup1xCwfDQ2z
                                  MD5:41CA1226030D49648879EABC1EDE1803
                                  SHA1:1AF26195F67943503F72A101BDC7FEB11989BF48
                                  SHA-256:05A25F96FFAA938648CFF0DC93E3AC787061AEFF905FBC8DF814D4DD924AB49B
                                  SHA-512:8278BA1AC142568F67335F10F079AE1E4F22C5C889A11C7B70C9F2F7B1DF905D480BD06121C62894280F18CAEECD4B33CFA28DA7FA5ED5669FD2A14104B7CE0D
                                  Malicious:false
                                  Preview: .Z..ZUsr.T<.....ZU.a:.~.....b@...E.v..TzN**.....D.e.>...........NK.O.J.e.i.%.f3Z.V.J.$/...?Nc.2..._.:=5...7.G...g..gP.mv...Z.....dKy....x$`."H.J...i..b:O...}....=MNa.'..45..|...%4....}....#..b.v.=.Q.3E....Q..s.....S.../x].^C../.EaB...!x.(.]...q#P'T..K.]2... .Dk.M.X.jz/.;...ZL.O..5..{@..!p.......UZ5....8Lx.H_..mE8..a.?K......J.?6.9.`....\..@.oK....g.....dS...UC...!e...<.R).X..9....s.1....|.....`.}..\Dv./.U@..n.sZ.T...`.....l.&=..M.<.~....a.j...J.d.e......O@..... .W.wk....$W......%.u\.e...FR..{E.....e.9......f....,.)d ...t2k.#......#..o...K.%57..... >......2.tYh...2vq..N..^QaQ...FBT@.c.................S...V.~......_.P.P4.Y.....3Z.4.G..e-.2.'....m.}B....O.v..b.f.2.=..)3..Hl-8]-DQ.~..uv>._.b.u.w. ..i....2..w...h.A_8.0.)u......l=4.`.AU.}}V.F.....A.$..D>T*.....4...@\.\........y6K... .h.,.8?......X..b!.f(D....i.f..p'.%.....Q.{~.........L..l...S..K|}tLn......a..n.)YX.r.O:.......m...'3.E>..+....%.y[^............[....s... .A.Ba..J......
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8386492C-CC3C-4404-A22F-F710B16E8A75}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6552
                                  Entropy (8bit):7.906473521073362
                                  Encrypted:false
                                  SSDEEP:96:1QRjuuvb8R7N9S79FF+d2mDqSO/kvsMQD6mWE946Vx0bm6Qi0qhcnelzgNRPjpBL:1QJ/6EoPqHkbfE9AmY0q6ne/C
                                  MD5:19AD8E0260662860030D1228A2A69CB9
                                  SHA1:71113237D9247C2A25FBCD38B7CFFF14F630F20E
                                  SHA-256:BBE1605859195B7C2CE6BFBA7EB0F126EBDDB63E93C1E53734389F215D734459
                                  SHA-512:E79B45D2CC4AC3FD67EE1A36BAD9608E55252E061F31A456C6016AE2D6C4F7A8A69108B395F126F6DB8EFCF98045FED9BD49B59E8F3DE18D170D4E8B11F18918
                                  Malicious:false
                                  Preview: \.J..eQ.zA)...D(.;4*9e...z....!...x..H.%...[.*..q.....^p.>.%.{....6.R.t.2.0......^..x.$<.3..w.U~...O...>9.NH...J..E...S....(6\.7..{....8...Q..t..)&...y...W..&.1,..Dk..z.../w...h.._....Yk.-n.Ie.....MB3h.8....V.G.{J.?U......:.]...'.A.p8_.C.8...N...y..d.<)..J.-..E.PG....!...sY.v..Z..1}%S.....4.......u;V..+QW.....ob"hH.\........,-.t}.D.\ ..%....M.^.....k.._)...b.*...mR.Sp..x.......]2..l..|A..#i..B.k......(Stag......Z...KTkN.~k?."........}._..Y.E..P....v.-E.{t....ux..,.....].S...u..S...d.]...s...l.....s..x..."0*M..O.....X.s...[..%...5...2.T......+.......L.@.......*...`.js...B)....P.=.>...xU&\..=y(]..u..$.....1.u.2p.hd..+..~f.<X.p......q.A.....7h......%..Xg9Y5'.;.+.B)..d..e...*....V..&3...!i.T.....m$.].b7..O$^...L...?.........EF...);k....P.n...tt_..g ..{I.=.......F.K%.[...E...h3.1.Y..K.@..{.....\;....n.Q.......0.yTq.J.9.yZe...;.......(R.....D...........)foWS.I60........G>.W.^.1.m.....O,...i/=..U~E";.|v...<g..:H..1Jan.>c..:..Jr...r.Y.t......
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A32653C0-0B8F-44FE-B032-70CE401BF60B}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6739
                                  Entropy (8bit):7.912048346570481
                                  Encrypted:false
                                  SSDEEP:192:gC/gLuJlkQcuUkNy3Lqk62RsAmiZE8K5gGF2ejL/Aykg:L/gLuJlkQcuzNy3mk63AtK59F5j7Ay9
                                  MD5:ECE10B6C89425336CBC1E0DAAEFC7235
                                  SHA1:848D8DAB4979793E9E1D9B4550062DF8A667DE9D
                                  SHA-256:0C7C70596B0FF551B0847F0C5FF545132AC1EF81080AA6B1BA07BCA0EA13BD47
                                  SHA-512:42FE063FC6EB99E9AFD4AECEC72F556A11A04C12BA89E55F341999778D27C37DF54AE9B4647CE9FB9727B395BC39B2C5C7BB1710477A41465F9994B992137777
                                  Malicious:false
                                  Preview: .`.Y....p...oi..cl.4..7......%3o3....g..cgfM.E.........,..tY~..M..9..R.m..M.T.D.)*...xZ.9B.}..-...U....T~..y.w9...... /.K..R.%...K]..jp...0..\....B........I..Mb..XVde.i..2.....e.......,.m6.....Tp.|....D..w.n.p....])....nF..O[..4....Nw\.J..`h..aJ^.f\3...P..m..mi........rWAY...2...E.R.x..9f...V9..\......+.sd8.....8|.4Q%%..Uvn@...7......S.....2...P...u...%.V......'U.b...b...F4.YQ.-.M.cx...u.4..K.~.k..i[.....mx.+... m...O.P........h..c6...._...^.i.;.A..b...wwo-9..g.9.X..f......L.J..>.r@.E.aH.......B_..F....!.;....O(....w...!..'..|..s.....(.a2.b.....T..z]..d..M.=..C....c...8..aFvT.-f.I...u..D.J..w..sH1...q.B.u\......V.a.q.6J.(.N....$...+.=u..........c.....8....V}.:..G..*..#^-....$AZ32.....65.X.f...2.t..%R.:......#....p.l.-..NB.....M.{*2..$...#..P.2..o.`.....D.....Q.O...l........*ZQ....D...[..%.T...,...8..E.i....[.....Y.{..9.+...5.l.."..VE.....&L+......&G.XY$..g..2F..i..gIH`.{..^.....5n....eL`F=..F.V..K....pc8..C...^..}....{4...].6B.. @.6h....
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{A5BB1EE2-9013-423F-A39C-D7954225062B}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6304
                                  Entropy (8bit):7.908239287858982
                                  Encrypted:false
                                  SSDEEP:192:naGKZr2kkiRUt12DR/Y3towqfTQMsi+hFvcfE:nxsF6t3CxbQB7hafE
                                  MD5:315B3A9516C01D35402A439210CEBC9E
                                  SHA1:312E88C6BD2B136A7CCAF3AA9A16806FCB6EE3F3
                                  SHA-256:9A944BA0412986497275722DE71B00B45F0CCF68F34F706069CD77A553AFFDC6
                                  SHA-512:29B67F621CECA1ED29797552CC51EE00CB40BBFA60E39152F53912C9E93A0A3E9CC4CA710150118FAD6EFCF1B3F143DED1FFE63E3FE02A9AC64AC7886B6B8844
                                  Malicious:false
                                  Preview: ....Z.l....B9..4^@..N......dj./...G..zu.-f.j..0u..~P{..]...,.!_[0$so.....[m....6O...........}...[...c:.w...L.^.{...T...ky.....^P..j@....bmY.=.....nA.....Q"..r..7\7.....[.B.b.VW%#.s.}Q..*j..D....<g..*%..;.C..&-.....YT..%...3........Y...Y.T..?.....fc.v.A..o...]kb.s.=2......l...z.|-......s=.mC..>S.....S..?...S]..Yc...u.P-.....~. .g.9.,...~..ax..p..n.i..b...-N0....7.../c.2..!.K.....(..]c...o....Y.]..h.BW.A..D.9...I.....Y.l8.;.L.......o.<g..U|..'.C...7.L..]q~.zGY...........V.I.Z.....!....W....R....N..J.(BX..ofM..;cz....Q\.{..{y=....q.F..la0.....>Z.Z.%.....qKf.rs.8.v._..e..&...3.....*.c!./k'R..I".;..8.L...]........!.L.~..@.?.<......P....V..>..........w..<.1.B.N.j.}/.O..6....F.f#.S..=.@..F...&,...1r..=..'].J..."..O..p.........S.W1a%G$-\._...``.........S.L....|...d.Z..h.K..,wJ...n.v.G......4x...y.~..a-:."z.vy.E..d......[%6....N.2cO..tHx..W...?......%.<5uqB...9`..&PCB2./(..5...]3.R.7..{.t}5.CQ......."..c...O...z........t..7...A.....*...)
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{C7207E76-8290-4B65-AC3D-69634195DCA0}
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):6519
                                  Entropy (8bit):7.908672613700522
                                  Encrypted:false
                                  SSDEEP:96:0c7YAk3m1+4zbi/dWBqvpTIGerZ6lIkrfN26UVBXswLE8zpBAXQlA8mU/A:0MYAk3g+4DBQIGXj126DwLWkA
                                  MD5:B3A32FBD2AE827C99F8F27DF5C395817
                                  SHA1:C3293C67E29F211714ED23B2A68F920B8B10943F
                                  SHA-256:373CFBE577C507CF1A8A48414B28454B507CDF9481295B6E7B19D2150F1F08B3
                                  SHA-512:9E2D706976098CC9441363622177CAC236860E5DEFDFF03A4BA9BF830BD8C7B83A2B9FBE775540EB45A7BEB6F49A4F7C0A9FAED5FE52229AD1C8143C15564D45
                                  Malicious:false
                                  Preview: ..@.4[}..Q9.W...._P..dS.*.f.>}_..P.w.d......j .-M>l.t.O..&.Cc,..g.......?.h,.U.~.".1Yk6..M....8R...-....;T7....UU.W(.."9...@.8..[.yK|^..:f.1[.#...qur.........X.+[.&.$...y):.3.E.e..t..+l...iG.yB..+...z~.gAo........<G.$.Z..+...&q...W.<1O.-..h!../\....B..e...=k.dw..]VF0.O......\_.=.l."L..l.../T".......W.....7....4.....Q%.u.....7R[.u.0.'.z...p.$..'...|.8..T..E..m.....()R~5.`.yV^I.........F.....N..=.R..Pp.~.T.f..;......4....,pkn...E..(=....^C3.....~.*|F2.xx/m.QW........`||.>;...6X.s..x.}T......:....&6....$.d.v.....Tb...8h..G..M...V.u....2.NX.9................w.?.@...k.D...0[. ......I.%CU.Q...k.)4e.J.^e....`......J.`...k...ae....:......y............;*8.0.....ee.-...$.[..c.j......L..3Z.0......I.o.+.~#.yW.x\.....y{z..f..i.s.........-,....`....3..ki..M....4*m.D.p.i]..........G.(...q.o....Z.:q..+....YW8....5...2>R.I..=l$....u.......9.up4...q..B..k....q..7..B.......*d......B..|.jO...w.YX..2.51J..!....d.p.....+..c.7e...s.>y.$.+h.$..<d,$.P...z0..
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\623288A5848E7220313E71DF9C11BF70
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1573
                                  Entropy (8bit):7.398182607039862
                                  Encrypted:false
                                  SSDEEP:48:ZK6rMUy2/YnEHFVDAd4M9/xJfAXxuqAsH:86vyo/6pBAXQqtH
                                  MD5:9C5294F429F123174120FE56213F1672
                                  SHA1:CACC06CCAD0FE740D0C09A39D665FC96E259F5AB
                                  SHA-256:84B7298202C82B66CBA9E6D4036D3BDF4811AFCBB03039B2A48499B502BF1E3B
                                  SHA-512:4C898DCD90F0EDBAB414265B076382B394FE2CC9D26B182BBF98CFD530BAA5A1F627C8A08816C2030645697F2D1586C623AF8F267C84EF954B442B80B59D73F0
                                  Malicious:false
                                  Preview: k.}!.%....W.........]..d...Ob4:....?...o`.5..h.v...5.....~.....-.g..f....6jV..U.....:"..=..~.3.b..x.....v..1L`"ig.....k_c.;3I.b..r....4u.db...g[....dem.sm=.I.x...}H..]...!..N....e%.W..1.H..f?...8Qz@...Qz.Re..38.>`.S.rb..C.r.X"y.0.'.pthP......Kx..4.....$(..T...O...+x...z.......O..{..4..J.Gl.:.4n=V0.........6.V._.uq:L.6..!...)\.k......0Wl..&.^.o.t..|.@.Ft.p.J.l...".|..`.i....,~.!.n[..&p..B...\..f.R..a.>.a..R}RHr<.h.:2.(...T.8...~.-i..`..%.......-_wt&vX.}.R..T-.y.Y....TG=S........#6.......~...eh-.{?...../5...3....8.@..0r.:.......lX..O............4C...(.Lk...W.G@...H=.a...J.D.K.z~.{.,......H[{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\A0137882FC829131E8629036339BD1FB
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1581
                                  Entropy (8bit):7.44064921812191
                                  Encrypted:false
                                  SSDEEP:48:p0L3XgBTmZ25yGAd4M9/xJfAXxuery4gZ4:ezwBTmZ25ypBAXQeedW
                                  MD5:8292AB28525AE68DA09C2953D5BD60C5
                                  SHA1:F09B64A00779C3A05769C7E70835AF1B80D9A7F1
                                  SHA-256:5133980DB6C1B4BD1030C27DFE6F1FDBB16845853254D55627AF29BDF60D943E
                                  SHA-512:5480CBDC90E5B9E6D722C7FEA1656DC7A60B3C6A467C4AAA28CE14625D2704FA04DB8DC5A23160C851EEA047E2E28282FF97FE9B01662D3C0A8153FBEB495CEA
                                  Malicious:false
                                  Preview: t.@..{............=a^.....iD:4..hB;.I............Q.gI.]....2Z..1CYk.zZ>..ao[....L....E.t.............}*..?...6t...L.....!.K..y....7....#................sc3...V.x.|.ig...... ....|.1...>r..e...[.....|.o....+`.U4.....r.....g...1.\9.M.dIM..yf..G.L.\.0:]...JF...-9...X........L}....KpN.......r.... .M/...h.4.....j...Lu...PT...),z.Vn!T..I.rIzw....R(.!j.....1R..[.&do]...,..x..7I7.#.d....qmOaT;..... t.X.r....e.......c...3..>p(.V..}.",o...)*..K.O5...e..^NL}e.dL.....,x-.;$...W8j.....m....8v{.O..*?[Y.M1....@|....U... n........}.....H..z..W..k..q.O.ma&_<.......#'..+..?.G.C..H_I.....0.G.....E..;...g..&.....Pj..Gy{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\MpDiag.bin
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):863
                                  Entropy (8bit):7.323649519333382
                                  Encrypted:false
                                  SSDEEP:24:++/Z84tFoze4ytP6qfHSgC0fNSZBzfteJTQR2kN9Jz:+MKAd4M9/xJfAXxuhkJz
                                  MD5:7567CF820A1C6EA2C6BC2828CC7772D8
                                  SHA1:680F7CFCED927D41EBCDDCD79F93393BF6B7D71F
                                  SHA-256:9B61FA973EED01C6A9AADBD42E315D5E446215D18FD607F94EC6E79135A5C3D0
                                  SHA-512:75CCA2DF0D0E73C2ED95A6C1CBE2B99AD6866B0CC685150B58F3CFEE75FE7B35F552A16936A94DC4E9FEC085545BFE907DD5A22A7F6F4B286EEB09321DD1B377
                                  Malicious:false
                                  Preview: F76.....?;.t..@.r...s@.jk..cc..,,......UU....55.z||....x{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.]R2. U..QSM.).}{.}{112}{000077000112000068000105000097000103000046000098000105000110}{bNbWbPbRbWbNbNb0}{4}...9{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\MpPayloadData\mpuser.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):76862
                                  Entropy (8bit):7.989190193130712
                                  Encrypted:false
                                  SSDEEP:1536:vjWQEMhicdbknTgIxGUiU58v90cuS7CHwVN1VGLISxC:vyQEM4Aw3ApU5i0cJ3H1VG5C
                                  MD5:578CF6B37B3D1A29FEBC4437EBA8354C
                                  SHA1:5B4E5F5A3AF2B57EBAB5F1E0AE53087B894D3B9F
                                  SHA-256:07668E53EEF41271A8F6EEE4609ECF434BB71E20E4C1BD42386C6CF211659FDC
                                  SHA-512:787971384C3059D6871F8B5DA861FB2FE52DC622F5FEE821E5812D20889CBAA555BC54E8576BA8F6F9FBC10432CCD813DD99593F52943956639DBC14B480E91F
                                  Malicious:false
                                  Preview: ]...|......h.5.5..^^.....]]................TT......88s..._Q-...H.u..|.o.! .OM../<.pr......]ZC.wp..g{.......=..tt...S..i..,.C&.M.S..G...NB........+..K.d....P.`.7.c.8-K.5...q)..~..|.~y..=..).<..."e.....8..l._.a....D.d....""77......[[...;_!.0.(.h2......?~\DO.....:^^.rii..t...--......22%%yioo....xxrx..FC&$..qq......{...;..........<<&&.. ++BB....XX66......ss........"",,v..jr"<<.....3LO....$.RA..6>.o..;;m?..`e....+...pp....AA??....!!....v^....?L......((.....o...xz''qqFF11..........$$AA.....ee.WV`....ZZ(...26........nn.....^.I_-8....,.....c..Ti..HH++..AAoos3((......i.....46''.....Ybb..bb..DD.....K3'..........122....w.........@@gg.............f..ddw5BB|x....tt......hhVV..;;A/..x{.m.wKN..........OI..==....\\......S...RR......YY,,ZZ....;;....bb...... ........QQ........CC..cc..\\LL....yy}}@@..eejj....hh..UU........GG........]]SS......FFqq...``00....rrGG..==....VV33..xx..ss.........."".....88""kk............||..''11..DDOO......KKJJ...YY......hh&&.......
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\MpPayloadData\mpuser.info
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):836
                                  Entropy (8bit):7.21507139198713
                                  Encrypted:false
                                  SSDEEP:24:Vt84tFoze4ytP6qfHSgC0fNSZBzfteJTQRsMUwFRfc:QAd4M9/xJfAXxu5MRFR0
                                  MD5:1F8B1CA066C70DDC5B8EC7466B2A9F95
                                  SHA1:4C1D36562DFB764AB494691183504DE560C20323
                                  SHA-256:A60035BF436459E11031A3938E054D33723D317CC53AF5AF552CA6A6A4991D37
                                  SHA-512:AFE11F34F3C24CC4D61E0234A7B73EB5A30A04A792D42E306522D27EF32ED9D223E77411D03F160E97BC53CC98127914C8DFEC05C4BC15386362DB9DFD37FB05
                                  Malicious:false
                                  Preview: e99gRm.......{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{.....,.....].5n}{.}{24}{000109000112000101000110000103000105000110000101000046000105000110000102000111}{bNbWbPbRbWbNbNb0}{4}....{ENCRYPTENDED}
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):2098219
                                  Entropy (8bit):7.999892268702878
                                  Encrypted:true
                                  SSDEEP:49152:NaFhNe5XMZqANqgJWk1MeqSG+frOymvDjo1zVyWC2r:siMZqcnWwMqHaymvDjoBVy0r
                                  MD5:2264764215DF57E8F2EF1C98BBDA9651
                                  SHA1:6A0890A6105CD6C15EEA4F9F87D57E2EC4C8AC4A
                                  SHA-256:2315769B0B7A92AFF54830BB3C558B46C4309D998B61497296A32D731BB4A25D
                                  SHA-512:707C616B27DCA04121551E2541CE0BA1CB379E3226F874EBD8D16BD1F30F7F2F6556D60DF94CCBCEC1D8D5A47FE3BF41582E844CABF3CED7868F5E02FA0CDF86
                                  Malicious:true
                                  Preview: ........UUEUvx....="s|l}......<<=.2#]^}c.......<..."|m||.-...,......|...3#../??"6..m.nO.....^/)....H?NO....?/.....#ON?_..../..Y...q]^NO...,./.J......^.Uee....WJ.......Z..."#.a?(....../?x.=.!.NO.Y....)I;<#.q_88T.....YY;<#.qY8.Y...)i[Z%..F...I....jJ.[..vf)......[..........t.]Y....V.^..o.......U.......C..:..Jp-.G..E..I.A;/..1....97...\&8..4..Z.sI..;..[..c..f._.q.M.(..f...=....;..I.v.C.Sb.....<.i....b.]!@.K.8......pa.l-T...@ H.;.-|y.....V".:Gz..p..}.....i......q.!..W..d.....@Y.e..%&...b....>.j.*...h......mZA.B_AD...2..jZ.ov....E.6..N.r.g..'..f.h..zR..F....'..5.....F.>r.....H.bq...t].BO^Xx...h..L.i..sQ..-+...`L.....,..C..{+...@...bB........_Ti.."......[ZU.d..*%....97...X....!~.R.m.Y..{%...u..,.5..+...F..0Vl.P.U...T.Z.N.....1........4.....X..Q..P.PWkU.............Tq|..9..H.%.k.....V.>..e...cV.(?Sk.#.....(+.FL..[.........kEh}+.....[.4fF...uM....h.%I]..{G]..:1(@D.h.0...S......DZ|..Wo*..G.z\....Z..f...B!!.=.!.%...pa....ou..+1k.b.)..?......V.c.../.@..L.E
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.20
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):145580
                                  Entropy (8bit):7.958723055521828
                                  Encrypted:false
                                  SSDEEP:3072:mTFC3AI5BJBrD04OEx0fs1rxqG+jTpGOZ0GQiwbdasaYg4WUEJkd:KFCwIjJtDZ0fs1rxT+jTpGAxQiyadghZ
                                  MD5:C66538E4E9DD0A776831F91677F19A18
                                  SHA1:0B06D3CF4DCB02F411E726EF670B9435BED48315
                                  SHA-256:F0959EEBCE850755BDEE80B12EB113DB19B32EE301EE611BACA0CD0CB6BD875C
                                  SHA-512:CC29B86BDBC357C8169F19036C965BE9A97053B2FCD786185B0734D70CFC5F2E81BE57461E739346AD65E04AE53871AF7C069571DE8296313E0734846DB9C77A
                                  Malicious:false
                                  Preview: z..2.#...kt..6.[.;.u.3{...:...[[......=...5..Gk...2..%T.8....F._.(..z...H....K....k..,..=......n....V....m....3!...5}t..o....@.4b.fb.L.z..3Y........?^.o1..y....K.....8C.<.s.E..wi..'~X......q...<-<...;....6..k..mk.M..s...ae....fv...)V@.I'.._...S.^.....r!$.Q.%.zR..,._.l.y..-. ........|j6.|s"...g..b@......I#;...8.,6...K...A(...........".Oq.?.#._N\.yZ.8...K..........u.....+..9....6.{........U.v....l. .i...).:.+...$..m?...s:Hp.|/E...1.K(.DZ..x1f..;.:Z ....,V..Y...._72..S..f^.....\..V.L.+.v.F......@...e.6....o.*A5.^...yE[......K.J?S.......'\.....N.n2.^...=.c..K&.x5z.oo>.%n.J|.v".......c..kO....H......W.x1.5z.0.q<...yF......-...?7..x=..{.......4...\. ...P...%......./G..:.E._J.....O...qGF...3)...KEY:.P.kZ{...s....1f.Q.....IUU..8D5~....u.._....mt.Z...l.0...0+=*..2...<....0..@..D.0....w]*..n...GE..).6.M.....F...g.a...{r..D....?..+.s...3.-...Z1....VDv-..d....P..e..;.l.ve.!.Fov...'....N+..._~........)........vq!....:Zl..."..HT3.2.K..+UJ...
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.55
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):231584
                                  Entropy (8bit):7.984601054346813
                                  Encrypted:false
                                  SSDEEP:6144:f7NWEXeIgfD9V1WTPZgCNRfOZ792V3eo8zOkr:gEXeXJCTPZpNOZU81
                                  MD5:086A3BC8721C541D0EBF3B18B01A20D0
                                  SHA1:DC9186869BF16AC9D9B4B39C09D610DD3D67D637
                                  SHA-256:6D25B70926FAC9F64DCBE08AEEF9CE0574D4031322D388041FB4CAA9F4EC4D9A
                                  SHA-512:FD2C28A559A7A1479F95CD842E441F707E6839DD55B5C5044356807B5D8C37D08662D379BAC55630860C4D78124CCE67AB76F760112DBE909BB00181C8175B0A
                                  Malicious:false
                                  Preview: ?...`"B..x$g...|.?.K...!..r..8.=/...P..w....<.&$.X..7r.g...p.N.....,..,.."...(..........]b\..KO.. ..eK......,........^.)...v..z.sj.......q.si...........|$u...a..WR.....:..6...({...%..4...$<9K,.!...Q. IN*..^@"@.a,?..S9BF..,.L......b.!/;.N}.r.w..j.{Es*@.8Pu...-...wz....^n..8?.y.FS..G...L.....?.....6........g.!i..3....:.M._<..Xp ^.0V71.U.........H."+g......{....n.ET.2..4u.....+..6...u.{!'4.-}..B9.#..I.iF.."..`....(.u$...da...%<..(m.U3.I...&D.t....7..Q...D9c..8.7.I.G.$.\..,.k..cv. $..D......Z/./..{B..S.gZ.]K......1v-......y...<d.../[=."...i..|+3e:.u]eo. .z....yII;..._..#.#%Q..ife.[.o.........&...=h=.7@.....1......[..T.J.22h....-vb-....O"..d....nM..b.9.[..~..:..7....&pC.....i..........*8..-.5..XPD6#3!......8._!........=.x.R.T.....x.(.........."7.o...Hj...=.;~T-6.'....|r.f.....u...W.8)w.K....s.........'Q........%.v...qh...F.....<.d..l$.....F{.G...,......!E....=.....dkf.../I(.4t!K8...._G....a.y.......HN..W..FN.....1w..K.NA..7.%.b...y..`
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.5B
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):868611
                                  Entropy (8bit):7.999208945257649
                                  Encrypted:true
                                  SSDEEP:12288:K2HloL6oii8zBCzumrtncjB13jGVWjf5olromZdMNJBQnFr3D/Z2mOTv6ja0TVlt:HHi8WqjGMt6iJByxD/Z0Y73BkUzhL
                                  MD5:C237D428346FC535A78EA818DB05D219
                                  SHA1:827E3305D7DB13E08C2155E814CB8A368474F6B8
                                  SHA-256:BAC874E457C933555668E13B14222031598AA44257D63795E588340FA7D4CAF8
                                  SHA-512:43A8AD0C7CC1C1053057C36F57C2330E0B2EE6515E57622405754CA1B33269405D479278E3BA8A07FFFB7B124B5D7173570B63788D9C871444CE0A44D40FB95B
                                  Malicious:true
                                  Preview: .xl&F..{:..ay#"....Vg.............^XQL..oo..20//~YGG.Nvj.....1..!..Sk..\l...6dQfK......(.4UR0..>_..xJ...(1....&....eW............].......~^...=............[T[[....*.......X+.(.....5<....X \,.i.jG5H-.....nn?L?Z............w...I?I*4\..............F.A........TT<L.................. L Sp.\/.v....HH...D6n.?L??,$....[2......8[..IAIIS$........NA...o}k....wQ}|..[<{....................... !..\\......HJ......no???<.......@@......66..IIIL...................)..........<4....@@..............77.. ..\]....GGHH......nb????..............~....IIII44............................TT<<..................... !pp\H......HI....DDno???>,,.....[[.....h88..IIIHSS............NN...../..........<=........................ =..\]......HV......no??? .......@@.....~66..IIIh.........................j.w.3<.....@,............7A.d S ..$\>.d.qGeHf....gnL?.?\...........].Q.gi......B0{.{....=.........i.....}./M......1S"G"....x.x.5.....N(...........%.
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.67
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751090
                                  Entropy (8bit):7.999510711766966
                                  Encrypted:true
                                  SSDEEP:12288:/SsiLupsQblGp9v92u/+50HGeAJ+KUzC9MAiQ+gMPruAkuRWmwyLXcqGYAhlYyjq:/SbLyRBG/v92uGKHvtrzkMAiQ/MPr6uF
                                  MD5:74248692C54AE7E016C76EDF2EDCD4A4
                                  SHA1:D31752E697D22C4EAED2DDE817B5C0F9CB637E2F
                                  SHA-256:495E03CA805192088ADEDE9685834F787DC5CC7B907863F928D64930C0F7615F
                                  SHA-512:B5FAFB9592817CA0938803CFF23364A6EC3DB3829162C29CD52C4B12B9AC1D114E3BEDE7D048F46A57C7B6220EE22982C1A363441D5B65B932AB8CEDA4954A2E
                                  Malicious:true
                                  Preview: .......]y.._..V.h......a8.bW.....\.....7...<..\f.7.(.R\......'y;..X...M.x.*......^..L...n{...\fQ....G...."...C..dz..x.....k..w~X.a...Iz..("Y.t........>....Z.4#..n.11.8#...h...,Wq.s..Un>P.k0`.....S..o..P=.+1....>m.}..o$.`\......-.|.t...N.....~CD.<.e.....zx..2tS...4.<...r.`<.}J..J.v..z.J+.....&J..)...m..............!......[r....h"...W|.....&.s.'k...$$9.s..|kAQ.[+.g..FY=,.0|`..R..r a..b..\...>...{...to....d5.qIn.w.....J..f.....!..\8.:.[R.{...U.8............I!.`v1\..C*..j%gi.....$q".i..:.h4.xbww}s.....7.....k...v..k....._2.t..W(....p..V..?E..I.i...X.2uB.......F.....x..R.....A.f...H$up....Og..D^W....T.!b..ub`w{.....jjS.N4.I'.:#.R..Zk..>.\.^.. 4S.+....i.gm.5.g...5..UrQ...W..e;.6.3q7j....G\........7..M~,`m.9.....E.....`.<8%D.a.N.{7..D....[V2(X....H..p......x.s..7s8.A6.v<@z........k...:.^cM^Q..^..2..t..+..$........S.A.b%p..'..<)..,r..mH.!.e:...G@k.n.tV7.$....}.....z.Z.Qf.=..<e. ..E..D]#*........!w..~.8.y|J(l..2..\P..B.../ ..... s.u...?.1..9...8.
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.6C
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751089
                                  Entropy (8bit):7.997757248914667
                                  Encrypted:true
                                  SSDEEP:12288:A2eImyz/0OqchofatmHaqq2zu1Na+2oWAPJc0rJStcuNiQob5/LipdNTlaJL66yG:FlVLhoitmDq110pbTd2ums9cw2R
                                  MD5:F5E21583C71BD32EDDB073C984EF2128
                                  SHA1:A816A603FD8024FCE4464650969DE6614633C3F0
                                  SHA-256:CED6D176FE7BC514071CA6563031E40D682C049608218A2ACF7FE5CAA97A1504
                                  SHA-512:E542EBCC4159186FC3822ADB2570D2183F9D29E391450889587121F28ED45B6DAE52658D5BEC3FD3E0C57246B15BEF9BD552E8BE41B0410FE81C634FD29831EC
                                  Malicious:true
                                  Preview: ..ma.d...~jj.x.........;q"....D..^:.#....nC...H$ _...........|.K.&.2.nP....0.a.\....c..:.R1...W...I.K.Z{.AO..{.*...T..~m..@...H.H.....C....4Jm...}...W*.....--..?..R.#\....../.{.]b..T.E..Fh.*.#...X.l.G..Jv..*./r~'.....".L..Y............M..4.R]...|.....ms.....w..K.y...p-.@...A...=.\..t...Z-.t9...4..zu|*....id&Y....N.=.BRp.*....I@.s.m..b........}{.UjA.m/K...n..kJ8.,.. -.W.1L......X..;.l;.t.....g.....>.r.jE[....9.K....9@].r ....)...,..PIhX.p.B'..i.F........T..j~Ps......Q.+U&......%.D./Qx.c.......s.......D...)s..E.U.F?.6...]......... .~..^0....T.&.^.GOL..#.qSx.ZC..z.h.LK...h.Khw.12(.]...G.m...JFA..-.........a,.T.........;.g......o......9....u...........^.&........d].h.....-.......D4..~..S...s..si..[.hH...#M..@._A..l.....9...".%.H.(...%&C<sA.........f".O;..f...}.....Y..tl.v....~6.dW.'....v:..z..!.w.EMw9....r.gEE ......&......_\..$..n.^...vK*........(.!...4.....<...)..~...s^.2x...h(...6.<4...\pq.b#...V.#.yYV...;.V..0......n...+..
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.70
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):314156
                                  Entropy (8bit):7.9542316855434
                                  Encrypted:false
                                  SSDEEP:6144:xHHyc8grO2MK4vgWlJfhVjK7MHq7nvt9ZFUukxmCF+cZF0VtJ6rufxrcm8:xHHxoZKGJfzjK7MHwLPDCF+cyri7
                                  MD5:51FAAF8DD5E81079E3568ED7581AFC9B
                                  SHA1:FE9BA13ECF3A1DB713B6E755C197A40C5971CC49
                                  SHA-256:1701EAC86552120A0BCD09D7AD78418C3E2BB16554FD2C44C1983CF9D92F427D
                                  SHA-512:C93B7CE7463DDE2FD6EF645A6B44F6D6A1EBC2800BD955FF23D8DD4F8D928DD2442B77467183A8DFD69042D3919A56C4FEF65E1F3FAD26ACF69A4B7673C6C418
                                  Malicious:false
                                  Preview: -..#{....Kl.......cE....F.....j..VV....&..]....... 6...0....U..`qIT.dz~,n..?....d......D..5?.....W..t...I.\.....m.. .J...O........N..7E.N!.p%#6....~...t&.."`.....o..C..Z.A...BG%..p....h/q.~......;R.*.......4 ...n..._..q.TH.?..[...sp....i.Ay.?h.....s...]u.:Jy,).@b=...^q.7Rta.5..'"...A.....j...F. 8..T..uqAf.BaT..=v.../.f..+,....]....=.>....^^...3..r(0.,.|;.7?..R...]r......~......B......Gg.w2...J..Hd44.......R_j}..a......o&.@B..qY.....WM.y...m..(a...y..1....l@8....C`A.\.2]....b/....t..K.nEV..../HY.S.U.wb.C.TI...291/..M...W...#..xZ.N...|R.%......{..o.....aS -.~s..g.!....tiz(S........W...0F....z.....3F...9-..c....../~.<.+..Px...$. ...J..C..e.:.p.HM..+Ou..M+....`B..lI....S9..UpUV....S.6.#.....@.%.@f.'..}-T.....h.q.s}.......f..!Km...)...h!...d.^.4.DN..;e..m5.H.D.....y'.$..d.T..C@t.....Vjo\Fd...x..99^~\Mo.R5"iG..H4.s.s,...k....T.Q....f"Iu[..H..zp.t.qR.....:J-..j.nl.]..m....2.R...!.r...m...=P..X.. @.wE....A..tL........*.%c.\z........K..Ivkb!x.k7...
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.79
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751090
                                  Entropy (8bit):7.99535437649649
                                  Encrypted:true
                                  SSDEEP:12288:0CfvyxdAHypVwT5jhugHjb/A0AlHF4wh5hGHDK/tvsH2D+uIHX9e0ane/OfpGJ3v:0CSxdAHE4HjOHWwRGHGFvsHk+n3w0p8W
                                  MD5:2D5CDCD309BA3BDAF650F4FDA6DEDB32
                                  SHA1:11BECC6CE9CCB6F11C426B05F3C44DA425802564
                                  SHA-256:7C4910CAC45E9AB2A567F4BB4E500BE5D5E5CE85BEE151AA1ACD19B3A7B18E9B
                                  SHA-512:8E6A8ECDAC776379E2BB8681C1DB6D77EF9555EAF5B4D0A4383C3E5F82622FC3E854FB2B4742D8126C58491DBA98E34592A9A52B2A533CAC6FB48DDE5EA01BE5
                                  Malicious:true
                                  Preview: :.pS....a.BB00........................h...b...&6....99....%%...ss.....D9yLL>>..zz..93%1$(z.......mWp,...a/..e*.\.G..N#z.....R.....#.V(~s19x)d!d!...A.A.........`_..'''...++HH..b.7'...Po..^....##......dd..HHHH....................++*+bb..EXT ZZ..MMM]&&......``......................9)$$($..........b"a"....)~7~...2}*}O....}$}.\.L.D.1..'.....N.L.Z.k//.E...)e........x......jjjj^^Y.^*p`..z.Ru......GG.F..IM......22....dd...K.X......ee.C.H..HH........nn(~................SS&&&&##..TTz ...}............!!....................*+@@@Pttw{....pa.b....[I...........I.$w+w.b;O.H.L.............NS.0`)`cM....ww..FFFF........//22i...HX...m...O[[Z[........,,@@....}}..((..n=....ggs i.ii.................._dyu.QQ..............11..........//./..RR..............._G^C....!!m+.2./s/x|5W....C.....U.. t eu8kX.....F....1~x/d*d7.V..#.I........@`..''.'..++hHHHLL7l.(\...^z}..m##......ed..LHHH....................Torb..q..aJZ..+...6&.....p.....o......U.....|M9$$$$
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.7C
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751089
                                  Entropy (8bit):7.998616741685269
                                  Encrypted:true
                                  SSDEEP:12288:Re8McImLZUnVKDWFtugD785gD+3nEDxIypnNslPjgQB1zDbvxau7IEzPp1i:48McImLZU0Q0F3EDx5pNoZvxau7FPni
                                  MD5:925F04F60391C6944B70AFCFE1B2E5DA
                                  SHA1:6F5A8176D65FAC60E87136B55DCF8EB63FE3A1E6
                                  SHA-256:F13DBC464496A7194F7DE386AC6555290A1E49869FD6AB216960B7F691CA747A
                                  SHA-512:2646D631BE12F640DEFFF6B27E0860E1B141FC64A16F67D67F2549220EFC278B96C7EFFD3B9E37F0DB06B6B7D4E24F4CE9583E5618416186A1AB4DB0EC4CB0C7
                                  Malicious:true
                                  Preview: f+......{...)(mm....._.......E............JJ>>{{/....L:'..^^.........}}]_........]]UU..fF.WW......td..uz...........aaV..Tn...\%l..m"..:f.....G...SWd.;..h=..n%.I...z4.@.&.ZTz...T.HH...8uuttK.....99...-.W.FVMi5..<hh.....F67..X\..TT..""..oo...Y....E.x5.iyN..vRHX.....G...|.!W.ue......TZ}(...........0>....0H]S.........pp..II{{``^^.._]((."8)....S.MM6&....MM..............Zz^^7y.....xt..33Mm..........))]]....f&......2++........AA9)`o.B........1S.w3.m+...9..~)/f,b.......].I....@..a$c...R`....6x..N~1[..].K.G..2...?s.3......0{....[k...;;[......_.o.C.%%......./'....oo.........i>........@B''..=.WW77p.?. ..hh..........CCr(......*...2"....{{VR......33.....{[u.|6;......GG..kk..ff..WW]]""HH.......t.......uu....]...rp..........;;..::YY..I=?......h.dd.......ggttTD77idqj90..XO.a....A..q--z.C^.Z.._.....t-$w....Z.,wE......N....w3......>z.5y..]...........R..5%...S....D...;.........]]CKkj..11.......v.f.5'.....\..f.....TT......??...........gs..""..))`d
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.7E
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751089
                                  Entropy (8bit):7.999099128466057
                                  Encrypted:true
                                  SSDEEP:12288:HrecD/9N30BmFKUTVYYWaAq7CIITyLsPXXAGfCrsulTSOlXXBzyNv9hjkHw/vIji:aEvwUTKYWalWPHALrsulTSinBOxsw3j7
                                  MD5:F981C5A759FC126376EB9FC4DDD1D950
                                  SHA1:F084402AB8DE8AF3E82556C168CF33AE4CEC512E
                                  SHA-256:FCF48793F8CFECF882864F3BDDCA042202C0F14E22B5E85F14B6C92A31CBE972
                                  SHA-512:0CCE0B4252D980C16239D9E28AC3F9FB61B769C86120DF1BE4397DBCAE6BEFC030BD27C91DEC33C7B733D6C0986A32FF89971DE525EDCE9567B71D2C5D07D8CC
                                  Malicious:true
                                  Preview: ..vz.Q15d.hl r..3Q..^3....;.....iWR3...+.~.rh}.Vyp5....k.<'q..D7J6.mHA....Jx.....R....>.........uQ,.k.....R1 PY.3...f....>`..u3..<.......i..+.....l.......7w...r.hs@U.....j.`Z.[..cFM}I.;...sMpnm..7m..=.4.-/.Y...{.Z..d.5. .P..;%.)."./,.2.Uc.6/..;.............]_.]=.Z.D5V...?..BP..S...i.aN........%...4Z.R...:.F.....R...............mPq..z......`.o...R...R..F.A..........> .......;.....$..1....)...h...f..Af1..]V..3+.m~.Iq.~....\.R..6]!..j........\I.....b.p.9.yF.7.=....B!......{~.......e)e\Nq.#w8.j............IA...).XiQ.3.........=]hj..ek.us.T.f..e`%K*X..W.:...#..$.Z9.(..X....5>....}...a.~.$*{sV.A.....I.T.a3\...?....T.=K@..q..qz..V..$....~....+.E~..$...c....WD.......v..#...0...L.i...]..X..........Q.F....o.~..Q...;Y>.q.N\m9.:...O.G.......]...UA.. .8...D}CM)..@.n.B...L......Z...i.3p_....Zk..-...H.Vj.<.R../A67X.TF...P.%.._P....C,s.....\.S\....9......dT0..Z.........K......z..oS...t.........h.F....P!.,C,a.w....2.rT\_Z8....\=..#.Y...S..v.6H._.P-*...$.
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.80
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751090
                                  Entropy (8bit):7.999280086243793
                                  Encrypted:true
                                  SSDEEP:12288:49BR64Y9Ml5fdC6cmSSkC5mzBBl86haCyT/XE7nrW8EE6CQ2qtWN9Pjy8NK:49xY9MTLc5Skjjl8+zyT/07nIE8PSjyz
                                  MD5:916F21E7B0E1150C141D5C6B63AA9923
                                  SHA1:DF0A7386143D1EF2BBC2CF477FDF81D843F10BC0
                                  SHA-256:7B2AE1A9F8219AA82C1332A1D8AA367E664B8ABA1DD5101E9B61A9B26B5443FB
                                  SHA-512:42BE8CF92E6A78575C151E48346574698B89CF77E4B77D565A8460700B00813CB9799D1059796B035487F72C41AF765BAB6AFB2AB141F32731559E339CEA2C2E
                                  Malicious:true
                                  Preview: ....e4..0...d........T........F..s...*o..O.t<.=.......J/L...%.{.k..N...I8...3}neRI;o.)...$;..".........d.......xd.A..........1]...e.:.s#.^...e.*...X....po... $.D.....#.oB..d..PF..o...i.Xg...S....G>.\..2.M.RA....8...>[.W...@.Gh..V?v.=.9mQW.0l..'s.(.5..]...z3#9...t.Z+....Dq...|23F....T...n.N.U..3iG.....;%/......)@......Y-.E..>>..=}...\.l......T.?....`.o......8..x.......WN..vs.G.+...t.b..G.d.@v9.V.......? ..]..>..AN.v= .W..jp...z5...7R..:..k......,...O.....#Ix...O.-...~<..G..+.]..z.2....?..G.......@a..k...]...v..X.?.&.V.#0../...B.b&.6.........(F....r....$.:2_......../....=....I.C.../....|; .*.u..Sh5....S.}Cm5f.;"P^.{.h.i..l.*q..J.]..3.Oju...`...(.jx......PQ.{d.T...!0..1.<9a....c../....?.i..................s....Q....&.N..:...dj.Mu..z. .....e.-..F.v......Y;C.b.7..v.`..7....$.K..4W..y...1jpr..)4.V...i.F.M|.S.&.........u...r.c...a....$.....{.).....}.........I....y....f.o..xK...'V<=......H!.d.y...Rx[.R......#..hy'...nK.*. ",.......H>f..<...
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.83
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1001005
                                  Entropy (8bit):7.9873502290037415
                                  Encrypted:false
                                  SSDEEP:24576:ohtvTTUfe/0CJxrkbCtGWRrwsdsGIx1Eb+uB0gUjpuqh:CTofE0CHgbCtmsqGiA0DjpB
                                  MD5:2B36B68D38DF6EF52E97DA209BCF50A7
                                  SHA1:21E29386531516CDCBD2762A0B33BE66313FF940
                                  SHA-256:DEF49279CD56B59134E2E5AB028274BBCA99537C1AF657BFE6594256C2F3A9E1
                                  SHA-512:3A050B2A1359B326C4130509184410AF91593364B495BACE7DA054DBB46FA4310D994CA84900487242B12C2795199526EBB43968D18923569ADD4F9EF1D3B676
                                  Malicious:false
                                  Preview: ...X...*i+.!}...xd.z...2\......'F9W.l..A.)L..c..h.pM>.S.K...E+(l..a..Rh$...l....g4.........}..I.\..yO".......y.....y|.b...ay...d"Q8[7^;.|..;g.F....bi.E1...."..WmC.U.#m.....\......7h(w...Q!..7N..|.....D....A(O.. A../....r.I,.d0l(a........q..#....J:....~.....m$.....z*..O..L..N...T.vX;r......3p.......I2.h8h4.......Y-....bP%f..~"../f'i......x$...._....v)...=P..........5v.. |.......Z.Y.z)...LI'S5.E......3C.......F.......D..We*.M...~-.C..}8.......s.A.$T..k.|....<...........Q.C....:uF..Ik78k.{(..........;X|#@wZi.....p|..d..,Ld'......S.h,.....y%e6................:L.d]/o.t(*XD+...Z.Kg..c...C&..{'....q.}..=I.....#.T.M...F.."uB..a2.@..C.E..(..g;n..}...~....I:6.....wwwC8{yC...N...Y.Z6y...\P.?l..d...E j..S..p/C&....r.EE,.^.wM.$s...#g...M.\.B...R7g.GW...Q4.s...|....=<...v*.....Q......Ud3.t.u.N........m ...M...A...j...............(IS=..9.E...\(..~b.t.....s/.b..r....a.....J+.`.......
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.87
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751089
                                  Entropy (8bit):7.9990488061230565
                                  Encrypted:true
                                  SSDEEP:12288:8BtVfacLGvv72PUAZ1rDaKbPZdZJoYE+hA9YSL4L6qQsH7QDtszIQH9rJeCbw5kP:MVfHavv728w1rDhbBdZPE+MpoH7g+B9t
                                  MD5:805987ACAE5DC84E05A6BF80A9B01B8B
                                  SHA1:3EAD50F249805DFFED07E2561723FCBA2BDDA11A
                                  SHA-256:817FC5544230B02468734EE6447AFA64FFB059C1585B722621BA492024A53375
                                  SHA-512:66DA2D1670070D07769FF609B43E55DB2BB5F091FCCB17BE3A2C77EBB5C7351FA3C99EAFAA1AF2F487B6F797FEE40E7FB8AC6281D435493FB4B33597E06570CC
                                  Malicious:true
                                  Preview: .....FG0.kj..D..%......<.}.j..R..("...H.."...G7x.A\.....J.h..>?^$....4....~....I.}Ma.s#......|.q..et..Gd..~.1.H..k.......lw.3.d..}J...~Q.X.....V;...Gq..Ea.....}.<..M.(..r.|.S~U.c*..]...u..#8#Arcc{..!.N...O..u.=(...phSz......CZ.~.\e.^.<c..]..F.N.h...S...9.,./......?..p..&.G....5t.m.........q$......N&........V.(8.1....$.....f.*.;.Q...jqr,....1:.....se..........z....|; EY,.i}L._g{.....P......:..J.O.K.....v..N..B%.I.^.P.3`./..26'.....m...0K.s.7F$A=....*?.u.B.....j..-...v..=.=...[..K...A..v...=m....`.|..dc..1`AV..........i.9.y..~...n.j....j.....?.-2.Z|..;..*.G..h..A.R.nl3F#.F....e..6..............p...e.yC.p9..N.........^.&.(.}Ft.l...__.d4ln...4".$...i.R...MT...c...Es..L..J.}.<.S...........6....O/..`..n.kh...v.k.JF)H@~.;u. .....1.4.R..........]..;....k.=.'.."....7...o.-.........$...D..y........%..\...a.eV.-..2....:..?.~..!.....J?.P.....P..E.o.........2...,....F.....ai.........{...)...s....<.m.$j U...{..I..`N.n..u.m.....H^....3/...
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.A0
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):751089
                                  Entropy (8bit):7.999696440620401
                                  Encrypted:true
                                  SSDEEP:12288:haQBnZttCKzcQhPTzKIWQOPoPwxM+Yhx0ESFK3GeOHSpo0aNiGDDn534xwFxX:nnZzCKAQhPHWo4xMpxUsGeOiI534xyxX
                                  MD5:7E8A1F576AEEECC8223FDE8BF68362A7
                                  SHA1:7FBED00672BEFFE47A0442DC39A7841D7FE5A25E
                                  SHA-256:0908A442E12A74FA61FB48319F209CF0635D7097F88D2FB632282D4F0A049FFD
                                  SHA-512:3ABEDE93A72586230777AB66F3620CB4EA8518FA1E78F4EA63B066556FC19C12AB02A819F74C158360AA8E0145C67B635FAFA4390E99FC7DC2F4C335A24C8215
                                  Malicious:true
                                  Preview: .....ki*-..!.;_.T~o(..OM[N..EG..|..........{../|P])..r.(;$.....{....SOc...L....m.q...r..S...1..-i.......}..o.......G.W.P..^.........G.S.=a..7.....c.zz..G%..3..F..w7........K.W.X.O./....Y..\.A.0.l0.RyM..LG..pK P.W.........`[..i.@...NE.H.pl....*.....ng. .y...e.6c...8~..k..3.....sK...r..J!${..........yD.hGk..b.U.4.9.7......t..D..U..m3lT......y.l&s@. ..d]2........2..d.<.D..sK"...z!..aB..{.....i<.N..>...YR.j1.<.t.s...M6.;..t..7....S.....BI.Q+...e....Xd.,~rzFn..Z0O.PY..V..9I2$7.. UM.a..3.v..uq..M.......i,.b.C..Io/..*(.PM...Wj..+._JJ.....f...(..[......._...$..OZ..B...c..E..r^..;.... .........S.......%..$...oj..5.e/.M.\.~..d...U...8.sE..k\..<...B..Q.......m.3s...$....j~e..h.E..CI...k.I/.Uq5"H.G4e%..$-B.(...........d..R......y..>.+.5...R1.Sn.p..Y.3.$.....i7..d..?5u_.O>.).WP....y[..j.;C..B.....G[v.&4....`s!E..`k..8.%i2np..9huU'...U.....bj..LKZK.<...2..V..w.b.F.3..".l.4S]..........m4.ga..=c..7}}>Q.-.5.........../..5f%....././.b....2b.:........&
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-75AA7CADA49CCFA36E050EBC1592844DDD43B44E.bin.CE
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):141776
                                  Entropy (8bit):7.990822069435878
                                  Encrypted:true
                                  SSDEEP:3072:ULAX9WNCVZ9NzrlAOizVQEd+0elTCL0nbS1L:MAlAOiZQ8+0v0nb4
                                  MD5:2DA8102F3E2D8F032B7423CD763F703F
                                  SHA1:0C6662DE771595086FF0FA96950F1FD85980EA02
                                  SHA-256:F69C37DA16CDB7637BC282687B16CE84BA18D4D0F52AFD1FC5B4FC288F40A5F5
                                  SHA-512:04F32CF43BD0BCBA100B0C72FC1BF2A33FF3A811537CD896D0C964619EB2E54BCF846EEB19499E079E8B0EDF25458E6376E58B4464BF86D9CE8DC857E156940B
                                  Malicious:true
                                  Preview: 0b}%D@cvk......j....7C.d...f...(..........p..e...w.V.}..K....../.:=....7.5Un4e......q[Z...1.r0..~..._..<.'..t.APjI.3H\..........(.....O.CM.+v....tN...nK._..&^xW......(\...6../r..%.l...9B..{.3.U7.1?LvL......|..y?Tw..q...p......w.....m..O......Z.c.J9..c.... ..0.!..\....8x.7. .|......]-..y\....un.%.r...4..S.z..gF."&\...P..........."H.x.z..R.G...&...%[..r..4;\..A......4...<.:......E..R'9B>..x....Z8. ;..-*g.5.,+........9...s...y..v....r~~L..J...3.....C......E..~t;...#...@?...WKv.....+G...l.2.R.....?*.%CU6..........v._..E5T.}_.....a....|/...9...._.......i~p.h.|..N|.A;y.s....."M[.....pU...3...?lu..1...U2.."............./.y.L.o.9......FF..y..J...5r..Y........?..QL....+Z..XT.....VO....2. _....u..CA.YAk].......+c.d...NgOJ....r..?.H......:...8......{..p.........F.w..hQ.E....Sp...g.x..u..S.FbJ....L^..F..js.O.=u..KY..z..N..........I....0..=laU..k.m5..>Bvw)..MO.>*.ud.*.._K....g.....b..F.#2&.U..}...A.........PwDG(88,..z..}{W......~.Q.s.!..w.
                                  C:\ProgramData\Microsoft\Windows Defender\Scans\mpuserdb.db
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):273212
                                  Entropy (8bit):7.999287955196481
                                  Encrypted:true
                                  SSDEEP:6144:YO+22luRVtNKdnhGnEgeKybxAsaNQUhNChSPRoomgO3SSUDLVFuw7:YyTY5hZKyleNChgzmgB3VFuw7
                                  MD5:FB108B61A36EA406D4DC08A9F5149D7B
                                  SHA1:E576623B5F4112D25D1F7D644423C2589C03B5DC
                                  SHA-256:D4B56818BCE3FB1F453E373553E86489181A12E0E39BC0BFB93B22BC7BA147BB
                                  SHA-512:3EA991B11CA60A2B3351DF909361E2D6A069995516668A8B3DD28AE3374AC7D08CAE04B69901904A75827641A69B514A82800A6220B1A436D0D3CBC6DCDE127F
                                  Malicious:true
                                  Preview: 7N.....\+].K^G......c(.d....$.i."d....*%..gP...+uG..pfG.7F.....6.H........K.......OU[KJ..X.*...2v...-j.1b.J...o..(../.P....Z...0.....F...,.................w\y..1#u..kz.0.....Kt.~.y....O.\0....x...O.87.-.g.X..8..#!.........x.O....j'..3P.T...\F.....~D.z.\|]f.<..o.....&,....S...n.`s..#..={....>..8...Or....I0..dJ....$...R...l..fw..1...5w@..0c.h......T..........R<0/.S([)...)..|^a../.=.m..f.;D....?F. ...D+D.O..U...T....Vv.d-..d;.y.!]FQ&.^.c.?.g.O.<.........^..n..H..A...<..y5.Z..z...k..+d:.T.....G#b.....R.b.HS...L{.J.L?.vk{B;...K5..s....X..K.'....X..%.,...W.Xs.2D.|...I....kN.......%.....Pz..tk.....$E.. Lf..N..6D..}.....g.#...3.z..2'c..n#.r.b.\..:.T...]..Z.Ei..m.."0.d....T.xt...3...~'.....8......$ ..h~i...a.)A.4.j.a.......x....I..L.t...?.U.H.....[..z.h|C%..G_..lh......./.?.G..W$~C..........$...h......LL.z.L?6...nn.2..sAvdQ.Q..94|&.5.n%..)..oy...~)..t.K;.........#..j.a\.6U.*....*s5....?.A.f..D^........Wq.......rg..6.I.L7O.'.4.T.u....-.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-012343-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.874220195807079
                                  Encrypted:false
                                  SSDEEP:192:wLjKKUxS3/y38XVO5vyMmS4TDliUXkCJpjHKg:0je4qsFQlr4TDyWgg
                                  MD5:2B41BCFB19A0CECD4515DFE9B0167CAF
                                  SHA1:F97F4A5334BB97DE1DD42853BD11E68A36BF0875
                                  SHA-256:AA99563523CA06B5620ED4BC4FCD8BD736DB7887980341C40DC59785912E2EF3
                                  SHA-512:FD055C50498AC2C20CE85BA5990FC951D154A55D090BE6AB03C7D7835B95FBA101E461291460309E527EF63F6CDC01BAD05EF364663D886DDC4E45DEEA946592
                                  Malicious:false
                                  Preview: ...ss>=..zzEE..``....99..mm..00\\....pp....++.fbf&.{.55........~~88.....)...wpy.Z..O0k...........tt..8(..cb.s!c..``.J9...r...I)..__....SW.....80....NN..W_kn....RT......_......%_i.M(....................//XX.............::.............=<64..CC...;;>~...,^.G4..-I...u...;....fW00......KK........PP......,,..........MMB@.........ZZ.G[[..w.R...~l.......s....$..YY%%...D-e...6Dt.).9..n\aQ..0.......r@xK.$0.4.. ".lY.c$$.'.H...o.t..I;.:Ww3.u.V72n......bH;.n..t.A....G)......+.,.`..q.<N..fQ(.....]<..+_....f...{....S.........(.|N..n_tM..Dt!.'.Fuk_xK/../..Gr.....Re."....S}..r\..{~..,.5.+Y]8..a..k .-r...k.;^...C&........8..!/....*..Xl0.a.(\..XX...........D........le.4.`app..TT....66LL..,,..\\....II...;;>>........$$@@GGww..pp...........|..~....(.....^....&2C.....ny4=xjR.OF..89..3;Lx....**....P.S..uU.......H........%.~O......BR...~x....6'..&f.~0.CB...k...lEMN.SG.d..........7..A..._d..QN%D..b.<|R-:...DD@...c.9.U..J.|.O..==!r..<;>#*.....O..(&.......
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-012648-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.887663550366695
                                  Encrypted:false
                                  SSDEEP:192:3FViShxlPykTiEBA7frruIWu7sUN0muo008nTkM5:3FEiekOYaWe6zj08TX5
                                  MD5:6577E044B9F16FB3DE7D183EAD42E3D3
                                  SHA1:8CE796C5360DA2ADF2DEECC53342869334EE5A47
                                  SHA-256:7D27B7842F275DE6CFEB2731DE0F1C91A11E1D4E7D461657E65F6FD311EE3AC0
                                  SHA-512:E9A03A3D211F0BF499936B63420C32E6C8BFA3A27A72CA9B6FEC68E0AD6DA0A40F40DFADD78FB06578E8E3337A0A4CB3541317ED8898A7550CB647750E0918F8
                                  Malicious:false
                                  Preview: .-=........xx..........LL..ff....DD....zzh|........4.....ee........SSss.....n.,..'...|u............. ..zpCBK...><11.w/0t.f.H.?_..,,.......[Z..NF........JB`e..LL......jj..9..'g..J0n.......m..c....N|.)....33ww....aauuXX||..%%..ll..PPmm........><....bbHH.............................bb..mm44AA..................XXuu..ss..jhgg.....)TT+....1..z.X..Eb||..&..j..^..........]...Aq.>........m\.....5N......&_g....................3Aa.l......`....9P...%J.W8.o.X....G)..0_...eE..k,O_*.y.....#`(........7k0|r...H;a=...DZ.fK..wA0.qF.......7.Eu....ZlT`......@m3.6P...L{.%...........h.i............r....j59K.}....;H........-.o^....SbuM!...;...............sq..........ha....IHee....77.."".....99..SSMM??66>>..``....99........llTT..$&..n.....vw..bS..\[9&....TVvbP.../Di~kb!3..njjkDX........44....C.K.*p`c..vv}..U&i".+b__.jHy..TT........(F,Z:+.....THK76$$.=.G.....dw],i50.kk:mUE..1v.. B0...;.U..<?a`.....Yw.....;n.6K.Sv.....af.3..IX..`}...J....my"B..6....
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-013521-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.852574916789307
                                  Encrypted:false
                                  SSDEEP:192:/cmyh9Olp3JbZD+eVXRMSx7ZZPECIqw0f66gHMsH:/OolZieXsCuHcsH
                                  MD5:C606B6D3D951436BE9171C0C5594F4B4
                                  SHA1:173883BF363951B39457645882F5EEB5F75ED019
                                  SHA-256:512C1825D86CD8C4F87D4BF17DDC7395333ADDDEAA35A5414918EE905CA119E0
                                  SHA-512:40EF2CBC33B23B8515E3BEBA037B5F66716C89C0AE70134063F6397914FF9280A339C178F6C3F0755DE3DEE1B9AF421AC2E8EDBADA8F6D84C709EE3AC47C4A22
                                  Malicious:false
                                  Preview: n2"@@..;;.........55..ZZ......;;""QQnn99..rq...."&Ut04{{rrHH........CC..SQ.nhj1y...j..Gk..aa..,,..77yy......Z...}..^.~F..Y.....ee;9..AE....mm^V;;ZZ99....;>..!!..9?..aa....JK..+_{..._:{....~....1....@q1.ll..uuGG........cc..XXyy.........38^^'&?=..........;{=IN4...q.j....Z6o... .;...4...99............<<{{....DD..ii..II......uw13....ccG..........gG.-.xSQv.......N...__RRggNN.."j@..*;........&..5..*Zw.4.N..;.".Q`nC9...rG...&eUo0l{+r.H'.z....C..|S'.mj61|.....G(..a...,p..7^y.........,.^=..*X.....e-;^.A-...|m1^.;TZ=9J...;s.,!...9...aV...6Kz..+.{K.._l{N...+.....0...@m1.l[..uFGs.......c...XnyM........3.^.'U?Z.........;.=.Nv... .(....ZkoW.. .;..4@..99...........Q<l{3....LD.._u..II......uu11....ccGG%%........{{..yyii....''....^^RRggNN.."3.y.E;.......%....="t;i`IK..^.PQe...U\...\..62..xd7?O{......i...~.n..1eO....1...j%..%l..M.0............kmK*z....(........&...V.?..|2!4E..Z....~nBs.P[O.V.....|<..@j?>....N..5$..*..A.E.[~nn..VQ...4....^nB_...I..q.11.?FW.I.J
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-013832-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.897689801537956
                                  Encrypted:false
                                  SSDEEP:192:AnFIf/hzHpZyGRruvYNnZFJJBrYs8Zc42ItqOut0DmTHN4r9:+FIF6GRigNnZzYsB42GuTar9
                                  MD5:0D4CFF8CDB4C2475DE9D9B43325858C4
                                  SHA1:E747C86A59CDA6281FD5C2C1F25E1D4B55902C19
                                  SHA-256:58E2246110919FE643E0AF38B2B17A94F2B3BD96A6C2A4ABC340180F9020D7AB
                                  SHA-512:F5A91FA2165E06730DE0675ABACCC1E9FB9B790226359B03254F170D74F47D2C9CC3F8994652401CE96E5F3648296F41D072E53D8699CB4243728D0D1E3EAD06
                                  Malicious:false
                                  Preview: .....?<gg..ee((..NN..BB.......................E.9:....``}}....''....aa.....C...U`i;...o..6..mmuu..__......on{...........$#.....GO........WW....XP..gg...'.w.............CC.........oJ8.o.Ek...J&`L..).0.'...................QQ..oo......uu..88V]....,...~~??........8B...dJd...?....!...0..gg.........................bb.......EG..vvRR`...6..'I...L.......\\.@..*Z.Tnn......u&Y.r!.......?..~LL|........Xk.....+.....2T...."f:g7..^1Z=..y.....q..D.A.....s.z([.."DE1..(A`....c.'T...B'....W>.J3\|@.o.p....vu.X.........Oh;~6..S~....gU......N.Qh.........>. .!....gJ........mZ...;.....)..m1\..Bt.!.K9X=Ek....5.`?...n..'B.m.].w....kSFv..@q..Zwo^.:m]..u[6S.J&..>>::..~|...../.I$-...x%.yx55..""......jjee::ggKK//GG..bboo...............vvhh..EGet.C..`.......'...st......TV.....]6QF..-?O...EA+*a}......__||......H...?....>NQ..a..u.<[...{..Q"..HHXEY......MZ........[..%-...cc...5P.{.4...um].....u&bd>9............#<][..'!G...mmee..qq..00FF..DD..YY..uu..}}....~~ww..44@@.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-013925-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.892569769725758
                                  Encrypted:false
                                  SSDEEP:192:T1TZ8XPIxq+8KYJZ/NvlNvLWj+1FbIXsYHTI+WTNMmLQZ8nWL/Rh:TueR8KyNvlNvw+1FkFHCTN3LlWL/Rh
                                  MD5:CEB065A52FA610ABEF772D344F119B69
                                  SHA1:7AEE720634E63E34015ACA615A299EA5C47E0518
                                  SHA-256:1E05B51B7932AB99D895DE66963C42E183012E24A9736EC9583FE28624E73B84
                                  SHA-512:ABEABF7941E489CEAA4D2BE878248464F5EE3D45097C3F69CF857B07D835CC837497C27D1988DF4AF6F69A901CE18B05F0A2204BB8BB488CFAD934F64ED57534
                                  Malicious:false
                                  Preview: .........21..gg&&99((,,...........))IIhh........9=@a..................qs...PY[Px......Qq.......tu....K[../..jw5MO....z......v.:2............]Uzz........jo............^...Y....P"..1B...9U......pA9...qq....]]""ffmm..88........qqTT..SXii........--....|<<H.........|..aMnC....aa11..}}....vv##yy........QQ..}}OO...-..(*..]]==uu........pTG....(>.4....8..W>.. ##......t'~6 s....Wa..w@5......2bO.....-.)\n..Jg..9.H}....N..1m..2@.g..\........I(...3Z..........L{,}.@.o..k.u?L...@.l.....j......Z.....W#..B..B..V%...5}.Q|Q...xJ.-......d]....&S`LupB'.Ux..4....zGjEt..Sb....Xv....<]/B.....g.#F......$..M?..A-s.b.}..m/...?.|L.%.#..=..#bZN~..bL8].....rr..yy.....h1a.....z...@V.A@......sr..oo..__.......ii??..^^......--....AA....11NN..SQ3"y..D.gj.........CD..b-......)b\].i....M_$o..LH....OG#.VV77%%..8)..x8.ds.DE..M...:&...-L....Z....NC....4n...~;...9&....o..}.H...VV.....L.$...,..0=;.....JV,r....k....Hc#.h.L..44j."i6.;._.......$............v.....e%Q.%.01//O
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-032831-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):7307
                                  Entropy (8bit):7.44031657730767
                                  Encrypted:false
                                  SSDEEP:96:vjGWoZAoHScQukZ4vzBDln+IOIGjZnxJfNDWM5IJErtpBAXQ3IlL:LGD3HsVZyVXheDN16JNv
                                  MD5:EF28D1E2042FFA3193D2A8D07FFABF6C
                                  SHA1:086DF047766F190DE7AF7F8AAE1CB2FD5EED8B28
                                  SHA-256:39228919B1FCD89DE4FC8CA91755062C5F1E400174773F4E6EA6F28579AA0F77
                                  SHA-512:68DC2DAB90F7B82026F7832F94AE4264B4CD5B082E5B1C4A92DF75D6B3B861BF524799BB8532C17B4394252E73CA2363B295B6F49DC47905CA6E420690BE9C62
                                  Malicious:false
                                  Preview: biyyyIJyy............rr............................1................!!....R.jh..]WW7V_W.6......yyyyZZyy.......N....||...<..+.G....cc......JJ......................HH.........rVWW.b.W-.......y.y..yU...........PP......00......II......................tt......<<.[....i..W$Wyp.W;........yHyH^^yy............................""..................RRR.zz...(...2...........G.r.VV........y1y*..yI...........Tm...-.....%.......'.?.....S.*:f.@...H/...z.v^..z.....W>W4x.W8........y%y.J#y.........r...h.o..i.......k.f.s.b.L.\...w....V...H.6!..-....hZ..WfWn_rWg......yHyTZmyT.....&......|O...3.,...|..cU...l.xJ/.$.b.c...O........z.hH-.5........WfWgbOWf........y.y..yy..........P......}90..s...II......................tt......<<..........WWWWppWW...........@^.y.c.........}z.............~...90...]`i[_..4(....tt''II..~o.yN..pV......+..E.._...mud...\\.Jhnvq..<.........GX.....A.55}}...........^^......**....88//..uullVV....zz..........hh..''..TT..!!66..**ZZhhCC^^......LL...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-032940-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):5258
                                  Entropy (8bit):7.744567783594619
                                  Encrypted:false
                                  SSDEEP:96:cGrBRRI6R58uuuuk9hjx7dakfwFuxfPpp7q67OXpBAXQ13lD:Hpp3sFuxfPa67OcU
                                  MD5:3809C95E5E7574373CB173B18F8FF7F8
                                  SHA1:233E196B9721983B85640D420920256D9989534A
                                  SHA-256:CC14671C4EADAB1CE38C25C5E3F4202E1AB8B7303E1C5408C349701E597C647B
                                  SHA-512:4DF2FF5183EE6F9DB83AEDCF98CF43B6476F2907690312498E93A9BF71CCEBDA77F73E8D808A793A89FA24FA20E9A68E1113347046C49E09724DDEFA4022E953
                                  Malicious:false
                                  Preview: ...............hh++........44..))%%..WWGS^]..K.JI...................zx..{.DF/...Hx..csO...``""......BB......t...OM^^..**.....[v...dd..........##fn.........rrVV....??""..W.RS...,V.c...q_..q.s...Id....Ft........ee..[[......DD..&&......--......a`xz..,,.....\u.....)L.Ke...s%I..3..-...............JJ&&33..11..++HH]]..11..........>>..j...X.ZZ2..;...:........@..M............Q.Pn=.......8jX.#..Qh~S.. .....Qel\..:.Ux[n............W0.b...2vD%-Y3R....0S..3\.@/S56B.E!v.}.....?.S...|.G5....Ii.......`.......)FF!f..R....].(........Ew4..../EhRb..............eP.....3pG.....<.......;V....E#2@....... z%...c..5P.r.....5.|Dn^Fr...-La.....1....G"{.\0TT..FF>>ca...|.k.........(.utLL......--......II..11........77pp....\\uu..qq.......^^..du..O.P@.{.....>....\C....31"6...y.......t?.........wC..~~..d.SBw.M.<,{.PQ..9.......V........f""........fW.. 8..ny..tr......~~..MM..QQOODD........%%......++........EE....GG....}}JJ......uu..__[[qq((mm..hh....''XX22..mm33ww...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-033020-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3210
                                  Entropy (8bit):7.509147259179185
                                  Encrypted:false
                                  SSDEEP:48:GfHUw8LR6Ts95HJbxATYHAOuwNM4pFFp/zXjP+/Ad4M9/xJfAXxuP7eYmsl7:44R6T+5pbxEYHrFp/n+epBAXQPq0l7
                                  MD5:E2D643AD498E4D55A753A413582C3AE5
                                  SHA1:8D5EC8DF4AAAC6ACF8C4C277514115681D618D60
                                  SHA-256:7787CA82ECCBBA69207DB88EC3424E2D5CA5055F23FF8F404F9FB2E06E1A553F
                                  SHA-512:20CE987C6F84E22C9647C6991B920BB89DA46C93E44B2DED553905AFB8C1CFF542377A25ED384286BA3E370171DD4F10DDC3A3ACDC4BBA373F4145E2D142EEBA
                                  Malicious:false
                                  Preview: +4$....ll..00::22....**...................KH......:.:>}}........((QQii....4021...|....T..+*..ZZ..yy..........Z..NL....ppqq..)s....::75``UU~~..........}}...KN33..OI.....<....H4@..{.dB1Lb....Ei..'...gU......$$........ffaa......nn..........ut....__....ff&f..@:"P..x......+G/...4..4..kk??gg..............uu..??..................IIZZm.rr.\MM.m.."..p......KKc...X.&.........v%..8k..1......,....7.8.....|O..#..,..cN..,.).a.uu..>R...c...G s......y....s.=p.m..............qB,6R..'PB1|\...D'$Qq....v...E.......4@y.._...yu.D.D..G.R...,....r@............).....0...+....5....%_l.. .]l&........,.z.!S9\-......0o.I,..=X.([.......%.$..7..yT....:..2..........[[....@..fV...D..~&..32..........zz..WWrr........yy....kkII....##MMjj8800..VV.u......]]22eeBB00........ww....AA..%%..JJ....YY((..::..xx[[..ooMMCC...VVggccGG..4444..KK....__..vv....++OO..;;.......BB....YY..99ffPP.......pp..bb..==HH**............CCPP....55..HHDD......``............))..))............WW..^^j
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-074759-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):7307
                                  Entropy (8bit):7.846417985655847
                                  Encrypted:false
                                  SSDEEP:192:0kJ4Kq17hbN3N/pjv3bzlrDtVfPvEMRaH5rEL+G7Kf2Z:j4V9dhtpj/lDj/fRaHqLR7Kf2Z
                                  MD5:5E1CFCA117E6B45D9D32B8045972D012
                                  SHA1:E00980616F60C17864612E499C27FE1633D2B420
                                  SHA-256:CB7E898D63A0D42578299203EA0D1E405E89C957F6A909AF9C78DDF137A108C3
                                  SHA-512:5268283A1BEBD51F6975EC4A19BCAF25E59F734DB3DB0EF837C9E0AC4AB7B4D6F565A5C7013801CF2A372C0D4B8AFE6759E79F6C1154430AEFF593A6207EDC40
                                  Malicious:false
                                  Preview: .........# ..........[[.....~~............lo..a.)*_~rv............FF..fd\^.....%,5.+#..>.....II..aa..nn.......G"`kiRR.>.hx......q...........ed..)!..kk......GB........33......;{.c........#n....P|Yt.....5......TTFF....66....ss....VV..aa[[..........00++....,,..z.L6u.~.C0..E!..Q={W....sBaP..NNKK22..ZZ22;;CC66HH..22....WW......((..EGYY~~..:...j...+@..]....5....[.iFd.P..........t<.F..wG..8..5>...7.."..*....%../..aLW`!.......A.....].m....O.O".L.c......;R3P.k.>M.......C*D*...v..A2=..../L.l#Q.....;t<.......Y1.R.........O. h.Rq\..8..#...".;....3.8....:3...^g......1.T2..?.......lX.?... %D...i_.._9$V...x......[r..lJ&...~.}.2..!$..=-.aP.(Wz..}E.5..Wy....x............<.LY.09.k..1...................^^......ss........RRcc..,,.....CC..gg....`bbs.=...."QSRR..AG..QN....FD..>u..5^....<."i......KW.......ll.P...."b...q.....I..."`..{"1..}!#...U...n_z=..c...UD...r..:..mm ..4.B.........m.....06.x....jn~f..PG.....Q.rr^^......XX..hhgg....$$......KK......66....,,..__..tt...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-074918-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):15499
                                  Entropy (8bit):7.894485921388087
                                  Encrypted:false
                                  SSDEEP:384:Su+28d9csgNEY38ntzItTQ3nQ+d97S/YoDmo3HT:Su+7YkYGIhQKzHT
                                  MD5:361026D091D69881733CAFCEFA74874A
                                  SHA1:2F7034F1AA65E04C132A14441D381D8C24F95B83
                                  SHA-256:1B842C0FB155A0B606673D37A2E02EF5C6B1047D76E6057B79FF8E1579026F38
                                  SHA-512:2A246F948B6F4C9A2D52695F12FF6996BB36F49ECE5061920E09CE5E223F6FF00840DE7DCDB07A6301E4A551E4DFB34B53C2532B9A0ABD92883493280D1DF530
                                  Malicious:false
                                  Preview: .......KH.......,,......//..........}d..[[XX.........II......[[........wu._YR..NEl...6744..""....}}iy....ig%..vv...ED .5n..dl..{{..""..//....vv..................^^[[..............\r..z..Uy..../...nn....=={{..77....||....HH.......__,'.....//..........}.T.[)X=..aO.y...... ....:.......dduu..RR..EEllll..44..""\\..}}yz....%%..vv..UU%...4..(...>..Cd**""...Tq..*ww...............+..[l...rC......bU..\e......Ub..../I..n-.8.R=m{.D+7P...V;...H<5T.....Q2,^..../I..T......}..l[,X+.....x...W%.d.....j...u...R.-aE*l..U.O......?...;.OxR`..3.:....xOuA.(.>Vn....gJ*..q..pA`W.>gT0.VxiX..J+..e..8.(.<N$A./p..+...J/........Fw>.tDsG...&. ..~F)..........CC..{{..8:209.e5]...Zj.%./7.}|......;;...88..nniiKKLL44....))}}....bb....OO..............UD..........KK....../0.Xxq..+?..qpU>....:(...@DDE....yM.............2..de``.FGX...yl..t]...m.**........i3...j..I..A9;...\e%.4......[.d.F...H...m]l....<K-=VJ..e.Q7...TY.......**l3Jg.|..~{N|.........@FIN.bo^...........N...UU.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-124643-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.8624903815566
                                  Encrypted:false
                                  SSDEEP:192:Bds2pPbbbbAGOYEoTVZMTKV/J/Et32b5IM7D:Ts2tbbbbTLE4xjF7D
                                  MD5:87A6E431608471A126A57F6502B5D585
                                  SHA1:074A6D186B71CC8D5D55FCAB782075AD4902FD64
                                  SHA-256:A109C5E0167735C542880682F89250ADF0B69FEEE4674D4A7DA241E3B56F2CEA
                                  SHA-512:D13B46A02D79125B4C4BBC3AC1CFAFFC1706C2ECF17DFCFF4303A698D5C7A30B89856DFDB2FF3FAA7ADBBA26D7FE544823CFCCB30BA539C1A634969EA50C962D
                                  Malicious:false
                                  Preview: ...++.........kk..88..nn!!..........""..............WWee........jj..[Y..L....OQY0\....V..gg..;;``ll``....=<..>|SQ.....#.. 7l.)!..02oo........08..BBMM .................%%._...*^..\...o.Ig<X....'....xIYk..hh..EE....88....xx..YY......;;")ssLM....WW..++...G....ok...8...n.!M.%......""..............WWee........jj..[[......YY00.._....gg....eAA.av....==....Xr.W..CC....6e..)z..0.oY...*...O0...BoM| ../.......3......%C.....*v..\...o.I;<]....j...x$Y...h..E*...8L...x...Y=.....;h"Gs.L9..W#.j+....b....ik...8t..n.!R.U........"......3.1.4.....WfeW........jG.&[v....1..Yn0....?..gI.;V`.lZ`T...=X..|.S ....C1....6S..)Z..0.o^...-...N0...BsMu ../......r......%%......*z.nT\..goI.7{.........xxYY..hh..EE....88....xx....aa..aa....]]..EE....?=..k.8z.R.....)...z}..r=..^\.....S8......7|..........j^......y...A8x.R.A....$..E.....66O...:<UU....qm&xNHW6g.4%[............B.T.^.....b.Z.<.....Rc.CNZ..."3.T.B.[.32..wo.a...-.P.F.....k8& st,17...rc.+{f2<.#WC.....~#2.['g.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-124934-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.8990192429226544
                                  Encrypted:false
                                  SSDEEP:192:S8Alt9TRh1FiCx8qSW8+pfVrVVlCH/xPh95YtYKVj+ggxYg:y9Hu68Y7XCH/1b5Yd+gOYg
                                  MD5:AF1BD33EA9B1C53A710E67F1DCFBEDA6
                                  SHA1:6FC6FD7C644AF71E7D6FB3FBE3A629DBB1B1D06A
                                  SHA-256:D4CB5AA72E973E225CE9A25489FA60C28A26A287F0B82754938046F503C8C476
                                  SHA-512:862BF29F03CAAF63A31E7B1E45AECAC21E2E54DEDCC963D9D849538B88F8BBAB9B00F36AFE65992EC1C4D500C8646E2607A490CA37463450D533F426E66507A8
                                  Malicious:false
                                  Preview: .sc....CC\_......,,""..UUUU......**tt....^]..~......qq....BB..............20..........."......!!..........LM.9/mb`..Si.......W&F......kkd`..DEXXLD......nAv~....KK++_Y......S.......R7.kEU1q.7[....Qc..{{DD..jj..........kk....[[....ZZ......JK....44CC.....X....{...t...........6..dU..RR....%%GG++OO..NN..qq....11::....,,....__GG~~1....m...J....4...#.....!(.X.. ..55......f.....Bt.........<..=..8...7.}N.."........))#`6.....i`......#NJ....B#{'o"...p.K$7D_0.u...K.........i..9..Y<...{........oH).....!}.......*y......Pf..-...l]..-..=Ew6...|O..\q.3.....]lOxkZ;.............|........Q............iS6$E...........-`T......PakS....#F'S/C......{{.....0..E]T.....1t....HH..HHqqii........''YY.....VVSS..,,>>...........;;{{....?..N.>..h......vp?8...........ut...ng...@/&.........""..I...A..V...l.....J..=!..r.jy.>:..uu([......u/7#^<Cs.....xhy(.[.R.f....$..... Z......-...?h...2l+..3Q#RzkD..G=..P..**.\n....g..g.*..........L....G0..7..p.X.....h
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-06272019-125636-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):5258
                                  Entropy (8bit):7.751782749069857
                                  Encrypted:false
                                  SSDEEP:96:Z1gn2qvnM4KXfTFecBt+g7LPdlLnnwKpOOhXpdqzcdN2ziJxp/xZkvpBAXQLkWtF:ZendU4s1mg7ZlLn9pthXv2cdN2ziJj54
                                  MD5:2512C5FB6C5911B061A73A2A96393A8A
                                  SHA1:BFAF29C03AA861158D4CF3F082B58564BFC98693
                                  SHA-256:2EC7074CD78A97D34E1EB04E7340A3304DF350A8902C8035FB32A14518F90783
                                  SHA-512:2717CB43F6EA02510E72CD19188CACAC8DB007AB1A4FBFD99A77C7256F8670C0C38E6703212BFC6A3EBFEEB155374BE28826053E2E95B71DBFDEBD573A963838
                                  Malicious:false
                                  Preview: T....olll..[[----..DDIIZZ..MMVV....AA.....QR......bC..............jj!!tv..Y.b`..........n&$%..........II................YY..%%.T.....^\qqppWWSR``..}}ss;;q^........71......(.fg.R..=O..+X.8..X4....jGM....'....llll..[[----..DDIIZZ..MMVV....AA.....QS......bb.........q...jD!Et....`M............%%..........II................YZ..%'.......^....pWWS$T..P.ro.$qq...w...(66......({g/.A....=...+..$..Xi....j[M....#....lAl[..[n-K--..D~I.Z..cM"V1...A,....oQ0..S.ob.........e...j=!Ht....`.......i..h%W.........I,.........\...Y*.O%v.F.....^hqCpGWeSc`Q..}PsB;.qD.........7./._9....NyDu]nYmZtsB...b...gS.v.}a.q_...#.#|..X=....j....yH..!....$..Ob.....*.7&.+N.~....QQ..SSJH...0O.B........Z.32..hh..zz....$$bb??....00..\\dd\\.....jj<<....OO..((gg........^..M..no..5."$....@......\<=............TPTUuikc!.__..ZZ. rc....|U....UZn]..y.a.....0.((].......J{(,..1.......f`............EE........ww]]..PP..hh..QQ........44...........}}..@@......__FF....rr.......pp$$..HH.....
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-07232020-104031-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.886981240823138
                                  Encrypted:false
                                  SSDEEP:192:u9w3iCReRVj3/r316hehD5GCD7ehSLZyviZm4rRrDLWnx5m8jvEYDCp2eH2:u+3iZLjT1oehFGFgLZlNrRu59BJeH2
                                  MD5:EF63F33C372BC6970C8DD649E0A55F41
                                  SHA1:F4C9B348A02EF6002E81B94D77380D6C36A80E7A
                                  SHA-256:418CA75E0B8515BDDB099B50C44E7091A814CCB3B992058C0A92869E4E239CAF
                                  SHA-512:7AF0D24FD8389EA0DD31765573AFC6CA9B9A8FE8B71A65FA94FC24FB47AE9C9BCB3E17C2ED7A148456DC1A3E4BDBA3A85AF347FCDC142735DB6CD255EC753DE3
                                  Malicious:false
                                  Preview: :..KK.|,,C@..""..........LL""..nnDDmm....c`ee.;....WS00yy,,....^^......><_.&$../&.K..t...JK}}mm..........J@..R.....''......Sg<.fneeIK....''........;;..)..TQ..II..71.....R.DE^..................uG%.....NN00MM.....}}..LL..WW..>>zzHH..dd...76..ttqq..RR..........;H....-A....{VbP.2..99UU..........gg..........>>.............KIVV...../...^ttb..d.N.`........~3fY.`...KKggll9j*b.........Wd#..(n\jZs^yHtD!... ..."...uX...b........=O2].=OP1..K..n..@....(Z.*Y]2..0D.O.....z......-n=7R{...%WM$P$.zoO..~.L ...k7H.`.[<].G.*y....r_.......=..n^.. ..........1Pc..Nc.6,....."............6...kV;..cU..&@........Z)..0o...d.{.......iX..........CntE.:Rb2.mC..........VV((WUsq..t$.....3;f.......II..........JJ..;;.....))..77..AA............uu........|mm..B.10..{J..VI/`:3^\......"5.....I..9=IH....K.......j...k3s..J.YXuu....)f....ff.m.....v.DT...F....|..f...{-LMUU.4f-_.N.........22(.fv.?.....W..-...1..fg...`......G.0...GC.@ll......+6.H..@"..22..c..`....>.-,...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-07272020-074617-7-5f-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):9355
                                  Entropy (8bit):7.8901976796744275
                                  Encrypted:false
                                  SSDEEP:192:K9yV/++o+zrDi8LbhfemI0vhaB5Eiaq3s8DV9cm3U:K9yVNo+HDi8Lb9eep65f3s8DVugU
                                  MD5:C0003457576413087F8FE79815E5CE1B
                                  SHA1:A9E357632553D47653C7690791E691ECCE309DB0
                                  SHA-256:FCA5273E6C8B064D5033A0BF77526F3DA939BFFCCB710BC10084384A26FAB541
                                  SHA-512:11A0732AD43CB37902837A7F605B0F2402AE3466FA5053A51F27F61189F0D90149F74624E067B3DA3DF42AE204FB5D93462A879585706B9391032B9AF6997B44
                                  Malicious:false
                                  Preview: .{k__........NN..xx//MM....QQ......[[BB'?..........tpww..66jj........NL........bk.....u........xx..hh...._^......B2.....i.A......wu............__NN...-....kk%%........xx..yx......s.M>....w.Bn'...)..)......ww....EE....mmTTNN........kkLL........XX..xx.............B.'KhD...)......ww..RRJJ........NN..>>....kk&&ee....../-..xx..!!.T..d.kk..t.'.D.C....OO.d...8.$vv.......B.W({.,N~...i^..k[.?.>.$..k\...*xI.......<D"...<...B.'Ui....i..6rw..s.m.Q.\.v....N!.e..}..k7.....g....Y..oxX.....S!.q.....B''F...s...jw..t..o<.Y.L)...Ny..#.Gu..kY_o...9... Nx.-xO/.Mz....Q7.......[hBv'......z..tBwC.a6Dj..?.m...N.......k..d..'.......(xI..hE....._k.....BB''.........^.Qw....[...m.A..__NO........kk%%........xx..xx.......ssMM....wwBB''..))....(..w..Y..EE. (.^Yze`/..........x...el...i`,(IH.......vv%%..^...B>.yih.........W;.|........i..""..J......8CT..j...M./o.`.&..!!.\@.o ....J...EC''.o<,nr.x~...u"3......T,-....S..Vj.O.CP...}..._...wF.\...(..............
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-012343-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.144295090029147
                                  Encrypted:false
                                  SSDEEP:96:hAKcQ2coJm+xs5x+xs5x+uU2pBAXQh+icl7:6m+xsD+xsD+Ljq6
                                  MD5:105EC5062572B54FD57E2FC5D8A185C9
                                  SHA1:193B35431CA6045F3179FEE78A12FB37FFF9E338
                                  SHA-256:B4B9529C8580A3FF0BF149C2F2A1B168CA98A178A8C492DAFF87032D6448B45E
                                  SHA-512:6149EA180C165B2AE2184E22814BFB65B4C7444FC801DB7CEF05E5AF7690F32528667780D31E06BAE806097322F7F28B7051AF73991DFF51129C729F32D22042
                                  Malicious:false
                                  Preview: .l|.............................77............................**.......j......7....M.9......||.............=.........h;..M..7?............................**................7w...s..d.9|.........&.%................77............................**..........e.r..7....m...:.%|M.............................77....................>>R......+.G............E.............@|8........%. .M..........&.%..7..........%.'............x.p*X........v.K..7^...n..x.q|..........x.`.........e.~.7N......{.c.b.........K.@*n........%. ..7......,...&.%|O.........%.'.R...........9.&..7V.......q.e.o.........e.r*F.......&./..7......,.../.'|H.............}F......6....-.67............................**...............77............II9999nnRR....yy9999..UU......??9999 ........ff9999>>..........9999||......zz..9999..^^....kk9999nn......VV..99..............99 ........bbhh99>>...........99||.. ..zz..3399..........gg99nn........UU99....ii....wwhh9
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-012648-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:DOS executable (COM)
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.500941117910915
                                  Encrypted:false
                                  SSDEEP:48:VZfR2uKJ5Xw6laRSPHrOiD/usDCGhrOh+o29h0ijZjFEAd4M9/xJfAXxup2EiYhT:VZpDEH/7DCGIZ29NVjFfpBAXQTi8xl7
                                  MD5:D8E1F8FEFA39B31CA386136F5D6FDFAF
                                  SHA1:A855C85B58DA7C59F9D525668FF9D0B8EEAD3CC6
                                  SHA-256:3F6512F099154C7E6C9FA4A4F458E1CF2FB6309DD90A4C33A1F503BB2B7B3A7C
                                  SHA-512:8A10498486FA306926CDD6E9B509F44531B72BDA7F9C211F57F4CFB99CF9AA7F49F6AB861D7A2DA2F68DE66FD250784E2D5709BCAFCDFD98712B7533BB85E0EC
                                  Malicious:false
                                  Preview: .K[..RQ......00....ll......NN...............ss......VR....tt00ss..dd..^\GE....f.t}?'5<9.........VV....3#......m/....GQ.2.'.........^\..`a....KKBJ..dd__....rw........ff...]vw..e\&..6Sw.P~(Li...iE..pB.5pB[[aa]]..33........kkiiRR..KK..........gf75......&&.....kr.`..w.......<Pw[>...yH..............33II==......''.....OO((NM..13..LL....|.......e.1....8......DD[.T..m.WNN..vv..K./k.VQ.....0...;.l\...>..N~.....&..........sA.1...Vl...t.0_s..d...^.i...f:..?V<_9K.i....y^*V....s........NG".w.........^..`....pB...d.....Lr%......1.fP........ \e..6.wFPb..i]..iD..p].6p@..aP]j..Bq......lB.}k.i..?..V0R .u.. R.......K..b....j..:..IqL|.."....;....:...tZ-H/[b.HH??.....9E.q.zs.........%%....''..88{{..##......$$``..##..........................$bb........oo...........bb..ww77......BB ........hh......qq55..LL..99.....AACCaa''MM..==ww!!........00......bbrr....))....WW................ff..AA....ZZ...]]BB.........GG....##..}}rraaVV..!!..OO........jj........00......kk.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-013521-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.517992558330904
                                  Encrypted:false
                                  SSDEEP:48:Q1NLcUPCMWEj/mpJeZyLc5qNWqjS1QgBIRaKBLKAd4M9/xJfAXxuJKC/iYgsl7:spwM7jw8yLcpXtIRxLVpBAXQJKC/iml7
                                  MD5:D93643CABA5313493A804F40151773C5
                                  SHA1:E26E1E7479F442B1FB765316CF9A485CFC09C182
                                  SHA-256:9DFB66ABA7D696928C96C0EE8CC27989C1894DA84D6359C7F6F3785A819FD68A
                                  SHA-512:A247A95245C39B60447E93AB3475DFC96C5D068D022F24C4AA42B4E2E7296B67099A00DA15E8C099E5C7FFCE6E7796D637C048AE752956EEB11BA9D78CC1758A
                                  Malicious:false
                                  Preview: ...zz....=>....88..&&..PP..XX..""........74``..sp..%!..11....FF....++..@B&.y{.O..y.LD(D=H..xxIH22GG==...>/%..u.T.eg....W.T3...o.rz..ki%%....VW....WW.....+..wr..==........::.B..m-......I:N`.}.`....!.Tf..zH{{PP.......II....!!yy..UU%%..ee....=6......__..NN||"".M..)S....j_q....Oc..'..02.........UU......VV....||..MM22....%&..HJ=?))BB..Z.llh.33.C+=.+..sT......;y.BT.22..dd..........@v0............#...Ra#..31....'Bo..n^hh.>......o.e-J......z..Q0....!H...j...O;4h.~.:T.r.}..T'...}7R.(]v.Y0..z..A.o.2Sv......M.N!.t..e2.....9.zJ.....)...:..........?..#...0..1..1*...fW.:............Fr.8J.y.....y!......%@..5F.uJd..?..(..L}....Du:.....zT...>R....8:...v..P...APX..K>........77``..pp..%%..11....FF....++..@@..{{....yyDD((TT..xxI............kk........22....88..//....9988....BB....NN....YY..pp..rr((..]];;..OOeekkBB..........""....oo......22hhPPoo.."".......''..{{....VV..II..SS++}}...''..oo.....$$....[[$$..........77....IIkk..............,,......
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-013832-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.528425687776965
                                  Encrypted:false
                                  SSDEEP:96:XxkwsFQreuGnCGTMIFZZT3vXpBAXQ1iMl7:hBsqNGnZxlUm
                                  MD5:E01EBD2A0886D39849002DCD5472ED22
                                  SHA1:8E45974CAB9F61970AC070E9DE7B538250C9EC3D
                                  SHA-256:B003082BE793661F276888419F6E399D223BDBA5D5C9C5E80055706B99744B4E
                                  SHA-512:111C828C835B72EA0373FD83DC86A2252F502E0F2E5C23694A965D285406266292B351399942E7D3E3E547D1EA39345502251F22CFA8F6DF474D6E253F02FD3C
                                  Malicious:false
                                  Preview: .GWdd'$SS..JJ..............--jj**.........kk.....6....00............#!Y...@.4=..V_....PQ..NN..DD..PPk{)#..."U...qqv.J...H=fD$DL......xy............00..CK....ll........uu.4'&...y......[u.k'KJ&.$Xu.!CreW..&&....!!....@@..kk......}}....99(#HH..&$..==**..hh...)S..;^S ...c..9U!.....gVbS<<....}}....==....ll............AA.|..b`....((JJ.{..Q::.o.I$.GG]..!!...oW...1,,.........../.............Js|Q,..........5;....%.4........7k..E7.U2..u.k.T...;Ob..F.I.......q.....u)|+..h......d[{s |...^+..*C3Gb.........xY-z..UL.....n2.$`z)..=....L~]j...-..aXCn....1.....5.nC............+.....+ ........dw.8.pD.R . .a..k....x./J.....{.......*.Xi.:......:.Sg....>J.b..77.............H...S.....aann..>>....[[..kk..nn..........hh..........,,..``..dd33.'...kk%%RRzz..MM.......``JJPPll00``....OO..zz........//..........::........<<33**....rr..>>......^^WW..KKZZ................uumm||22..MM00vv......!! ..44cc]]...$$..::..66.....eeIISSNN22....{{....]]..//]]WW.......NN............
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-013925-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.39146245682242
                                  Encrypted:false
                                  SSDEEP:48:vKaQ/B3Fu2K8dozQvKpbhPxHx3l3l3l3lzpOSByAd4M9/xJfAXxuzIiYFnsl7:vzQ5K8dkDPD1111zpBtpBAXQzIiLl7
                                  MD5:A3C6017584FC36F490A4ECA774577397
                                  SHA1:15C83ADD750B3D3939845A904BF160C94D3A17DF
                                  SHA-256:5C70C5684741A2869E7608F49E60D6DE3ACBB8D836AC712205E2C8F3452C435E
                                  SHA-512:B53261A3B057F0CFFB7490E19CF901D9938327A41A793A9DD25AE6B3E7D21D99141479BEAA03224A4805AAE3C8E89D9C394901961B5254821D70B5302CAD7154
                                  Malicious:false
                                  Preview: ...66....>=^^.....nntttt...............................uuoooo..YY......J......:....L.........YX............k)nl...d..@..I..i...........8889..........).......66....==^^...*..n.t.t.....e.8......................uuoooo..YY............................YY...X...s.d)Zn@........:..........8888..........))......66....=>^^.....nnttt.RR&....s.....b..........b#2".7..uuooo8..Y..[.5.................... ."..Yk.-.5.....3.1))n-.........y..}.T..8Y8d.E.....e)Z...|6j..=S^:....nNt't.....d...............w....u.o3o8..Y..[.5.................... ."..Yk.-.5.....3.1).n_.............%..}.t....8^8J.m.....>)v...d6S..=X^p....nZtEtD.......&................_._wLEK.OGGvh.bc....::pq5555..ccqqqq!!..vvvv""..mmmm.........&&]]]]..RR!!!.....DDDD..NN......[[[[..WW....QQ.......jj....FF........''................JJJJ<<......99MM................||OO....##__......................vv............HH....ttRR....AA....AA...............yy....++.....MM..WWWW..zzWW.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-032831-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.517212065989414
                                  Encrypted:false
                                  SSDEEP:48:qFPmzldiFYn/rzX5O59Fn0XHkYmFDWJ50EpXEURwYrA0SsDtKAd4M9/xJfAXxuyf:Zd7/HX5O76ID8EURRisDtVpBAXQyi8l7
                                  MD5:61B95651EC33E78EADE0D6786F57DBCE
                                  SHA1:A78EF63CDDBB42BC5DC72DBE5A968C00C60E91BA
                                  SHA-256:1ACF78AD95A9550B4F7F408F9A073458FF2D1958CA906F650E5ED756F156B80D
                                  SHA-512:F044AE1987D21B2B578F36B95EFAFC5352B41A88F2D770CB96E0E0DE225B19004D49A8C09D7BB504A9EB2718AC0743A6D65473FAA8BEC4DB2F46549D6AC3DE8B
                                  Malicious:false
                                  Preview: Q........$$==......""......==<<..qq..~~....llRR...^=9&&xxuu..[[SS....'%..s..SWeo..qx.-o...........$$..YI-'z{.\-oqs.......=U.......;9uu#"....yqJJ......:2....NN--........4....z.>DA3...lyW.f.w.....6..$....,,AA//..kk...**..zz[[.......KK..RY..............11...(R...~.i..w.,@......N|..Ximm.........77....CCJJ..@@........66..YY..SQ.......@....h.F.e..=...;..33.?.=..3........0g_.z)....%...M.`W...o^./..uE.)kY.../o^..../.9..........T..y...T&w..f....V7..K..._<....Z5r....u"Y0.....b!V.9...d.T7...'N.{*S<.S....;Wl...-q.W..z.d..Lo8..~-..1.|LpFL~;...<.`QmT.1..^mpB....+..+'...iYq\..(.=.;..(./pAN`.8U..fP..d....-....t.........n..W23.M|/..&+.EtyICn~O2.Ue.3.....$HBB..-/...Br"....~.T].A..:;..........@@..TT..VVaa....xx..............KK....gg..ll..K.qq......**__..........;;..............]]..3355gg..ff....99vv..,,....]]gg.......gg..ii..UUMM}}RR>>11jj............jj..zz......HH....YY..FF...................EE..99....VV..}}..55..........RR...>>YY....xxTT....nn..::....tt...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-032940-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.525314930834174
                                  Encrypted:false
                                  SSDEEP:48:cvB02vOn3eOSoSn7pnC2LLmu5gcrhZ4cmWYAd4M9/xJfAXxuCiYrJsl7:oFy3ey2vmrcdZ4abpBAXQCijl7
                                  MD5:FA3C28D4088FEEE85B244EC52ECCB6F4
                                  SHA1:8BA57FF4167D84F870F11AE05A79DA17F56361E6
                                  SHA-256:578BFC2CE28A1B99D04999CD17770242A9E5FD35E6DF222D94250F383E8EF45C
                                  SHA-512:3E75B939F3AAA19BFFB418D287DE4DE23978EB6D088CB9F89AB594C3A53C71CEB5234EBD3699C5F8748932115C68F0D40F546329EEC00CA36AAC26D195F1AB38
                                  Malicious:false
                                  Preview: .td...-.................^^......vv..NN.."!.......+......>>..uu..~~.....>..:........\.%$%..OO....ss....Q[KJ`.T.uwFF....OOkk..x.......||DD....zr..NN..q^{s?:]]FF..........\......;I.@3.....o.s..-...............vv....mm......XX..RR..mm....kk......77......'gz......4G..i.o..Fj0...bS$...HHmm..LL..DD......OORRFF..88..KKOO...............^...,jj<..h..B.$1..%%......4.s....tt..../kT.M.iDqA................. .9Qh..L|q\....Ky..ff..Wm....,^.{..3A.^3\...x.+J.......a.........Q'pQ8d.N*../\.....>]..R .._+.../g....~...n2..T;..`..KA...v%.F..tD....`W... ..?...Yi....<.H|N~p]......%...........*...ApZt..3W.3..X>.n.bU{p....2..E7.o.j.i..L)..Bs.1......4.....<..MyQ....b...EE....y.(x..s{..KCT...*+..............--....<<33..gg..))@@......cc....uu**..cc...O..kk....qq....00....YYCCllxx....??....&&.............--]]..xx....ss..OO..@@vv..__....GGVV..77..........__eeHH......hh77......;;......RR....aaMM......rr..........kk``....@@II..==........ff88))....hh..XXzz....{{\\<<ff........QQ...
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-033020-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.361956416741625
                                  Encrypted:false
                                  SSDEEP:48:/qhTx6+gpg3u0yIMXZja3wdE41PnHZPLWAd4M9/xJfAXxu9iYKsl7:/qN1gpge03aKwdr1PHV5pBAXQ9igl7
                                  MD5:A711EC418AB940A8EBDC7674F80F4D2A
                                  SHA1:1AB0170953ACF10AC5FCD50971A27AD1EA26C3E0
                                  SHA-256:CDBD5E66A6786598800C193D919F04E3B4A2BFC84600CAE9B496F0A48C661864
                                  SHA-512:F0BD49AF45A6C300E6BAB7091C30C0BCCE8E039D79FB6B09D310FEB891EC7408863299726D5F418FCB8B68BD80B499E165C46AB05C01523EFAD9F83A3DC1E3CC
                                  Malicious:false
                                  Preview: .#3OO......&&22..........DD....==ww44rr.....uu...-..)-xx....LL99..........#.....XQ.._W0..@....44..ww--..K[DN...BC.....VV\\....f<..\\OM..;;....)!...............$$........B......j.^;..n@....c...7..<...\\kk......PP..........QQ..dd..HHoo....kkZ[........ddyy `.j...G".{.8...h.....!.....!....HH::tttt[[..ee..FF..KK............;;/-..ll......bbx...,...X.}SE..\\ww.0Mu..O.......99..'c...V....Bt...6..=.+.......(.m^n^.8P`*.......l\uu..uOL......!S.s....e.....,E...d........Q.|+.G...;T?H.t\|}......s...e.....0U..........3\........Id....#.i[...8..#.&...........jG....0.Hx..pA.0~O..o[..l]...c........Q7c.8]...`?L..%zF4J/...m...#F.%./.....'Hx.1Et...$1.)..|.y.ff44......O.....Z.......NO......&&uu......--..DD..##==ww44;;........--....xx....SS9...!!........ee.............NN........dd......SS..MM......{{......YY...||....kk....pp....__NNbb55jj..<<YY''--]]..jj..rr....$$..uuzz..nn....VV............bb,,..''**...................... KK....GG``...............AA..aa,,88..9
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-074759-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.493644821078225
                                  Encrypted:false
                                  SSDEEP:48:pUSOyPJ7/r1G7GhRFtqEvabGEH9RyScAd4M9/xJfAXxun5iYrj8sl7:pdx7pbF8EvBEH9bnpBAXQ5imrl7
                                  MD5:4F5FF9983425D1D4160984BCD54EFDB0
                                  SHA1:70712DF8AD810C37BD7717C297EE161792B216FA
                                  SHA-256:0286DDDD2369363CC74C99084651E2474B7BD416E8A3A34740B36A76BB12F21A
                                  SHA-512:316D1ECABB2D5DC272D07B8D14A8D4136EDB073F59CAE91E07A982B19A12A07B2652AD76CF387BCB89DA533C51748C3D1CEB327ACE723EB0C07F418D7092C5DE
                                  Malicious:false
                                  Preview: ....30.. #......%%..__.............77OOsi:9............ttuu......00.....u.."rgn.......uw........==......ON{....hh;k..Kk..Q..................'/__ddKK......KK......jj::......@......9\...a..N"..r_..Et<......11..XX.......................4?xxWVjh.....^^nn....c R...]s..........Te>.....//WW..cc00....ttEE..66......YY....EE........q.LL.....q.q\.S..Kl..ee.?+.<."..99.....U.7d.@cNAq.*...."Wg...;gJp@.....=.._f@m.....$....O.Pj{'...~E*.1C0QV;...qY-...U..m......z........y...g.u(_....4gx..jY,.q...I0._..x...c.^6.RT....zx.....O.....R.......;EwM}..|EiD....`T.........Cn.4..........}S...#..o...7Pd..f..l..5G.....L>..t..b.*YT1......aQbV..hX....f^vF.../.y..BB.....}. Q..Q..]....... ......55..pp..oo..||iiLL......BB........44}}........kk..j...--VV..UU..........ss44......XXddII....PP........DD.............oo..LL....qqkk..RRee....oo11..ww......hh...............eeLL....gg..ZZXX............ee...........ee<<{{..ee...XX..kkKK..((YY..UU....||.........oo.....
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-074918-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.408783001553208
                                  Encrypted:false
                                  SSDEEP:48:fb3ELbW4ifUPP5C53HmY3/5xKf6YesEHP9VRJx1oXAd4M9/xJfAXxu0IiYrlosl7:z0PW4icPPgp33BxOoVd/pBAXQ7imJl7
                                  MD5:B83C27EE8A055FD284ACCC71D03EC782
                                  SHA1:251DB094F6DBB99307CA973C8815C085578D8DAF
                                  SHA-256:D31F2C8A5C519653E746B80E34DB2756ADB8E466D92F0679B56CB9FBC53A2C32
                                  SHA-512:02927BA51D3AB5D27AD00B34EC23008F139CFDD68C48D51E741464C16A9CE8E23BD1FC49D71F6F156F57CA8F5C2E232151827579ABE59F5B99C2E16EEDEF00E2
                                  Malicious:false
                                  Preview: .8(..IJ........ZZ==""==YY..,,......QQ..UU........`c.1okGGYY..55}}""....-/DF..MO.})".....B..\]....''WW''...............m.....i......mmfd..-,88......uu......7?......009?..........P...}...FhZ>._3....[i\mo]..``..SS........{{%%[[%%..ss..ss((..JA........ZZ==""==Y..,V..y.Q..U9....../cR.!ooGGYY..55}}""....--DDccOO.."".......]]....''WW''.OCC.....j.9.Y...==.....-A.gg..--88......u6.1....?....!..0.9...........Pa...*.....FvZZ._e..[)\3o...`...S....m..{6%L[8%W.rs..s.(\..J....y....Z-=N".=nY<.,Y..u.Q(..U........ic..Lo#G(Y>..5i}*"f....-.DtcUO}.."..........O..4.4...4...oX..o]-.HeTe...+....$L}....y.r...........Y+..Nz.S...g...x..y......:..Bv...............F2..))..NL....$t_....8..>.........JJ..((....aa......II......FF......................00....SS.......55..//JJ11....tt....jj......99..&&nnyyLL88.......99??..9900qq..==.........==..\\....OO......YYhh.....YY........--....!!ll..--.....PP..@@......ZZ..66//zz``....KK..UUyy~~yy..66__66nn........!!......!!..22......EE......
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-124643-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.459235466031378
                                  Encrypted:false
                                  SSDEEP:96:ZFVGD2PFazkj0IbgXvHdx7pBAXQzCixul7:ZFVGaP4zSwfQAG
                                  MD5:DBA05EE29640C53281AFB5A3E7B6E2EE
                                  SHA1:430CA465EE6A0BBCDCDA0D6D9C08033711384A41
                                  SHA-256:D973CFCFB7D9C4B1641C002E3804E065F70094B3DDF7455C82D9AE2D2EF5F865
                                  SHA-512:B2EBF68DE9862725648B2D198D0F8F54D9FC962DB5865C10AC3BC85F5EA006F5555760F1AB19A0DA9FD8E059C79200920EB09D427FEFD2D8EB355EDD9F6257FB
                                  Malicious:false
                                  Preview: .qq.......YY!!..>>..,,...%%||{{....gg..<?....................ff00.._].[XZp.t|.08&?..1099?>ff....++..hb<=...M..'4...d.^>....13..Z[""..55zr##.......DA}}....[]................%@....+Om.....yT.,6.......ff......CC..........II..rr''......))..,.EE..{{.........p..Lb....i........q@.......YY!!..>>..,,...%%||{{....ggOL>>......77.*..F.nn..V...Y..uR.........*....**.....@o<d'.......pG.....y@He7.........<...dS..+.."AA]....Uf6...q.|s..........q-O..6U.....-B[=y....F/......+\.....d....Z(1X8L{....PZ?.8T9M...7{..-J... w,h........7..0......&......7....j\......i^....Dt.#....M|Fu....[j....F"SeZn...C&.*..........m.G&4G.K..zK.......?rB..vG.....#fH..i...bb..46SQ...>.>6F*..*3.*....MLII........jj.....&&88;;]]66nn//..........JJ....ggqq....GGQQ................DDxxll......!!XX......BBgg[[RR..ZZ......LL..cc...hh^^......++......''............ddyy..........DD..........ff&&.....$$>>``....;;..^^&&""RR......{{ss.......KK...............uu..MM..99......hh......``OOee||9
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-124934-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.5109628565643884
                                  Encrypted:false
                                  SSDEEP:48:whbCJArBZmyHtY4ZDLsSAg65M3XpDog65xyO3W1sz5Ad4M9/xJfAXxuNNiYJjsl7:NJ0kyHlZnsSAS35s5mYYpBAXQNNifl7
                                  MD5:E2D88F4610BE3FC84E129B2BCD432F35
                                  SHA1:795D0418217625F12ADDA8C3CBDE894B7A67D0FB
                                  SHA-256:510CC649864BBEAF3A3D311BBE920D58AAA8964EC8380B96144E1D489ABB711C
                                  SHA-512:C781B86DFFEB3FC3F3127ACBEC3591986FD9FF917FCC736524CFBBB333DD203386D9C03FE84CD2F76A5D9D86FD41B8938407CF743E5861F2226CCCFC0B87924D
                                  Malicious:false
                                  Preview: 0....|...21....................ff..............8.....00GG..PP..))11.....]..q.) .*...5....qq....&&....kjM.5w..{{.Q....*.S..........................r]DL8=..((,,....@@..d! p0c.x.q....2.{O#......Cq...3ll..............PP....**...................KK//[[..-m.7M^,...6....j......=.rC.......WW............qq]]......gg..47..xz/-..==kk.0EE.6..U._...?... .HHCC....g++....ee.m)-~.p].<lZ?.3......N..1..!.3.-............ff..........c..8Y....0QG3.dP..D)@1R..;H.eq. T.J...{...q......&C...k.H!w..{[........}....u.......R........rDL~8...(.,.....@q.... .pCcWxUqF....,.2O~......Cw...0lB...{.....<...P5...*Y............y.h..Ks/.[o..-...7.^f....6....r......=?rpc...0..Wk............qq]]......gg..44..xx//..==kk....66..UUjjww......[[CC.J....MM..yy66........==....??......tt..ZZ.......++....pp..~~uu""--YY..........''??...............................44gg99......55LL.....,,....??``ee{{..GG}}......))......kk||....zz..........]]....\\....77........>>..uu..<<.......
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-06272019-125636-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.502307368385819
                                  Encrypted:false
                                  SSDEEP:96:wdLNEWksmqQuXc2pWYSJ/nveR85x9bpBAXQJikWJl7:eLRkbqQuXc2UnveR8j9Yl
                                  MD5:1334182A21435D0539D5B1174B9C48D4
                                  SHA1:01B09BA583D93A63818297CAD27ACE9E3126F7BD
                                  SHA-256:00556D50059A785C2270AA2D870AB4C2421BC172267D4FC0423202673F20E0A2
                                  SHA-512:7CCCC82DFDC2EE711B2FB3D4FC95003192CDC3D4AA413FD4720A5682B043A8749A6CF3AF1C18B9ACC7FF1755533BF3A4A50483325EA261C9D821662B9C5C43FA
                                  Malicious:false
                                  Preview: ...WW....gd....IIhh...........HH......5 ......<?..jn....WW......77..CA...gb`.z...D..N&._......GGkk....]M......M.....{{....ee.........MM......88..??....Q~..............GG..F.45...}i....r.zP~*NW;....2.Pb..sA....pp11..........ee22....XX..AA.....t........00..CCUU!aU!8B>L4Q..1a.....9...8.8.......HH..aa.........]]WWqqAA$$....AB..,.dfCC..77;.......@7f .]p.MP......H..L..;.00..>>...^......M}..tFI~fT......He0.......:...Tc.>....MM.RHr...Z(h..u..'F..C......r..E,\?N<...b"M.o...........d.h....{.$G.y-_..N:..*.U-Hz._3....*v..........R..8{.......Fq..0..9iP....O}PeH~.<....i^..sAsC......1."....../......aWQeo.A3.}........ ]/0U.d...!R..0...4....;.(...?...:.*..Y<..z.....ac......zel,.zrq..p..xx..%%,,..dd!!FF..;;}}....@@ee....LL....kkHH......11....[[.......... ..{{......GG33......RR..EE@@CC......66::..NNWWvv..... \\..GG....................;;....}}__==''..ZZ.....NN....@@qq......##..ttKK....gg,,..JJ((..DD{{AAll..@@......''....~~..............OO....JJ..kk__..==..~~......QQ[
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-07232020-104031-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.506313257795474
                                  Encrypted:false
                                  SSDEEP:96:9IFVR0YMx1trZtiEZcc1T7Dd5jHpBAXQ0ql7:Y0YM9rfRccuk
                                  MD5:62E80299414F45629B39BF68D60C001C
                                  SHA1:18F82EA6077AFB12C0D2D9BFCF3764558D1328E9
                                  SHA-256:77F8BB13D4E142B5EB058158FC15AAA2E71751CBF375DAEA72FB90C2CA5F9CFF
                                  SHA-512:27BB6CA5E29F5BCEDBE1D1C4DFA46CE8DF7CC8A8E26B547B5E4788A3F5660C995895D74FAB70144BD4582EC099926F5D883662BDC474F8FE13B429CDD1194C3B
                                  Malicious:false
                                  Preview: .....bbmnFFhh..[[..ll..^^77==......AA....12NN..........,,ww..>>......^\..p........n..'..#.......**......eo?>D.Q.31.....X[...t/......RP::..cc....MEBB....+.h`..HH..""....BB........B6...;^..Mc.rz...1.,......6ccmm....................................44......6v%Q.a'U E.f....b.n.FjhE.#[j..ll..^^77==......AA....11NN..........,/ww..><......^.99O....)c...c.&.!.....:)jv2u.....ee??A..W3`.........uF.....&Rb:...cS...OM~Bs....+.`R..HH."...UB0...m....B/...;O..M..[z...1C,C.....bc.m1.U......u..........x.s...........4@...6Y%B.h'{ w.Q..bOn^FqhZ."[i..l^.8^s7.=......Ap...%1.N|........+,.wC.$>.......^:.........p'T........*O.u..|eK?.Ay.#3..........uE.....qR&:V..cc...}..B.....+.h`......""....BB........BB....;;..MM..zz..11,,......ccmm..........JJnn55..VV33??......%%vvss!!WW......................xx..........--............^^$$..11.....qq..__HH........JJ...{{11WWsstt...ss00............pp......00..22ss....<<....99..;;....................))..44......44&&II..''11.
                                  C:\ProgramData\Microsoft\Windows Security Health\Logs\WDSC-07272020-074617-7-20-17134.1.amd64fre.rs4_release.180410-1804.etl
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):3216
                                  Entropy (8bit):7.519235657082698
                                  Encrypted:false
                                  SSDEEP:96:JU2N0b1n7jeG6DTUF7tpBwkFDpBAXQog0ql7:JVN05neURtpukFAo
                                  MD5:2D332EE2F3AA272FC9DE2EA0F061A6B8
                                  SHA1:B7F627D6AFDA3F2A9FEA877BBEC5FD66DBB5995B
                                  SHA-256:F4C085F19441F4CCFAF09FC032235ADEA099BAEB209DCA0967855888F52620C4
                                  SHA-512:BF6E40757506B54113DBB5ACCBFC83256C5547D20D8065169B6107D0C7EA23194B42ECAB1761263D818180802735B414CC360C05811462217EF698544559D9B5
                                  Malicious:false
                                  Preview: d<,..30............dd....##....RR..//....8!......LO....JJ||......nn......i..}.xq.}..w..RS..SR33..77uu....-,....|~??....<5.".....................ww...B......nnWW%#......i.....H<.......!E.\0tXjG.........TTpp..II....!!.........%%........wv........II......J0P"N+.m..t....`.................DD....[[......WW...............DF.......G...6>>..G..3.bJ..^..dd..!.....hhbb......'tK...fV.1....Jx&.......dTL{.3. ;..!Ty........7t ...l<..V1.7V.sH.....u.$x........I:.AI/.....j......7DOoH....j..*X.(\X!.=..U0.f....._.Fe.x........./l|Q.1.......L|..........,.....eR..zM]p.. .lA..cT........$3..j..G#..)...n...8...e..E.K9.......d.?Z>..,;.........uX......2.9....y....^\TV..%u+[V_;.?7f.3.#"..ml..MM.....<<::88JJ>>PPyy........\\^^}}..xx..PPww......).55ff........,,OORR@@...PP..[[......22..PP..~~33....;;ggpp..``rr,,........11.................qq..........rr....''..CC..UU\\....nn..OO..........^^]]..55!!....99.....{{....YY..{{::RR..==qqJJ..??............AA))...>>..AA....WW.
                                  C:\ProgramData\Oracle\Java\installcache\baseimagefam8
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):750838
                                  Entropy (8bit):7.999636263623507
                                  Encrypted:true
                                  SSDEEP:12288:aEVTzx2vD85ULsnVBOYkWuV3uJ7rrdxPTCXWAX1qxII:aE5zx2rSVBORW7prXeXWAFqOI
                                  MD5:71EA3980D4CB8A6E6E68EC784198F056
                                  SHA1:5377BDF648D45E562975F52455F98DA7D601B524
                                  SHA-256:B00BC0950725611EE11D916D268952BABF3D287B65149F11F28795F8A8831B42
                                  SHA-512:2818FC0C6D996787F8CD7D8B105546F2EAFC7B9B25A00DE4A2BE4AF7E6689060CD06AB32F75EB91BB230160471165C3D1DA420E97CED733E64642B28E791A16E
                                  Malicious:true
                                  Preview: ......//II..*.....Y.,,.`..6?....el.......MPS.~........cf4.%%..SQ.vien..YE.`)8jjB]HZ......S\....(c..S....[...AI......ss.97...AV..^Z^_vR.N..Q............OZ.........OZ.......pm......}fZ[.s...%#...kmox.........@H.....|BT..XENO.......s2...{*0....TS......|o...........j....QKPY....UAh$........E.WA.......i{..u}......c3...........J%3}zt8..RY........~vbx......L^.K`{..........B......S.....p%g5.;..............3&..}........^R....gx.s.. &..[..O....9a..UO..$/........ql......ro...)>z.]F..4)t0..ht.........V..9w...\......5(+i!R....=5BM*w.......J.....00......TY.............&*......CE....BXYX.rn......#/..4=ZZ........V.pkP.....ydK(.........TI;n.6.....lgql! ..7i....DL]@......~=.....^_..GP.............A......v...ST.........cl.....g|.I..`s..#"...ho=x........N.h....{.AN...BU.D.......?6..z?1&.....U......=h..........$-...Y.A].........8/.Z..l{id 1.biZL.....lj...?*..a`..PC..a%..<h...9D`n..................dof|...J...E-....<z..h<jg....]S....
                                  C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\state.rsm
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1219
                                  Entropy (8bit):7.568159546207757
                                  Encrypted:false
                                  SSDEEP:24:l1kOL9yPiyT/EG1cf6pA84tFoze4ytP6qfHSgC0fNSZBzfteJTQRfOVG0:zh+3IOAd4M9/xJfAXxux
                                  MD5:1D8714E71819DAFD45479C6770E59EA1
                                  SHA1:3F7B54C91FFC78A6DACDE6372FB1A1FC2E762C98
                                  SHA-256:6742395F63D375B205B19B456C06C808E312848A42A94C8878E594656561933A
                                  SHA-512:FF1862872BEA21FBB0CDCF795AD220F0AC2EAC60410475617D6EAF0B34A3D5A1F7520378728A4219713866C242CF401D59CB597F06A734B17AEF0E97A42D1168
                                  Malicious:false
                                  Preview: .nn..__..SS....ii..44]]........``........qq""66cc..~~}}....MM........tt....PP.........PP.......88}}..............SS..77.................BB..nn..__..SS??..77..ww..ee..oo........//ccjj............ZZ.....wj......'e......}...b...c........aN=.P1]/...`.....B%\9..!!........RE.....GZ"t6.g...0\....j.g........e..z.....m....PP........33.......... 7`......=HA/.....a/..p.....+......f.L>Q>9J.....9.>h{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}
                                  C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):231546
                                  Entropy (8bit):7.987061661589684
                                  Encrypted:false
                                  SSDEEP:3072:NKOWYwGSvtWXiwVYn9loz1cpaSOpBj4oiK40CtL+X4XiVsWIulNCVnQOr6S5wTVx:HwGSvwOEpc9OpWoi7tLdSVsWIcmVKTVx
                                  MD5:924C76998F0BC94707E1B6576DFCEA6A
                                  SHA1:C34ACEA78C3EF1C79E6D7F6A2DA8FF038374488C
                                  SHA-256:FB66659D643C34526D19001721E86FF249E2982491801D9DD9C3F88E4F366032
                                  SHA-512:16FDF1FDF77167D44A75E3A94346FA5E2CF9C9A7012F759664A3C3A9218357B690A8055C05CF981085DFAE92114F0C943E5A3B4AEAA16DC09097E27A94A2E96D
                                  Malicious:false
                                  Preview: ..L30.......*...8UU..EE..KKIIJJll..........LL{{........))"".f.....V`n.a....:.D1HI...T\...........P....=:...p=..q:...5AA**LL.......!.>.p..'.0...U..6..N....b8.W..f..Q.2.t.`V..r..`..O.9.Q...&;.0..~.?.M...`.U5.*.}.....t..-TT......<<......%`p<42.......tt??A.xz....aa.W..................evv...........DE......................M...&.3#..............FF......JJ.............L.W....................<.....C.O.......................0.....k...............Q.3....jj......DD.............."3......G......u....................AW.....>........G..#...JJ..............................99......LL..g.xf.........'...75...................&>......jj..#...FD..............VV..g.67....W....................33.........].F..S....J...............................99......LL......................55......................RR......jj......DD..............VV......DD............................33..............FF......JJ...................................99......LL.............
                                  C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20798
                                  Entropy (8bit):7.9902829652636385
                                  Encrypted:true
                                  SSDEEP:384:Fgwsc4DK/FOVQZzPFF10MErKjR3tBDkBQSWbo7peJi7my3pFUPFSrR:q5DD6ygRjkBQi0Jiay3fUPFSrR
                                  MD5:68CA625352F6A202BCD1BDB2A69AB5EC
                                  SHA1:6D72D84C6EC68D1EAF991783A2AA0D96740FA820
                                  SHA-256:A7E5172588A8DEC496BA2A6487690D4A9F4E645AAA68F1885E75496731C27BD3
                                  SHA-512:D62DF2CF14D606CE23BA113C8934E82972658E7AFE2E123435B2050708A2920957B9CB38E6BDF1D782636B1F732DA59DEF731A950CF97AFC44286512ACE69555
                                  Malicious:true
                                  Preview: .%}11....P.x........LL?..l..]A......!...kn.......^.......j......~>!........`|.D..Cs...vC.!!. ...ST9.........DDVf...I.-...P..:.FC......y3.....1.@t....?.R.'.zojPU=h...W<<6..<Uu......9}.+=P..jo!w............55y....p..VSX...y3..Zj.Q.FN,..?.*h......?:w-....22hXs......./.C........`;!</eqq......a.xx..f$.....<9..AG..++...,....hh.....gk......J.S..........r.....mh......66....L..O..*.M.f.._Z.......w..=l........[....I...Z}Du..Z.f.....\.O..@..X....1.J.c,....%`.y...kk.s...*T....%...ZF....U..@.Lc7&.A.U&............e>.7.[u>k...#.M....9.B.y2.].e.l.....d...Og..d19pY.......|..O.R.K..T..hh...3.......%t.c.>A..p.#^t.f.-...-.7O..uA...ookc..c..r<A.Z.9..=..r.$l..:..;.a..^..JM.....j..6...;.G.:......+...I.Z...3s.......4....h~}G.~.Z....q/..Zt..t...M4.GIea..$...\..UHl._..........1$k..Y.^..o..V[J..w....H....>v=..p~`zZ..Z[.ib....2P.k.9Z%v./.Z...Z ....T>'.l...H./.C...\N.b..<W..S!...gv}J...S..-..$ax.+.0..W....E..%.RhWx-i..w2.../.#..l.w.xO.A1r....*.]......KCt..`.....R7lF]
                                  C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):95126
                                  Entropy (8bit):7.996457731967303
                                  Encrypted:true
                                  SSDEEP:1536:RIz+xn76GODgLxeUz+VYrkCb+3IxoSqhrvPbvCAQ4cWM3tIx0XtGLAnk:RrR7bm5KoCC3IuhvY4u6x0rnk
                                  MD5:CB53F3FE25EECB6A2DA57A14AB95EC18
                                  SHA1:72A84775EED4DE72F81D6DF0C6DC8D94AEE040C6
                                  SHA-256:2F7255684BEA5005D48B8C0FBB55D70CCBA854D8C5EDC9FDB90C1290A4ACDF4F
                                  SHA-512:55BD2EA53EACEF01153CE2B0F3F9182DFA9C0E69A0DB1D5C323CB9B893FAF6936C474D38AAB4679D0C422CB105D98DD84325C4B81CF40C5F0D57A861F744D80B
                                  Malicious:true
                                  Preview: .@...U.3.....%%..((....?....G.................++hhFFXX..QS55:;PP...0XX...Y.....ww....\\....::..??........YY....NN........}}LLkkkk................DD..||^^KK....;;..VVcc...........((........ZZ........99))......xx..||........ggmm@@++II..ZZ..........aa..........MM..oo........RR..........JJ..ee__%%..ww......aa..%%99mmjj""..::++......BB..$$......IIee......uu..........\\........ ..((..EEqq77..QQ;;......<<&&IIuuvv....bb55%%..ww..............JJ..TT....//vv....jj..XX.. ..~~..........bb............//...)....MM..//.....``II^^....JJhh..II.......................%%..((...vv..QQ..OO...............++77FFVV..//55{{PP..RRJJXX......33..GG{{....BB......hh__....BBXXyy......NN//,,..66..oovv..<<uu..bbKK==......vv55................$$GG..HH..++<<YY..tt....PP..........SS......ww......rr..............ww....;;..uucc..pp]]..CC......EEvv..++KK..))..........................{{.........zz..........RR....oo...............88........11uu((.............CCBB..........VVyy.............,
                                  C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20797
                                  Entropy (8bit):7.989848596330798
                                  Encrypted:false
                                  SSDEEP:384:OJpC8OncNN5Vsd+LTHlgtYPH5QYDF4zeE631grD3BdDYAMgjDeeBcQmFR7S1r/rG:OJpEnKG+LTHEYPZRJGeEW1Eb3JMQDeee
                                  MD5:F43F27F3CA10E130D0DD872426D25206
                                  SHA1:BD0D6B6627D0E3ECD767EDBC273D6375C1CAFE6C
                                  SHA-256:218821EB4928488AD342703035D4C471C20EA7F25E066809E3C8396D8BEFE19E
                                  SHA-512:8D32FACA15E4A760283399CE939BEEBAAF3815CE5781836D996B3AB766556127561081E272FA6210E640D12757EC0409C6F0B355F6C8E4AE40DEE0D2B11D227F
                                  Malicious:false
                                  Preview: <n....kk..(......'!..^M..%;XM............D...H..Q...M..[P..Q\......BA#L.....R..6...........MK7-..s`.....X...>N@.....5(.....j/.9...MF....0.....nk1b.......3.$...ee..T.mY..........?....zy.=}Fp...`.j.BJ.M"!0qzS....,Nu.P..0.j...;..-........JJD.]A...Y.s....E..v....R.Ed.F...z....it..[...W....`.H...A....X..|....T....pW...-.X:0.=..~.f...;..c.4y.E.[T...|....gB ..#.isB.._...&._2....nuh.*J&.q/8...<....".|...h0I7...r..1.2....*F..z.Y..R.Tet... ........DK*0x_.Dg....|.wvG;.....Y......".e......2.h^.*.........S-/.o7hO.H.'.....S\!.^...P..x........P..$...]..O.WD3Pn.L_..\..WS.?..]F#..n..OoY.{G...4.}...",VX.v.z..u..X.4...n../..O.....pr..@.u....9.u...<WY9......I.....s$.$./<.....+..8...y.I....7+.@....{.Jl.O..x....:..-r...-.Rx.00.l..@NiW.\K&..j..kb.;.d.....Px..Cg..mu.G.........(<D.uz<..,4[.Cd.@...Z../..(=..Wj......0.....dNAR...i.:fp.l0I...1m_..:.6...i...zi...=ga..^-.,.-.&..1.Y.dM.D......y+5.vX...=M..3....j.P.k.@_.....J....W~.......d......]KH.Kg...U#us.T.q.....
                                  C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):72580
                                  Entropy (8bit):7.995552216317876
                                  Encrypted:true
                                  SSDEEP:1536:17rBfmL1YI4KnQSbBKoItVK2LfEiQDhiPp1sWt3taoUMz2Ser:zfPI4umoI3zLfEiQ1i0Mz2tr
                                  MD5:D5113D4A2E248AB568824B8F4864FDF4
                                  SHA1:8B328995D475D9853345A7C466F9635D0745887F
                                  SHA-256:734EF16304213E9D05F66EAC18082DC570EAE18B8C0DC0A68E4DCF589A57E91F
                                  SHA-512:0BFD6838AFD583C20E462DAFB104C5FCC7D087EBDD37BF5603B192EE2D3A1740A84AC50D8BC8E7AFF43474E1DFF67C61EBD80CC9727694F56E6F0991984F5ED8
                                  Malicious:true
                                  Preview: .^.......##......;;..;.cg.W./....yy44,-##...>?==>>...br(*............``{{...1....oo..OO..{{....QQ..33CC....++JJMM&&..55..--..GGQQTT........>>$$..GGxx..--.............................88^^........55LL..22..EEJJ......ttxx..YY..........FFzzKKRR''..ee....>>..TT==??yy'' DD....mm.. $$......KK==.....""........................yyKKMM..SS..vv@@..>>....gg.... ......NN............HH........//........YY..BB..33AA......XXUUii..ZZ.....^^OO..........}}..............&&..66....>>................ttBB..GG......e.......II.....PP..CC..``......--..ii..........**..RR.....SS....yy%%.........55yy....TT.............@@44..cc$$~~..SSkk>>........xx....MM........&&22........GG....qqoo..||[[....AA{{..........NN..ee....7777......ff....22....JJEEhh||......CC..........##))..99........::....||&&...$$SS......ss........88........11wwDDzz.... zz..................66!!tt..cc..>>...XX..XXHH.......``..LL||..nn.....KK......JJ..ff....gg..XXTT..SS....EE.........::RRqq....22..{{....TTkk]].....
                                  C:\ProgramData\Package Cache\{19F7E289-17B8-44EC-A099-927507B6F739}v14.21.27702\packages\vcRuntimeMinimum_x86\cab1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20798
                                  Entropy (8bit):7.991487263851046
                                  Encrypted:true
                                  SSDEEP:384:t/vs5Z5Pew3Qhgp6SK4WjM5F7BaWPkXBXlhKzUQCF9KO5mVNxqVGtKjAah1G24:t8z9ewAhMWYNMXhlUzWSxtivG24
                                  MD5:B977509D27BB9C67B9EDC8CCF8D6B1B4
                                  SHA1:E346CDA18F34E7A733834973221C772F077317EF
                                  SHA-256:1C5EF4E200E5D023EEF7369FDF8CFE658B7F0FEDB091179D84DB7378595A7542
                                  SHA-512:12D01D49F8CFBC42FBAA73214134A310EDB8526C52C9B9FCDCB17925BA0365F85D031BC01A07613F1A76002C877DCF40B50B31DDB51B00179E7AFBC3855ABA22
                                  Malicious:true
                                  Preview: ."ssss...b-W.................(.....,T..........D..........VdyU......6!G|yl2#ws....B,I&6|tt.no$..c.662.].h1...GukG....XTI^...n|Dw(F!O......{..l...........8..5....6:'-.ox........vqx@C.T:8WI...y.3jjR..OO@}.C.....>................n.ku?.......i..::.....C.OOV`R..#=L}AM..F....1.A,.....j....z...oR#l^.>_.....%.......nW......&H.c}7..<..II.xx;.w87n......Vz..gVjf........ ....@.Af,zz.Y...!......`9#BSJ.......-NB..0...Ghu(.}.|?u...\.....@...<.Lx!^?.7!...!?8.W[........s{ut..E+.....1]N.&&Q..|...d........eM...-....rw..7$..........L#...1....(..........'.........+............PX5...E...H...V..##4.&i y.m............(.......F.r..\...>.....tVV:.y6...s....E[..dhny............j....EM..0....62..8Ih..1..=...........oU..xt.....6-\]......g.%;...d..Y.........../.,2.:..Iu....?=....TS......iZ6X..tj..........rv...3I..cr3.tj.&..mQex.......ohHR........Z4....G+i...)......T.......3).........fo......p......].....]]kVt;L.'Fmt......"bn0'..........0..U`.G(
                                  C:\ProgramData\Package Cache\{19F7E289-17B8-44EC-A099-927507B6F739}v14.21.27702\packages\vcRuntimeMinimum_x86\vc_runtimeMinimum_x86.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):95108
                                  Entropy (8bit):7.996227864629541
                                  Encrypted:true
                                  SSDEEP:1536:FeLtDaXimCSHl3xCo232XiZ6LMv7wWGbBt4wrPQWuUnt7GxA79jf0lpQMu1dj+y0:uDaSmDW2XWwWGbwsQHisM9jTMuDC0O
                                  MD5:01BFBB090AAFBE94B305817D60F5DF3A
                                  SHA1:B147D45A894AD75CD8A3A688E8AC441213C6CD01
                                  SHA-256:40732DEB14B08F989005822158F8C8DB137E72A78AAD8193BFA8D0D2FEEDBD22
                                  SHA-512:3234B07BC4C3AFC2E7974A313F1881819D11514D00540D9173F4BA6D3DC9330ED98BC7F3A4A9028224E5A0CFBDC101D00313A708DF75307F005148B99A20D308
                                  Malicious:true
                                  Preview: C0..H$.9...CC........779.?;.E.X....,,..\]......IH..hh..OO....;;ih...b......BB**}.......dd22..FF........DDzz.....................^^..!!......ss....jj''....hh..jj........DD..~~]]..VV..........LL...........cc....TT...........dd22..FF........DDzz.....................^^..!!......ss....jj''....hh..jj........DD..~~]]..VV..........LL...........cc....TT...........dd22..FF........DDzz.....................^^..!!......ss....jj''....hh..jj........DD..~~]]..VV..........LL...........cc....TT....}MM^^..[[....44....[[ss........\\22......44LL....FF..ee......ll..........CC........7799??..TT....,,..\\......II..hh..OO....;;ii..........BB**}}MM^^..[[....44....[[ss........\\22......44LL....FF..ee......ll..........CC........7799??..TT....,,..\\iiyy............VV.........WW''........uu..RR;;--xx....GG....**..&&....44..@@??cc^^[[....dd..xx....rr....<<YY00.................OO......ss..LL..\\rr...........ttPPSSYY``....((..................dd..QQ99..eePP@@ddzz..==....44......##WW.
                                  C:\ProgramData\Package Cache\{213668DB-2263-4E2D-ABB8-487FD539130E}v14.21.27702\packages\vcRuntimeAdditional_x86\cab1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20798
                                  Entropy (8bit):7.989583657087928
                                  Encrypted:false
                                  SSDEEP:384:WzUxn3079NgbG4Q5TbVppZngpIzx6uRJYvns+pYZxCrNRFmK:Rx3V4NpjqWPdFkZRFmK
                                  MD5:B47AD24F7F4137C8A2C570D0C8CAEE13
                                  SHA1:5FA7F1EAF801B2BC2DE28C8C9E272B406C4DCBE2
                                  SHA-256:3FC761A9D7D1F1727B67547E423407547E5CA1444CC0A77B555334FCB07F1097
                                  SHA-512:D93189641568F2085E0E781E0DCABC6975A794A28B5CCF90CED65345296EFEFE5901D23D967F4829193E8FD89CCD3B509B8FCCC359E016D13924D0151592272F
                                  Malicious:false
                                  Preview: <.......^.:wrR..E.GC{1zz..1.gW.h...)'..4.._ZMH......**,..At..............li.`|..RR..vQ8.e..B..|/.}.LI.........9TU......]./...|y.X..<v...&..w...._.K.?...`e..d1.........8.........a.o..Y\.....pp.1..p /<..R.6v..Y\..~'..,f...;<.'..88p...T.$!50..{eQ.....T.j.@A||.H.<..l...36<g....oo....v....&.=..u.~..........]]N~..........0n.....z.&cv<88....:z#.CC.>+.S.b....EA..??..,t....i.q............G+.............3b..QWM.b....F..fW?E0..,.'%..be..>........}..U....Q6.}.X.AVn.LW........Cg.l..gF-....8CO.N..g.M.w7.B..%...V...]F....3V.&.4.<.LkM^.|..V..I|:6...$lG...Q..<).....}...[...U.pl&....|. ..VU.T_z....g7|.e.Y..X..R...o..z@.....$.` ....p...D....].+....>....p..:..0./y...re..^......he.j|....._......l.2l.8i.......... I.5...|wP.z.q.RQb.#..~o..e$.>X.b..U...w.y.....ufs..h.n.....?sV...?(.m..n. A.:7.......UY..h...T....Q{..nC.F.LW0.[O....j..J..RXDj%.6(.r3?..Sz~.}.....T.J...uLn*_...U..S..P..A.c.......^......n...-..o...6...L.{.QZI...e....36..{n0...z.......
                                  C:\ProgramData\Package Cache\{213668DB-2263-4E2D-ABB8-487FD539130E}v14.21.27702\packages\vcRuntimeAdditional_x86\vc_runtimeAdditional_x86.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):93078
                                  Entropy (8bit):7.960145390652951
                                  Encrypted:false
                                  SSDEEP:1536:FbERtQvHVDbGQboHlrU22umzdmIXjqO5qGudOXdf0W1E/z0rJLMdgc:FzfJG0Z8mzddzqa1tf0AprmSc
                                  MD5:92F99E9C2ED54D7F7E913988277E5FFD
                                  SHA1:3807A80615190CF2B417BAE5C2EA62CEEDBC29EC
                                  SHA-256:1D4E52A9A25C6160ECC0F18D4AFE057C91CE2BB90A48C36F54ED87577EF9C7E2
                                  SHA-512:92D8211C661FA745DB798D7BC596F0DEEF73A0906E1B2B4898375F28124BBD32D64D0F91642E9833752AFDE49E4327836774276BF377730BA5E4B7123B9AB3AD
                                  Malicious:false
                                  Preview: u.C..3.c.....bbbb1111........nbd9999........bbbc.......IYY[bbbcppp.}}}.xxxxbbb.....}}}}????........}}}}..........}}}}MMMM....!!!!}}}}............}}}}............}}}}????........}}}}..........}}}}MMMM....!!!!}}}}............}}}}............}}}}????........}}}}..........}}}}MMMM....!!!!}}}}............}}}}............}}}}????........}}}}..........}}}}MMMM....!!!!}}}}............}}}}............}}}}????........}}}}..........}}}}MMMM....!!!!}}}}............}}}}............}}}}????........}}}}.....b9999........bbbb.......YYYYbbbbpppp....xxxxbbbbRRRR........bbbb1111....yyyy}}}}........||||LLLLxxxx....bbbb((((...........||||................................====............^^^^zzzz........6666....[[[[||||..............YYYY....dddd................tttt~~~~....%%%%........((((JJJJ....kkkk6666....ooooYYYY...........VVVVrrrr........................MM......//..||..%%..II..........aa..33..ii..RR""..II..~~..33..11^^..ZZ....__YY........OO......55....aa..VV.. ee..........cc..::....J
                                  C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):1213
                                  Entropy (8bit):7.538094078376995
                                  Encrypted:false
                                  SSDEEP:24:hDB2Pk3ecJX5hL38zPOP84tFoze4ytP6qfHSgC0fNSZBzfteJTQRAVG2q:hd2PpMDsrOEAd4M9/xJfAXxuw
                                  MD5:F70E69E30092E16ECF4048C388EADBD6
                                  SHA1:C1369DF1025B65D279FC492AD196D2ADAF21C3AB
                                  SHA-256:4D45ACD65D949B675191B6051CE494C5B6E45A073851D1AE709958C3753D9B9C
                                  SHA-512:245D53AE08129B5E69124633C57D50111DB22CADF9FCC3928DCC22417314811C583C603F992FC9409624240C2CD16676BDF003943FA1EF9F17ADB0935C30686A
                                  Malicious:false
                                  Preview: h..VVOO..................\\TT\\....ii..gg..55..##::..::ww..$$....++..++........33........44yy44....tt...........YY..YY................UU.......TT**TT...............................bbggbb....--......_6.....\2....c%...V5.V2U.b...b..~6D.6f.......S4.....\\vv..""....U.....N.d..!M......J>l9..l..D+P%.j.b^;..NNhh.....FF..45..??.Z3...@5.r...$A...|.n........T.\5.oP"a.p.V9......p....s{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492B
                                  C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):228706
                                  Entropy (8bit):7.999097796561967
                                  Encrypted:true
                                  SSDEEP:6144:tBJEH3mxhopU7imsuq+SRihEo6Oay3xa21gtFe+hQ:XaHshkzu7SRiNTayHuHQ
                                  MD5:A450E4F15234489B6B5BAC02A100BC81
                                  SHA1:D86C0FD66DE5659D9495CD040B9DBAF0B8462899
                                  SHA-256:E889D08D8627830CC9499C5B79C8057390C6ACD769FE7F4C44D06B44B7681FA4
                                  SHA-512:D97040F398B959E9154D029B628EBC69AEBBCAAD1360E03E05C6CAA57228494C542BA29DF1784461449D24D423787A8189A02C9BE8C074595B2FB5EE625CBFC6
                                  Malicious:true
                                  Preview: 6.k_\qq....P.).m.................yy................``qq........}... J.....7B..1bge~v@S..............WP.tLP.B......JdRR[[...".E...D....f>X...7F.[6g.....V...0...X......!x|?.u..."aQ...>f.k*s.j)...f>&.J@m..\.................EE$$g7.....h.[m?..''..,.eg....ii.lyy......,g..zzzj.....S..............II..........h$$%!-U*.13.TO.TD........BB..VV....JJjjOO..%%..........M.).....VVss99..4...mS...hU..././;..uuFF..??..JJ....xx......dd.Cn-.............G?..pp%%..vv..zz..OO..LLbb..\r.......W.......7..LH]]...qq........T........S}......~nNN..YY^^..1188NN..bb....lv...Y.......,OO,..aa....!!...T..6X..c.......""0u..PR..............P..R.....ww..$......Ft...5**......mm...TT.~....]>.v7...i.....(..........rr..qq......pptt..YYUULL.....??......//.............tt--....==......JJ.......::AA]]..CC......xx......uu......VV....$$..............ee........&&..DD....vv.......... ....................&&..OO.......LLrrjjaa....kkZZ..>>ww..oo..**..OO``..XXGG..nnPP``......rrgg.....
                                  C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\cab1.cab
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):20798
                                  Entropy (8bit):7.9901305941776695
                                  Encrypted:true
                                  SSDEEP:384:esrGyVaWfiazYIgQXM573v9P0fCk6FRIkW7FpvtG+PJxCGi7DE31:nhVaWfrLEh9PG6FSkW7Vo7431
                                  MD5:FD79BB131E7D8917F7210564BA72E61A
                                  SHA1:9698DD1E3B19DE1ED7AFE543D4D3CCD9B25ABC4C
                                  SHA-256:32ED00A96635ED9E54018FFB3E362029CF7D74B4B0B140442BDDD42B32C0D587
                                  SHA-512:34C96E7EE9EE95CB3C9544FBAF9AB298B17AF02EEDE4549D8FDBE5F684E56E230D44C8F899FB4F2848D8695AEE103906D60EA7B31F8AE8C7E02FADFFFF52EE29
                                  Malicious:true
                                  Preview: ^@......##r...~^....VL%6.. +..........j.........u*..c.T_..WZ.$.....X8#Eb`b.L.yG.&z....eU~!..ht..qwob..qt.....StPRW.e@.'...C`P^............CC.....9...Z.5.B....|{K..Z{gry &....'"....5.....@!.....ww.L...^..PL.....1.....ex7.......h.....1.P............{h^y..e5......z..%|#.Owk....bo{ITQ......Dc....h......J.bR..'a..SX-+......kkf<....B@.r.F..uu.`@p_.!glp..@F.....++....Z}caL...RJ........s,{=OS..F@58...............sX0....".,..U....?4}{|q....)).Vq....>_.!..pp.>...&`..~u..- ..WR....>....w..LPP...?..6p.........&....rs...?..........\..7^Gbd..?,......q0..........=%Y......o..^....IO..TX.....w9..=d...}.<4h.....kB..:.%B..B>.}...O......o. u.o.8.{.1...|C..|@>.....r{..up(.s..S....T.]..%..k$9.] .....Y.........@.....`;"TP......L...../6\B;.m T..aI...=A.'.f.q....e...r.utc?F0.$......a...]`..@7.?........|..u....g.lP..R18........EO..d6...\.A.........W~2....p.}.z.r?-.l.PX..=.~%F...WM...c..u..u....*.9/.......!./N...]...=.. ...a1...s..$.9L..Q....D.
                                  C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\vc_runtimeAdditional_x64.msi
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):76694
                                  Entropy (8bit):7.968350192817751
                                  Encrypted:false
                                  SSDEEP:1536:Sffx4df38Sp7SRdd/twLxUgNkxA6FjnNrkMMg3VkDz2U:Sffmd/8K7SRdUotZnH3Yz2U
                                  MD5:C14C62202D953AFAEE80F740463E5F92
                                  SHA1:3C0169CD73505953667EA15E714E909C8998BA27
                                  SHA-256:BF584FBCFB542CA831A81D7AFFE68DE2324689E2AF4501A67F84375CF045AD77
                                  SHA-512:25840BC90B4A25C878748853DA3FCA19897F2D349AA71A2D4015E2F178A2DC43E406ACC136B0809013ED8C3D9060A69571E842EB62AB27D4A298E06A37EE1CED
                                  Malicious:false
                                  Preview: z|.i(..R........((..(((.TP...XTR........TTjkTTTUXXffXXXXtd..dddeQQ. ...QLL..LLL.++..++++VV..VVVV.....................................zzeezzzz==..====..zz....LLvvLLLL99OO9999.................xx......................nn......!!......<<....++..++++VV..VVVV.....................................zzeezzzz==..====..zz....LLvvLLLL99OO9999.................xx......................nn......!!......<<....++..++++VV..VVVV.....................................zzeezzzz==..====..zz....LLvvLLLL99OO9999..............T........TTjjTTTTXXffXXXXdd..ddddQQ..QQQQLL..LLLL...............66..6666TTjjTTTTXXffXXXX11GG1111''zz''''..........OO.......................((..((((TT..TTTT........TTjjTTTTXXffXXXXdd..ddddQQ..QQQQLL..LLLL........??..????........................ZZ..ZZZZ;;..;;;;CC..CCCC....... }} [[........bb....QQ..2222...............ttss{{{{............HHFF@@............gg...........==XX..AAnn......AA33cc..vv...................VV..........KKRR::......LL..rr77..........;;.....WWWWss..?
                                  C:\ProgramData\Package Cache\{49697869-be8e-427d-81a0-c334d1d14950}\state.rsm
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):589
                                  Entropy (8bit):7.262255874031099
                                  Encrypted:false
                                  SSDEEP:12:x/NN/7NZffyU3lHXJP64nRtpMorPMsU0t9XkHoyNFUWNUn:x/TzNZfPlHXlDRtpBfs7BU
                                  MD5:1AEA17E9DEA0312E54F70879B5021102
                                  SHA1:E6E4E49F07E59BF2AA455F8390F55B8FBAB3DB61
                                  SHA-256:53105676078610AC32F62D3774E5DD869621FA9D7AB507CE9316DA0ACA458FAF
                                  SHA-512:6DF2F7D4008B1968BFC5FD177F84AC2F7C15D7D70DC5628F4AC40DF9334DD7F208033C31A7B46FFEB9521966324F12A6968EAA3413CC883C25522AE356143270
                                  Malicious:false
                                  Preview: .,,.......qq.......yy..ZZ..........))....QQ....NN..................................[[##........''..FF..QQ.....rr....mmCC......--%%..33jj......~~}}ggvv......''##]].......~~ffNN......\\oo....BB..77......ZZ((....##..JJttMMnn..%%8%^^....j..=S..,@.z....q......ly..Z;....p..f)H...QQ....NN.............K..............[/#v....u.'H.F4.Q4.....rr....mmCC......--%$..33j=...~.}.g.v....h'J#F]_.......~.f.N<.f...\(oOe3...c.......=........=_n..tY..cS9.......a..`...V$(A..C6.x...w...../.,TvN.(..|\..Ww.....9..&.3FtQf.....-..@A....@@%rm.|...I<b.
                                  C:\Users\user\AppData\Local\Temp\c-1619687684.log
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:news, ASCII text, with very long lines, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):51141
                                  Entropy (8bit):3.8216821793124303
                                  Encrypted:false
                                  SSDEEP:384:H384OWJx3XGr2c+tPVTsMiRKmBqQtzWZo9MkBWfCrpIqqnF:tQtzWZo9MkBWfCrpIqqnF
                                  MD5:3AD8B1D94A194195CBB1C18523054464
                                  SHA1:A7724E080B15C46FD22D021E19C17AC8E7E61069
                                  SHA-256:B067B8B3530BCCF618DBE33F277BB68B7A2A824E3BB02ED2770EE6E633F1C65B
                                  SHA-512:D4CAE777043D8C1F7B5F2B64BF7159C81271ED5CF15523B9FA65D70BB06B191F5F564483C6E2536B804A674EC6B8713C8E5CABA6451663B1B32145F67EB843B1
                                  Malicious:false
                                  Preview: Path: c:\..c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\appv\setup\OfficeIntegrator.ps1..c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\applica
                                  C:\Users\user\AppData\Local\Temp\how_to_decrypt.hta
                                  Process:C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe
                                  File Type:HTML document, ASCII text, with CRLF line terminators
                                  Category:dropped
                                  Size (bytes):6235
                                  Entropy (8bit):5.539437289911165
                                  Encrypted:false
                                  SSDEEP:96:7SICBg9TlfXNQBg9TlfXMrmd7BW5olrfYBeYDXDcFG0ACw5FYP1:7jTlfXXTlfXMrmdNXEcNwDYt
                                  MD5:E55070B33A0DDB3492FC065ABE10B5C8
                                  SHA1:0460221A542D9BEF00AC75D2C5E6E872C1882BC0
                                  SHA-256:352DE6E46097DDB3FE2FEB3B9EE24477920F5B1F679F69CE98F69C7CB9B38A32
                                  SHA-512:3F8C94B949DEA72E0EDF3082A602669473A51B947B484872D5386054E4F0E346B018E62635101B31CE562157F1108A37F58B8954CA27A03C3002F48977906D5E
                                  Malicious:true
                                  Yara Hits:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: C:\Users\user\AppData\Local\Temp\how_to_decrypt.hta, Author: Joe Security
                                  Preview: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">..<html>..<title>CryLock</title>..<hta:application showInTaskBar="no" APPLICATION="yes" ICON='msiexec.exe' SINGLEINSTANCE='yes' SysMenu="no" applicationname="CryLock" border="thick" contexmenu="no" ..scroll="no" selection="yes" singleinstance="yes" windowstate="normal" MAXIMIZEBUTTON="NO" BORDER="DIALOG" width="100" height="100" MINIMIZEBUTTON="NO"></hta:application>..<script language="JavaScript">..var ud=0;..var op=0xc7bf30;..var zoc=0;..function document.onkeydown() {.. var alt=window.event.altKey;.. if (event.keyCode==116 || event.keyCode==27 || alt && event.keyCode==115) {.. event.keyCode=0;.. event.cancelBubble=true;.. return false;.. }.. }..function document.onblur()..{..alert('Attention! This important information for you!');..}..function ChangeTime()..{..var sd = new Date('May 4 2021 09:14:35');..var dn = new Date();..if (sd.getTime()<dn.getTime())..{..var dt=document.getEleme
                                  C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  Process:C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):214528
                                  Entropy (8bit):6.650869352669812
                                  Encrypted:false
                                  SSDEEP:3072:wPjRTnHvzG31UsczGF9Fu7/SppSH7WwmH4er1Csax00NOWmVaW0gxLjx/KitCaR:OlTPejc0pSbWA3x0cgxRiit
                                  MD5:61B2F50B1B79F50E074A8D5E05926A4C
                                  SHA1:D4BF226519262DA7EA1746DAC3D8DE7DC0AD7675
                                  SHA-256:6BC21092F49A473B0FD4D1E1A77CE5D7E97E961334764B606B7014710FB75466
                                  SHA-512:F10A8D50BFD32905A44710E72ACBB1CDFB05D03AA8F5F6A5E361B6278EFC015B07A90FB5AD0A505B28A4CE6D53823FEF45B13992D8C11B3621799677AD61B5B6
                                  Malicious:true
                                  Preview: MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................d...........W............@..............................................@................................... ..............................................................................................................CODE....Pc.......d.................. ..`DATA.................h..............@...BSS.....e............r...................idata...............r..............@....tls.....................................rdata..............................@..P.reloc.. %.......&..................@..P.rsrc........ ......................@..P................................................................................................................................................................................
                                  C:\Users\user\AppData\Local\Temp\svcuwq.exe:Zone.Identifier
                                  Process:C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe
                                  File Type:ASCII text, with CRLF line terminators
                                  Category:modified
                                  Size (bytes):26
                                  Entropy (8bit):3.95006375643621
                                  Encrypted:false
                                  SSDEEP:3:ggPYV:rPYV
                                  MD5:187F488E27DB4AF347237FE461A079AD
                                  SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                  SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                  SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                  Malicious:true
                                  Preview: [ZoneTransfer]....ZoneId=0
                                  C:\bootTel.dat
                                  Process:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  File Type:data
                                  Category:dropped
                                  Size (bytes):852
                                  Entropy (8bit):7.297737624671621
                                  Encrypted:false
                                  SSDEEP:24:fEX84tFoze4ytP6qfHSgC0fNSZBzfteJTQRD0rgZdO:ffAd4M9/xJfAXxuNgG
                                  MD5:9A4E2A9157D9397CB328FD5A622C2F0D
                                  SHA1:D55FEC129843C3C1174CA91D03509FB9470A387D
                                  SHA-256:EF652647B66FBAB8F1957626C1F156E319C5EC889E4C1A016E6237B24BAD79CB
                                  SHA-512:1A5AFE2B4EAD5D4CE13209882A7D5F4180E1DEABD5A0A2DAE472F3B458D3BF415B4B9942AD6DC2785B03CC1EC2BE8EE2D3AAB160E0C19726641538F05FBDC021
                                  Malicious:false
                                  Preview: lvv......3#.8..T...H..H........B6.....{ENCRYPTSTART}{111}{550}{-ag.4.Xp|.Sr.xtY-.l...6.f..b..o.-8.'.e....x../NLS....0$....)}MI..*~!.._..[X.4...`.B4.`...|..@....-_....{..A.X......Q.f".....!.h.q7.yP..F+.we].I77F.....l....2..?."u.ME9.8.C..~k._O..1...4e..6.].L.q@.y.r.%.X.!..l..+}..e.j....M..d.4[.../.<..........F~.N..[x.wiz...Yd(.X........U9..S........OI..!...p....{R.l.)G...9F..s.Bw.7.(.F..1.R,..6e.".Wi.h....|.O..=...h:g.^..R.6...$).2R{}>.\0<e.=...A..;...........*.E.P.;...X......,......-...l{r...GM.....^.#N..2M?}.....dI.y.gJ....4...'....D=....@b...?A.. >....e.|.....]...{......3s...H.y.|.}{222}{6492BED7-7C13DE55}{2.1.0.0}{F9A1330209EACEA8FEABF83D09753ED0}{592C6F583A9CEBAB2434C0B6F7F0FBCF}{}{......'q..Hv.-..}{.}{80}{000098000111000111000116000084000101000108000046000100000097000116}{bNbWbPbRbWbNbNb0}{4}P..){ENCRYPTENDED}
                                  \Device\ConDrv
                                  Process:C:\Windows\SysWOW64\wbem\WMIC.exe
                                  File Type:ASCII text, with CRLF, CR line terminators
                                  Category:dropped
                                  Size (bytes):48
                                  Entropy (8bit):4.305255793112395
                                  Encrypted:false
                                  SSDEEP:3:8yzGc7C1RREal:nzGtRV
                                  MD5:6ED2062D4FB53D847335AE403B23BE62
                                  SHA1:C3030ED2C3090594869691199F46BE7A9A12E035
                                  SHA-256:43B5390113DCBFA597C4AAA154347D72F660DB5F2A0398EB3C1D35793E8220B9
                                  SHA-512:C9C302215394FEC0B38129280A8303E0AF46BA71B75672665D89828C6F68A54E18430F953CE36B74F50DC0F658CA26AC3572EA60F9E6714AFFC9FB623E3C54FC
                                  Malicious:false
                                  Preview: ERROR:...Description = Initialization failure...

                                  Static File Info

                                  General

                                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):6.650869352669812
                                  TrID:
                                  • Win32 Executable (generic) a (10002005/4) 99.79%
                                  • Win32 Executable Delphi generic (14689/80) 0.15%
                                  • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                  • Generic Win/DOS Executable (2004/3) 0.02%
                                  • DOS Executable Generic (2002/1) 0.02%
                                  File name:61b2f50b_by_Libranalysis.exe
                                  File size:214528
                                  MD5:61b2f50b1b79f50e074a8d5e05926a4c
                                  SHA1:d4bf226519262da7ea1746dac3d8de7dc0ad7675
                                  SHA256:6bc21092f49a473b0fd4d1e1a77ce5d7e97e961334764b606b7014710fb75466
                                  SHA512:f10a8d50bfd32905a44710e72acbb1cdfb05d03aa8f5f6a5e361b6278efc015b07a90fb5ad0a505b28a4ce6d53823fef45b13992d8c11b3621799677ad61b5b6
                                  SSDEEP:3072:wPjRTnHvzG31UsczGF9Fu7/SppSH7WwmH4er1Csax00NOWmVaW0gxLjx/KitCaR:OlTPejc0pSbWA3x0cgxRiit
                                  File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................

                                  File Icon

                                  Icon Hash:00828e8e8686b000

                                  Static PE Info

                                  General

                                  Entrypoint:0x4257cc
                                  Entrypoint Section:CODE
                                  Digitally signed:false
                                  Imagebase:0x400000
                                  Subsystem:windows gui
                                  Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, BYTES_REVERSED_LO, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, BYTES_REVERSED_HI, RELOCS_STRIPPED
                                  DLL Characteristics:
                                  Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:4
                                  OS Version Minor:0
                                  File Version Major:4
                                  File Version Minor:0
                                  Subsystem Version Major:4
                                  Subsystem Version Minor:0
                                  Import Hash:87ddc95a1f7aab80a186e9e47f6c9516

                                  Entrypoint Preview

                                  Instruction
                                  push ebp
                                  mov ebp, esp
                                  mov ecx, 0000002Dh
                                  push 00000000h
                                  push 00000000h
                                  dec ecx
                                  jne 00007FA3389285CBh
                                  push ebx
                                  push esi
                                  push edi
                                  mov eax, 00425688h
                                  call 00007FA338909809h
                                  mov esi, 0042A654h
                                  xor eax, eax
                                  push ebp
                                  push 00426CEBh
                                  push dword ptr fs:[eax]
                                  mov dword ptr fs:[eax], esp
                                  mov eax, 004257A8h
                                  call 00007FA338907304h
                                  mov dl, 01h
                                  mov eax, dword ptr [00414AE8h]
                                  call 00007FA33891791Ch
                                  mov dword ptr [0042A34Ch], eax
                                  cmp byte ptr [004285C8h], 00000000h
                                  je 00007FA3389285FEh
                                  mov dl, 01h
                                  mov eax, 00426D08h
                                  call 00007FA33891D7AEh
                                  mov dl, 02h
                                  xor eax, eax
                                  call 00007FA33891D7A5h
                                  mov dl, 03h
                                  xor eax, eax
                                  call 00007FA33891D79Ch
                                  mov dl, 04h
                                  xor eax, eax
                                  call 00007FA33891D793h
                                  call 00007FA33891D7F6h
                                  push 00001388h
                                  call 00007FA338909B30h
                                  cmp byte ptr [004285C8h], 00000000h
                                  je 00007FA3389285E3h
                                  mov dl, 01h
                                  mov eax, 00426D1Ch
                                  call 00007FA33891D76Fh
                                  call 00007FA33891D7D2h
                                  call 00007FA33891A765h
                                  call 00007FA338905B98h
                                  call 00007FA33890C6C3h
                                  add esp, FFFFFFF8h
                                  fstp qword ptr [esp]
                                  wait
                                  lea eax, dword ptr [ebp-18h]
                                  call 00007FA33890C290h
                                  mov eax, dword ptr [ebp-18h]
                                  mov dword ptr [0000A64Ch], eax

                                  Data Directories

                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x2b0000x13e4.idata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x320000x9694.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x2e0000x18.rdata
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                  Sections

                                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  CODE0x10000x263500x26400False0.505387050654data6.50748775781IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                  DATA0x280000x8140xa00False0.533203125data4.84628499224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                  BSS0x290000x16650x0False0empty0.0IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                  .idata0x2b0000x13e40x1400False0.391015625data4.89686284576IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                  .tls0x2d0000xc0x0False0empty0.0IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                  .rdata0x2e0000x180x200False0.05078125data0.20448815744IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                  .reloc0x2f0000x25200x2600False0.00328947368421data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                  .rsrc0x320000x96940x9800False0.841539884868data7.57456615528IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ

                                  Resources

                                  NameRVASizeTypeLanguageCountry
                                  STRING0x323340x960data
                                  STRING0x32c940x10ASCII text, with no line terminators
                                  STRING0x32ca40x61fbdata
                                  STRING0x38ea00x155ddata
                                  RT_STRING0x3a4000x264data
                                  RT_STRING0x3a6640x19cdata
                                  RT_STRING0x3a8000xecdata
                                  RT_STRING0x3a8ec0x20cdata
                                  RT_STRING0x3aaf80x3d0data
                                  RT_STRING0x3aec80x374data
                                  RT_STRING0x3b23c0x2c4data
                                  RT_RCDATA0x3b5000x10data
                                  RT_RCDATA0x3b5100x184data

                                  Imports

                                  DLLImport
                                  KERNEL32.DLLSetFilePointerEx, GlobalMemoryStatusEx, GetFileSizeEx
                                  KERNEL32.DLLGlobalMemoryStatusEx
                                  KERNEL32.DLLGetLongPathNameA
                                  KERNEL32.DLLTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
                                  KERNEL32.DLLSleep
                                  KERNEL32.DLLWriteFile, WideCharToMultiByte, WaitForSingleObject, VirtualQuery, TerminateThread, TerminateProcess, Sleep, SizeofResource, SetFilePointer, SetFileAttributesW, SetEvent, SetErrorMode, SetEndOfFile, SetConsoleCursorPosition, ResetEvent, ReadFile, QueryDosDeviceA, OpenProcess, MoveFileW, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GetWindowsDirectoryW, GetVolumeInformationW, GetVersionExA, GetTickCount, GetThreadLocale, GetTempPathW, GetSystemInfo, GetStringTypeExA, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileAttributesW, GetFileAttributesA, GetExitCodeThread, GetDiskFreeSpaceExA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentThread, GetCurrentProcessId, GetCurrentProcess, GetCPInfo, GetACP, FreeResource, FreeLibrary, FormatMessageA, FindResourceA, FindNextFileW, FindFirstFileW, FindFirstFileA, FindClose, FillConsoleOutputCharacterA, FileTimeToLocalFileTime, FileTimeToDosDateTime, ExitThread, EnumCalendarInfoA, EnterCriticalSection, DuplicateHandle, DeleteFileW, DeleteCriticalSection, CreateThread, CreateMutexA, CreateFileW, CreateFileA, CreateEventA, CopyFileW, CompareStringA, CloseHandle
                                  KERNEL32.DLLDeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle
                                  advapi32.dllRegSetValueExA, RegOpenKeyA, RegDeleteValueA, RegCloseKey, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueA, GetUserNameA, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, AdjustTokenPrivileges
                                  advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey
                                  advapi32.dllOpenSCManagerA, EnumServicesStatusA, CloseServiceHandle
                                  mpr.dllWNetOpenEnumW, WNetEnumResourceW, WNetCloseEnum
                                  Netapi32.dllNetApiBufferFree, NetShareEnum
                                  ntdll.dllNtQueryObject, NtQueryInformationFile, ZwQuerySystemInformation
                                  oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
                                  oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                                  PSAPI.dllGetProcessMemoryInfo
                                  shell32.dllShellExecuteExA, ShellExecuteW, ShellExecuteA
                                  shell32.dllSHGetSpecialFolderPathW
                                  user32.dllMessageBoxA, LoadStringA, GetSystemMetrics, GetKeyboardLayoutList, GetFocus, GetCursorPos, CharLowerBuffW, CharNextA, CharLowerBuffA, CharToOemA
                                  user32.dllGetKeyboardType, LoadStringA, MessageBoxA, CharNextA
                                  WS2_32.DLLWSAIoctl
                                  wsock32.dllWSAStartup, gethostbyaddr, socket, inet_ntoa, inet_addr, closesocket

                                  Network Behavior

                                  Snort IDS Alerts

                                  TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                  04/29/21-09:14:29.634877ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:29.669847ICMP449ICMP Time-To-Live Exceeded in Transit84.17.52.126192.168.2.6
                                  04/29/21-09:14:29.676215ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:29.711458ICMP449ICMP Time-To-Live Exceeded in Transit5.56.20.161192.168.2.6
                                  04/29/21-09:14:29.711903ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:29.747354ICMP449ICMP Time-To-Live Exceeded in Transit91.206.52.152192.168.2.6
                                  04/29/21-09:14:29.749369ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:33.673539ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:37.673692ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:41.674029ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:45.676622ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:49.675313ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:53.675089ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:14:54.430855ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.1192.168.2.6
                                  04/29/21-09:14:55.940347ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.1192.168.2.6
                                  04/29/21-09:14:57.456094ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.1192.168.2.6
                                  04/29/21-09:14:57.676367ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:01.678275ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:06.533616ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:10.176517ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:14.177342ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:18.177472ICMP384ICMP PING192.168.2.613.107.4.50
                                  04/29/21-09:15:18.213481ICMP408ICMP Echo Reply13.107.4.50192.168.2.6

                                  Network Port Distribution

                                  UDP Packets

                                  TimestampSource PortDest PortSource IPDest IP
                                  Apr 29, 2021 09:14:22.703088999 CEST53545138.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:29.306957960 CEST6204453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:29.356638908 CEST53620448.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:29.581690073 CEST6379153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:29.633533001 CEST53637918.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:30.180875063 CEST6426753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:30.231923103 CEST53642678.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:31.669512987 CEST4944853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:31.731419086 CEST53494488.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:32.949384928 CEST6034253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:33.000786066 CEST53603428.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:33.901808023 CEST6134653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:33.950565100 CEST53613468.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:34.692115068 CEST5177453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:34.745950937 CEST53517748.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:35.588011026 CEST5602353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:35.636734009 CEST53560238.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:36.401264906 CEST5838453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:36.452766895 CEST53583848.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:37.250912905 CEST6026153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:37.302531958 CEST53602618.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:38.495620966 CEST5606153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:38.544888973 CEST53560618.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:39.599998951 CEST5833653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:39.648718119 CEST53583368.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:40.506972075 CEST5378153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:40.556843042 CEST53537818.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:41.656236887 CEST5406453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:41.705303907 CEST53540648.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:42.598750114 CEST5281153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:42.650523901 CEST53528118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:43.832837105 CEST5529953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:43.887130022 CEST53552998.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:46.586956978 CEST6374553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:46.635919094 CEST53637458.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:48.787024975 CEST5005553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:48.835872889 CEST53500558.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.830375910 CEST6137453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.833406925 CEST5033953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.837137938 CEST6330753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.839966059 CEST4969453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.842716932 CEST5498253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.847480059 CEST5001053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.847839117 CEST6371853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.851617098 CEST6211653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.853542089 CEST6381653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.855389118 CEST5501453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.857357979 CEST6220853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.859128952 CEST5757453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.861771107 CEST5181853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.863349915 CEST5662853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.864162922 CEST6077853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.870518923 CEST5379953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.879298925 CEST53613748.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.881967068 CEST53503398.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.885546923 CEST53633078.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.886981010 CEST5468353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.887693882 CEST5932953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.888468981 CEST53496948.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.891226053 CEST53549828.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.891233921 CEST6402153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.893861055 CEST5612953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.896353006 CEST53637188.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.896945000 CEST5817753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.898699045 CEST53500108.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.899234056 CEST5406953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.901663065 CEST5701753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.902132988 CEST53638168.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.902954102 CEST53621168.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.903980970 CEST5632753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.904164076 CEST53550148.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.906897068 CEST5024353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.907633066 CEST53575748.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.908580065 CEST53622088.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.909697056 CEST6205553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.910196066 CEST53518188.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.912581921 CEST53607788.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.912637949 CEST6124953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.914707899 CEST53566288.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.915019989 CEST6525253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.917639017 CEST6436753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.920685053 CEST6021153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.921926975 CEST53537998.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.923011065 CEST5845453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.926707029 CEST5518053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.936130047 CEST53593298.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.938400030 CEST53546838.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.942101002 CEST5872153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.942436934 CEST53561298.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.942615986 CEST53640218.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.944947958 CEST5769153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.945755005 CEST53581778.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.947726965 CEST53540698.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.947828054 CEST5294353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.950211048 CEST53570178.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.952855110 CEST53563278.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.955419064 CEST53502438.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.957427979 CEST5948953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.958271027 CEST53620558.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.961242914 CEST53612498.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.963433981 CEST53652528.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.963764906 CEST6402253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.966280937 CEST5719353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.968813896 CEST6441353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.969047070 CEST53643678.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.969728947 CEST53602118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.972285032 CEST6042953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.974689007 CEST53584548.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.975042105 CEST6034553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.975419044 CEST53551808.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.976897001 CEST5873053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.977914095 CEST5383053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.986715078 CEST5788053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:53.993727922 CEST53587218.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.993755102 CEST53576918.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:53.996390104 CEST53529438.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.006000042 CEST53594898.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.012419939 CEST53640228.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.012985945 CEST6409153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.014859915 CEST53571938.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.016427994 CEST5572853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.017244101 CEST53644138.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.019088984 CEST5569453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.022599936 CEST6553153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.023735046 CEST53603458.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.023761988 CEST53604298.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.025317907 CEST6543753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.027664900 CEST5459053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.028283119 CEST53587308.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.029535055 CEST53538308.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.030288935 CEST5131853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.033621073 CEST6088853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.037231922 CEST6457553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.038223982 CEST53578808.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.040210009 CEST5909253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.043271065 CEST5748353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.045990944 CEST4980953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.048455000 CEST5281453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.061764002 CEST53640918.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.065057039 CEST53557288.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.070705891 CEST53556948.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.071084976 CEST53655318.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.076565981 CEST53545908.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.076601982 CEST53654378.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.078864098 CEST53513188.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.082245111 CEST53608888.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.085706949 CEST53645758.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.088670015 CEST53590928.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.091780901 CEST53574838.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.094530106 CEST53498098.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.097089052 CEST53528148.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.127681017 CEST5106953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.129982948 CEST5652653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.137837887 CEST5051253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.139513016 CEST5167953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.162828922 CEST5675953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.165133953 CEST6221153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.168189049 CEST6203353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.170886993 CEST6124453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.173496008 CEST5369653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.176640987 CEST5073353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.179322958 CEST53510698.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.179836988 CEST5577053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.181452990 CEST53565268.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.182146072 CEST6176053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.184875965 CEST6382253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.186441898 CEST53505128.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.187273026 CEST5966653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.188361883 CEST53516798.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.189990044 CEST5222353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.211560965 CEST53567598.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.213747978 CEST53622118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.216734886 CEST53620338.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.219460964 CEST53612448.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.221999884 CEST53536968.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.224411011 CEST6013653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.225353003 CEST53507338.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.227612972 CEST5564953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.230958939 CEST5152453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.230992079 CEST53557708.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.231015921 CEST53617608.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.232907057 CEST5914153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.235337019 CEST4968253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.236406088 CEST53638228.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.238543034 CEST53596668.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.238825083 CEST5938453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.241369963 CEST5308953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.241403103 CEST53522238.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.243928909 CEST5056353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.246500015 CEST5026553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.248967886 CEST5544253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.251777887 CEST4956153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.255261898 CEST5409753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.259299994 CEST5950253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.260601044 CEST5497153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.261883974 CEST5096953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.271569014 CEST6335453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.273021936 CEST53601368.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.276247025 CEST53556498.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.279469967 CEST53515248.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.283857107 CEST53496828.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.284364939 CEST53591418.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.287333965 CEST53593848.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.289920092 CEST53530898.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.292363882 CEST53505638.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.294847012 CEST53502658.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.297444105 CEST53554428.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.299310923 CEST5776353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.300235033 CEST53495618.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.306529045 CEST53540978.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.308058977 CEST53595028.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.309065104 CEST53549718.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.313318014 CEST53509698.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.314870119 CEST5011153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.318481922 CEST5720653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.320343971 CEST53633548.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.321454048 CEST5713253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.324162960 CEST6162653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.327122927 CEST5967553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.331511021 CEST6014953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.335448027 CEST6214153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.338474035 CEST6407453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.342015982 CEST5582953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.347842932 CEST6226053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.347986937 CEST53577638.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.350392103 CEST6421153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.353693962 CEST5071153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.355741978 CEST6182053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.357508898 CEST5773553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:54.363343954 CEST53501118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.367110014 CEST53572068.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.372787952 CEST53571328.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.375504017 CEST53616268.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.375536919 CEST53596758.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.380158901 CEST53601498.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.384115934 CEST53621418.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.389765024 CEST53640748.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.393286943 CEST53558298.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.396233082 CEST53622608.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.398849010 CEST53642118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.402080059 CEST53507118.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.406977892 CEST53618208.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:54.408905983 CEST53577358.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:56.202967882 CEST5440253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:56.254816055 CEST53544028.8.8.8192.168.2.6
                                  Apr 29, 2021 09:14:59.163398027 CEST5051953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:14:59.222388983 CEST53505198.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:16.329988956 CEST5465153192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:16.471084118 CEST53546518.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:17.403024912 CEST5562453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:17.476876974 CEST53556248.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:17.615963936 CEST5340753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:17.644031048 CEST5550053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:17.707981110 CEST53555008.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:17.722064018 CEST53534078.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:18.300088882 CEST6105553192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:18.410870075 CEST53610558.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:18.847014904 CEST5809353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:18.904407024 CEST53580938.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:19.461689949 CEST4938853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:19.510546923 CEST53493888.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:20.054850101 CEST6133253192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:20.117146969 CEST53613328.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:20.639895916 CEST6419053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:20.697259903 CEST53641908.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:21.683917046 CEST6201753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:21.741080999 CEST53620178.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:22.733582973 CEST5502353192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:22.782660961 CEST53550238.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:23.867439032 CEST5651753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:23.919156075 CEST53565178.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:33.204560041 CEST5030753192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:33.265995979 CEST53503078.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:39.501229048 CEST5184853192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:39.502201080 CEST5091653192.168.2.68.8.8.8
                                  Apr 29, 2021 09:15:39.549932957 CEST53518488.8.8.8192.168.2.6
                                  Apr 29, 2021 09:15:39.550925016 CEST53509168.8.8.8192.168.2.6
                                  Apr 29, 2021 09:16:05.078999043 CEST5542053192.168.2.68.8.8.8
                                  Apr 29, 2021 09:16:05.137768030 CEST53554208.8.8.8192.168.2.6
                                  Apr 29, 2021 09:16:06.629122019 CEST5127453192.168.2.68.8.8.8
                                  Apr 29, 2021 09:16:06.677947998 CEST53512748.8.8.8192.168.2.6
                                  Apr 29, 2021 09:16:11.383059978 CEST5784953192.168.2.68.8.8.8
                                  Apr 29, 2021 09:16:11.454129934 CEST53578498.8.8.8192.168.2.6

                                  ICMP Packets

                                  TimestampSource IPDest IPChecksumCodeType
                                  Apr 29, 2021 09:14:54.430855036 CEST192.168.2.1192.168.2.682a0(Port unreachable)Destination Unreachable
                                  Apr 29, 2021 09:14:55.940346956 CEST192.168.2.1192.168.2.682a0(Port unreachable)Destination Unreachable
                                  Apr 29, 2021 09:14:57.456094027 CEST192.168.2.1192.168.2.682a0(Port unreachable)Destination Unreachable

                                  Code Manipulations

                                  Statistics

                                  CPU Usage

                                  Click to jump to process

                                  Memory Usage

                                  Click to jump to process

                                  High Level Behavior Distribution

                                  Click to dive into process behavior distribution

                                  Behavior

                                  Click to jump to process

                                  System Behavior

                                  General

                                  Start time:09:14:30
                                  Start date:29/04/2021
                                  Path:C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe'
                                  Imagebase:0x400000
                                  File size:214528 bytes
                                  MD5 hash:61B2F50B1B79F50E074A8D5E05926A4C
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:Borland Delphi
                                  Yara matches:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 00000000.00000002.348130497.0000000004DE0000.00000004.00000001.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 00000000.00000002.348121933.0000000004DD0000.00000004.00000001.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 00000000.00000002.348126087.0000000004DD8000.00000004.00000001.sdmp, Author: Joe Security
                                  Reputation:low

                                  General

                                  Start time:09:14:38
                                  Start date:29/04/2021
                                  Path:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Users\user\appdata\local\temp\svcuwq.exe'
                                  Imagebase:0x400000
                                  File size:214528 bytes
                                  MD5 hash:61B2F50B1B79F50E074A8D5E05926A4C
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:Borland Delphi
                                  Yara matches:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 00000002.00000002.596775343.00000000036B4000.00000004.00000001.sdmp, Author: Joe Security
                                  Reputation:low

                                  General

                                  Start time:09:14:39
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'ping 0.0.0.0&del 'C:\Users\user\Desktop\61b2f50b_by_Libranalysis.exe''
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:39
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:39
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\PING.EXE
                                  Wow64 process (32bit):true
                                  Commandline:ping 0.0.0.0
                                  Imagebase:0xc80000
                                  File size:18944 bytes
                                  MD5 hash:70C24A306F768936563ABDADB9CA9108
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:47
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'vssadmin delete shadows /all /quiet'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'wbadmin DELETE BACKUP -keepVersions:0'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\vssadmin.exe
                                  Wow64 process (32bit):true
                                  Commandline:vssadmin delete shadows /all /quiet
                                  Imagebase:0xea0000
                                  File size:110592 bytes
                                  MD5 hash:7E30B94672107D3381A1D175CF18C147
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:moderate

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:48
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'wmic SHADOWCOPY DELETE'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high

                                  General

                                  Start time:09:14:49
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:49
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} recoveryenabled No'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:49
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:49
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Windows\System32\cmd.exe' /c 'bcdedit /set {default} bootstatuspolicy ignoreallfailures'
                                  Imagebase:0x2a0000
                                  File size:232960 bytes
                                  MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:49
                                  Start date:29/04/2021
                                  Path:C:\Windows\SysWOW64\wbem\WMIC.exe
                                  Wow64 process (32bit):true
                                  Commandline:wmic SHADOWCOPY DELETE
                                  Imagebase:0xa0000
                                  File size:391680 bytes
                                  MD5 hash:79A01FCD1C8166C5642F37D1E0FB7BA8
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:50
                                  Start date:29/04/2021
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff61de10000
                                  File size:625664 bytes
                                  MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language

                                  General

                                  Start time:09:14:54
                                  Start date:29/04/2021
                                  Path:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222'
                                  Imagebase:0x400000
                                  File size:214528 bytes
                                  MD5 hash:61B2F50B1B79F50E074A8D5E05926A4C
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:Borland Delphi
                                  Yara matches:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 00000016.00000003.389950507.0000000005E90000.00000004.00000001.sdmp, Author: Joe Security

                                  General

                                  Start time:09:15:02
                                  Start date:29/04/2021
                                  Path:C:\Users\user\AppData\Local\Temp\svcuwq.exe
                                  Wow64 process (32bit):true
                                  Commandline:'C:\Users\user\appdata\local\temp\svcuwq.exe' -id '6492BED7-7C13DE55' -wid '222'
                                  Imagebase:0x400000
                                  File size:214528 bytes
                                  MD5 hash:61B2F50B1B79F50E074A8D5E05926A4C
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:Borland Delphi
                                  Yara matches:
                                  • Rule: JoeSecurity_CryLock, Description: Yara detected CryLock ransomware, Source: 0000001A.00000003.407325119.0000000005E80000.00000004.00000001.sdmp, Author: Joe Security

                                  Disassembly

                                  Code Analysis

                                  Reset < >