Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
IZArc_4.5.exe

Overview

General Information

Sample name:IZArc_4.5.exe
Analysis ID:1524802
MD5:6a3326cf6e377ffe29f946104514b9db
SHA1:00a76e4983e1655389e70e148721c5e4bf86c3cc
SHA256:557dc67478b7ab0fd71187de08b3e4164a6d9b8e7d432dbe06713e930df60fe0
Infos:

Detection

Score:5
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Sigma detected: Classes Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • IZArc_4.5.exe (PID: 7052 cmdline: "C:\Users\user\Desktop\IZArc_4.5.exe" MD5: 6A3326CF6E377FFE29F946104514B9DB)
    • IZArc_4.5.tmp (PID: 7112 cmdline: "C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp" /SL5="$90280,5047654,194560,C:\Users\user\Desktop\IZArc_4.5.exe" MD5: 296B3061BB1D0A1EFD08719210F3C19F)
      • regsvr32.exe (PID: 2980 cmdline: "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll" MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E)
      • IZArc.exe (PID: 1100 cmdline: "C:\Program Files (x86)\IZArc\IZArc.exe" -sa MD5: 6AD69B02B1A5BA995EADC7FD9CC6A705)
      • chrome.exe (PID: 1244 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
        • chrome.exe (PID: 3116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2000,i,11753767500346397328,11824077582812530869,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
      • notepad.exe (PID: 6440 cmdline: "Notepad" C:\Program Files (x86)\IZArc\WhatsNew.txt MD5: E92D3A824A0578A50D2DD81B5060145F)
  • IZArc.exe (PID: 3788 cmdline: "C:\Program Files (x86)\IZArc\IZArc.exe" MD5: 6AD69B02B1A5BA995EADC7FD9CC6A705)
  • cleanup
SourceRuleDescriptionAuthorStrings
C:\Program Files (x86)\IZArc\is-GD2P4.tmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
    C:\Program Files (x86)\IZArc\is-GD2P4.tmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      SourceRuleDescriptionAuthorStrings
      0000000E.00000000.1509843590.0000000000AB1000.00000020.00000001.01000000.0000000B.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
        Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: {BC593DF5-466F-44EC-8FFD-C4DBC603B917}, EventID: 13, EventType: SetValue, Image: C:\Windows\System32\regsvr32.exe, ProcessId: 2980, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\IZArcCM\(Default)
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        There are no malicious signatures, click here to show all signatures.

        Source: IZArc_4.5.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficDNS traffic detected: DNS query: 15.164.165.52.in-addr.arpa
        Source: global trafficDNS traffic detected: DNS query: www.izarc.org
        Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52234
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52231
        Source: unknownNetwork traffic detected: HTTP traffic on port 52237 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52237
        Source: unknownNetwork traffic detected: HTTP traffic on port 52231 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52235
        Source: unknownNetwork traffic detected: HTTP traffic on port 52234 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 52235 -> 443
        Source: IZArc_4.5.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: classification engineClassification label: clean5.winEXE@23/159@3/43
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Users\user\AppData\Local\Programs
        Source: C:\Users\user\Desktop\IZArc_4.5.exeFile created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp
        Source: Yara matchFile source: C:\Program Files (x86)\IZArc\is-GD2P4.tmp, type: DROPPED
        Source: Yara matchFile source: 0000000E.00000000.1509843590.0000000000AB1000.00000020.00000001.01000000.0000000B.sdmp, type: MEMORY
        Source: C:\Windows\System32\regsvr32.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Windows\System32\regsvr32.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile read: C:\Windows\win.ini
        Source: C:\Users\user\Desktop\IZArc_4.5.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
        Source: C:\Users\user\Desktop\IZArc_4.5.exeFile read: C:\Users\user\Desktop\IZArc_4.5.exe
        Source: unknownProcess created: C:\Users\user\Desktop\IZArc_4.5.exe "C:\Users\user\Desktop\IZArc_4.5.exe"
        Source: C:\Users\user\Desktop\IZArc_4.5.exeProcess created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp "C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp" /SL5="$90280,5047654,194560,C:\Users\user\Desktop\IZArc_4.5.exe"
        Source: C:\Users\user\Desktop\IZArc_4.5.exeProcess created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp "C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp" /SL5="$90280,5047654,194560,C:\Users\user\Desktop\IZArc_4.5.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe" -sa
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe" -sa
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2000,i,11753767500346397328,11824077582812530869,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2000,i,11753767500346397328,11824077582812530869,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Windows\SysWOW64\notepad.exe "Notepad" C:\Program Files (x86)\IZArc\WhatsNew.txt
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Windows\SysWOW64\notepad.exe "Notepad" C:\Program Files (x86)\IZArc\WhatsNew.txt
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: unknownProcess created: C:\Program Files (x86)\IZArc\IZArc.exe "C:\Program Files (x86)\IZArc\IZArc.exe"
        Source: C:\Users\user\Desktop\IZArc_4.5.exeSection loaded: apphelp.dll
        Source: C:\Users\user\Desktop\IZArc_4.5.exeSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: apphelp.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: mpr.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: version.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: uxtheme.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: kernel.appcore.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: textinputframework.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: coreuicomponents.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: coremessaging.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: ntmarta.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wintypes.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wintypes.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wintypes.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: windows.storage.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wldp.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: profapi.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: shfolder.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: rstrtmgr.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: ncrypt.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: ntasn1.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: textshaping.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: riched20.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: usp10.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: msls31.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: sspicli.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: explorerframe.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: sfc.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: sfc_os.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: propsys.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: linkinfo.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: ntshrui.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: srvcli.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: cscapi.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: apphelp.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: aclayers.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: sfc_os.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: kernel.appcore.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: uxtheme.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: msimg32.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: version.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: windows.storage.dll
        Source: C:\Windows\System32\regsvr32.exeSection loaded: wldp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: apphelp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: msimg32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: version.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: mpr.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: urlmon.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: apr.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wsock32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: iertutil.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: srvcli.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: netutils.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: uxtheme.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: kernel.appcore.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.storage.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wldp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: unrar.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cabinet5.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: olepro32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: propsys.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: profapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ntshrui.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: sspicli.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cscapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: tar32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: 7za.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: bga32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ungca32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: yz1.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: winmm.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: textshaping.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windowscodecs.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: thumbcache.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dwmapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: textinputframework.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: coreuicomponents.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: coremessaging.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ntmarta.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: ieframe.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: iertutil.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: netapi32.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: userenv.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: winhttp.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wkscli.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: netutils.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: msiso.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: windows.staterepositoryps.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: urlmon.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: edputil.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: secur32.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: mlang.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: wininet.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: policymanager.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: msvcp110_win.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: onecorecommonproxystub.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpSection loaded: onecoreuapcommonproxystub.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: kernel.appcore.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: uxtheme.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: mrmcorer.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: windows.storage.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: wldp.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: textshaping.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: efswrt.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: mpr.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: wintypes.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: twinapi.appcore.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: oleacc.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: textinputframework.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: coreuicomponents.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: coremessaging.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: ntmarta.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: urlmon.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: iertutil.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: srvcli.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: netutils.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: propsys.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: policymanager.dll
        Source: C:\Windows\SysWOW64\notepad.exeSection loaded: msvcp110_win.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: msimg32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: version.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: mpr.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: urlmon.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: apr.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wsock32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: iertutil.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: srvcli.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: netutils.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: uxtheme.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: kernel.appcore.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.storage.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wldp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: unrar.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cabinet5.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: olepro32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: propsys.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: profapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ntshrui.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: sspicli.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cscapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: tar32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: 7za.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: bga32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ungca32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: yz1.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: winmm.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: textshaping.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windowscodecs.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: thumbcache.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dwmapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dataexchange.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: d3d11.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dcomp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dxgi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: twinapi.appcore.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: textinputframework.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: coreuicomponents.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: coremessaging.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ntmarta.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wintypes.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: dui70.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: duser.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: edputil.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: explorerframe.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: policymanager.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: msvcp110_win.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.ui.fileexplorer.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: oleacc.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: xmllite.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: structuredquery.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: atlthunk.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.fileexplorer.common.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.staterepositoryps.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: windows.storage.search.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: apphelp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: ieframe.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: netapi32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: userenv.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: winhttp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wkscli.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: msiso.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: iconcodecservice.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: linkinfo.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: twinapi.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: actxprxy.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: networkexplorer.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: secur32.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: mlang.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: wininet.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cryptsp.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: rsaenh.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: cryptbase.dll
        Source: C:\Program Files (x86)\IZArc\IZArc.exeSection loaded: xmllite.dll
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpWindow found: window name: TMainForm
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Program Files (x86)\IZArc\IZArc.exeWindow detected: Number of UI elements: 13
        Source: IZArc_4.5.exeStatic file information: File size 5460056 > 1048576
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Windows\System32\regsvr32.exe "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files (x86)\IZArc\IZArcCM64.dll"
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-89GT3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-GD2P4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-5320F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-RCQMA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-298O3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-2IJKA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-EL6HL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-FJT9H.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-1FA2S.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-F7RL9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-COCN4.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-P6KVM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-SHJIS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-DUQ4P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-BULUJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-B448I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\is-5KKH7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-GFOJB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\Desktop\IZArc_4.5.exeFile created: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-H091R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\Program Files (x86)\IZArc\SFXS\is-3U52R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\IZArc.lnk
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\IZArc Help.lnk
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\What's New.lnk
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IZArc\Uninstall IZArc.lnk
        Source: C:\Program Files (x86)\IZArc\IZArc.exeRegistry key monitored for changes: HKEY_CURRENT_USER_Classes
        Source: C:\Program Files (x86)\IZArc\IZArc.exeRegistry key monitored for changes: HKEY_CURRENT_USER_Classes
        Source: C:\Users\user\Desktop\IZArc_4.5.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Windows\System32\regsvr32.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Program Files (x86)\IZArc\IZArc.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-P6KVM.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-89GT3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-SHJIS.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-DUQ4P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-BULUJ.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-5KKH7.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-B448I.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-5320F.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-RCQMA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-GFOJB.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-H091R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-298O3.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-2IJKA.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-EL6HL.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-FJT9H.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-1FA2S.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-3U52R.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\is-F7RL9.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpDropped PE file which has not been started: C:\Program Files (x86)\IZArc\SFXS\is-COCN4.tmpJump to dropped file
        Source: C:\Windows\System32\regsvr32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
        Source: C:\Windows\System32\regsvr32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
        Source: C:\Program Files (x86)\IZArc\IZArc.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
        Source: C:\Program Files (x86)\IZArc\IZArc.exeFile Volume queried: C:\ FullSizeInformation
        Source: C:\Program Files (x86)\IZArc\IZArc.exeFile Volume queried: C:\ FullSizeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess information queried: ProcessInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.izarc.org/donate
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Windows\SysWOW64\notepad.exeQueries volume information: C:\Program Files (x86)\IZArc\WHATSNEW.TXT VolumeInformation
        Source: C:\Program Files (x86)\IZArc\IZArc.exeQueries volume information: C:\ VolumeInformation
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
        DLL Side-Loading
        11
        Process Injection
        1
        Regsvr32
        OS Credential Dumping1
        Query Registry
        Remote ServicesData from Local System2
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        Registry Run Keys / Startup Folder
        1
        DLL Side-Loading
        2
        Masquerading
        LSASS Memory1
        Process Discovery
        Remote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
        Registry Run Keys / Startup Folder
        11
        Process Injection
        Security Account Manager2
        System Owner/User Discovery
        SMB/Windows Admin SharesData from Network Shared Drive2
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
        DLL Side-Loading
        NTDS1
        File and Directory Discovery
        Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets22
        System Information Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        IZArc_4.5.exe0%ReversingLabs
        IZArc_4.5.exe4%VirustotalBrowse
        SourceDetectionScannerLabelLink
        C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp4%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp0%VirustotalBrowse
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_isdecmp.dll3%VirustotalBrowse
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_setup64.tmp0%VirustotalBrowse
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-QE0BH.tmp\_isetup\_shfoldr.dll0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\7za.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\7za.dll (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\Bga32.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\Bga32.dll (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\IZArc.exe (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\IZArc.exe (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\IZArcCM64.dll (copy)2%ReversingLabs
        C:\Program Files (x86)\IZArc\IZArcCM64.dll (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcARJ.dat (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcARJ.dat (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcBH.dat (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcBH.dat (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcJAR.dat (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcJAR.dat (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcLHA.dat (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcLHA.dat (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcRAR.dat (copy)4%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcRAR.dat (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcSZip.dat (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcSZip.dat (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\SFXS\IZArcZip.dat (copy)2%ReversingLabs
        C:\Program Files (x86)\IZArc\SFXS\IZArcZip.dat (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\Tar32.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\Tar32.dll (copy)2%VirustotalBrowse
        C:\Program Files (x86)\IZArc\UnGca32.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\UnGca32.dll (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\Yz1.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\Yz1.dll (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\apr.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\apr.dll (copy)1%VirustotalBrowse
        C:\Program Files (x86)\IZArc\arc.izp (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\arc.izp (copy)0%VirustotalBrowse
        C:\Program Files (x86)\IZArc\cabinet5.dll (copy)0%ReversingLabs
        C:\Program Files (x86)\IZArc\cabinet5.dll (copy)0%VirustotalBrowse
        No Antivirus matches
        SourceDetectionScannerLabelLink
        15.164.165.52.in-addr.arpa0%VirustotalBrowse
        cdnjs.cloudflare.com0%VirustotalBrowse
        izarc.org1%VirustotalBrowse
        www.izarc.org0%VirustotalBrowse
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        cdnjs.cloudflare.com
        104.17.25.14
        truefalseunknown
        izarc.org
        162.213.251.221
        truefalseunknown
        15.164.165.52.in-addr.arpa
        unknown
        unknownfalseunknown
        www.izarc.org
        unknown
        unknownfalseunknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        172.217.18.3
        unknownUnited States
        15169GOOGLEUSfalse
        142.250.184.238
        unknownUnited States
        15169GOOGLEUSfalse
        162.213.251.221
        izarc.orgUnited States
        22612NAMECHEAP-NETUSfalse
        142.250.186.74
        unknownUnited States
        15169GOOGLEUSfalse
        104.17.25.14
        cdnjs.cloudflare.comUnited States
        13335CLOUDFLARENETUSfalse
        66.102.1.84
        unknownUnited States
        15169GOOGLEUSfalse
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1524802
        Start date and time:2024-10-03 09:16:03 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:defaultwindowsinteractivecookbook.jbs
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:25
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        Analysis Mode:stream
        Analysis stop reason:Timeout
        Sample name:IZArc_4.5.exe
        Detection:CLEAN
        Classification:clean5.winEXE@23/159@3/43
        Cookbook Comments:
        • Found application associated with file extension: .exe
        • Exclude process from analysis (whitelisted): dllhost.exe
        • Excluded IPs from analysis (whitelisted): 13.107.5.88, 2.23.209.189, 2.23.209.149, 2.23.209.140, 2.23.209.179, 2.23.209.187, 2.23.209.130, 2.23.209.141, 2.23.209.133, 2.23.209.182
        • Excluded domains from analysis (whitelisted): fs.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenKeyEx calls found.
        • Report size getting too big, too many NtProtectVirtualMemory calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:93AA6A76E2F245C85C76FB4C993BC9CB
        SHA1:6D39D98588AD4623DCC423A94FCFAADBB22A0104
        SHA-256:0C19B611525E2B4FB5F04581B61F4119821A10EABDF73151F22BE18DB2C805B8
        SHA-512:35E4B4E797DDC1AF09C755ABE7D55A1F6E7053F03F2F18A5C8CF406DCFC2A8D6211A623D7A1DFAE1E58FEE6CAE4F927219E8137D9CCBD8BBE3A4AC629B8F2C43
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*o;+n.Uxn.Uxn.Ux..[xw.UxX(_xP.Ux...xo.Uxn.Tx..Ux...xi.UxX(^x..Ux.x.xy.Ux.x.xl.Ux..Sxo.Ux..Qxo.UxRichn.Ux........PE..L....S.L...........!.....F...<......U........`......................................................................p..........P....`..........................8$...................................................`..d............................text....E.......F.................. ..`.rdata..c^...`...`...J..............@..@.data...........:..................@....sxdata......P......................@....rsrc........`......................@..@.reloc...5.......6..................@..B................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D13A7CC98FC3CBDCAC897747EB30D9E5
        SHA1:B9C6B7822674D318494ACB7F5A45BB38658C7019
        SHA-256:EACD666AD079917AEE7392F55E5F3653843AF92C2DFBBCB2EBBBE55B2B8DA1B1
        SHA-512:0E3327BBDD761D4BCD3F53E1FA32841547F4BC56167D0A2A71B3E0D82FA21FD1323784D58BA087AF1A169BB6E7D14F069D058CFE6F453429558A7D85DDF00E32
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........?K}@^%.@^%.@^%.;B).C^%.@^%.R^%.@^$.._%."A6.O^%./A..J^%..B+.[^%./A/..^%.9...t^%.F}/.S^%.F}..^^%..X#.A^%..~!.A^%.Rich@^%.........................PE..L...F..<...........!................0........ ............................................................................. ........P...%........................................................................... ..h............................text............................... ..`.rdata..q.... ....... ..............@..@.data............p..................@....rsrc....%...P...0... ..............@..@.reloc..NS.......`...P..............@..B........................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2DF7FD7AA617D06891058D8996B60CCE
        SHA1:400F57E4CFCD7FF6B6706D420E5D68BBAE3873B2
        SHA-256:5F188A02C6AF935F3F118A892B4F3F2B4EBD26737EB0629AA904B0BE858E595D
        SHA-512:84698662E4CA309BFF4B709811310797021BE0265D342C12102A6FA8922707233B0B373D13B08D7AA571A596054B9B35F294038868C6F215D6A198CD8DDA097B
        Malicious:false
        Reputation:unknown
        Preview:============================================================================.. GZIP.ABZIP2 ....k............ Bga32.dll version 0.37.. ... ...... Toshinobu Kimura..============================================================================.......O.D........============.... ........uBga32.dll.v..._.E.....[.h........................B.... Bga32.dll..A.....k.............P..t.@.C.............{............ ..........( ? ).AWindows...........g.p.........( .... ? ).. GZIP( .GZ ).ABZIP2( .BZ2 )...........A.....t.@.C......k........... ..y..s......................z........... DLL....B.... ........k......... .GZ/.BZ2....k.....t.@.C........( .GZA/.BZA ).. ...........A.....i.[.t.@.C..................\.........B.. ...k.E...E.i.[.t.@.C.....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:05DD8B4D4653AE8AE58684E3DC049FDB
        SHA1:A4E4F059BF65884450CCB983762D7179946BC90E
        SHA-256:51E64818CD99C1049245E01D5EB19D857EC150F927A4FBD49475E38657812AF1
        SHA-512:7E03AA768B4A219A628EEBC3C9ECC8C7BF6F15D35C57BDA25B45B50CEE10353C17F820F2E5D534FCD224DAD5541E29B0A5147A0F5992EA85A1AA62EB3D971D54
        Malicious:false
        Reputation:unknown
        Preview:If you want to know about tar32.dll, please look one of following..documents... http://openlab.ring.gr.jp/tsuneo/tar32/index-e.html (English).. http://openlab.ring.gr.jp/tsuneo/tar32/ (Japanese).. ./html/index-e.html (English).. ./html/index.html (Japanese)....Yoshioka Tsuneo(tsuneo@rr.iij4u.or.jp)
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F1E5445D19CDF34AFDE4D4092D83B7E4
        SHA1:E7B220CC41578FE0DFC0CE028AAB82C0D463B80C
        SHA-256:D752BE2264B2313479D8919176E62546A1E95BCBA653E07899B08A1D8230AC31
        SHA-512:6420FE93D4E313FC660081B82B19CBF0AB16D1B604B9006788443EDD032765B30B7616551C52BE1A24D4C5D16B44E81432B603AE153AE474E2CFF75FEA3C331E
        Malicious:false
        Reputation:unknown
        Preview:=========================================================...@GCA.......pDLL UnGCA32.DLL.....@.@.@.@.@.@.V..W.....@.@.@.@.@.@URL:http://www6.plala.or.jp/amasoft/..=========================================================.......y.T.v.z.....@......C.u......A..........k........k.`.......GCA.........DLL....B...@Windows95/NT4.0...........B...@DLL..............@.\..A........GCA.W.J............B.........y.g.....z.....`.D.....[.U......@DLL....A.P....g.......B.......A.v...P.[.V........g.p............B...@UnGCA32.DLL ...V.X.e...t.H..._..R.s.[............B ....t.@.C.......K.v..........B.i95.n.. \WINDOWS\SYSTEM.ANT.n..\WINDOWS\SYSTEM32.j.....a.D.v...O...}......A.v..............@......API.d.l.....Q...........B...@.s..\.t.g/.V.F.A.E.F.A.......A.....R....p..................B.........y...........z.....E.z.z.t.@.C....W.J.......AUnGCA32.DLL.....\.........B...@Explorer .....[.U.[...w.........ADLL..\..........B...@.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):2453
        Entropy (8bit):6.020528286894727
        Encrypted:false
        SSDEEP:
        MD5:F1E5445D19CDF34AFDE4D4092D83B7E4
        SHA1:E7B220CC41578FE0DFC0CE028AAB82C0D463B80C
        SHA-256:D752BE2264B2313479D8919176E62546A1E95BCBA653E07899B08A1D8230AC31
        SHA-512:6420FE93D4E313FC660081B82B19CBF0AB16D1B604B9006788443EDD032765B30B7616551C52BE1A24D4C5D16B44E81432B603AE153AE474E2CFF75FEA3C331E
        Malicious:false
        Reputation:unknown
        Preview:=========================================================...@GCA.......pDLL UnGCA32.DLL.....@.@.@.@.@.@.V..W.....@.@.@.@.@.@URL:http://www6.plala.or.jp/amasoft/..=========================================================.......y.T.v.z.....@......C.u......A..........k........k.`.......GCA.........DLL....B...@Windows95/NT4.0...........B...@DLL..............@.\..A........GCA.W.J............B.........y.g.....z.....`.D.....[.U......@DLL....A.P....g.......B.......A.v...P.[.V........g.p............B...@UnGCA32.DLL ...V.X.e...t.H..._..R.s.[............B ....t.@.C.......K.v..........B.i95.n.. \WINDOWS\SYSTEM.ANT.n..\WINDOWS\SYSTEM32.j.....a.D.v...O...}......A.v..............@......API.d.l.....Q...........B...@.s..\.t.g/.V.F.A.E.F.A.......A.....R....p..................B.........y...........z.....E.z.z.t.@.C....W.J.......AUnGCA32.DLL.....\.........B...@Explorer .....[.U.[...w.........ADLL..\..........B...@.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):19586
        Entropy (8bit):5.933026789333976
        Encrypted:false
        SSDEEP:
        MD5:2DF7FD7AA617D06891058D8996B60CCE
        SHA1:400F57E4CFCD7FF6B6706D420E5D68BBAE3873B2
        SHA-256:5F188A02C6AF935F3F118A892B4F3F2B4EBD26737EB0629AA904B0BE858E595D
        SHA-512:84698662E4CA309BFF4B709811310797021BE0265D342C12102A6FA8922707233B0B373D13B08D7AA571A596054B9B35F294038868C6F215D6A198CD8DDA097B
        Malicious:false
        Reputation:unknown
        Preview:============================================================================.. GZIP.ABZIP2 ....k............ Bga32.dll version 0.37.. ... ...... Toshinobu Kimura..============================================================================.......O.D........============.... ........uBga32.dll.v..._.E.....[.h........................B.... Bga32.dll..A.....k.............P..t.@.C.............{............ ..........( ? ).AWindows...........g.p.........( .... ? ).. GZIP( .GZ ).ABZIP2( .BZ2 )...........A.....t.@.C......k........... ..y..s......................z........... DLL....B.... ........k......... .GZ/.BZ2....k.....t.@.C........( .GZA/.BZA ).. ...........A.....i.[.t.@.C..................\.........B.. ...k.E...E.i.[.t.@.C.....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):13776
        Entropy (8bit):6.15101970010498
        Encrypted:false
        SSDEEP:
        MD5:1B56E3820E387DDB5CCA4B78C6E7FFB9
        SHA1:C7A130DC8C700D17DC36BDFE317E423C6617AFE1
        SHA-256:70A9BD165306EA7A811D82D03D151AFFFCB06830F1ACFC61BECF4DFDB46E5B32
        SHA-512:997FEFCDD7F5CD4D5132BC23C9358C4FD467CCCAEE4A8D479B766B31F1D0071A6400AD02426CAE61A6C7DB87669B18160CE37545561683A48CDAC2A4296C922B
        Malicious:false
        Reputation:unknown
        Preview:..---------------------------------------------------------------------------- .. .YZ1.... ...k..DLL.... YZ1.DLL Ver 0.24 / Unyz1.dll 0.03..---------------------------------------------------------------------------- .........O.D.......... ._.E.....[.h.L.............B.... ......C.u......A........BinaryTechnology.....J........ "DeepFreezer" ....k.`.......AYZ1.........DLL....B32.r.b.g.... ......AWindows 95/98/Me/NT/2000/XP.ii386.p.j........\....B.... ....A.... NIFTY-Serve FWINDC MES #3 ...i.s....w.....A.[.J.C.o.. .`.o.h.d.l.x.i....j..............B.u.`.o.h.d.l.v.....i.s.`.... .v...W.F.N.g....B..........A....DLL ......@.\...A..I....... ................[....F......g.p.........B.........P.D.g........ yz1d024.exe .....s.....A..............B........... .u.n.j.v.{.^..................B.... .S...t.@.C.....n.[.h.f.B.X.N.. \Program Files\ArchiverDLL\YZ1\ .. .t.H..._.......A.K.v..t.@.C.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:ASCII text, with CRLF line terminators
        Category:dropped
        Size (bytes):327
        Entropy (8bit):4.730115283350169
        Encrypted:false
        SSDEEP:
        MD5:05DD8B4D4653AE8AE58684E3DC049FDB
        SHA1:A4E4F059BF65884450CCB983762D7179946BC90E
        SHA-256:51E64818CD99C1049245E01D5EB19D857EC150F927A4FBD49475E38657812AF1
        SHA-512:7E03AA768B4A219A628EEBC3C9ECC8C7BF6F15D35C57BDA25B45B50CEE10353C17F820F2E5D534FCD224DAD5541E29B0A5147A0F5992EA85A1AA62EB3D971D54
        Malicious:false
        Reputation:unknown
        Preview:If you want to know about tar32.dll, please look one of following..documents... http://openlab.ring.gr.jp/tsuneo/tar32/index-e.html (English).. http://openlab.ring.gr.jp/tsuneo/tar32/ (Japanese).. ./html/index-e.html (English).. ./html/index.html (Japanese)....Yoshioka Tsuneo(tsuneo@rr.iij4u.or.jp)
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Non-ISO extended-ASCII text, with CRLF, NEL line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:1B56E3820E387DDB5CCA4B78C6E7FFB9
        SHA1:C7A130DC8C700D17DC36BDFE317E423C6617AFE1
        SHA-256:70A9BD165306EA7A811D82D03D151AFFFCB06830F1ACFC61BECF4DFDB46E5B32
        SHA-512:997FEFCDD7F5CD4D5132BC23C9358C4FD467CCCAEE4A8D479B766B31F1D0071A6400AD02426CAE61A6C7DB87669B18160CE37545561683A48CDAC2A4296C922B
        Malicious:false
        Reputation:unknown
        Preview:..---------------------------------------------------------------------------- .. .YZ1.... ...k..DLL.... YZ1.DLL Ver 0.24 / Unyz1.dll 0.03..---------------------------------------------------------------------------- .........O.D.......... ._.E.....[.h.L.............B.... ......C.u......A........BinaryTechnology.....J........ "DeepFreezer" ....k.`.......AYZ1.........DLL....B32.r.b.g.... ......AWindows 95/98/Me/NT/2000/XP.ii386.p.j........\....B.... ....A.... NIFTY-Serve FWINDC MES #3 ...i.s....w.....A.[.J.C.o.. .`.o.h.d.l.x.i....j..............B.u.`.o.h.d.l.v.....i.s.`.... .v...W.F.N.g....B..........A....DLL ......@.\...A..I....... ................[....F......g.p.........B.........P.D.g........ yz1d024.exe .....s.....A..............B........... .u.n.j.v.{.^..................B.... .S...t.@.C.....n.[.h.f.B.X.N.. \Program Files\ArchiverDLL\YZ1\ .. .t.H..._.......A.K.v..t.@.C.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [InternetShortcut]
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5EDE8FD9DD6AA1C48ECBF416EBF18C7C
        SHA1:738A5A9282AB7ABD91A1A78454864E7E7FB33EC2
        SHA-256:45E78315F26D722386335DB3039C3A0BAC5C53DE2EDAD2705207AA2A2251E39F
        SHA-512:D71D68EB3C38CCDBDD8FBA426E6B89FA88941C92348976E8D00D15E7E08875DE9A43ECAC55BEF9BED5296E6580EACA3BB98B17701FAFA4792AE6E729CD34919D
        Malicious:false
        Reputation:unknown
        Preview:[DEFAULT]..BASEURL=http://izarc.org/donate.html..[InternetShortcut]..URL=https://www.izarc.org/donate..IDList=..IconFile=http://izarc.org/favicon.ico..IconIndex=1..HotKey=0..[{000214A0-0000-0000-C000-000000000046}]..Prop3=19,11..
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows HtmlHelp Data
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:092E24B7B052302139111F0C65BD25AC
        SHA1:651CF2AA4F5861996B77757D7AD6CD78A8D40850
        SHA-256:B06D04139EC6B0E810AD6073C2E84EDEE7F49ACF672E09771EA3D67002DADAA4
        SHA-512:132AEBA9036860F144E38151AC60DDA4AF119D86FD4275D1551E444BB493F0D26742D75D1D66A2F3406E8AC4ACEC49ED42EE8F74DABDDB70AB003213E0D72096
        Malicious:false
        Reputation:unknown
        Preview:ITSF....`..................|.{.......".....|.{......."..`...............x.......T........................g..............ITSP....T...........................................j..].!......."..T...............PMGL)................/..../#IDXHDR...O.../#ITBITS..../#IVB.....\./#STRINGS......./#SYSTEM....../#TOPICS...O.@./#URLSTR..._.5./#URLTBL.....P./#WINDOWS...>.L./$FIftiMain...t..[./$OBJINST...5.?./$WWAssociativeLinks/..../$WWAssociativeLinks/BTree...=.L./$WWAssociativeLinks/Data.....r./$WWAssociativeLinks/Map...{../$WWAssociativeLinks/Property.... ./$WWKeywordLinks/..../$WWKeywordLinks/BTree...f.L./$WWKeywordLinks/Data...2.a./$WWKeywordLinks/Map....../$WWKeywordLinks/Property.... ./180.htm..@.l./aboutarchivefiles.htm...,.$./aboutizip.htm...P.../addfilestoanarchive.htm...m..!./checkout.htm.....;./clearhistory.htm...I.../closearchive.htm...`.5./commandlineinterface.htm......../configuration.htm......-./convertarchive.htm...K.>./convertcdimage.htm.....B./copyarchive.htm...K.X./createanewarchiv
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6AD69B02B1A5BA995EADC7FD9CC6A705
        SHA1:0EECB19E7D06E36165D36B12A2572EF8493AF835
        SHA-256:79074936D195049D1380E7FF085221C970D7A2283EC612C40BD15B8006AEAEB4
        SHA-512:B0031AEEE86BD4C1D1D7F6B0C041C552BE662B34620EEB6E70DC017212AF319DD676468E0DB6A50BB6712645385DC32A5E1CF48A2BEFAB00DF6AAEF95855A84F
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...~..b..................#..v......X.#.......#...@..........................p;...........@......@............................+..@............................,. i............................,.......................+..............................text...l.#.......#................. ..`.itext........#.......#............. ..`.data.........#.......#.............@....bss..........$.......$..................idata...@....+..B....$.............@....tls....H.....+.......$..................rdata........,.......$.............@..@.reloc.. i....,..j....$.............@..B.rsrc................D'.............@..@.............p;......04.............@..@................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F64E891A69B8274CB7D011883F8B2A65
        SHA1:0EDCFCE898FBEA3AB417BE9C30C5565BBD7EC95D
        SHA-256:C79474CE574887482BC455FEE365FC4F89904102AEB1DF0D449DE5460C553D45
        SHA-512:F199958F2A1D833FA46D90B4234FA53797AF8DCB2950FAB6D77E4ACB326CD37362934E6090481001CAEA0A7CE05C3C19315A642F544CC940552990658578F8A9
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 2%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..d...q..\.........." ..........................@...............................&...................................... ................".......".6N...0&..d...p$.8.............#.Dn..................................................(.".X....."......................text............................... ..`.data........ ......................@....bss.........!.......!..................idata..6N...."..P....!.............@....didata.......".......".............@....edata........"......(".............@..@.reloc..Dn....#..p...*".............@..B.pdata..8....p$.......#.............@..@.rsrc....d...0&..d...L%.............@..@..............&.......%.............@..@................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:105AE6BB92C7F5A355203C75CF483A5A
        SHA1:CA9EFA180D679D83EC266D1E1A48F3F97901595A
        SHA-256:65888D9D296D0D9DF665D4672A2411ED6EA3EF244D987B69328D04EF713FDE55
        SHA-512:359DF4B2B1EB544FEB7B0F378C2D18E68D9BF1F9F5CF032CFD20E33D7C3AC51348C8C8AC2ECD67B8FB442F1E32375B2F8A7D39B3350161B123C46FE6F43B2EE2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*.. ..........NG..........h....S..........h...^W.. .... ......\.. ..........nm..00...........v..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................U................"..."..."...$...$...$...$...%...%..d........................................................................................................................6...6...8...8...8...8...............9...;...;...;...;...<...<...<...<...=.................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5F6F8D97BEF979672565271F452829C4
        SHA1:EB7269646EDD67851889673A185C7A56CE2B1B1D
        SHA-256:232637B8A066EC8305CBB482FFAC9DC3C9436910239C9095F6521A5DE92A65E5
        SHA-512:446C6B6EED0622A1A53A15AEC76A7B3AD89C776A2A1D34C6D2BE741FF973E7C7982888FF6D1D79517146A38798820B7F5052F6B82685538B12C79ED00844B371
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. ...........U.. ...........b..........h...Fk..........h....n.. .... ......t..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................6......................................E.........................................................................................................................................................................i................!..T!..."..."..."...$.............................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B8024CA7B237603BFEAA066BFF09DAF3
        SHA1:2E67FC1AE88521DEEDB474A24EB560A1D9E1D308
        SHA-256:069CB3C5DA6973D9DAE8666923E58E40E9CF7FCE714F88D977D5FD3C06BFA304
        SHA-512:B26728E27387E4DCBD25D4508A929C153239B24E0CA3E07FFEF4C3471ECFDF8DB49C273840F5A1E5399007A12399FE2B0065FFE6041BD88D731EE0D05DCF4B7D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&.. .... ......*.. ..........N;..00...........G..00...........d.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................$...=...8...............................................n............................................................................2...........9...................................U...........................^.......................................................?................0...0...0...0...1.......1...1...1...1...1...........2..T2...2...2...2...2...........4..Z4...4...4...4...4...4...5...5...5...5..!............................D..9D...D...D...D...D...D...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:C13C65504AF492DA6E95C7E8E7AA5426
        SHA1:BFC3A6E1997333DA0FC6DF1D1253F18E2BD04B16
        SHA-256:5DFA9C8F9215840744DD56B1EAF9ECB107110015CB3844F8934CC812A751A698
        SHA-512:BF4336A3B5EA7A9194C9558AF6CE7F23A3AFF7017A1BCC37548C269C35261B57DE6577E8004B64E0E6AF82B24480A32E670FBCFC3065F58C19A05A0BB7B1077D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................(.......Y................................................................................................................................................................................................0..t............................................................<..F<...<...<.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:4ECB934D889DDEA447BE7E6AB1931C62
        SHA1:007D9B1C9171C3252BEA7F3A459835629F94E2FB
        SHA-256:B6447A8F43ECB8C3B5E838EE58133E0268CB18DFBCEE520840C9293036775C8B
        SHA-512:FCD29994DED4D6490A4AF334FA0F1B038D488C5BD75D253FCAE924CD6FC4FB11697CA9D31994AAAAC4BDDBE0E3C9E6360BA2AC6FACCFFBFFD13F661515EAAEB2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&.........................................o...................................................!.......................................................V..........................................................................................>........................".."..."..."..."..m....................................................4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:94AB32A58C76ACEF9F75C2BB4131CF0E
        SHA1:535F39D53A47DBE697573C01E07D9668FECF48A7
        SHA-256:E230A755D407B93194D858B7AAEFEDF12F53C105369EDC820EA5BDFBC326FD41
        SHA-512:92661F271BDEEFE4A118EC06BA676A8577B96DC4985BA2EE06A38BD1D524A657CED89466819054C468FE7EE6DBA54D2C08BE232487F85323B68BAD97AD30F472
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&...........'...............................................^...................................................................................V......................................................................T................!..y!...!..."...".........................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F4A5CBF4D386EC4C8E3CA912EA2D228C
        SHA1:A0494F203A0BAEEF84B36A301EE67C7417940682
        SHA-256:B818660588A822DD48E16A7E3D6B39FC7706DBA5C79476A28EC48D49933A6802
        SHA-512:36BFB01DA63322D6DA864AD9EB511890AFDE45E2021F45A2383785BA739E9E7F43AF35073BDB4C07FCE4AFD88F6971C4D4D74B49CEEE1F07D4488C0D6CEC3C32
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&...........2...........................................................5..............h...........................................................V......................................................................Y...................!..o................!.."..."..."..."...........................................................4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5946EBE9F9F5AAA93EE54B46C5B07D6C
        SHA1:5F3B6B367B240EF7015D91A1BF3D05752B043B0B
        SHA-256:967473BC2BDF07BCEE4275D87CEDE082A3CDEF45418609B81563AECF6CC07B5F
        SHA-512:67D5B0BE316097527B85BB1A61C5E11C62454CF5C1B31550C77B25A7D611D281FC339E39E7C6885D11BE0585FA4D2224F4E134D0257623B0AE0C2CF1C7EEFEE6
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................i......................................Q...................................................x...................................................................................................+................0...0...0...0...0...0...0...1.......1...1...1...1...2...2...2...2...2...2...2...4...4...4...4...4...4...5...5...5...5...5..D....................................................D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:29C014B29A9191F93B9C13636BDD2C4A
        SHA1:D99C5FFC597D6758DBC81B299BDCC668F6A12A80
        SHA-256:12571FF68DC07BB9B564B07CDFA78F57A387B0EFBF7F4398A88C1D979ED29F97
        SHA-512:D8361CF52FBC26B8F5D82971A5FD24E82B02CEB3063C59849F2A55B5F5180777A8D4487299B4FD9EE6E7156CDDD57563E5BC4174BEB2F62A5F2755092157A779
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. ...........U.. ...........b..........h...Fk..........h....n.. .... ......t..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................2......................................k.....................................................7......................................Q.......................................................................................................3...........................................!..4!..!...!...!...!..}................"..S"..."..."...$...$.......................................4...4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:99FDC3DF50698C684AF6EE7B87671023
        SHA1:FF540435C35987122E5573E183DDEED37144C385
        SHA-256:0CEDDAF2659B8003C4103A29DF77AF428818CAF686E57FF3ADA0140E880BDD7F
        SHA-512:18B2478BFA7AF7F6CD5A156E47A07AF835498AB42EF9A57FE7E5537BC388C2EF1601D4868ADC3A33C4CD5A5EF6D1153CB9E9923FB584D8C4A94B00475F071EF9
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................9...=...$........................................................................................................................................................................... .....................................j.......................................g...:.......................................................................................................................0...0...0...0...0...0..Z0..B1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4...4...4...5...5...5.......................................................D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:12E7241B57B768F45990C34A6FCB59C4
        SHA1:972C1B1C2C39055DB27E9AE91A4EA116B0E3A8DA
        SHA-256:E6DA09C239FC3AFE899859D6D72CB77683C8AD612B617049A68BD4A37C2C9AAE
        SHA-512:A438380126B6574BC5D6B37D987D14209AC7C97B3B019EF9501BFCAA4604A660186E9A0BFE0F6FF5638CAFC807E8FDF4145DE1AFD26349AA56FBBFE3C9ED91AF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................)...g...|...s...J...................:...=...*...............................4...=...6...............=...=...=...=...=...=...1.................................................................................................g.....................................................................................................@............................................................0...0...0...0...0...0...0..<0...1...1...1...1..r................2...2...2...2...2.......2...4...4...4...4...4...4...4...4...5...5...5.......................................D..&D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:87DBA4381032D805A33D7E481CA03832
        SHA1:5672C6C724D4252928501C370148F95B38899727
        SHA-256:A3C15B842ACF03EA7A3A57DF399E66D8558C8CB5BA09E29FB9ABE5793B543ADE
        SHA-512:8EB78A27597E335EF9F8A5D5350643223FF7B8B93D9866FC8C9C74994ED6DE9F9018BD757B7BC66D0BF26CD4A3AE25BA4D351C29A765DB1AFC9F5C8EC88905DD
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................s...................2...............N...\...\...\...\...\...\...V...,...........................l...|...|...t...".......................................................................8..................................*..............................................n....................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:32511197792DC691270F10497A96A77F
        SHA1:CAA56E82F02E918AD159615031BC71E41046154E
        SHA-256:6A4EE4C3B79D8ED51F5D530189E39133F10E40FA330C221417A9176630832E52
        SHA-512:30870D133B8DB42C55458FE4AE1B15942FE74107ED436967C0A88265380F7D7ECBF9C74139F6B2533AEDC3562983676585E38BEDD8B884E42D3B2782FC536488
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................3...=...(...............................................................................................................2...=...).............................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:23FF01E18C148F67B30371B4C179B31E
        SHA1:A0D268B00FC543469A11E5CD9FEC4332BEC692D9
        SHA-256:3847C1FC694A7024F763445519AECB79D71F39F7C47AB5AEAD72D056A84A4B15
        SHA-512:6DCB73C7AC37BD36B7E801301E8521F68D4B9D010BAFEA1F766857B4AF1FCEE60AA45CC2869103BC269EDCE23AD8A3A5F1320CED0F1B68759A256DC6BC9E6F2D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................:......................................-...................M..............................................i......................................Q...............................................................................................................................................!..M!..+!...!...!...!...!...!..."..."..."..."..."..".......................................4...4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:571B611D9373A6E37248153539065A07
        SHA1:46A9E7694C85484B26DBFCB83551E74A6E2EAA54
        SHA-256:A0A49FBB245CB182E6749002D5B0DF34D0FA218F27C760190D9AF6E0ABA32E11
        SHA-512:B5DD42C4C736D151373888E04A187C81780A0D557853705B353877545630F77917BD99040598F5C965600E902CA9000C7EF940B37E3F4D1F8516C0200119FAA7
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................<...(...................................................&...<............................... ...a...|...w...O...............................................-...............................................@.......................................................D..........................................................................................................0...0...0...0...0...0...0...0...1...1...1...1..1............2..02...2...2...2...2...............4...4...4...4...4...4...4...5...5...5...5..N................................D..lD...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 8 bits/pixel, 32x32, 8 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B7EDA7668A75AA575AF5167C96D27C4B
        SHA1:5C912238093CD4DAA7D19B09D48C4DDE5DF94FF7
        SHA-256:8D0C2EECB63A6105CC812FD40592C6972788384B5398119AA2C9686AD89562F7
        SHA-512:E09DFA6C02D29F2D8B93E4ED6FA69E36F82700976E10B707A2AD354F2AC6B5ADD14B9758CE495AE78F1C77B722E3A73FF3699FE03AD0DD62C9F4FF76D181DAE6
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@.......................|WR......Q3..O1...b.sP?..Q2..Q2..Y9..^G.....`E.....cE..bE.........o7..f@..gD..eD...........b...c...c...d...c...d...d...s ..x(..>..zZ........g......x..$..&..*..+..+..,..-..-../..0..4..6...I............................................................................................~~~.}}}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:40DFAB257A5118EC91133215111D322D
        SHA1:50C959A750B50308F8324AA1CD001E9625A48864
        SHA-256:2DA10104A875361B0E7E7A0D5B8017CD386D791A7D10C0DF14344B3DFC5C46AA
        SHA-512:5F864DB9408317EE5CCE4E1F14BD15E81935CBB9E2C8C53CD9712D8626AE76C5EAD310F6037731E6F2FAE2D0B12B78708F525AE5E0A8EB91C468DF87AC0E346A
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................z.........................Q.........................+.........................O.......6......................................E............!..!...............................................0...0...0...0...0...0...0...0...1..5........1..-1...1...1...2...2...2...2...2...2...2...4...4...4...4...4..j................5..T5...5...5...5...5...............................D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:875F2E1576EB44C48D2C00E94EE87968
        SHA1:729990196979C8B3053E98917EA9F800CE0F379C
        SHA-256:EBA6D70EEDD9CC197B8A9739419E5892F61DAFC3A17E0526BEDEF02A700AD837
        SHA-512:6FE98DF68B6435D4290B9A93FB46E07C1BEBE7D1DDBF193D7C74225498110CB68B066D405C9FAB4AFE34CF5A9DF160EF9B76E14D20EB23D1F3C5BC433E87B2A2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................O...\...S...0...................................................)...=...=.....................................................................................................................................................h...........................................y............................................................................................................0...0...0...0...0...0...1...1...1...1.......2...2...2...2...4...4...4...4...4...5...5.....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:90F66425CFF7319A8A222FC0D40A2862
        SHA1:C9E817F24AD6E00422FCE32055A82DE2327F7EC5
        SHA-256:899DDF2939769991E6F0FC99D19FF1CD02441EBC71407FEE06D6463DC3D3F388
        SHA-512:1F8ED23AB41215AACC809FCC7DD2A3B37CAECE1CFEE455966A6A9068AF25EAA96F1168E4E6CA56D136AB6E2ADD99287EDBD43E2A236A3C6C0E7F83D52E949610
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................$...S...\...O...,...................................................-...=...<...........=...=...#...............................<...=................................................... .........................................I...>.......................................Z..................................................!...!..........................................................0...0...0...0...0...0...0...1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4..8............5...5...5...5...5...5.......................................D..vD...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:922D0DF8BA0A9F28319DBE0A5B729A5D
        SHA1:B1BCE258420B0A3485710E363A8798D118100DE4
        SHA-256:70F1C88356ED8C3CE38C528340CF1975884EA056623334D4492AAC6F2A629276
        SHA-512:73A8CF3117FBB00B5E809DD035FE994E9E61CF0C3E89072B1A7312B6FAFDB122C1E49D6CA2BAF060E27F078087BE7CA8764AC520F81166A9F5B5275DBB4F9AD5
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................q...............M.......................................................................................8...........................................................................u.......................................................C...q........!...!......................"..."..."..."...$..i..............................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:BAC40A94D1BDA434323F10197B36D1E1
        SHA1:8D6CE657DC5403C66E06E74FFEC9966575209574
        SHA-256:B76E895CF5A24027B9A2E78C93A2E95EBBE8D79C45810C0377A3BD95FA467317
        SHA-512:CAD644F037B8D391B91ED13CF58978CDF25EDDF18AF78883E8F7C07E9C3D7F519CD38E57214450D99760161EC7EC0F14E733DC602B984661457623E26C2821E4
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................l...|...|...t...".......;...\...\...\...............m...\...........0...\...\...\...;...........................i............f...............R.....................................................................h..................................<.......R...................................`...........................................:...........................................P................0.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F9152E1DCCBD200B0544CC0DD5F591FF
        SHA1:F386C344078F3F144C7778165F1446D4BEF11F94
        SHA-256:9E1EB684DA5C5BB3C2988C5C4B35A18587206889270B14B27C7AFB9972741D0F
        SHA-512:90909A301354E5B41CEB0915E60CF35EFE83C5685757544C26DE5309868EF44C793D1B180E1347539D8FDF8F197585DA3146D3259006AF292C26ECF46D8850A0
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................\..................................b...................................o......................[........................................................................................,..<,...,...,...-...-.......-...-...-..............E................0...0...0...0...1...1...1...1...1...1...2..O......................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:64624CA25F58262611C64EA982C00687
        SHA1:C96BC5D1E1125F5AA01F4828A4C19E4801CC9E7F
        SHA-256:299B6AACD0B6BC0BA1A68651C8828C936EBCEF0F9D3C3B7D464D6BFB82F6D0D1
        SHA-512:BB4EFB15267E9F8824003D6831991065C88169CEC75A86C471EEC9C68472964F3BBDFFEFC3E77399982EFBA9A7EDFC99CDA3F0A2039B3CDD4DA4B91372D69860
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................[...............~......................................6.....................................'...............................................................................;..........................................................................!...!...!...!...!...!..."..."..."....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:CF079F2F016CDFD2B2E590D83925EEC1
        SHA1:D22E4DD61ACFCADCEE5EDFEF87C795CAC2FD3CAA
        SHA-256:A839CAA9A864851E222236FA572780ACFBD4F206ABFC2F4AA8CD34CBDE250AF6
        SHA-512:66DF8DA9C0561FAEC2FAA13BF9E9FBAE475A90392F150B6FE15360496106E842459A806AB0AB63C2FBF74869B4212447CA7333AF6B01ACDAD999C81B0A650223
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................(.......Y................................................................................................................................................................................)...)...)...)...)..t............................................................................................................................................................................<..\<...<...<...<...<.._....=..3=...=...=...=..}....................?..:?...?...@...@...@...@..~@...@...@...A..D........A...A...A...A...C...C..+....................................................O..gO.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2781CD60ECB2055B103A682A9E714210
        SHA1:5FB8893D575ED54F9E23174DA6674D29FA9950A9
        SHA-256:31F028EA7DB1FF525CFCADBCFC6B2FF9D8DAB28FBB81D3B45E616805025209F0
        SHA-512:B0791A715893193FF0D7F5F604C8A758870AFC12D6E496D79F84FE65FF814434265C847EF0D8E192161FCA1D04EF588C3C2B70F5B8557C2754572CC1129FDBE8
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................U.............................................../...|...............X......................................u.........................................................................+...................................................!..!..'!...!...!...!...!...................".."..."...$...$..............................4..-4...4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:670A69DF73048A6589FADEDB2318E8CA
        SHA1:5E6F60E1E96A6E7C3D74477DD9094DDB8FEE6FA7
        SHA-256:6F6B9A7539E9D1F5D816BF9323FAA2C07CA4602B1C4A70E15603918317A5DE3A
        SHA-512:EB6535B39B4CE5B232B25D0FA1104E566D89A348ACE3DF7DDD3E97B850DD70D0803BE19692E82D30B0C11631F68023C7CFBA150BB38D94ADE693E7B045BB5F28
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................0...=...=...=...=...........6...=...=...1...............=...=...=...=...=...=...=...........................................................................................;..............................................................d..............................................r............................................................................................0...0...0...0...0...0...1...1..81...1...1...1...2.......2..R2...2...2...4...4...4...4...4...4...5...5...5.....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:AC96B04B17F1074D19D0D46EF40837A1
        SHA1:0A8270DB7D121CC498A2A490E267BCBC16C3DC8F
        SHA-256:BF500031C9BEF27DDF045826F57F917126F7A4F9CA8CA3F6AB3F5B5CA66B8E62
        SHA-512:CF09957F4D0EFA20630183A2CA3AD53EBE8218159E23B28CF99EBA77EBE0DFFD405C6C50CE9047125EB5A42CA0FB91C77D071DC991357CDDB09C58220CA7321D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................8...........................................................................|.......m............y..........................................................................................................................................................................J........!...!...!...............!..."..."..."..."..."..l............................................4...4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D6758F4D1F85D5E63F47E6E75CB31EF5
        SHA1:9F8127A183A76EDC12D633DCD79CC4FEFF6E1C6B
        SHA-256:87719A57DFDAED9EAE8A473080E2E4544ECF9D6F90BFF94FBEE19A311CAF7C69
        SHA-512:174929E357D9B7897F21C446C6AAB63A690BCEC3ACDD2136B5E0022BEC59BFAF4D61ACBC9003BABB0B3364F8C76B30EEB6BE15488AA90EC33395D12D2590D9CF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%........................................................................................................................................................................................................................................................................................................................................................................................................................................B................................................i......................................Q...............................A...................................................[....................0...0...0...0..w....0..C0...0...1...1...1...1..+1...1...1...1...2...2...2...2...2...2...2...2.......4...4...4...4...4...................................................D...D...D...D...D...D...D.. D...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2AFBF00CC69EE58E49BFF202B852462C
        SHA1:843A14E65DDB029C6AC5FA546286A30351B5B9CF
        SHA-256:E7EAA0D5559E6D5225E624286115501C802A8F2A1AC84DB2043D6870D4D4AF6C
        SHA-512:B611C605F2A0F2094BCFD6294E7B3C1004384BBE6E68E07EEFAB58A4840E9AD12D9A271A89A7FCFD4FD876A37CE2624C63633A7B63033535C0B7C185A23B9E90
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................=...=...=...8...............v...............7...=...=...=...........,...=...=...=...=...=...=...;...............................+...\...\...\...-...............................................................,.......6.................................x..............................................`.................................................................................w...............~....0..Q0...0...0..~....0..`0...0...1...1.......1../1...1...1...1...2...2...2...2...2...2...2...2.. ........4..+4...4...4...4...4...........................................D...D...D...D...D.......D..gD...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:62041C9330E43A8551C92E5E3DBEC3F6
        SHA1:76D8623244E20CCAE431FC5874721564884810EA
        SHA-256:5136F90C0987B5E520C116C7670A4DA027BC58FB6F7BFFA3B21EE764731FBAAF
        SHA-512:3E9AD4C048DD70C1A0ED5DB5FA0E01C39A37756798D6992B2B2A9B9B9A54633B5BBD0FE68A9717D4A274FAE91B4E1A87E369AEE2622229DC64F28ECD713690AF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................'...........................\.......+...............................................:...................4..........................r............n..................................................................................................c.............................f........!...!......!...!...!...!..`...."..N"..."..."..."..."...................................4...4...4...4...4..j....5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A8F0DD7258283173F6E3BB41AF9E1436
        SHA1:95A9DA36ACAF9D1B855D5A41BB6243686C9239A6
        SHA-256:EB0F7E9B75617CEB307010C7D0D8C5B0C9412A75944F570581660E7392DB468F
        SHA-512:9F4EC405AF409A32A639972EC95E415E563D6BD9B62CA27D0D0E5E7BBE5D6E6438C17B36C498BAEBF52A2DAABB5E5406AD4649035A43BB824078260428A35899
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................I.........................................................(.....................................................................t...T.............................f..................................f...........................................y...........S................!...........!...!...!...!...!..."..."..."..."..."..."..."..."...................4...4...4...4...4...4...............5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F94B8F10DB5769BCDA18DE949991D529
        SHA1:A72D14B418796B26F74DBB421D73A5F3C6D6D505
        SHA-256:6205FFAAEBFD5E4E958F896B442A1928C0652B9610A546BFEE0FA4AA2A3B1522
        SHA-512:2578BD1E5528F8BBF3444EDF7692AAD66D9188358B083D0A380DF91C2EDAAD925413F5749182C260660FD9EAA0F2BDB470649ADF9BC4E05754746B41E7F35A9B
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................>...................................................n............................................................................'...............................d...............................................9...................................................?.......................................!..!...!...!...!..z........!..."..."..."..."..."..............................4...4...4...4...4..y..............
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:DFAC47BA2F4DBB34DD0C926DA1372A9E
        SHA1:AF58FE72BD0DB0C3DED9E554CF5615EC623CD0DC
        SHA-256:1C66A32494EBCA2A32CD7F7EEB5DBC53412FA38C1B50EA8873BE73E9FFE0E118
        SHA-512:A1F0C6D777F3324B518E78AB90A96203CC577CFDF5D8DAEBAE1FCFEF848FCD12E5F2FF436C290AEA431F9624ABAB71F8AB67590DE796ED939B3A87BDBFD6A6B9
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................}...............v...............................................................z...).......................................#...........................................................b...........................................................................................!..!...............!..."..."..."..."..x........................................................4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:0DD5C59F3F04980F08DCCE4D543F3424
        SHA1:3C3AC213CA57B007757DD2899C0998E89F55B9F1
        SHA-256:5ED3D3CEBCFBF740C54081317647F4856702B347D316DCDD2AEA6B8B51627582
        SHA-512:3D62D2D9B81A8FE200937F53F8859FD65D70B353F75B8F3430EFF9D92F666633CC5596D22B57541EAD11A2726247961A10627061BBE890947CD1E0F955FAD541
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................C...\...\...q...9.......................................f...|...{...Z...................S...|...|...u...........H...y............].................................................................................................................................T....................!...!...!..!..!...!...!..."..."..."..."...".."...............................................4..,4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:94F14785ED460021F1D30A38B7B54EC0
        SHA1:B2E361B2AA0A8632B76786E031E1152847F9828D
        SHA-256:7D99FAF7702AAFE01B9089765BF774455B1A951397446F3AE07C01393C9A84AC
        SHA-512:DD5A7CE61EFC466EEB31A7CEFD58ED938239FAE4904CC61F9B8D1BA5500B1D24DE858F2C2DB894D3A8BC7BE0EE1A712261CE2CF92F1FB8E65226077A6ACB177F
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................}...............m............................k.............................................................}............m...........................K...............................i...............................................].....................................4................!..+!..i!...!...!...!..............."..."..."..."..."..]............................4...4...4...4...4...4.......5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6AACAE0CAA8625FC7B9F2A567CF14B15
        SHA1:78A22A5091558882AD57B3C3EECC646DAA874627
        SHA-256:88EFE2FFEF998D5B220891D7377EA4B8B71E8E2A766E61C14112BBED0110506D
        SHA-512:4F117C77D96BC641A20F035B9886B4F0416AFDB8B05C38C570502B222587518C387F896060E9AC3193CDD82D3DD880FE969983969B248FBBADCCA5308AD90936
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................=...=...=...+...................=...=...=...$.......<...=...=...Z...........................................=...=...=...!...........5...b...............=...=...=...4.......................X.....................................................................o...................................5..................................a...................................................................>........0...0...0...0...0.......1..u1...1...1...1.......................................2...2...4...4...4..!....4...4...4...4..*....5...5...5...5...5..l....................D...D...D...D...D..}........E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 8 bits/pixel, 32x32, 8 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:91B78F90A9E6FF976257D4419D02C401
        SHA1:1ED34CDB3A998E05C8A4985A2AA450F294CCCE04
        SHA-256:BC8A7FF536A79F594A3B0539BE6A7DAB575780377C62FA67954EF1AF8BDF813E
        SHA-512:2614165EFB1C842AD35F476C1081275FD15B73E4F104DFF5FFA8FB73AD43F6E314EC691D7A8C60D07662A1B59FA3D050DB0903436EE774B36DF8257F441B2396
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@................................................|~......................................................................................................................||..................cc.`II..ii..........}}.N>>.........tt.....oZZ.|ee.=22.;11.............................................^]].................................................t.843.............qfb..................................................................]..............BA@...h....................P..Q...^...v..m......h...h...x..p........q.......................................c...t.....).!.!.%.......,.1.B.S.k.]..lmm.....6...a...............:...........................................}}}.vvv.sss.nnn.bbb.WWW.PPP.KKK.:::.444.///.....---...................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:922C3CDAFBAF6F6E2A1FC44BD1940BBC
        SHA1:3FAED4A89FD6C1FEB41C06159EB8D2A26B7C710F
        SHA-256:647C9B30B2F5AA213DCE9CEE67D4B7F489EA1C60C945FC6059DBC454F22C79B8
        SHA-512:0AAD5F87FFEA39AA5E6612091E858F21B884037CF2A880DECE629E6133B09DF6142BA7479CB5A2BAC1328651041F259E73A4CB41297BEA557905357F31CDB90D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................!...=...=...!.......................=...6...............................)...=...=..."...........................................................................................................................n...............................-...................>...................*.................................................k................................................................0...............0..[0...0...1...1...1...............1..;2...2...2...2...2..(2..G2...4...4...4...4...........4...5...5...5...5..S................................................D..(D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:AA64F6AB977725E4C4F9D23AB5CB6081
        SHA1:570BF2E43081C14C7E785DD1E9832E705A47C4D3
        SHA-256:20DA3C722B933B4FC685CE106681E06E77557EB843C1DA99EB38897F5E50F3FA
        SHA-512:E3A14BF7D84BD73EBAA00A70BD3BE6071E48BC2DEE0F381FC78408D3A08E74257DB37F77700CFB9EA25DEE4B778928E2FF9C5329795A4CB9C14000F11F4C62E3
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................6...............................X............V.......................`............s..................................M...............................................................................:...........!................... .......................................!...!...!...!...!...!..."..."..."..."..."...........................................................4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:FFC452FA86A72D94B6095DE2C858652C
        SHA1:D03224D66BE864CB536E164FD24ECD677722C226
        SHA-256:05F2A5052DA712F878960656F8857D647364AADF36E35AA3A0F57B4D78E6717D
        SHA-512:B94369AC700F9A79AD5ABF560389DB1E0314CBC91C3E97E04C1C6270F7FEABD5638BA3E47310CF42D89147870E677AE86E8582FCE21D784917DA714B37E2FFC2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................!...=...=...!.......................6...=...=...=...=...=...=...)..............................................."...=...=.......................................................................................n...............O..........................................#...............................................................................................................................0...............0...0...0...1...1...1...1...1...1...2...2...2...2..L....2...2...4...4...4...4...4...4...5...5...5..2............................................................D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A688C5C783ACDFFF134F001F627CADEB
        SHA1:262C372DEEECF82F111C35E8C53F47ABCAFE73EC
        SHA-256:C3F400EC426D9853E16A6DC9FBD1770F06A7FF8D1FE4D4F8C0B9E523AF4E6CDA
        SHA-512:C8B4C74AF92BFAFB640598F65F567A9E2E4098F1E77FCC23F4F95D1911252B76ABF9CCA73F6524D8A26BB67203FE31455184D3E340DF424F0A50F1692A0E472B
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................1...=...0...........................................F...\...Z...8..................................................."...=...=...............................................................b............................................................................................................................................................................................................0..B....................0...1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4...4...4...5...5...5..2........................................................D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:43AD8858A10ADC5BA2C6ECECB99CB224
        SHA1:677F649167E4A9FCD9A92C830C06B7323C468F2C
        SHA-256:EC5E191ABA2CB2A3450E93E4CADAA018FD5BD000B84C5E7D0460DBA6C328717C
        SHA-512:623970FB76B9CE6C446569A99A82057B8D7B70FAB3412914A19349E371D1F801FB8053FF3C895C91576DA359FB9AB8E010B4ADE5728A408AF213F57AC9380CD3
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................x.......................................................................................................................]........................................................!...!...!...!...".............................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 24 bits/pixel, 32x32, 24 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:54099DD5003ACCBCA386467EA200A4EB
        SHA1:882294D9A353828CA1C8C0B7395E0C066B2FB814
        SHA-256:00538C07106E22C94C87DF62294D017722E8EE9AC8C0FD37E0ACD76DB5497D53
        SHA-512:06BEC0492B0A3662585BE7D3C867B5499CC66A28D58F0548D2F6A3CC57909C9279A9C99EF2FD8A631827F070763AE7A096D66654034393C0572E7CA4E07518C6
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@............................................................................................................................z(..`..\..\..\..\..\..\..\..\..{..............................................\..............................\..............................................\..............................\..............................................\..............................\..............................................\................................\..............................................\...................U.D......E.D......9.B......\.............................................].....................ip..??...tco./)....85.;H.~....................................................................................................................O..(... ...@.................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5120EB11C8F746C42893C1B8CCF5C87D
        SHA1:2F265740BB7C91A438FFDF03062EE88DCD654448
        SHA-256:6E3C46392499E2A59879970AE19D67D8DB2F525A692BE55FA4BF22435615B79A
        SHA-512:8EC1B2B8197F53CCB9F33AEB20EEEE8C650FC8F45874A3B8A49F034BA745551170C23A2C91EB10073177533D582A6D871A87E4EEA050C148E84B20EF9356E9CF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................d..................y...P...............................S...............~...\...!...................\...\...\...\...\...\...\...\...s...u...........................................*.................................................................................................,........!...!...!...!...!...!..."..."..."..."..."..k....................................4...4...4...4...4...4...5...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B52C5125BF04619F9DCBD780B90A9C55
        SHA1:3D1A987C50F2F29FFCA31D02F70A2D78AEB664CC
        SHA-256:7B2E5F7EA69840F12B024A6E48A2B373DAEBCE510044F67227D14A1A2AB40549
        SHA-512:83D83A73623F3CF18104FEAF15CA6A63BC67CFC5BF4614C6AD8BBC915FF4039DC1C21F20DC66438A6495FF756886834DF8CDC5D303639E076B6FEE07AD9B3F10
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................~......................8...............(..............................1...........................!...!..?!..!...!...!...!..%........".."..."..."..."..*................................4...4...4...4...4.......5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:C5CDE25EF247A55651DD4B49C4972BF7
        SHA1:8BF47A2A8ADE7523B261998FC62C71394B460549
        SHA-256:7802155896F5A5D00E7F178AC9E940F9B28130AFE7C90B9DE04DFDD32B057495
        SHA-512:CB52C517BFEA943E3C3ACC9BA16EA57C5A529A589F4C57ED0E8A6429B932F5C6DAC428BF80750B23BB88B947AAE82AF22D51BFDEE06FBD084B0134B47152A60D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................#............................M................#............................M.......................................4...............................................................+...........6.......................................+...........6....................!..!...!...!...!...!..."..."..."..."..."..............................................4..x4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5E6FF87451930BAF97ED6D3AA2DC9EF9
        SHA1:EEEEBDC5EDA00B507753033865D3A0EC1B6285E3
        SHA-256:D2EE6925A9D77D817F56121E318541AF2BE913EE1674F30C1BFD26BF85597995
        SHA-512:5EC50D0A2DF88881AAA2886581C8C7BAACB24D53D6D34A5BC48D4348A5BC4C2D303E122A4DA4BD0ACB8C43735A2BF052F5B743DB7CDA7296F124F54FF7CA8E24
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[...\...\...V.......................)...\...\...\...\...\...\...o...|...u...........#...\...\...\...............................................................................................................i...................N.......................................Z.......).............................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2ACF35F67D35A0A80D73A69212EE82E1
        SHA1:A9D0EA89527CB0C561B58ACF2FAB72C49A545ACC
        SHA-256:B74924B6C7ACBF127FDC8A0B7749EE4E05F45719B9E40BCEF7BDBB26BAC8E3AB
        SHA-512:DC0E1CBE10ECF8E2FC06BC6EAFAC1A1A7F32029795A337E82DDB6B9B26FBC6A817F5AB6EAD833B3A57383664024D5EC01A693298E42418303A9520D3968ABFF6
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................... ...................................G........................................................................................................................................................................................!...!.............................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:FAA695299089FE6EAF4F174DDE60D46C
        SHA1:3803E46BDC917A2F145251F87760E403509D399E
        SHA-256:B6F5FFF3CF866CF5D3F091A16F2D05E2BCE06E7541CA1996EAE2C59453607D8A
        SHA-512:DF119FB67DA0FFBCC7855CED6879461E240CE1CFCA608B780ABAAF0E8CABFB9957CD2D968707E4C197FA312FD762B231ACD19AE348857250402C1D99FED34474
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%......................................................................................................................................................................................................................................................................................................................................................................................................................................................................... .......................................G......................R.......P..........................................................................................................................................................................................$........!...!...!.........................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:9B3EFA246E7355E0C98CB2968F269514
        SHA1:E2E0F094EC372C374674FFED93093EFD61D6FC59
        SHA-256:6DCC9CED34C838AB7BB264B8D49FDA268ABE0F646E2F30F34E1559D28ED5974C
        SHA-512:901B8864C4EDF89C713B4CE5AD70FBE4F5C1CAE553AA71AB4715E3AC7F5C2E4AD5B9F0E01C14324E0002E1A227BA8E9EE8DC0256A321DB7D1DD0F28E06EB5E9C
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................-...=...<...........................&...g...|...u...N...............................................;...o...|...m...A...............................................>.......................................Z.................................................&...........................#...........................................................................................0...0...0...0...0...............1...1...1...1...1...1...1...2...2...2...2..t2...............4...4...4...4...4...4...4...4...5...5...5...5..F................................D...D...D...D...D...D...D...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.663216278888936
        Encrypted:false
        SSDEEP:
        MD5:2AFBF00CC69EE58E49BFF202B852462C
        SHA1:843A14E65DDB029C6AC5FA546286A30351B5B9CF
        SHA-256:E7EAA0D5559E6D5225E624286115501C802A8F2A1AC84DB2043D6870D4D4AF6C
        SHA-512:B611C605F2A0F2094BCFD6294E7B3C1004384BBE6E68E07EEFAB58A4840E9AD12D9A271A89A7FCFD4FD876A37CE2624C63633A7B63033535C0B7C185A23B9E90
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................=...=...=...8...............v...............7...=...=...=...........,...=...=...=...=...=...=...;...............................+...\...\...\...-...............................................................,.......6.................................x..............................................`.................................................................................w...............~....0..Q0...0...0..~....0..`0...0...1...1.......1../1...1...1...1...2...2...2...2...2...2...2...2.. ........4..+4...4...4...4...4...........................................D...D...D...D...D.......D..gD...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 8 bits/pixel, 32x32, 8 bits/pixel
        Category:dropped
        Size (bytes):9062
        Entropy (8bit):4.5297100937915316
        Encrypted:false
        SSDEEP:
        MD5:B7EDA7668A75AA575AF5167C96D27C4B
        SHA1:5C912238093CD4DAA7D19B09D48C4DDE5DF94FF7
        SHA-256:8D0C2EECB63A6105CC812FD40592C6972788384B5398119AA2C9686AD89562F7
        SHA-512:E09DFA6C02D29F2D8B93E4ED6FA69E36F82700976E10B707A2AD354F2AC6B5ADD14B9758CE495AE78F1C77B722E3A73FF3699FE03AD0DD62C9F4FF76D181DAE6
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@.......................|WR......Q3..O1...b.sP?..Q2..Q2..Y9..^G.....`E.....cE..bE.........o7..f@..gD..eD...........b...c...c...d...c...d...d...s ..x(..>..zZ........g......x..$..&..*..+..+..,..-..-../..0..4..6...I............................................................................................~~~.}}}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.398005619343916
        Encrypted:false
        SSDEEP:
        MD5:DFAC47BA2F4DBB34DD0C926DA1372A9E
        SHA1:AF58FE72BD0DB0C3DED9E554CF5615EC623CD0DC
        SHA-256:1C66A32494EBCA2A32CD7F7EEB5DBC53412FA38C1B50EA8873BE73E9FFE0E118
        SHA-512:A1F0C6D777F3324B518E78AB90A96203CC577CFDF5D8DAEBAE1FCFEF848FCD12E5F2FF436C290AEA431F9624ABAB71F8AB67590DE796ED939B3A87BDBFD6A6B9
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................}...............v...............................................................z...).......................................#...........................................................b...........................................................................................!..!...............!..."..."..."..."..x........................................................4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.333573698613099
        Encrypted:false
        SSDEEP:
        MD5:94AB32A58C76ACEF9F75C2BB4131CF0E
        SHA1:535F39D53A47DBE697573C01E07D9668FECF48A7
        SHA-256:E230A755D407B93194D858B7AAEFEDF12F53C105369EDC820EA5BDFBC326FD41
        SHA-512:92661F271BDEEFE4A118EC06BA676A8577B96DC4985BA2EE06A38BD1D524A657CED89466819054C468FE7EE6DBA54D2C08BE232487F85323B68BAD97AD30F472
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&...........'...............................................^...................................................................................V......................................................................T................!..y!...!..."...".........................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 8 bits/pixel, 32x32, 8 bits/pixel
        Category:dropped
        Size (bytes):9062
        Entropy (8bit):6.0759708733378375
        Encrypted:false
        SSDEEP:
        MD5:91B78F90A9E6FF976257D4419D02C401
        SHA1:1ED34CDB3A998E05C8A4985A2AA450F294CCCE04
        SHA-256:BC8A7FF536A79F594A3B0539BE6A7DAB575780377C62FA67954EF1AF8BDF813E
        SHA-512:2614165EFB1C842AD35F476C1081275FD15B73E4F104DFF5FFA8FB73AD43F6E314EC691D7A8C60D07662A1B59FA3D050DB0903436EE774B36DF8257F441B2396
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@................................................|~......................................................................................................................||..................cc.`II..ii..........}}.N>>.........tt.....oZZ.|ee.=22.;11.............................................^]].................................................t.843.............qfb..................................................................]..............BA@...h....................P..Q...^...v..m......h...h...x..p........q.......................................c...t.....).!.!.%.......,.1.B.S.k.]..lmm.....6...a...............:...........................................}}}.vvv.sss.nnn.bbb.WWW.PPP.KKK.:::.444.///.....---...................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.577842672186702
        Encrypted:false
        SSDEEP:
        MD5:23FF01E18C148F67B30371B4C179B31E
        SHA1:A0D268B00FC543469A11E5CD9FEC4332BEC692D9
        SHA-256:3847C1FC694A7024F763445519AECB79D71F39F7C47AB5AEAD72D056A84A4B15
        SHA-512:6DCB73C7AC37BD36B7E801301E8521F68D4B9D010BAFEA1F766857B4AF1FCEE60AA45CC2869103BC269EDCE23AD8A3A5F1320CED0F1B68759A256DC6BC9E6F2D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................:......................................-...................M..............................................i......................................Q...............................................................................................................................................!..M!..+!...!...!...!...!...!..."..."..."..."..."..".......................................4...4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.421133191221316
        Encrypted:false
        SSDEEP:
        MD5:670A69DF73048A6589FADEDB2318E8CA
        SHA1:5E6F60E1E96A6E7C3D74477DD9094DDB8FEE6FA7
        SHA-256:6F6B9A7539E9D1F5D816BF9323FAA2C07CA4602B1C4A70E15603918317A5DE3A
        SHA-512:EB6535B39B4CE5B232B25D0FA1104E566D89A348ACE3DF7DDD3E97B850DD70D0803BE19692E82D30B0C11631F68023C7CFBA150BB38D94ADE693E7B045BB5F28
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................0...=...=...=...=...........6...=...=...1...............=...=...=...=...=...=...=...........................................................................................;..............................................................d..............................................r............................................................................................0...0...0...0...0...0...1...1..81...1...1...1...2.......2..R2...2...2...4...4...4...4...4...4...5...5...5.....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.455377657334597
        Encrypted:false
        SSDEEP:
        MD5:F4A5CBF4D386EC4C8E3CA912EA2D228C
        SHA1:A0494F203A0BAEEF84B36A301EE67C7417940682
        SHA-256:B818660588A822DD48E16A7E3D6B39FC7706DBA5C79476A28EC48D49933A6802
        SHA-512:36BFB01DA63322D6DA864AD9EB511890AFDE45E2021F45A2383785BA739E9E7F43AF35073BDB4C07FCE4AFD88F6971C4D4D74B49CEEE1F07D4488C0D6CEC3C32
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&...........2...........................................................5..............h...........................................................V......................................................................Y...................!..o................!.."..."..."..."...........................................................4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.485215440274961
        Encrypted:false
        SSDEEP:
        MD5:C5CDE25EF247A55651DD4B49C4972BF7
        SHA1:8BF47A2A8ADE7523B261998FC62C71394B460549
        SHA-256:7802155896F5A5D00E7F178AC9E940F9B28130AFE7C90B9DE04DFDD32B057495
        SHA-512:CB52C517BFEA943E3C3ACC9BA16EA57C5A529A589F4C57ED0E8A6429B932F5C6DAC428BF80750B23BB88B947AAE82AF22D51BFDEE06FBD084B0134B47152A60D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................#............................M................#............................M.......................................4...............................................................+...........6.......................................+...........6....................!..!...!...!...!...!..."..."..."..."..."..............................................4..x4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.614970648132169
        Encrypted:false
        SSDEEP:
        MD5:62041C9330E43A8551C92E5E3DBEC3F6
        SHA1:76D8623244E20CCAE431FC5874721564884810EA
        SHA-256:5136F90C0987B5E520C116C7670A4DA027BC58FB6F7BFFA3B21EE764731FBAAF
        SHA-512:3E9AD4C048DD70C1A0ED5DB5FA0E01C39A37756798D6992B2B2A9B9B9A54633B5BBD0FE68A9717D4A274FAE91B4E1A87E369AEE2622229DC64F28ECD713690AF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................'...........................\.......+...............................................:...................4..........................r............n..................................................................................................c.............................f........!...!......!...!...!...!..`...."..N"..."..."..."..."...................................4...4...4...4...4..j....5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.334738426107614
        Encrypted:false
        SSDEEP:
        MD5:F9152E1DCCBD200B0544CC0DD5F591FF
        SHA1:F386C344078F3F144C7778165F1446D4BEF11F94
        SHA-256:9E1EB684DA5C5BB3C2988C5C4B35A18587206889270B14B27C7AFB9972741D0F
        SHA-512:90909A301354E5B41CEB0915E60CF35EFE83C5685757544C26DE5309868EF44C793D1B180E1347539D8FDF8F197585DA3146D3259006AF292C26ECF46D8850A0
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................\..................................b...................................o......................[........................................................................................,..<,...,...,...-...-.......-...-...-..............E................0...0...0...0...1...1...1...1...1...1...2..O......................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.536238764591297
        Encrypted:false
        SSDEEP:
        MD5:B52C5125BF04619F9DCBD780B90A9C55
        SHA1:3D1A987C50F2F29FFCA31D02F70A2D78AEB664CC
        SHA-256:7B2E5F7EA69840F12B024A6E48A2B373DAEBCE510044F67227D14A1A2AB40549
        SHA-512:83D83A73623F3CF18104FEAF15CA6A63BC67CFC5BF4614C6AD8BBC915FF4039DC1C21F20DC66438A6495FF756886834DF8CDC5D303639E076B6FEE07AD9B3F10
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................~......................8...............(..............................1...........................!...!..?!..!...!...!...!..%........".."..."..."..."..*................................4...4...4...4...4.......5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.544582199815174
        Encrypted:false
        SSDEEP:
        MD5:2781CD60ECB2055B103A682A9E714210
        SHA1:5FB8893D575ED54F9E23174DA6674D29FA9950A9
        SHA-256:31F028EA7DB1FF525CFCADBCFC6B2FF9D8DAB28FBB81D3B45E616805025209F0
        SHA-512:B0791A715893193FF0D7F5F604C8A758870AFC12D6E496D79F84FE65FF814434265C847EF0D8E192161FCA1D04EF588C3C2B70F5B8557C2754572CC1129FDBE8
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................U.............................................../...|...............X......................................u.........................................................................+...................................................!..!..'!...!...!...!...!...................".."..."...$...$..............................4..-4...4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.313690872107128
        Encrypted:false
        SSDEEP:
        MD5:875F2E1576EB44C48D2C00E94EE87968
        SHA1:729990196979C8B3053E98917EA9F800CE0F379C
        SHA-256:EBA6D70EEDD9CC197B8A9739419E5892F61DAFC3A17E0526BEDEF02A700AD837
        SHA-512:6FE98DF68B6435D4290B9A93FB46E07C1BEBE7D1DDBF193D7C74225498110CB68B066D405C9FAB4AFE34CF5A9DF160EF9B76E14D20EB23D1F3C5BC433E87B2A2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................O...\...S...0...................................................)...=...=.....................................................................................................................................................h...........................................y............................................................................................................0...0...0...0...0...0...1...1...1...1.......2...2...2...2...4...4...4...4...4...5...5.....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.38081563272643
        Encrypted:false
        SSDEEP:
        MD5:FAA695299089FE6EAF4F174DDE60D46C
        SHA1:3803E46BDC917A2F145251F87760E403509D399E
        SHA-256:B6F5FFF3CF866CF5D3F091A16F2D05E2BCE06E7541CA1996EAE2C59453607D8A
        SHA-512:DF119FB67DA0FFBCC7855CED6879461E240CE1CFCA608B780ABAAF0E8CABFB9957CD2D968707E4C197FA312FD762B231ACD19AE348857250402C1D99FED34474
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%......................................................................................................................................................................................................................................................................................................................................................................................................................................................................... .......................................G......................R.......P..........................................................................................................................................................................................$........!...!...!.........................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.595279901844826
        Encrypted:false
        SSDEEP:
        MD5:90F66425CFF7319A8A222FC0D40A2862
        SHA1:C9E817F24AD6E00422FCE32055A82DE2327F7EC5
        SHA-256:899DDF2939769991E6F0FC99D19FF1CD02441EBC71407FEE06D6463DC3D3F388
        SHA-512:1F8ED23AB41215AACC809FCC7DD2A3B37CAECE1CFEE455966A6A9068AF25EAA96F1168E4E6CA56D136AB6E2ADD99287EDBD43E2A236A3C6C0E7F83D52E949610
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................$...S...\...O...,...................................................-...=...<...........=...=...#...............................<...=................................................... .........................................I...>.......................................Z..................................................!...!..........................................................0...0...0...0...0...0...0...1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4..8............5...5...5...5...5...5.......................................D..vD...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.511596063915327
        Encrypted:false
        SSDEEP:
        MD5:B8024CA7B237603BFEAA066BFF09DAF3
        SHA1:2E67FC1AE88521DEEDB474A24EB560A1D9E1D308
        SHA-256:069CB3C5DA6973D9DAE8666923E58E40E9CF7FCE714F88D977D5FD3C06BFA304
        SHA-512:B26728E27387E4DCBD25D4508A929C153239B24E0CA3E07FFEF4C3471ECFDF8DB49C273840F5A1E5399007A12399FE2B0065FFE6041BD88D731EE0D05DCF4B7D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&.. .... ......*.. ..........N;..00...........G..00...........d.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................$...=...8...............................................n............................................................................2...........9...................................U...........................^.......................................................?................0...0...0...0...1.......1...1...1...1...1...........2..T2...2...2...2...2...........4..Z4...4...4...4...4...4...5...5...5...5..!............................D..9D...D...D...D...D...D...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.670943735623652
        Encrypted:false
        SSDEEP:
        MD5:6AACAE0CAA8625FC7B9F2A567CF14B15
        SHA1:78A22A5091558882AD57B3C3EECC646DAA874627
        SHA-256:88EFE2FFEF998D5B220891D7377EA4B8B71E8E2A766E61C14112BBED0110506D
        SHA-512:4F117C77D96BC641A20F035B9886B4F0416AFDB8B05C38C570502B222587518C387F896060E9AC3193CDD82D3DD880FE969983969B248FBBADCCA5308AD90936
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................=...=...=...+...................=...=...=...$.......<...=...=...Z...........................................=...=...=...!...........5...b...............=...=...=...4.......................X.....................................................................o...................................5..................................a...................................................................>........0...0...0...0...0.......1..u1...1...1...1.......................................2...2...4...4...4..!....4...4...4...4..*....5...5...5...5...5..l....................D...D...D...D...D..}........E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.576375380495186
        Encrypted:false
        SSDEEP:
        MD5:94F14785ED460021F1D30A38B7B54EC0
        SHA1:B2E361B2AA0A8632B76786E031E1152847F9828D
        SHA-256:7D99FAF7702AAFE01B9089765BF774455B1A951397446F3AE07C01393C9A84AC
        SHA-512:DD5A7CE61EFC466EEB31A7CEFD58ED938239FAE4904CC61F9B8D1BA5500B1D24DE858F2C2DB894D3A8BC7BE0EE1A712261CE2CF92F1FB8E65226077A6ACB177F
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................}...............m............................k.............................................................}............m...........................K...............................i...............................................].....................................4................!..+!..i!...!...!...!..............."..."..."..."..."..]............................4...4...4...4...4...4.......5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.460255935249949
        Encrypted:false
        SSDEEP:
        MD5:A688C5C783ACDFFF134F001F627CADEB
        SHA1:262C372DEEECF82F111C35E8C53F47ABCAFE73EC
        SHA-256:C3F400EC426D9853E16A6DC9FBD1770F06A7FF8D1FE4D4F8C0B9E523AF4E6CDA
        SHA-512:C8B4C74AF92BFAFB640598F65F567A9E2E4098F1E77FCC23F4F95D1911252B76ABF9CCA73F6524D8A26BB67203FE31455184D3E340DF424F0A50F1692A0E472B
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................1...=...0...........................................F...\...Z...8..................................................."...=...=...............................................................b............................................................................................................................................................................................................0..B....................0...1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4...4...4...5...5...5..2........................................................D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.537011997728003
        Encrypted:false
        SSDEEP:
        MD5:571B611D9373A6E37248153539065A07
        SHA1:46A9E7694C85484B26DBFCB83551E74A6E2EAA54
        SHA-256:A0A49FBB245CB182E6749002D5B0DF34D0FA218F27C760190D9AF6E0ABA32E11
        SHA-512:B5DD42C4C736D151373888E04A187C81780A0D557853705B353877545630F77917BD99040598F5C965600E902CA9000C7EF940B37E3F4D1F8516C0200119FAA7
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................<...(...................................................&...<............................... ...a...|...w...O...............................................-...............................................@.......................................................D..........................................................................................................0...0...0...0...0...0...0...0...1...1...1...1..1............2..02...2...2...2...2...............4...4...4...4...4...4...4...5...5...5...5..N................................D..lD...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.452299561711739
        Encrypted:false
        SSDEEP:
        MD5:5946EBE9F9F5AAA93EE54B46C5B07D6C
        SHA1:5F3B6B367B240EF7015D91A1BF3D05752B043B0B
        SHA-256:967473BC2BDF07BCEE4275D87CEDE082A3CDEF45418609B81563AECF6CC07B5F
        SHA-512:67D5B0BE316097527B85BB1A61C5E11C62454CF5C1B31550C77B25A7D611D281FC339E39E7C6885D11BE0585FA4D2224F4E134D0257623B0AE0C2CF1C7EEFEE6
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................i......................................Q...................................................x...................................................................................................+................0...0...0...0...0...0...0...1.......1...1...1...1...2...2...2...2...2...2...2...4...4...4...4...4...4...5...5...5...5...5..D....................................................D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.547335285034606
        Encrypted:false
        SSDEEP:
        MD5:5120EB11C8F746C42893C1B8CCF5C87D
        SHA1:2F265740BB7C91A438FFDF03062EE88DCD654448
        SHA-256:6E3C46392499E2A59879970AE19D67D8DB2F525A692BE55FA4BF22435615B79A
        SHA-512:8EC1B2B8197F53CCB9F33AEB20EEEE8C650FC8F45874A3B8A49F034BA745551170C23A2C91EB10073177533D582A6D871A87E4EEA050C148E84B20EF9356E9CF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................d..................y...P...............................S...............~...\...!...................\...\...\...\...\...\...\...\...s...u...........................................*.................................................................................................,........!...!...!...!...!...!..."..."..."..."..."..k....................................4...4...4...4...4...4...5...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.567560885382007
        Encrypted:false
        SSDEEP:
        MD5:40DFAB257A5118EC91133215111D322D
        SHA1:50C959A750B50308F8324AA1CD001E9625A48864
        SHA-256:2DA10104A875361B0E7E7A0D5B8017CD386D791A7D10C0DF14344B3DFC5C46AA
        SHA-512:5F864DB9408317EE5CCE4E1F14BD15E81935CBB9E2C8C53CD9712D8626AE76C5EAD310F6037731E6F2FAE2D0B12B78708F525AE5E0A8EB91C468DF87AC0E346A
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................z.........................Q.........................+.........................O.......6......................................E............!..!...............................................0...0...0...0...0...0...0...0...1..5........1..-1...1...1...2...2...2...2...2...2...2...4...4...4...4...4..j................5..T5...5...5...5...5...............................D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.323632159657291
        Encrypted:false
        SSDEEP:
        MD5:C13C65504AF492DA6E95C7E8E7AA5426
        SHA1:BFC3A6E1997333DA0FC6DF1D1253F18E2BD04B16
        SHA-256:5DFA9C8F9215840744DD56B1EAF9ECB107110015CB3844F8934CC812A751A698
        SHA-512:BF4336A3B5EA7A9194C9558AF6CE7F23A3AFF7017A1BCC37548C269C35261B57DE6577E8004B64E0E6AF82B24480A32E670FBCFC3065F58C19A05A0BB7B1077D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................(.......Y................................................................................................................................................................................................0..t............................................................<..F<...<...<.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.139856701681819
        Encrypted:false
        SSDEEP:
        MD5:105AE6BB92C7F5A355203C75CF483A5A
        SHA1:CA9EFA180D679D83EC266D1E1A48F3F97901595A
        SHA-256:65888D9D296D0D9DF665D4672A2411ED6EA3EF244D987B69328D04EF713FDE55
        SHA-512:359DF4B2B1EB544FEB7B0F378C2D18E68D9BF1F9F5CF032CFD20E33D7C3AC51348C8C8AC2ECD67B8FB442F1E32375B2F8A7D39B3350161B123C46FE6F43B2EE2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*.. ..........NG..........h....S..........h...^W.. .... ......\.. ..........nm..00...........v..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................U................"..."..."...$...$...$...$...%...%..d........................................................................................................................6...6...8...8...8...8...............9...;...;...;...;...<...<...<...<...=.................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.383282575971899
        Encrypted:false
        SSDEEP:
        MD5:87DBA4381032D805A33D7E481CA03832
        SHA1:5672C6C724D4252928501C370148F95B38899727
        SHA-256:A3C15B842ACF03EA7A3A57DF399E66D8558C8CB5BA09E29FB9ABE5793B543ADE
        SHA-512:8EB78A27597E335EF9F8A5D5350643223FF7B8B93D9866FC8C9C74994ED6DE9F9018BD757B7BC66D0BF26CD4A3AE25BA4D351C29A765DB1AFC9F5C8EC88905DD
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................s...................2...............N...\...\...\...\...\...\...V...,...........................l...|...|...t...".......................................................................8..................................*..............................................n....................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.308049033836208
        Encrypted:false
        SSDEEP:
        MD5:922D0DF8BA0A9F28319DBE0A5B729A5D
        SHA1:B1BCE258420B0A3485710E363A8798D118100DE4
        SHA-256:70F1C88356ED8C3CE38C528340CF1975884EA056623334D4492AAC6F2A629276
        SHA-512:73A8CF3117FBB00B5E809DD035FE994E9E61CF0C3E89072B1A7312B6FAFDB122C1E49D6CA2BAF060E27F078087BE7CA8764AC520F81166A9F5B5275DBB4F9AD5
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................q...............M.......................................................................................8...........................................................................u.......................................................C...q........!...!......................"..."..."..."...$..i..............................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.307055815037344
        Encrypted:false
        SSDEEP:
        MD5:5E6FF87451930BAF97ED6D3AA2DC9EF9
        SHA1:EEEEBDC5EDA00B507753033865D3A0EC1B6285E3
        SHA-256:D2EE6925A9D77D817F56121E318541AF2BE913EE1674F30C1BFD26BF85597995
        SHA-512:5EC50D0A2DF88881AAA2886581C8C7BAACB24D53D6D34A5BC48D4348A5BC4C2D303E122A4DA4BD0ACB8C43735A2BF052F5B743DB7CDA7296F124F54FF7CA8E24
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[...\...\...V.......................)...\...\...\...\...\...\...o...|...u...........#...\...\...\...............................................................................................................i...................N.......................................Z.......).............................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.407365366030171
        Encrypted:false
        SSDEEP:
        MD5:CF079F2F016CDFD2B2E590D83925EEC1
        SHA1:D22E4DD61ACFCADCEE5EDFEF87C795CAC2FD3CAA
        SHA-256:A839CAA9A864851E222236FA572780ACFBD4F206ABFC2F4AA8CD34CBDE250AF6
        SHA-512:66DF8DA9C0561FAEC2FAA13BF9E9FBAE475A90392F150B6FE15360496106E842459A806AB0AB63C2FBF74869B4212447CA7333AF6B01ACDAD999C81B0A650223
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................(.......Y................................................................................................................................................................................)...)...)...)...)..t............................................................................................................................................................................<..\<...<...<...<...<.._....=..3=...=...=...=..}....................?..:?...?...@...@...@...@..~@...@...@...A..D........A...A...A...A...C...C..+....................................................O..gO.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.372288111374727
        Encrypted:false
        SSDEEP:
        MD5:64624CA25F58262611C64EA982C00687
        SHA1:C96BC5D1E1125F5AA01F4828A4C19E4801CC9E7F
        SHA-256:299B6AACD0B6BC0BA1A68651C8828C936EBCEF0F9D3C3B7D464D6BFB82F6D0D1
        SHA-512:BB4EFB15267E9F8824003D6831991065C88169CEC75A86C471EEC9C68472964F3BBDFFEFC3E77399982EFBA9A7EDFC99CDA3F0A2039B3CDD4DA4B91372D69860
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................[...............~......................................6.....................................'...............................................................................;..........................................................................!...!...!...!...!...!..."..."..."....................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.496032578296134
        Encrypted:false
        SSDEEP:
        MD5:922C3CDAFBAF6F6E2A1FC44BD1940BBC
        SHA1:3FAED4A89FD6C1FEB41C06159EB8D2A26B7C710F
        SHA-256:647C9B30B2F5AA213DCE9CEE67D4B7F489EA1C60C945FC6059DBC454F22C79B8
        SHA-512:0AAD5F87FFEA39AA5E6612091E858F21B884037CF2A880DECE629E6133B09DF6142BA7479CB5A2BAC1328651041F259E73A4CB41297BEA557905357F31CDB90D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.....................................................................................................................................................................................................................................................!...=...=...!.......................=...6...............................)...=...=..."...........................................................................................................................n...............................-...................>...................*.................................................k................................................................0...............0..[0...0...1...1...1...............1..;2...2...2...2...2..(2..G2...4...4...4...4...........4...5...5...5...5..S................................................D..(D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 4 icons, 16x16, 24 bits/pixel, 32x32, 24 bits/pixel
        Category:dropped
        Size (bytes):9574
        Entropy (8bit):4.54227345974643
        Encrypted:false
        SSDEEP:
        MD5:54099DD5003ACCBCA386467EA200A4EB
        SHA1:882294D9A353828CA1C8C0B7395E0C066B2FB814
        SHA-256:00538C07106E22C94C87DF62294D017722E8EE9AC8C0FD37E0ACD76DB5497D53
        SHA-512:06BEC0492B0A3662585BE7D3C867B5499CC66A28D58F0548D2F6A3CC57909C9279A9C99EF2FD8A631827F070763AE7A096D66654034393C0572E7CA4E07518C6
        Malicious:false
        Reputation:unknown
        Preview:..............h...F... .................... .h...V... .... .........(....... ...........@............................................................................................................................z(..`..\..\..\..\..\..\..\..\..{..............................................\..............................\..............................................\..............................\..............................................\..............................\..............................................\................................\..............................................\...................U.D......E.D......9.B......\.............................................].....................ip..??...tco./)....85.;H.~....................................................................................................................O..(... ...@.................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.583899802657778
        Encrypted:false
        SSDEEP:
        MD5:12E7241B57B768F45990C34A6FCB59C4
        SHA1:972C1B1C2C39055DB27E9AE91A4EA116B0E3A8DA
        SHA-256:E6DA09C239FC3AFE899859D6D72CB77683C8AD612B617049A68BD4A37C2C9AAE
        SHA-512:A438380126B6574BC5D6B37D987D14209AC7C97B3B019EF9501BFCAA4604A660186E9A0BFE0F6FF5638CAFC807E8FDF4145DE1AFD26349AA56FBBFE3C9ED91AF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................)...g...|...s...J...................:...=...*...............................4...=...6...............=...=...=...=...=...=...1.................................................................................................g.....................................................................................................@............................................................0...0...0...0...0...0...0..<0...1...1...1...1..r................2...2...2...2...2.......2...4...4...4...4...4...4...4...4...5...5...5.......................................D..&D...D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.479257660502805
        Encrypted:false
        SSDEEP:
        MD5:4ECB934D889DDEA447BE7E6AB1931C62
        SHA1:007D9B1C9171C3252BEA7F3A459835629F94E2FB
        SHA-256:B6447A8F43ECB8C3B5E838EE58133E0268CB18DFBCEE520840C9293036775C8B
        SHA-512:FCD29994DED4D6490A4AF334FA0F1B038D488C5BD75D253FCAE924CD6FC4FB11697CA9D31994AAAAC4BDDBE0E3C9E6360BA2AC6FACCFFBFFD13F661515EAAEB2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................v.....................................&.........................................o...................................................!.......................................................V..........................................................................................>........................".."..."..."..."..m....................................................4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.4442395438071465
        Encrypted:false
        SSDEEP:
        MD5:0DD5C59F3F04980F08DCCE4D543F3424
        SHA1:3C3AC213CA57B007757DD2899C0998E89F55B9F1
        SHA-256:5ED3D3CEBCFBF740C54081317647F4856702B347D316DCDD2AEA6B8B51627582
        SHA-512:3D62D2D9B81A8FE200937F53F8859FD65D70B353F75B8F3430EFF9D92F666633CC5596D22B57541EAD11A2726247961A10627061BBE890947CD1E0F955FAD541
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.................................................................................................................................................................................................................................................................................................................................................................................................................................................C...\...\...q...9.......................................f...|...{...Z...................S...|...|...u...........H...y............].................................................................................................................................T....................!...!...!..!..!...!...!..."..."..."..."...".."...............................................4..,4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.523062991532171
        Encrypted:false
        SSDEEP:
        MD5:29C014B29A9191F93B9C13636BDD2C4A
        SHA1:D99C5FFC597D6758DBC81B299BDCC668F6A12A80
        SHA-256:12571FF68DC07BB9B564B07CDFA78F57A387B0EFBF7F4398A88C1D979ED29F97
        SHA-512:D8361CF52FBC26B8F5D82971A5FD24E82B02CEB3063C59849F2A55B5F5180777A8D4487299B4FD9EE6E7156CDDD57563E5BC4174BEB2F62A5F2755092157A779
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. ...........U.. ...........b..........h...Fk..........h....n.. .... ......t..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................2......................................k.....................................................7......................................Q.......................................................................................................3...........................................!..4!..!...!...!...!..}................"..S"..."..."...$...$.......................................4...4...4...4...4...5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.595851687240913
        Encrypted:false
        SSDEEP:
        MD5:D6758F4D1F85D5E63F47E6E75CB31EF5
        SHA1:9F8127A183A76EDC12D633DCD79CC4FEFF6E1C6B
        SHA-256:87719A57DFDAED9EAE8A473080E2E4544ECF9D6F90BFF94FBEE19A311CAF7C69
        SHA-512:174929E357D9B7897F21C446C6AAB63A690BCEC3ACDD2136B5E0022BEC59BFAF4D61ACBC9003BABB0B3364F8C76B30EEB6BE15488AA90EC33395D12D2590D9CF
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%........................................................................................................................................................................................................................................................................................................................................................................................................................................B................................................i......................................Q...............................A...................................................[....................0...0...0...0..w....0..C0...0...1...1...1...1..+1...1...1...1...2...2...2...2...2...2...2...2.......4...4...4...4...4...................................................D...D...D...D...D...D...D.. D...E...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.4614235990597235
        Encrypted:false
        SSDEEP:
        MD5:BAC40A94D1BDA434323F10197B36D1E1
        SHA1:8D6CE657DC5403C66E06E74FFEC9966575209574
        SHA-256:B76E895CF5A24027B9A2E78C93A2E95EBBE8D79C45810C0377A3BD95FA467317
        SHA-512:CAD644F037B8D391B91ED13CF58978CDF25EDDF18AF78883E8F7C07E9C3D7F519CD38E57214450D99760161EC7EC0F14E733DC602B984661457623E26C2821E4
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................l...|...|...t...".......;...\...\...\...............m...\...........0...\...\...\...;...........................i............f...............R.....................................................................h..................................<.......R...................................`...........................................:...........................................P................0.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.589550157586819
        Encrypted:false
        SSDEEP:
        MD5:A8F0DD7258283173F6E3BB41AF9E1436
        SHA1:95A9DA36ACAF9D1B855D5A41BB6243686C9239A6
        SHA-256:EB0F7E9B75617CEB307010C7D0D8C5B0C9412A75944F570581660E7392DB468F
        SHA-512:9F4EC405AF409A32A639972EC95E415E563D6BD9B62CA27D0D0E5E7BBE5D6E6438C17B36C498BAEBF52A2DAABB5E5406AD4649035A43BB824078260428A35899
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................I.........................................................(.....................................................................t...T.............................f..................................f...........................................y...........S................!...........!...!...!...!...!..."..."..."..."..."..."..."..."...................4...4...4...4...4...4...............5.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.567104661738473
        Encrypted:false
        SSDEEP:
        MD5:9B3EFA246E7355E0C98CB2968F269514
        SHA1:E2E0F094EC372C374674FFED93093EFD61D6FC59
        SHA-256:6DCC9CED34C838AB7BB264B8D49FDA268ABE0F646E2F30F34E1559D28ED5974C
        SHA-512:901B8864C4EDF89C713B4CE5AD70FBE4F5C1CAE553AA71AB4715E3AC7F5C2E4AD5B9F0E01C14324E0002E1A227BA8E9EE8DC0256A321DB7D1DD0F28E06EB5E9C
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................-...=...<...........................&...g...|...u...N...............................................;...o...|...m...A...............................................>.......................................Z.................................................&...........................#...........................................................................................0...0...0...0...0...............1...1...1...1...1...1...1...2...2...2...2..t2...............4...4...4...4...4...4...4...4...5...5...5...5..F................................D...D...D...D...D...D...D...E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.050305242163412
        Encrypted:false
        SSDEEP:
        MD5:5F6F8D97BEF979672565271F452829C4
        SHA1:EB7269646EDD67851889673A185C7A56CE2B1B1D
        SHA-256:232637B8A066EC8305CBB482FFAC9DC3C9436910239C9095F6521A5DE92A65E5
        SHA-512:446C6B6EED0622A1A53A15AEC76A7B3AD89C776A2A1D34C6D2BE741FF973E7C7982888FF6D1D79517146A38798820B7F5052F6B82685538B12C79ED00844B371
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. ...........U.. ...........b..........h...Fk..........h....n.. .... ......t..(...0...`..... ......%.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................6......................................E.........................................................................................................................................................................i................!..T!..."..."..."...$.............................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.143367720401177
        Encrypted:false
        SSDEEP:
        MD5:43AD8858A10ADC5BA2C6ECECB99CB224
        SHA1:677F649167E4A9FCD9A92C830C06B7323C468F2C
        SHA-256:EC5E191ABA2CB2A3450E93E4CADAA018FD5BD000B84C5E7D0460DBA6C328717C
        SHA-512:623970FB76B9CE6C446569A99A82057B8D7B70FAB3412914A19349E371D1F801FB8053FF3C895C91576DA359FB9AB8E010B4ADE5728A408AF213F57AC9380CD3
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................x.......................................................................................................................]........................................................!...!...!...!...".............................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.439423254523167
        Encrypted:false
        SSDEEP:
        MD5:32511197792DC691270F10497A96A77F
        SHA1:CAA56E82F02E918AD159615031BC71E41046154E
        SHA-256:6A4EE4C3B79D8ED51F5D530189E39133F10E40FA330C221417A9176630832E52
        SHA-512:30870D133B8DB42C55458FE4AE1B15942FE74107ED436967C0A88265380F7D7ECBF9C74139F6B2533AEDC3562983676585E38BEDD8B884E42D3B2782FC536488
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................3...=...(...............................................................................................................2...=...).............................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.417333469666287
        Encrypted:false
        SSDEEP:
        MD5:AA64F6AB977725E4C4F9D23AB5CB6081
        SHA1:570BF2E43081C14C7E785DD1E9832E705A47C4D3
        SHA-256:20DA3C722B933B4FC685CE106681E06E77557EB843C1DA99EB38897F5E50F3FA
        SHA-512:E3A14BF7D84BD73EBAA00A70BD3BE6071E48BC2DEE0F381FC78408D3A08E74257DB37F77700CFB9EA25DEE4B778928E2FF9C5329795A4CB9C14000F11F4C62E3
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................................6...............................X............V.......................`............s..................................M...............................................................................:...........!................... .......................................!...!...!...!...!...!..."..."..."..."..."...........................................................4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.491037275991864
        Encrypted:false
        SSDEEP:
        MD5:99FDC3DF50698C684AF6EE7B87671023
        SHA1:FF540435C35987122E5573E183DDEED37144C385
        SHA-256:0CEDDAF2659B8003C4103A29DF77AF428818CAF686E57FF3ADA0140E880BDD7F
        SHA-512:18B2478BFA7AF7F6CD5A156E47A07AF835498AB42EF9A57FE7E5537BC388C2EF1601D4868ADC3A33C4CD5A5EF6D1153CB9E9923FB584D8C4A94B00475F071EF9
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................9...=...$........................................................................................................................................................................... .....................................j.......................................g...:.......................................................................................................................0...0...0...0...0...0..Z0..B1...1...1...1...1...1...1...2...2...2...2...2...2...4...4...4...4...4...4...4...5...5...5.......................................................D...D...D...D...D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.539673803641596
        Encrypted:false
        SSDEEP:
        MD5:F94B8F10DB5769BCDA18DE949991D529
        SHA1:A72D14B418796B26F74DBB421D73A5F3C6D6D505
        SHA-256:6205FFAAEBFD5E4E958F896B442A1928C0652B9610A546BFEE0FA4AA2A3B1522
        SHA-512:2578BD1E5528F8BBF3444EDF7692AAD66D9188358B083D0A380DF91C2EDAAD925413F5749182C260660FD9EAA0F2BDB470649ADF9BC4E05754746B41E7F35A9B
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................>...................................................n............................................................................'...............................d...............................................9...................................................?.......................................!..!...!...!...!..z........!..."..."..."..."..."..............................4...4...4...4...4..y..............
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.509193788530208
        Encrypted:false
        SSDEEP:
        MD5:AC96B04B17F1074D19D0D46EF40837A1
        SHA1:0A8270DB7D121CC498A2A490E267BCBC16C3DC8F
        SHA-256:BF500031C9BEF27DDF045826F57F917126F7A4F9CA8CA3F6AB3F5B5CA66B8E62
        SHA-512:CF09957F4D0EFA20630183A2CA3AD53EBE8218159E23B28CF99EBA77EBE0DFFD405C6C50CE9047125EB5A42CA0FB91C77D071DC991357CDDB09C58220CA7321D
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.........................................................................................................................................................................................................................................................................................................................................................................................................................................8...........................................................................|.......m............y..........................................................................................................................................................................J........!...!...!...............!..."..."..."..."..."..l............................................4...4...4...4...4.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.054477987093805
        Encrypted:false
        SSDEEP:
        MD5:2ACF35F67D35A0A80D73A69212EE82E1
        SHA1:A9D0EA89527CB0C561B58ACF2FAB72C49A545ACC
        SHA-256:B74924B6C7ACBF127FDC8A0B7749EE4E05F45719B9E40BCEF7BDBB26BAC8E3AB
        SHA-512:DC0E1CBE10ECF8E2FC06BC6EAFAC1A1A7F32029795A337E82DDB6B9B26FBC6A817F5AB6EAD833B3A57383664024D5EC01A693298E42418303A9520D3968ABFF6
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................... ...................................G........................................................................................................................................................................................!...!.............................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 48x48, 32 bits/pixel, 16x16, 32 bits/pixel
        Category:dropped
        Size (bytes):33982
        Entropy (8bit):5.4202803491249085
        Encrypted:false
        SSDEEP:
        MD5:FFC452FA86A72D94B6095DE2C858652C
        SHA1:D03224D66BE864CB536E164FD24ECD677722C226
        SHA-256:05F2A5052DA712F878960656F8857D647364AADF36E35AA3A0F57B4D78E6717D
        SHA-512:B94369AC700F9A79AD5ABF560389DB1E0314CBC91C3E97E04C1C6270F7FEABD5638BA3E47310CF42D89147870E677AE86E8582FCE21D784917DA714B37E2FFC2
        Malicious:false
        Reputation:unknown
        Preview:......00.... ..%............ .h...>&..00...........*..00..........NG.. .... ......U.. ...........f.. ..........Fs..........h....{..........h...V...(...0...`..... ......%.............................................................................................................................................................................................................................................................!...=...=...!.......................6...=...=...=...=...=...=...)..............................................."...=...=.......................................................................................n...............O..........................................#...............................................................................................................................0...............0...0...0...1...1...1...1...1...1...2...2...2...2..L....2...2...4...4...4...4...4...4...5...5...5..2............................................................D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6A91B87D5EDCF48AAC55612A71B1E8C6
        SHA1:CD673F85F0EC9565E5E7142B391E4C22995BFFED
        SHA-256:1F520A0EA43845F9CB2ACFC81DE965025A54379A4591632E27B1DA9B2EDD0FD6
        SHA-512:3CD75DB705B169766F88BF5A17536E6B629FCD9E77300F28ABB596745624A26136079C94DD32860E5FDEFBD1BDEAE6B61147662A467899A5B4DC3EC8FBE757AB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.'.D.9.1.(.J.).....T.r.a.n.s.l.a.t.i.o.n.=.'.D.#.3.*.'.0. .9.H.6. .".D.-.9.'.&.6. .'.D.:.'.E./.J.....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.,./.J./.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.%.F.4.'.!. .%.1.4.J.A. .,./.J./.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.*.-.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.*.-. .%.1.4.J.A. .E.H.,.H./.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.%.6.'.A.).....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.%.6.'.A.). .E.D.A.'.*. .D.D.#.1.4.J.A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.-.0.A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.-.0.A.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.%.3.*...1.'.,.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.%.3.*...1.'.,. .'.D.E.D.A.'.*. .E.F. .'.D.%.1.4.J.A.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.9.1.6.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.9.1.6.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:705CB330C0D5C0A1623B2899743D509B
        SHA1:E71CB66C57531FC5480F2791CA9DC51A1C6438DC
        SHA-256:D0C77918CA48064A89EB404ED47F32DCBD2F7ED5AD33FDF8F5F44DFE5EB7382B
        SHA-512:6B8DCF5F6724400352789FBCEB076B1FCDC0AC6B51C066666A1D64887DC64C539AD5A59E38961A20E7BA5CC9E75342F001D6F5B75588CBE9B4992BEA2C6BCEAC
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.n.d.o.n.e.s.i.a. .G.a.u.l.....T.r.a.n.s.l.a.t.i.o.n.=.D.a.n.i.e.l. .H.a.m.o.n.a.n.g.a.n. .(.0.1.h.i.r.a.g.a.s.a.i.t.o.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.1...0...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.B.a.r.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.N.g.e.b.u.a.t. .b.a.r.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.B.u.k.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.N.g.e.b.u.k.a. .a.r.s.i.p. .y.a.n.g. .s.u.d.a.h. .a.d.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.M.a.s.u.k.k.a.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.M.a.s.u.k.i.n. .b.e.r.k.a.s. .k.e. .d.a.l.a.m. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.k.s.t.r.a.k. .b.e.r.k.a.s. .d.a.r.i. .a.r.s.i.p.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:77A04A09217C143D1C0F4A06086D4855
        SHA1:75C9C598FAA987EAB3D21641DFCAEF3D5BB018E0
        SHA-256:E41D3AC59B8C450F810B2FCADF6DCFCF155CBF17C1E52835CA2E076715BB6EEB
        SHA-512:584D35B81D1B0FA6C689F7825574417850CFFE4564594E5067ED23F5396B620431FD67981F7D2946B3FADDD223230C70AF24A81E658DB3DEA05C6D05B84DB7B2
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.n.d.o.n.e.s.i.a.....T.r.a.n.s.l.a.t.i.o.n.=.N.u.r.a.h.m.a.t. .A.g.u.s.t.i.a.n.t.o.....V.e.r.s.i.o.n.=.0.3...2.0.0.7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.B.a.r.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.M.e.m.b.u.a.t. .a.r.s.i.p. .b.a.r.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.B.u.k.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M.e.m.b.u.k.a. .a.r.s.i.p. .y.a.n.g. .s.u.d.a.h. .a.d.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.M.a.s.u.k.k.a.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.M.e.m.a.s.u.k.k.a.n. .b.e.r.k.a.s. .k.e. .d.a.l.a.m. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.M.e.n.g.h.a.p.u.s. .i.s.i.a.n. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.M.e.n.g.e.k.s.t.r.a.k. .b.e.r.k.a.s. .d.a.r.i. .a.r.s.i.p.....M.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:5FB3036A47BB74780FA77DF34388AD9E
        SHA1:8DAA05C9C54AE7D49CC6037D6C77040067BC7106
        SHA-256:5AC8811060318CD468222DAD984216865FBE50C7E60225D9864AF1A127690E4C
        SHA-512:9937933BC1FAA80B643EE0F382898036B3A74D997242FEB672F2D3AD72E7ED4742EEAAAED8C1E419991A5DCC651D7D531519CF57228E9039169A127012939E47
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.o.s.n.i.a.n. .(.B.o.s.a.n.s.k.i.).....T.r.a.n.s.l.a.t.i.o.n.=.F.E.D.....V.e.r.s.i.o.n.=.4...1.....[.B.o.s.n.i.a.n. .f.o.r. .I.Z.A.r.c. .4...1.].............[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.v.a.r.a.n.j.e. .n.o.v.o.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.o.r.i. .p.o.s.t.o.j.e...i. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.v.a.n.j.e. .d.a.t.o.t.e.k.a. .u. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.I.z.d.v.o.j.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.I.z.d.v.o.j.i. .d.a.t.o.t.e.k.e. .i.z. .a.r.h.i.v.a.....M.a.i.n.F.o.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:945D7CDF34FFCD97EC92346555C06476
        SHA1:F48AD795BC4CAC941811B9BA48F1BA0356B98195
        SHA-256:7E349B4453EF6D2EAFB678BFA2A7B84C50033C07D9F48D40A959172F5E4AE66B
        SHA-512:7B6AC3161A31B7E49F46C7B522CB84BD3F8B1EF8D7A2BDB40F93079984A282DCD01506E912972A3333ADBC15B8B6522BDD97A8234DA0D36C056C15ECEAF8307E
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.o.s.o. .J.o.w.o.....T.r.a.n.s.l.a.t.i.o.n.=.m.a.s. .y.a.y.a.n. .(.y.a.y.a.n.p.u.j.i.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.A.n.y.a.r.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.N.g.g.a.w.e. .a.r.s.i.p. .a.n.y.a.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.m.B.u.k.a.k.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.m.B.u.k.a.k. .a.r.s.i.p. .s.i.n.g. .w.i.s. .o.n.o.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.N.a.m.b.a.h.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.N.a.m.b.a.h. .f.i.l.e. .n.i.n.g. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.m.B.u.s.a.k.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.m.B.u.s.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.n.g.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.n.g.E.x.t.r.a.k. .f.i.l.e. .s.o.k.o. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:AC17D2D801C88F2DF46DC29BE7CA501F
        SHA1:352CD506A0096852D00089CD859CD5FA0A6E7EC8
        SHA-256:9FC8091E6B713FBA9981FAC96AC7B907A044326CC2926BBE72389697E45DE83C
        SHA-512:7D613E3CB2B7FD09B68E6057A24939FBF03706F8356D0DE9537F2C7027826C53EC3AAA9920B03EFEDBBC16139E65705BA4DDC1462C1660CEA1CC35E6401B98A5
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.r.e.t.o.n.....T.r.a.n.s.l.a.t.i.o.n.=.K.A.D.-.K.o.r.v.i.g.e.l.l.o... .A.n. .D.r.o.u.i.z.i.g. .(.d.r.o.u.i.z.i.g.@.d.r.o.u.i.z.i.g...o.r.g.).....V.e.r.s.i.o.n.=.3...4...1...5.........[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.e.v.e.z.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.e.v.e.l. .u.n. .D.i.e.l.l. .n.e.v.e.z.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.D.i.g.e.r.i.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.D.i.g.e.r.i... .u.n. .D.i.e.l.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.O.u.z.h.p.e.n.n.a.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.O.u.z.h.p.e.n.n.a... .R.e.s.t.r.o... .e.n. .D.i.e.l.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.D.i.l.e.m.e.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.D.i.l.e.m.e.l.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.z.t.e.n.n.a.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.z.t.e.n.n.a... .R.e.s.t.r.o... .a.d.a.l.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:11528D17E57B542525A40C295897E300
        SHA1:5116B27B06298301AE06334BF4E3127E143CEF0B
        SHA-256:BA0E5B5C62CEA33BCDF82805EADC8EE816746D3273EA3F16DE42D68379E644FE
        SHA-512:7B75BD47D3D9D6A3480E2056AD12244567DC1BAA64B6CFC9CBAE4E3C76A9BCFF3E1F96C49C2C414EB5403EBF2153DA75DA180F9F28F73D5D38E6CAC91C1E0D71
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...J.;.3.0.@.A.:.8.....T.r.a.n.s.l.a.t.i.o.n.=...2.0.=. ...0.E.0.@.8.5.2. .(.I.Z.A.r.c.).....V.e.r.s.i.o.n.=.4...4.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.J.7.4.0.2.0.=.5. .=.0. .=.>.2. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.0.@.O.=.5.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.0.@.O.=.5. .=.0. .A.J.I.5.A.B.2.C.2.0.I. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.1.0.2.O.=.5.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.1.0.2.O.=.5. .=.0. .D.0.9.;.>.2.5. .:.J.<. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...7.B.@.8.2.0.=.5.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...7.B.@.8.2.0.=.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...7.2.;.8.G.0.=.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...7.2.;.8.G.0.=.5. .=.0. .D.0.9.;.>.2.5. .>.B. .0.@.E.8.2.0.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7D31F6D711D528404C400D0DC7456165
        SHA1:97B8DDDD8F7F316861A19139E8E7AFC87DA62010
        SHA-256:BA422E17829D9F835465CD29BA4A65D173158AE3D20DCFDE15E63A729E38A2EC
        SHA-512:EC91781D4DA6EDC32C4E78F44A150C3397F282BF1749E149D2D68F39137C3823B3D23AF982EE3E1B0D10DE6EAB84868377B76D0711A8023AF915E5D403A65592
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.a.s.t.e.l.l.a.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.J.o.s... .M... .F.d.e.z.-.S.a.t.o.r.r.e. .<.j.m.@.s.a.t.o.r.r.e...e.u.>.....C.o.r.r.e.c.t.i.o.n.:.S.e.r.g.i. .M.e.d.i.n.a.....V.e.r.s.i.o.n.=.4...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=. .N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .a.r.c.h.i.v.o. .n.u.e.v.o. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.e. .u.n. .a.r.c.h.i.v.o. .c.o.m.p.r.i.m.i.d.o. .y.a. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.e. .f.i.c.h.e.r.o.s. .a.l. .a.r.c.h.i.v.o. .a.c.t.u.a.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .l.o.s. .a.r.c.h.i.v.o.s. .s.e.l.e.c.c.i.o.n.a.d.o.s.....M.a.i.n.F.o.r.m...t.b.E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:3D4B90085FA73FACBA260F66C105FDF4
        SHA1:625353CCC23DAA6C4CFB54DB672328CDA2BBC401
        SHA-256:12B8B6AAAE6BF6A1D861B1D89AD68AA2DE644B127EA394CA718EFF2F3B74DE00
        SHA-512:13EFD6867351559A6EFC8B08B60E1A9A0D8A21FD90D8AF93C8804C9FEB3E6B3ED16403203D9EB98DD4CF0B645B9164FC6EF535FC2D444DBF15F177277737032D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.a.t.a.l.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.P.a.u. .B.o.s.c.h. .i. .C.r.e.s.p.o. .<.p.a.u.b.c.r.e.s.p.o.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.3...8.1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .a. .a.r.x.i.u. .n.o.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.b.r.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.b.r.e. .u.n. .a.r.x.i.u. .e.x.i.s.t.e.n.t.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.f.e.g.e.i.x.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.f.e.g.e.i.x. .f.i.t.x.e.r.s. .a. .l.'.a.r.x.i.u.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.e.u.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.e.u. .f.i.t.x.e.r.s. .d.e. .l.'.a.r.x.i.u.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2CA5C6D630680859F86A2D2794BD18ED
        SHA1:9A4BBF8771A6ACAE2F56E2E6E3DEB3DDED9298A7
        SHA-256:48A4E02DA2DFF1337B0D1A3D38DA8A8338A70CCCEB5FDAECDA67B74A199038FD
        SHA-512:DDB91B3E93AE8074B320FD1599741C82A56C8DD037F055C736E040C677165BFB14DF9CDCCA5B538DBA500FC4D731066393BD92E0F85EC156A95201E7429ADFD8
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Traditional Chinese..Translation=Ken(kycken@yahoo.com)..Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=......MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...............MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=......MainForm.CloseArchive1.Caption=......Ma
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:0E94362AFA8635B09A23AD388CD9B48D
        SHA1:4A508B12FC0B83D3ACDDF4B17C3CEC4D75ED74A6
        SHA-256:C0683512169C38C5F5B5CE7CF6C212BBA4B478D0C81BCE93815D75BC0DFEF6D2
        SHA-512:B38E72DDFA0E5DE01FCB6A2655816A9BD63960F1132D2A679FA3F4F0AA3985A6DBDBD8C2652839462D0E468EDCBBF0771B2E041E0DBCF95AF01DBBA89CC531B7
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Simplified Chinese..Translation=Ken(kycken@yahoo.com)..Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=......MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...............MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=......MainForm.CloseArchive1.Caption=......Mai
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7E1EC6A6E5D4504B06A9D1430A0C042C
        SHA1:0E24231CC3268D786661233E78B0A4058D6F1628
        SHA-256:3591C27BEFCA05895A76B3B9ABCD6D778BBB9E13ECCCA50D49CF2C272F9C1015
        SHA-512:013CE9892BDA91CD729BD6A6794D759ED5F7DAA85934A570F2FB12FE096D91DF285F8DF25BCC9A1EA07824854ED262385929436A7478955B3E2CA07649017127
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.h.i.n.e.s.e. .T.r.a.d.i.t.i.o.n.a.l.....T.r.a.n.s.l.a.t.i.o.n.=...8.-.....V.e.r.s.i.o.n.=.4...1...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..e.X....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..^.z.N.P.e.v.X.~.j....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=..._U....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=..._U.N.P.]X[(W.v.X.~.j....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=..ReQ....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..ReQ.jHh0R.X.~.j....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.*Rd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.*Rd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...X.~....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...X.~.O..X.~.j..v.jHh....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=..j......M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..j...X.~.jKNgQ.v.jHh....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.=..[.....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...H.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:9DDA0629C86D501CD1AD12CBE3695D7F
        SHA1:1547E80E0E1DDB2429E480A9C9617299CFC936FD
        SHA-256:8D9F5E2D16F026B73C2AF35EAD9CC1FDB2C3A179BFBD6D8443847C9F5780A26E
        SHA-512:F4F95D14C9DFD2DF52DD171B5828905DBC1AAB0F6876D5F542AAA8CA05CC0A2770752CD9CF5FB6AC8F7FD8C3EDD8DBBC917D3C7B26CD9317FDACDB1A2C343832
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.h.i.n.e.s.e.....T.r.a.n.s.l.a.t.i.o.n.=.J.A.K.E. .L.I.N... .<.j.a.k.e.-.l.i.n.@.y.a.h.o.o...c.o.m...t.w.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..^.z.ech....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..^.z.N*N.e.S).ch....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.._/T.ech....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.._/T.N*N.sX[.v.S).ch....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=..ReQ....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..ReQchHh0R.S).ch....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=. Rd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=. Rd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=..S).....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=..S).eg.S).ch..vchHh....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=..h.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..h..S).chKN.Q.vchHh....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.=..[.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF, CR line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:DEE3B1EF18FD88C9FFBA029D0F6A4F84
        SHA1:0C006DFD5EF0945D4AED62FDC06521149B713479
        SHA-256:9C70A7CD7BA4CC8DEE94FC041B312588B7CEEEC59F0FD4CB3BAA0DB3C0E133D0
        SHA-512:66F28D215A60C79BB39FE1FA0E7E48D34EA23F91305338B94B11D9ACF28E89D8357F68D3EA54205EA8B14A9E809607D065BF7A756B052FE42CF7D8D6971612A2
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.r.o.a.t.i.a.n. .(.H.r.v.a.t.s.k.i.).....T.r.a.n.s.l.a.t.i.o.n.=.S.t.e.v.a.n. .G.r.u.b.i.......V.e.r.s.i.o.n.=.1...0.....[.C.r.o.a.t.i.o.n. .f.o.r. .I.Z.A.r.c. .3...8.1. .(.B.u.i.l.d. .1.5.5.0.).].............[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.a.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.v.a.r.a. .n.o.v.u. .a.r.h.i.v.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.a.r.a. .p.o.s.t.o.j.e...u. .a.r.h.i.v.u.....M.a.i.n.F.o.r.m...t.b.F.a.v.o.r.i.t.e.s...C.a.p.t.i.o.n.=.O.m.i.l.j.e.n.i. .d.i.r.......M.a.i.n.F.o.r.m...t.b.F.a.v.o.r.i.t.e.s...H.i.n.t.=.P.o.p.i.s. .a.r.h.i.v.a. .u. .V.a.a.i.m. .o.m.i.l.j.e.n.i.m. .d.i.r.e.k.t.o.r.i.j.i.m.a.....M.a.i.n.F.o.r.m...t.b.P.r.o.p.e.r.t.i.e.s...C.a.p.t.i.o.n.=.S.v.o.j.s.t.v.a.....M.a.i.n.F.o.r.m...t.b.P.r.o.p.e.r.t.i.e.s...H.i.n.t.=.P.r.i.k.a.z.u.j.e. .s.v.o.j.s.t.v.a. .a.r.h.i.v.e.....M.a.i.n.F.o.r.m.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:3222AD02502F6BE24D3D1E143778BA4D
        SHA1:0DA9488CF6FF172D4A9298745B4214CE5D0E15A4
        SHA-256:712A539CA8CA619C6F3AFC8A7511933A9899E1536565991F2836468729BBF391
        SHA-512:3C5097E9D1AE85FB1CCDF4BE1DC8DA82476187ECEB5EFD5C906FDE0E4102F368AD4752E50D8F967AE892618B5EF567541429FDFF08217D9F4A5D951D3F193F04
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.....................T.r.a.n.s.l.a.t.i.o.n.=............... ..................... .-. .............V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=....... .................M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..................... ......... ...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.................M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=............. ....... ............... .................M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.............M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=......... .................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...............M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=........... .................M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.V.i.e.w...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:4363ECF6852366B41D94EED4AAF38F35
        SHA1:629C4C92565E56C7A7E101CB9DDF582A775DCB8E
        SHA-256:EF3035912424061BC06DD3242DF3688CEF20F3DB9B2E07FC33CB06ABBB8396FB
        SHA-512:C829B11C6AB76C9286A0E461BAE1BDAF9B804F2106C779C7826AF5A749585D2B598AC47BA1A656CDD128A9E426A731B6A0E256F3A155427DBABD35E9957781BD
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.h.e.b.r.e.w.....T.r.a.n.s.l.a.t.i.o.n.=.n.s.i.s.1.2.3. .....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=....... ............. ...........M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=....... ............. .............M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.............M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=......... ........... ...................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=....... ........... ...................M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=....... ............. .....................M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D68A8CC8F9782BA228687A9F44F23A6F
        SHA1:CF0A0915F2EACF2F5034E2ED8E3991EF46E8FE7D
        SHA-256:2FFF4C9C7D7C8AC9D185C19F2DCC4413C155B42EE794BF86BD02F21E41F78D8B
        SHA-512:9AA42F4B06981F1CF19A3F292AEFF3521B67B663CE85E2B84A17BC66D35478FC9B00A6233A0901EF1554B43D18D6A95207868261EE7EE2707D8B1994F6A5ED87
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.H.e.l.l.e.n.i.c. .(.G.r.e.e.k.).....T.r.a.n.s.l.a.t.i.o.n.=.I.o.a.n.n.i.s. .(.P.r.o.w.l.e.r.). .Z.o.u.m.b.a.s.....V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.........................M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..................... ......................... ...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=............... ......................... ...................M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.....................M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=................. ............... ..... ....................... .................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.....................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.....................M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...................M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:E893DF72116BE02DDEBFE31E468D8F58
        SHA1:55207E547CA0D1ECC04393D91723C3E332FA1085
        SHA-256:24F9727E75A60FC7F26E5A7BDF4C75D239CDCB08B97203A2FAB291A0BE004FA0
        SHA-512:4144D59BE56EDF15D9122CBFAB44041152367D3FD4DA8FCC66B31C88374B738971719AA8346E4574E77B7C77D72E9F842EE50D1944A72D4F8294B6F331C9B724
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.M.a.g.y.a.r.....T.r.a.n.s.l.a.t.i.o.n.=.D...b.r...n.t.e.i. .S...n.d.o.r. .(.p.h.o.e.n.i.x.@.h.o.t.m.a.i.l...h.u.).....V.e.r.s.i.o.n.=.4...1...9.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...j.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...j. .a.r.c.h...v.u.m. .l...t.r.e.h.o.z...s.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.M.e.g.n.y.i.t...s.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.L...t.e.z.Q. .a.r.c.h...v.u.m. .m.e.g.n.y.i.t...s.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.H.o.z.z...a.d...s.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.F...j.l.o.k. .h.o.z.z...a.d...s.a. .a.z. .a.r.c.h...v.u.m.h.o.z.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.T...r.l...s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.T...r.l...s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.K.i.c.s.o.m.a.g.o.l...s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.F...j.l.o.k. .k.i.c.s.o.m.a.g.o.l...s.a. .a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:231521907BE13DDCF185777B545C0280
        SHA1:04D609245CB23A3BBB39651C5FF33BCB78BB8F4D
        SHA-256:F64DFC5C2A930D97CE54C9A895E783B11A6F9658FE75E42BECD5C02F0B1B1DD9
        SHA-512:F55D328B6DC6EA5D3BE42D6984A1409FEA21661DAC52A597094D59A69A34E648E0E7611ECFDCC530002F5606D033AE197280AEA05801E90C2C920F80A0151ED0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.c.e.l.a.n.d.i.c.....T.r.a.n.s.l.a.t.i.o.n.=.E.r.l.i.n.g.u.r. .J.o.n.s.s.o.n. .<.e.r.l.i.n.g.u.r.1.0.1.0.@.h.o.t.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.1...0. .B.e.t.a.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N...t.t.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.o.f.n.a. .n...t.t. .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.p.n.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.p.n.a. .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.B...t.a. .v.i.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.B...t.a. .v.i... .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.y...a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.y...a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.k.k.a. ...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.k.k.a. ...t. .s.k.r...m. .f.r... .s.a.f.n.i.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.S.k.o...a.....M.a.i.n.F.o.r.m.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with very long lines (305), with CRLF, CR line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:49B9AD024276A7421213C482FC79D14B
        SHA1:35583B57C6D93B627FD10C97C9D175D7C9957AFD
        SHA-256:F501922A317D7327F919BA092F0B0CB7156269EB6182F9C8F5F3B2FFC87CBD9A
        SHA-512:07AC7A9674144BD40E32EE1E20EFD2C830DC21F00EBFE6587FDCF862A81A2FEBF9A98A924403840F917463C763A5CAC0EA4C2B89935D6C6E994454D8A6A673F9
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.n.g.l.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.I.v.a.n. .Z.a.h.a.r.i.e.v. .(.I.Z.A.r.c.).....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.a.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.u.t.h.a.i.g.h. .C.a.r.t.l.a.n.n. .N.u.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.s.c.a.i.l.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.s.c.a.i.l. .C.a.r.t.l.a.n.n. .a.t... .a.n.n. .c.h.e.a.n.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.C.u.i.r. .l.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.C.u.i.r. .C.o.m.h.a.i.d. .l.e. .C.a.r.t.l.a.n.n.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.c.r.i.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.c.r.i.o.s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.B.a.i.n.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.B.a.i.n. .C.o.m.h.a.i.d. ... .C.h.a.r.t.l.a.n.n.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.A.m.h.a.r.c.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:DE5C2F98E0208DBA5375A59C088C99A1
        SHA1:7E34F34EF8FDC15259F82B6821A616D697BFD2D8
        SHA-256:FA81788C02A9A704A067FC32F053F2A7846A8E5A2F16F3658472C3B37421A6EB
        SHA-512:594E10664E8D7524BDBC29F6B455CC7C017CBC72BF5A3C4D27A7E351565B8C4966BF4F433417EBAB3E9DA13B29A785152968A0CF74D689FFAF31375A5D6B285B
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.t.a.l.i.a.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.L.u.c.a. .S.n.o.r.i.g.u.z.z.i.....V.e.r.s.i.o.n.=.4...2...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .n.u.o.v.o. .a.r.c.h.i.v.i.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.p.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.p.r.i. .u.n. .a.r.c.h.i.v.i.o. .e.s.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.g.i.u.n.g.i.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.g.i.u.n.g.i. .d.e.i. .f.i.l.e. .a.l.l.'.a.r.c.h.i.v.i.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .i. .f.i.l.e. .d.e.l.l.'.a.r.c.h.i.v.i.o. .s.e.l.e.z.i.o.n.a.t.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.s.t.r.a.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.s.t.r.a.i. .i. .f.i.l.e. .d.e.l.l.'.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:DBD92F73A4E67842BA0CCE7333079EF7
        SHA1:94A173C5776BB9B719CA16D5C0C6B5A530DA6FE7
        SHA-256:442980D4DA69281ECABE9E26690955F42248CB75D3FF55BEAB96E9441D7DF62A
        SHA-512:A55E44009665369FDAD2A1676DC21EDB1EDFE8CAAE60E38E3527DD6E44323FE9B261FB91A461065399CB3EC4C540982045583D96AB9B0B66630DBBFC8E769147
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.J.a.p.a.n.e.s.e.....T.r.a.n.s.l.a.t.i.o.n.=.c.h.i.n.Q. .(.c.h.i.n.Q.@.b.a.s.i.l...f.r.e.e.m.a.i.l...n.e...j.p.).....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..e......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..eW0D0.f.^.0\O.bW0~0Y0....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...O0....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=..eX[n0.f.^.0..M0~0Y0....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=....R....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..f.^k0.0.0.0.0.0...R'W.~W0~0Y0....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.JRd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.JRd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...Q....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=..f.^K0.0.0.0.0.0.0..QW0~0Y0....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.........M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..f.^k0<h.}U0.0f0D0.0.0.0.0.0.0....W0~0Y0....M.a.i.n.F.o.r.m...t.b.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:75CC94BC2E626D3AE6C4CF99803D8B18
        SHA1:D73B4901768D4A923518DDDAA0D2D8B1BF83DA90
        SHA-256:EC15EA484393CFE96EA62F8E593590EAC391685B97547E71C7606E0E4195642D
        SHA-512:23FD9646070BDD993D3F914BBE0FA2D0F4A66361189AFE8A4826D0DBE718826EE9EEDBACFC27F5D4F95842D06B20E790DAC8AAC616EB82CCC78D0C3476835424
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.o.r.e.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.S.i.n. .M.i.n.S.i.k. .(.s.i.n...m.i.n.s.i.k.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...\.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=... .U....|. ...0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.0.t. .U....|. ...0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.#.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...|.D. .U....|... .#.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=....0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=....0.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.U....|..... ...|. ...0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.U....|... .... ...|. ...0.....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:4DB95839F5AA06A02D2B0D8B9AC0E42F
        SHA1:878C69417EB2CFEF6E93F382209DE9440D7D7895
        SHA-256:EC5E996ADC1D2BA197C247DD9BC0227E1461A038EFFFDD525E22CF5BDCD9CCB2
        SHA-512:79AF6FA7280978185A234F54757B07211D408D88A735396A758A7C913E8A7EEFF8B05EADFCEB75CE80B0CEB3F4908A1B13FE10D523CFCB09B7B868663CC26C3A
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.......T.r.a.n.s.l.a.t.i.o.n.=.O.c.c.o. .M.a.h.a.b.a.d. .(.o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.A.r._...v.e.k.e. .N... .....k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.V.e.k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.r._...v.e.k.e. .H.e.y... .V.e.k.e. .....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L... .Z...d.e. .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.s.y.a.y... .T.e.v... .A.r._...v... .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.J.i. .H.u.n.d.i.r... .A.r._...v... .D.o.s.y.a. .D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.N.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:179A1425CE75D75F1E4B8A8520E621EF
        SHA1:75084B67079F226DEE883829630D98F866153EA6
        SHA-256:7390747E33874C654BEA46A0A743E41330D3F5EC6F7E5C17E4106D678FD5CAF9
        SHA-512:4E583AF2B87B6A2152C0056E4FD26ECEAE448DB9B2A66D0E17D4C8400EF064F1735B75B00D9303E5B51BBB09DA5334CC283413950B07C406696441361A2BEB0D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...H.1./.......T.r.a.n.s.l.a.t.i.o.n.=.(.g.o.r.r.a.n.9.0.@.g.m.a.i.l...c.o.m.). .....1.'.F. .:...1...(.....V.e.r.s.i.o.n.=.d. ... .a. ... .g.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.F.H.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=./.1.H.3.*...1./.F... .&...1.4...A....... .F.H.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...1./.F...H.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...1./.F...H..... .&...1.4...A... .&...3.*.'.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.2...'./...1./.F.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.2...'./...1./.F... .A.'...D. .(... .F.'.H. .&...1.4...A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.3.....F...H.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.3.....F...H.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=./...1.G...F.'.F.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=./...1.G...F.'.F... .A.'...D.....'.F... .F.'.H. .&...1.4...A.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:1B08C7D68D741500684278EA2E836A58
        SHA1:64F6E9D9675B377F151F2181855B3C37D5902761
        SHA-256:0C8350B48B57FED16DFB7073C69C7D2CD395928FAA0683643B4F426DB18052D0
        SHA-512:B98A71953EAE7FC798D9C04532A8AF482A3BC2DD4DAB2C7B4FF0353D8AC2F6325D1BEE887EC2E8ADABFBB37C36DB51EBECB701BC738BF52882E487E69F33CA93
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.O.c.c.o. .M.a.h.a.b.a.d. .(.o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.A.r._...v.e.k.e. .N... .....k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.V.e.k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.r._...v.e.k.e. .H.e.y... .V.e.k.e. .....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L... .Z...d.e. .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.s.y.a.y... .T.e.v... .A.r._...v... .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.J.i. .H.u.n.d.i.r... .A.r._...v... .D.o.s.y.a. .D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:62B98BA414850D8BF457DBFD432C2A76
        SHA1:EAE1E848A57C5E5E0A5997129C4C337A8616384F
        SHA-256:BFBF96113C691BDAA546C897416896293919DF0C36AAE23ADC1641462509DF3D
        SHA-512:B0A4BD39268ACB8F44E71067455D5DFC4177362B0C006099FB8AA2AEBAA2BB9C977F0842D0D05A3EDF4FE57F31B2E7A1F2D7583BE340947D0DAEDE1795AACCD3
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.L.a.t.v.i.a.n. .(.l.a.t.v.i.e.a.u.).....T.r.a.n.s.l.a.t.i.o.n.=.A.g.r.i.s. .K.n.a.u.e.r.s.....V.e.r.s.i.o.n.=.3...1.2...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.J.a.u.n.s.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.I.z.v.e.i.d.o.t. .j.a.u.n.u. .a.r.h.+.v.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.t.v...r.t.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.t.v...r.t. .e.k.s.i.s.t...j.o.a.u. .a.r.h.+.v.u.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.P.i.e.v.i.e.n.o.t.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.P.i.e.v.i.e.n.o.t. .f.a.i.l.u.s. .a.r.h.+.v.a.m.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.D.z...s.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.D.z...s.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.A.t.a.r.h.i.v...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.A.t.a.r.h.i.v...t. .f.a.i.l.u.s. .n.o. .a.r.h.+.v.a.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [MainForm]
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A8A1C840DF9363A30884EA0A1BFE0D1C
        SHA1:3CEC0B1D09C3B5961B0C0293CCC56CE9D4DA542C
        SHA-256:CAD586B60CB607C0721E05CB074FA82E56C6A71E143AA88BB5685C8BD3473890
        SHA-512:99A48C90BFCCA75D4C1C385D944FC9715E1EEDE9811A27A829EAAAF25344ED55FC76716DA0BEABE01874F09ED17635901D395A59992C309AD14BBFB72BC2E481
        Malicious:false
        Reputation:unknown
        Preview:[Info]..Language=Lithuanian (Lietuvi.)..Translation=Giedrius Naud.i.nas <gimp@projektas.lt>..Version=3.4.1.3..[MainForm]..MainForm.tbNew.Caption=Naujas..MainForm.tbNew.Hint=Sukurti nauj. archyv...MainForm.tbOpen.Caption=Atverti..MainForm.tbOpen.Hint=Atverti esam. archyv...MainForm.tbAdd.Caption=.traukti..MainForm.tbAdd.Hint=.traukti bylas . archyv...MainForm.tbDelete.Caption=Trinti..MainForm.tbDelete.Hint=Trinti archyv...MainForm.tbExtract.Caption=I.spausti..MainForm.tbExtract.Hint=I.spausti bylas i. archyvo..MainForm.tbView.Caption=Per.i.ra..MainForm.tbView.Hint=Per.i.r.ti byl. archyvo viduje..MainForm.tbInstall.Caption=Paleisti.....MainForm.tbInstall.Hint=Paleisti program. i. archyvo.....MainForm.tbCheckOut.Caption=Valdymas..MainForm.tbCheckOut.Hint=.traukti programin. grup. . meni. "Visos programos" su byl. i.spaudimu i. archyvo . laikin.j. aplankala ir .enkliuk. sukurimu...MainForm.LedRed.Hint=Spragtel.kite jei norite baigti .. veiksm....MainForm.LedGreen.Hint=B.senos indikatorius:
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:E73AE230FBC039A792FC38A6D924A186
        SHA1:32C51FE904B96CCB09D380E0AD25214C7DD91102
        SHA-256:49658912EBFF571FC2B6180634904AB7D90CB83C19639FF479413995246F44C6
        SHA-512:478B4EB88A761A3DF5A1D68A1A1B0926E1ECD36F092A49615CA9B499BB0FECB34704EF57F723FF8A299210DAF8C489225ECE8F23358DACD4A207A9750410B8F0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...0.:.5.4.>.=.A.:.8.....T.r.a.n.s.l.a.t.i.o.n.=.m.i.t.e.7.1.....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.>.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.>.7.4.0.2.0.Z.5. .=.>.2.0. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.>.@.8.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.>.@.0.Z.5. .?.>.A.B.>.5.G.:.0. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.X.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.2.0.Z.5. .4.0.B.>.B.5.:.8. .2.>. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...7.1.@.8.H.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...@.8.H.5.Z.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...B.?.0.:.C.2.0.X.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...B.?.0.:.C.2.0.Z.5. .4.0.B.>.B.5.:.8. .>.4. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...@.5.3.;.5.4...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7B70F96059CDB0E7A2176ABD71945CBE
        SHA1:E842F899329E961F9C79FCD9EF250400A33A094F
        SHA-256:0D567B80AD6195988B8D1D83ACA1E9FE01BF65416DA58F3A708F808981131BF0
        SHA-512:D842B856EFBF574A66D76510894DFEBBB615B52053679B8B508816A3790AD60DD0A64F2D72C28EE5A4F587AB6A46AFAEAF5CE3FC40E7D7216883F54EAB62D21D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.N.o.r.w.e.g.i.a.n. .(.N.o.r.s.k.).....T.r.a.n.s.l.a.t.i.o.n.=.S.t.e.i.n.-.O.v.e. .B...t.h.u.n. .<.s.t.e.b.o.t.@.s.t.e.b.o.t...n.e.t.>.....V.e.r.s.i.o.n.=.3...8.1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.y.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.O.p.p.r.e.t.t. .n.y.t.t. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...p.n.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...p.n.e. .e.k.s.i.s.t.e.r.e.n.d.e. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L.e.g.g. .t.i.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.L.e.g.g. .t.i.l. .f.i.l.e.r. .i. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.l.e.t.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.l.e.t.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.k.k. .u.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.k.k. .u.t. .f.i.l.e.r. .f.r.a. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:C64C8B245276F8D87CEACD2E725BD6F0
        SHA1:A72B7938057920964C264DFF63381CEAA86754B5
        SHA-256:8A7C9B899C10DA2316B69A4DD8A9A4B984EA3E6D10083F60FCCE7A64C28C5B08
        SHA-512:D4A953E7DF871B45CBF46899A1AE59A846705C231A7E7F8B0A6AD123DE9C5C3C4DA155BAA718E328B6C5F5D6BD045729EB245A27F39418C9A975023D089E7C6E
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.l.s.k.i.....T.r.a.n.s.l.a.t.i.o.n.=.P.i.o.t.r. .M.u.r.a.w.s.k.i.,. .R.a.f.a.B. .L.a.m.p.e. .<.w.w.w...l.o.m.s.e.l...c.o.m...p.l.>. ./. .P.o.p.r.a.w.k.i.:. .W.a.v.E. .<.w.a.v.-.e.@.w.p...p.l.>.....V.e.r.s.i.o.n.=.v.3...8. .+. .v.4...0. .b.e.t.a. .1. .b.u.i.l.d. .1.7.6.0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.w.y.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.T.w...r.z.y. .n.o.w.e. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.w...r.z.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.w.i.e.r.a. .i.s.t.n.i.e.j...c.e. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.j.e. .p.l.i.k.i. .d.o. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.U.s.u.D.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.U.s.u.w.a. .w.y.b.r.a.n.e. .p.l.i.k.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [MainForm]
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D68458F9F95E9C2212936C1BC0F69A20
        SHA1:F348781924C3E4913A97EFB565A8A7F560E894EC
        SHA-256:AD1816DD14A513B13830BA0AD1E90F3A08C60D7CB891549F87BA81CC719ED38F
        SHA-512:C8EC4BAC1A6E7EF820CB56A38D8E65AF10FF5CE0A13C23D4056981EEFCBC8354D45096A5DB1D02197427522AAEFEE0CBDD9DFFEFAD5E2AE5D38A6777D44DE034
        Malicious:false
        Reputation:unknown
        Preview:[Info]..Language=Portugu.s (Brasil)..Translation=CyberFox <foxfear@gmail.com>..Version=IZArc 4.1.7..[MainForm]..MainForm.tbNew.Caption=Novo..MainForm.tbNew.Hint=Criar um novo arquivo..MainForm.tbOpen.Caption=Abrir..MainForm.tbOpen.Hint=Abrir um arquivo existente..MainForm.tbAdd.Caption=Adicionar..MainForm.tbAdd.Hint=Adicionar arquivos ao arquivo compactado..MainForm.tbDelete.Caption=Excluir..MainForm.tbDelete.Hint=Excluir..MainForm.tbExtract.Caption=Extrair..MainForm.tbExtract.Hint=Extrair arquivos do arquivo compactado..MainForm.tbView.Caption=Visualizar..MainForm.tbView.Hint=Visualizar arquivo..MainForm.tbInstall.Caption=Instalar..MainForm.tbInstall.Hint=Instalar o software existente neste arquivo..MainForm.tbCheckOut.Caption=Avaliar..MainForm.tbCheckOut.Hint=Criar grupo de arquivos no menu iniciar para teste..MainForm.LedRed.Hint=Clique para cancelar a opera..o..MainForm.LedGreen.Hint=Esta luz de status ficar. verde quando o IZArc n.o estiver ocupado e vermelho quando ocupado..MainF
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:92D6F3904A29CD24CBECEBB1C55BE410
        SHA1:E0C5F95F1915D40E65E7DB72F8D71298969C6B89
        SHA-256:64A7769CA0C68410AF2DEE2259AC2AD3AD5F0AB36625DD62157601EC6389C449
        SHA-512:AF6728737352B311195D59B4D93235FDAEBC25EF39A870566A3E8B20B44829C112E3F416D787A0C1394C5E10880F6A1BE06D3B9FDAFA70067F864343B098DD58
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .(.P.T.).....T.r.a.n.s.l.a.t.i.o.n.=.A.n.t...n.i.o. .E.d.u.a.r.d.o. .M.a.r.q.u.e.s. .<.a.e.m.a.r.q.u.e.s.@.h.o.t.m.a.i.l...c.o.m.>. .e. .N.u.n.o. .R.e.g.o. .<.n.u.n.i.t.o...m.o.k.i.t.o.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.4...1...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.i.a.r. .n.o.v.o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .a.r.q.u.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.i.c.i.o.n.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.i.c.i.o.n.a.r. .f.i.c.h.e.i.r.o.s. .p.a.r.a. .o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.i.r.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:565C440264C0D82C3BC04753E3D900FD
        SHA1:20E3229D57A195946D4A94AD7F141784E7471629
        SHA-256:4D1444EA94D5A02A4C27B7701E04E5DC626AB2D0491EE88056FFEE4804ACB4BB
        SHA-512:563B92B08F68F0E1DE16429974F6D95968A3F80E9071E904EEAA8302DD8CBBE41828F7DC0065CB81BDDCBFFA2F1F2B92D0D60A3E2C2D72FE4E4E7DC7467F6A2F
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .(.B.R.).....T.r.a.n.s.l.a.t.i.o.n.=.A.l.e.x. .M... .S.a.n.c.h.e.s. .<.a.m...s.a.n.c.h.e.s.@.i.g...c.o.m...b.r.>.....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.i.a.r. .u.m. .n.o.v.o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .u.m. .a.r.q.u.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.i.c.i.o.n.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.i.c.i.o.n.a.r. .a.r.q.u.i.v.o.s. .p.a.r.a. .o. .a.r.q.u.i.v.o. .c.o.m.p.a.c.t.a.d.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.i.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.i.r. .
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A76A23B6BC1D57574EC95E76C6BF7FB1
        SHA1:F3AE884CD77E0F6FA3779C2D1CD0D05B11554A97
        SHA-256:0F75EBB230C13C4CE6D203FDA967843B2233684EFC8B810C95571F726BC6553C
        SHA-512:E7C00F5CC8F151AA1012C29661B09AE0583CDF34E6297DAC4EE312283ABF66B9F0BA5303216627794E738C4639ED81E2B8F67A625B9033833FDEC03BD035F600
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.o.m.a.n.i.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.A.l.e.x.a.n.d.r.u. .B.o.g.d.a.n. .M.u.n.t.e.a.n.u. .h.t.t.p.:././.m.u.n.t.e.a.l.b...b.r.a.v.e.h.o.s.t...c.o.m./.....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.e.a.z... .o. .A.r.h.i.v... .N.o.u.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.D.e.s.c.h.i.d.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.D.e.s.c.h.i.d.e. .o. .A.r.h.i.v... .E.x.i.s.t.e.n.t.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.a.u.g.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.a.u.g... .F.i.l.e. .l.a. .A.r.h.i.v.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...t.e.r.g.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...t.e.r.g.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.g.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.g.e. .F.i.l.e.l.e. .d.i.n. .A.r.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:27A5596A47F7A1D312F1035D3E317F69
        SHA1:2690661E2220B6D99F2045A1270F0A0AE11A516B
        SHA-256:B6F10D5EF77FBFE54F6B2281DF73F1D118D3D3AA41C71E426E3384B65433289D
        SHA-512:6E08EAA7604707143AF6B5BB61088ADE46D70D7A2612521B98B77B3D4499017A6C10A9FD5EB7ACC85BC1304F8F0BC1278587B3BCE21552AD5BCDF7976A31BBA0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.u.s.s.i.a.n. .(. .C.A.A.:.8.9.).....T.r.a.n.s.l.a.t.i.o.n.=...0.2.5.;. .!.Q.<.8.=.....V.e.r.s.i.o.n.=.4...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.K.9.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.>.7.4.0.B.L. .=.>.2.K.9. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.:.@.K.B.L.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.:.@.K.B.L. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.1.0.2.8.B.L.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.1.0.2.8.B.L. .D.0.9.;.K. .2. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.#.4.0.;.8.B.L.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.#.4.0.;.8.B.L. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...7.2.;.5.G.L.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...7.2.;.5.G.L. .D.0.9.;.K. .8.7. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...@.>.A.<.>.B.@.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:63A7881572D216880919637216DAB0E5
        SHA1:5F67965549B1F193DDD806C8777C38761F6CD84B
        SHA-256:1F5970637830A67B6BA3E391269D65E2078FFB15DB20120B2ECF80E72D09E945
        SHA-512:07C04D896CE104317AB7BD167ACCDC75A246ABFEBD28EC3AB224619B1114F378CC96FB0C74BC9B09B593FCE3C8DA9A670CE3F05665B550E34577860396439F0D
        Malicious:false
        Reputation:unknown
        Preview:.. .T.r.a.n.s.l.a.t.i.o.n. .m.a.d.e. .w.i.t.h. .T.r.a.n.s.l.a.t.o.r. .1...3.2. .(.h.t.t.p.:././.w.w.w.2...a.r.n.e.s...s.i./.~.s.o.p.j.s.i.m.o./.t.r.a.n.s.l.a.t.o.r...h.t.m.l.)..... .$.T.r.a.n.s.l.a.t.o.r.:.N.L.=.%.n.:.T.B.=.%.t.........[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.e.r.b.i.a.n. .(.C.y.r.i.l.l.i.c.).....T.r.a.n.s.l.a.t.i.o.n.=.B... .J.o.t.e.v. .(.b.j.o.t.e.v.@.y.a.h.o.o...c.o.m.).....V.e.r.s.i.o.n.=.3...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...@.5.8.@.0.Z.5. .=.>.2.>.3. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.0.@.0.Z.5.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.0.@.0.Z.5. .?.>.A.B.>.X.5.[.5.3. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.2.0.Z.5.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.2.0.Z.5. .D.0.X.;.>.2.0. .0.@.E.8.2.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...@.8.A.0.Z.5.....M.a.i.n.F.o.r.m...t.b.D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:8D6BE8D55A175723E0A32DC55EE6389E
        SHA1:88F6115D3256CA841868DB45F3C6747644582EAF
        SHA-256:479ADF7C747416DB3C998AAC00F792F8889D3D2B1FB095215B8F697A48D5609E
        SHA-512:6CF04B264469283F1BD586F14F3988CE587E6E97125BA1B746D20DB98E6FC44B54747CA79AEF46369EFD6DC7F43C9AD508E91826818EAA065699824DA28C4A2E
        Malicious:false
        Reputation:unknown
        Preview:.. .T.r.a.n.s.l.a.t.i.o.n. .m.a.d.e. .w.i.t.h. .T.r.a.n.s.l.a.t.o.r. .1...3.2. .(.h.t.t.p.:././.w.w.w.2...a.r.n.e.s...s.i./.~.s.o.p.j.s.i.m.o./.t.r.a.n.s.l.a.t.o.r...h.t.m.l.)..... .$.T.r.a.n.s.l.a.t.o.r.:.N.L.=.%.n.:.T.B.=.%.t.........[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.e.r.b.i.a.n. .(.C.y.r.i.l.l.i.c.).....T.r.a.n.s.l.a.t.i.o.n.=.B... .J.o.t.e.v. .(.b.j.o.t.e.v.@.y.a.h.o.o...c.o.m.).....V.e.r.s.i.o.n.=.3...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.K.r.e.i.r.a.n.j.e. .n.o.v.o.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.a.r.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.a.r.a.n.j.e. .p.o.s.t.o.j.e...e.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.v.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.v.a.n.j.e. .f.a.j.l.o.v.a. .a.r.h.i.v.i.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:916D341B2FEE098C4B00044E266CAD63
        SHA1:830E111C8744913AF878AA33AD8530DB23753C97
        SHA-256:EECC99911C59745E45C5144BD2D935419B9BBDCBCCAE0716BDBB0E3239F86579
        SHA-512:5A8D370B0352551E12A370FC427DA47A8C609B7A3BA014138202077EF408F6D5B5725737E6F3E0E8DFACC55DF5CD37DC4BB6192F6C55E4CE60850D0E7960099F
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Simplified Chinese..Translation=Ken(kycken@yahoo.com)&...~..wcxu21@126.com...Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=........MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...........MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=........MainForm.Close
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:2D7BDB945A18A5F1F9B1136C168EDF07
        SHA1:5E16D13E0E5003E5712ED71DBAF2A05A28A26FDA
        SHA-256:B557EE0289C3834525971A13D1E27276AD0005768BAA34FE3F97CBB0CC61C382
        SHA-512:DCCB02B22D2D4EEA9A9ADBBCB36D9501F87650CF5599A3F43B1C07DC73AF73D99B9B31A6A547EA0465157AE0700EAEAB0417F509A64792DDD7094C39E012AEDE
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.a.k.....T.r.a.n.s.l.a.t.i.o.n.=.R.o.m.a.n. .D.u.a.i.n.s.k... .<.r.d.u.s.i. .a.t. .i.n.m.a.i.l...s.k.>.....V.e.r.s.i.o.n.=.4...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.V.y.t.v.o.r... .n.o.v... .a.r.c.h...v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.o.r... .e.x.i.s.t.u.j...c.i. .a.r.c.h...v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.P.r.i.d.a.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.P.r.i.d... .s...b.o.r.y. .d.o. .a.r.c.h...v.u.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.V.y.m.a.z.a.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.V.y.m.a.~.e...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.R.o.z.b.a.l.i.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.R.o.z.b.a.l... .s...b.o.r.y. .z. .a.r.c.h...v.u.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:498DB23D790B83F585D2B6A548FEA2A3
        SHA1:9B58B3AB67C2C394CE7C719F5EAE7E385953502D
        SHA-256:5ABE5A4DD6E954C3F8B3B0563ED61F08832FF6A9D2A6E11BC75A0097A47A7A4B
        SHA-512:F13909D61C770084737BA82B717189588438FC76E239804718097BFB5C720627E2CC8B510301B212E29190A335DD32F2885B5A8194D3A3D4BF1518DAE8904C00
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n.i.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.J.a.d.r.a.n. .R.u.d.e.c. .<.j.r.u.d.e.c.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.4...4. .(.T.r.a.n.s.l.a.t.e.d. .0.9...0.7...2.0.1.9.).....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.U.s.t.v.a.r.i. .n.o.v. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.d.p.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.d.p.r.i. .o.b.s.t.o.j.e... .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.j. .d.a.t.o.t.e.k.e. .v. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.I.z.b.r.i.a.i.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.I.z.b.r.i.a.i. .d.a.t.o.t.e.k.e. .i.z. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.R.a.z.a.i.r.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.R.a.z.a.i.r.i. .d.a.t.o.t.e.k.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7F12B6119FEFFB69B3AC35BC3CEC087B
        SHA1:F402F56805551EE1104DC60378198417E7FEF50F
        SHA-256:F44DFA3724F069930BFB2861DABFF003D5FCDA514C312D9F9F4914C3CC011782
        SHA-512:BCFE9C3ECAAAD811D3F42D3812ECF0620BB13A3F9268F4466E08C3A561BAC413E291D53A638986614FF0B208446DAC483D2BA36109E468330BCF29C8CE04B8BD
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l. .C.h.i.l.e.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.B...h.o. .N.i.g.h.t. .B.l.u.e. .(.b.u.h.o.n.i.g.h.t.b.l.u.e.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.1...0. .....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .u.n. .n.u.e.v.o. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .u.n. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.r.e.g.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.r.e.g.a.r. .a.r.c.h.i.v.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.o.r.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e.r. .a.r.c.h.i.v.o.s. .d.e.s.d.e. .o.t.r.o. .A.r.c.h.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:BD4570BAAE2AF76D0434A75B468D31AE
        SHA1:0FAEECB2B97628C1E92971E01AEA26D566AA3185
        SHA-256:919C54F0E1CDB81572A9A915E76063E95AA047DA17A8A014B26862BB9795B77B
        SHA-512:880F2C2B3087F19BB0388D8A315EBA45CE622DB998A731B283720505E9EE53ADB98FECA7E70B4872D089D95E92AB8DBD1CA4B7E4F9D4A1B2274E236F5E1914B6
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.p.a.n.i.s.h. .M.x. .(.L.a.t.i.n.o.a.m...r.i.c.a.).....T.r.a.n.s.l.a.t.i.o.n.=.M.a.r.c.o. .A... .A.n.d.r.a.d.e. .R.o.d.r...g.u.e.z. .(.m.o.s.e.v.i.l.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.3...5. .b.e.t.a. .3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=. .N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .a.r.c.h.i.v.o. .n.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.r.e.g.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.r.e.g.a.r. .a.r.c.h.i.v.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.r. .a.r.c.h.i.v.o.(.s.). .s.e.l.e.c.c.i.o.n.a.d.o.(.s.).....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:661BBC05C74F58768A0551646F43FD4C
        SHA1:F9AFCEDD483BD8F2E465D31B5947F8B8655BA8D5
        SHA-256:7014E3CAB1F3A50811D89A39FEEF7B0AEA2990860547DFF11E05A78A3B3438B3
        SHA-512:C38E0C3670A5C97CFF960F667D7FDA4889DB8D63854D3E3512BC7EB8134E9C0712A3B63E57A3CE4F132355D360A6777770673D24CE3853CE65F5613E5B3F6FAB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.p.a.n.i.s.h. .(.U.r.u.g.u.a.y.).....T.r.a.n.s.l.a.t.i.o.n.=.G.o.n.z.a.l.o. .F.e.r.r.e.i.r.a. .<.g.o.n.z.a.f.e.r.@.i.n.t.e.r.n.e.t...c.o.m...u.y.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .n.u.e.v.o. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .c.o.m.p.r.i.m.i.d.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.i.r. .a.r.c.h.i.v.o.s. .a. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.o.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.B.o.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e.r. .a.r.c.h.i.v.o.s. .d.e.s.d.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7BB308AB48959363EBC8F6AA92403CC1
        SHA1:02B04F96BC5345DE2F2A528995384CACFFCC4679
        SHA-256:C5F864CBE68A49D206142CF78B4C6B39CFBA3B43F850DA4251F530BC32F072BE
        SHA-512:5519F820E5E40F546F282116A1A0DF0A96C8841E8D47DD1198A488B3EAF9540241B5DADC721FE44FA4A4B6B48F92A81329CDCC41733DB86D726B1C912A847986
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l.....T.r.a.n.s.l.a.t.i.o.n.=.V.i.c.t.o.r. .E.m.m.a.n.u.e.l.,. .v.i.c.o.k.o.b.y.@.g.m.a.i.l...c.o.m.....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .n.u.e.v.o. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.e. .u.n. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.e. .f.i.c.h.e.r.o.s. .a.l. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .f.i.c.h.e.r.o.s. .d.e.l. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e. .f.i.c.h.e.r.o.s. .d.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:39951B0DF9613A5485CAFBD81B40A201
        SHA1:E3E26EA2FB9A5C5D08796D7D222C8F2002F962DE
        SHA-256:C731A966D48F08A87F02E2B171498E764F88794CCD6C60F20346117D5F8F2265
        SHA-512:22AF7F46793C3333FB888C90852DEC32A45E8DEDEA38272BA08258C18CCD05A3C0375720F569D2FB5B24D4AC3086077AFF2149C27FD043FC9AD9959321AE0900
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.w.e.d.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.P.e.t.e.r. .R.u.n.e.s.s.o.n. .<.i.z.a.r.c.@.r.u.n.e.s.s.o.n...r.u.>.....V.e.r.s.i.o.n.=.4...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.y.t.t.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.k.a.p.a. .n.y.t.t. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...p.p.n.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...p.p.n.a. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L...g.g. .t.i.l.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.L...g.g. .t.i.l.l. .f.i.l.e.r. .i. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.T.a. .b.o.r.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.T.a. .b.o.r.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.c.k.a. .u.p.p.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.c.k.a. .u.p.p. .f.i.l.e.r. .f.r...n. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.V.i.s.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:EB0B580DA805B80A3C60611189F7DB45
        SHA1:8EDAB325BF892A72BDAA50888C7FE8E7541FE7BD
        SHA-256:47A431291903736DEE39AAFA3DB1533EAE61138D68E343A09BF0B21E3DDD82F0
        SHA-512:5435CE338B1D51D9DFE8E309ECAEE6A934E6D427781AAA06DC99A282D8E64D96DF954DE7D94A0FB1150335DEE6AB696222DE999AE1685D2FD0A2EBFEBB786F0D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T.a.i.w.a.n.e.s.e.(.R...O...C. .i.n. .T.A.I.W.A.N.).....T.r.a.n.s.l.a.t.i.o.n.=.J.A.K.E. .L.I.N... .<.j.a.k.e.-.l.i.n.@.y.a.h.o.o...c.o.m...t.w.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...8...?...s. .).....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...8...?...@...3...s. ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...}...2.".". .).....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...}...2...@...3...{...s..... ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...[...J.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...[...J. .)...7...L. ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...R.........M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...R.........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...1. ...!.Y.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...1. ...!.Y...3..... ...!.Y. .).Y.8..... .)...7.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:273754C196D8E8817C1E678E1BD240EE
        SHA1:D4D340D2A83EFBC6024D4C42F0BAAB8D6B0A110F
        SHA-256:B7627AB556B2584BE95CA3EFBF1CB9C51CDA2437148630FDD8BDE51D23C82757
        SHA-512:5AEC57DC17EE675060AEA1DED7EF21666C88FEADD471261E1D143C1AF0AD9475E742F9346C0A3163DA003B67A97003C4FB50F200FB69BB844EBEE693D1CC4E02
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.D...".....T.r.a.n.s.l.a.t.i.o.n.=...$...4.'.1.....L. . .@.!...5...8.%.....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.C.+.!.H.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.*.#.I.2...@.-...*.2.#...5...-.1...C.+.!.H.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.@...4.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.@...4...@.-...*.2.#...5...-.1.....5.H.!.5.-.".9.H.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...3.@...I.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.@...4.H.!.D...%.L.C...@.-...*.2.#...5...-.1.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.%.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.%.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.*.H...-.-.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...6...D...%.L.-.-.....2...@.-...*.2.#...5...-.1.......M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.*.3.#.'.......M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:30D8BE574026EB425EEA1FEAA23FD9FE
        SHA1:7A7F684A6C5BC127AAE7B28AF5549D45969D6C3B
        SHA-256:B3FF4F1729FE8664DD251AF60405798E88942B35068AD0E42BFC6FD6C505F9F6
        SHA-512:A06539EBE70693D253F42C291FCD769425E56B0A02832F1827E8AA05A7ABEAE0BA4AF057E58A39DD2B425A9DE9A47B2C4B2591C3E52FD778E7B9B6FC4699DBAB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T...r.k...e.....T.r.a.n.s.l.a.t.i.o.n.=.N.e.z.i.r. .T.O.P.A.L.O...L.U.....V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.Y.e.n.i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.Y.e.n.i. .A.r._.i.v. .Y.a.r.a.t.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M.e.v.c.u.t. .B.i.r. .A.r._.i.v. .A.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.E.k.l.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.r._.i.v.e. .D.o.s.y.a. .E.k.l.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.i.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.i.l.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...1.k.a.r.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.A.r._.i.v. .I...i.n.d.e.n. .D.o.s.y.a. ...1.k.a.r.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.G...s.t.e.r.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.A.r._.i.v. .i...i.n.d.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6C22B655A7C3279B00209D7829345527
        SHA1:24B980BEE91D893096BC6D2BC0B834E009A87657
        SHA-256:8ED7FF7555B065E2185DAD544A600E8B9FD0C36611AD977FD19A66D4091F5111
        SHA-512:9FA5B620D2065595F84DD425FF9EBEB65B3CF0ED4D0166234B576E9F2D4EEB13D027497D9EE5F63261FAE96FFAA0B558AB4358D7372C0B43822646F2CE53F922
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.#.:.@.0.W.=.A.L.:.0.....T.r.a.n.s.l.a.t.i.o.n.=...5.=.>.2.V.9. ...5.<.`.O.=.G.C.:. .(.w.w.w...u.k.r.f.a.c.e...k.i.e.v...u.a.).....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.8.9.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.B.2.>.@.8.B.8. .=.>.2.8.9. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...V.4.:.@.8.B.8.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...V.4.:.@.8.B.8. .V.A.=.C.N.G.8.9. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.B.8.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.B.8. .D.0.9.;.8. .2. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...8.4.0.;.8.B.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...8.4.0.;.8.B.8. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...8.9.=.O.B.8.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...8.9.=.O.B.8. .D.0.9.;.8. .7. .0.@.E.V.2.C.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B747F4F638380C759633D61BE5428072
        SHA1:6400AF259A9293086703CF0836A20B9109572794
        SHA-256:1C68DD5B848B8479A236967B922C730A04F368CBD23101AF9C0B16A1F37E4167
        SHA-512:3AE67443D3FDE90016A8940E06F02E6243C1B83CFBE4B1DD014E3BD82D47A072EC0BBD7C3E1C167213F3B3E765687FD0AFED816D759FBBA6A5CFA244748D5D49
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.t.i...n.g. .V.i...t.....T.r.a.n.s.l.a.t.i.o.n.=.T.h.a.n.h. .T...i. .(.t.h.a.n.h.t.a.i.2.0.0.9. .-. .h.t.t.p.:././.f.o.r.u.m...k.a.s.p.e.r.s.k.y...v.n. .-. .h.t.t.p.:././.a.f.u.b.l.o.g...c.o.m.).....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.M...i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.T...o. .m...t. .l...u. .t.r... .m...i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.M.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M... .m...t. .l...u. .t.r... ..... .c.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.T.h...m.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.T.h...m. .t...p. .t.i.n. .v...o. .l...u. .t.r.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.X.o.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.X.o.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.T.r...c.h. .x.u...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.T.r...c.h. .x.u...t. .t...p. .t.i.n. .
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):71484
        Entropy (8bit):3.7166887480697652
        Encrypted:false
        SSDEEP:
        MD5:1B08C7D68D741500684278EA2E836A58
        SHA1:64F6E9D9675B377F151F2181855B3C37D5902761
        SHA-256:0C8350B48B57FED16DFB7073C69C7D2CD395928FAA0683643B4F426DB18052D0
        SHA-512:B98A71953EAE7FC798D9C04532A8AF482A3BC2DD4DAB2C7B4FF0353D8AC2F6325D1BEE887EC2E8ADABFBB37C36DB51EBECB701BC738BF52882E487E69F33CA93
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.O.c.c.o. .M.a.h.a.b.a.d. .(.o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.A.r._...v.e.k.e. .N... .....k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.V.e.k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.r._...v.e.k.e. .H.e.y... .V.e.k.e. .....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L... .Z...d.e. .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.s.y.a.y... .T.e.v... .A.r._...v... .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.J.i. .H.u.n.d.i.r... .A.r._...v... .D.o.s.y.a. .D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72166
        Entropy (8bit):3.7102894116460328
        Encrypted:false
        SSDEEP:
        MD5:E893DF72116BE02DDEBFE31E468D8F58
        SHA1:55207E547CA0D1ECC04393D91723C3E332FA1085
        SHA-256:24F9727E75A60FC7F26E5A7BDF4C75D239CDCB08B97203A2FAB291A0BE004FA0
        SHA-512:4144D59BE56EDF15D9122CBFAB44041152367D3FD4DA8FCC66B31C88374B738971719AA8346E4574E77B7C77D72E9F842EE50D1944A72D4F8294B6F331C9B724
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.M.a.g.y.a.r.....T.r.a.n.s.l.a.t.i.o.n.=.D...b.r...n.t.e.i. .S...n.d.o.r. .(.p.h.o.e.n.i.x.@.h.o.t.m.a.i.l...h.u.).....V.e.r.s.i.o.n.=.4...1...9.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...j.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...j. .a.r.c.h...v.u.m. .l...t.r.e.h.o.z...s.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.M.e.g.n.y.i.t...s.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.L...t.e.z.Q. .a.r.c.h...v.u.m. .m.e.g.n.y.i.t...s.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.H.o.z.z...a.d...s.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.F...j.l.o.k. .h.o.z.z...a.d...s.a. .a.z. .a.r.c.h...v.u.m.h.o.z.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.T...r.l...s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.T...r.l...s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.K.i.c.s.o.m.a.g.o.l...s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.F...j.l.o.k. .k.i.c.s.o.m.a.g.o.l...s.a. .a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):76944
        Entropy (8bit):3.7198265717700774
        Encrypted:false
        SSDEEP:
        MD5:2D7BDB945A18A5F1F9B1136C168EDF07
        SHA1:5E16D13E0E5003E5712ED71DBAF2A05A28A26FDA
        SHA-256:B557EE0289C3834525971A13D1E27276AD0005768BAA34FE3F97CBB0CC61C382
        SHA-512:DCCB02B22D2D4EEA9A9ADBBCB36D9501F87650CF5599A3F43B1C07DC73AF73D99B9B31A6A547EA0465157AE0700EAEAB0417F509A64792DDD7094C39E012AEDE
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.a.k.....T.r.a.n.s.l.a.t.i.o.n.=.R.o.m.a.n. .D.u.a.i.n.s.k... .<.r.d.u.s.i. .a.t. .i.n.m.a.i.l...s.k.>.....V.e.r.s.i.o.n.=.4...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.V.y.t.v.o.r... .n.o.v... .a.r.c.h...v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.o.r... .e.x.i.s.t.u.j...c.i. .a.r.c.h...v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.P.r.i.d.a.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.P.r.i.d... .s...b.o.r.y. .d.o. .a.r.c.h...v.u.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.V.y.m.a.z.a.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.V.y.m.a.~.e...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.R.o.z.b.a.l.i.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.R.o.z.b.a.l... .s...b.o.r.y. .z. .a.r.c.h...v.u.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):69990
        Entropy (8bit):4.289778672706227
        Encrypted:false
        SSDEEP:
        MD5:11528D17E57B542525A40C295897E300
        SHA1:5116B27B06298301AE06334BF4E3127E143CEF0B
        SHA-256:BA0E5B5C62CEA33BCDF82805EADC8EE816746D3273EA3F16DE42D68379E644FE
        SHA-512:7B75BD47D3D9D6A3480E2056AD12244567DC1BAA64B6CFC9CBAE4E3C76A9BCFF3E1F96C49C2C414EB5403EBF2153DA75DA180F9F28F73D5D38E6CAC91C1E0D71
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...J.;.3.0.@.A.:.8.....T.r.a.n.s.l.a.t.i.o.n.=...2.0.=. ...0.E.0.@.8.5.2. .(.I.Z.A.r.c.).....V.e.r.s.i.o.n.=.4...4.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.J.7.4.0.2.0.=.5. .=.0. .=.>.2. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.0.@.O.=.5.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.0.@.O.=.5. .=.0. .A.J.I.5.A.B.2.C.2.0.I. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.1.0.2.O.=.5.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.1.0.2.O.=.5. .=.0. .D.0.9.;.>.2.5. .:.J.<. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...7.B.@.8.2.0.=.5.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...7.B.@.8.2.0.=.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...7.2.;.8.G.0.=.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...7.2.;.8.G.0.=.5. .=.0. .D.0.9.;.>.2.5. .>.B. .0.@.E.8.2.0.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [MainForm]
        Category:dropped
        Size (bytes):37842
        Entropy (8bit):5.211234989273437
        Encrypted:false
        SSDEEP:
        MD5:D68458F9F95E9C2212936C1BC0F69A20
        SHA1:F348781924C3E4913A97EFB565A8A7F560E894EC
        SHA-256:AD1816DD14A513B13830BA0AD1E90F3A08C60D7CB891549F87BA81CC719ED38F
        SHA-512:C8EC4BAC1A6E7EF820CB56A38D8E65AF10FF5CE0A13C23D4056981EEFCBC8354D45096A5DB1D02197427522AAEFEE0CBDD9DFFEFAD5E2AE5D38A6777D44DE034
        Malicious:false
        Reputation:unknown
        Preview:[Info]..Language=Portugu.s (Brasil)..Translation=CyberFox <foxfear@gmail.com>..Version=IZArc 4.1.7..[MainForm]..MainForm.tbNew.Caption=Novo..MainForm.tbNew.Hint=Criar um novo arquivo..MainForm.tbOpen.Caption=Abrir..MainForm.tbOpen.Hint=Abrir um arquivo existente..MainForm.tbAdd.Caption=Adicionar..MainForm.tbAdd.Hint=Adicionar arquivos ao arquivo compactado..MainForm.tbDelete.Caption=Excluir..MainForm.tbDelete.Hint=Excluir..MainForm.tbExtract.Caption=Extrair..MainForm.tbExtract.Hint=Extrair arquivos do arquivo compactado..MainForm.tbView.Caption=Visualizar..MainForm.tbView.Hint=Visualizar arquivo..MainForm.tbInstall.Caption=Instalar..MainForm.tbInstall.Hint=Instalar o software existente neste arquivo..MainForm.tbCheckOut.Caption=Avaliar..MainForm.tbCheckOut.Hint=Criar grupo de arquivos no menu iniciar para teste..MainForm.LedRed.Hint=Clique para cancelar a opera..o..MainForm.LedGreen.Hint=Esta luz de status ficar. verde quando o IZArc n.o estiver ocupado e vermelho quando ocupado..MainF
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):80502
        Entropy (8bit):3.5763969815009022
        Encrypted:false
        SSDEEP:
        MD5:BD4570BAAE2AF76D0434A75B468D31AE
        SHA1:0FAEECB2B97628C1E92971E01AEA26D566AA3185
        SHA-256:919C54F0E1CDB81572A9A915E76063E95AA047DA17A8A014B26862BB9795B77B
        SHA-512:880F2C2B3087F19BB0388D8A315EBA45CE622DB998A731B283720505E9EE53ADB98FECA7E70B4872D089D95E92AB8DBD1CA4B7E4F9D4A1B2274E236F5E1914B6
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.p.a.n.i.s.h. .M.x. .(.L.a.t.i.n.o.a.m...r.i.c.a.).....T.r.a.n.s.l.a.t.i.o.n.=.M.a.r.c.o. .A... .A.n.d.r.a.d.e. .R.o.d.r...g.u.e.z. .(.m.o.s.e.v.i.l.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.3...5. .b.e.t.a. .3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=. .N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .a.r.c.h.i.v.o. .n.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.r.e.g.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.r.e.g.a.r. .a.r.c.h.i.v.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.r. .a.r.c.h.i.v.o.(.s.). .s.e.l.e.c.c.i.o.n.a.d.o.(.s.).....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72500
        Entropy (8bit):3.563998422132268
        Encrypted:false
        SSDEEP:
        MD5:7F12B6119FEFFB69B3AC35BC3CEC087B
        SHA1:F402F56805551EE1104DC60378198417E7FEF50F
        SHA-256:F44DFA3724F069930BFB2861DABFF003D5FCDA514C312D9F9F4914C3CC011782
        SHA-512:BCFE9C3ECAAAD811D3F42D3812ECF0620BB13A3F9268F4466E08C3A561BAC413E291D53A638986614FF0B208446DAC483D2BA36109E468330BCF29C8CE04B8BD
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l. .C.h.i.l.e.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.B...h.o. .N.i.g.h.t. .B.l.u.e. .(.b.u.h.o.n.i.g.h.t.b.l.u.e.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.1...0. .....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .u.n. .n.u.e.v.o. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .u.n. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.r.e.g.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.r.e.g.a.r. .a.r.c.h.i.v.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.o.r.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e.r. .a.r.c.h.i.v.o.s. .d.e.s.d.e. .o.t.r.o. .A.r.c.h.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77672
        Entropy (8bit):3.7127478252337225
        Encrypted:false
        SSDEEP:
        MD5:C64C8B245276F8D87CEACD2E725BD6F0
        SHA1:A72B7938057920964C264DFF63381CEAA86754B5
        SHA-256:8A7C9B899C10DA2316B69A4DD8A9A4B984EA3E6D10083F60FCCE7A64C28C5B08
        SHA-512:D4A953E7DF871B45CBF46899A1AE59A846705C231A7E7F8B0A6AD123DE9C5C3C4DA155BAA718E328B6C5F5D6BD045729EB245A27F39418C9A975023D089E7C6E
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.l.s.k.i.....T.r.a.n.s.l.a.t.i.o.n.=.P.i.o.t.r. .M.u.r.a.w.s.k.i.,. .R.a.f.a.B. .L.a.m.p.e. .<.w.w.w...l.o.m.s.e.l...c.o.m...p.l.>. ./. .P.o.p.r.a.w.k.i.:. .W.a.v.E. .<.w.a.v.-.e.@.w.p...p.l.>.....V.e.r.s.i.o.n.=.v.3...8. .+. .v.4...0. .b.e.t.a. .1. .b.u.i.l.d. .1.7.6.0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.w.y.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.T.w...r.z.y. .n.o.w.e. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.w...r.z.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.w.i.e.r.a. .i.s.t.n.i.e.j...c.e. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.j.e. .p.l.i.k.i. .d.o. .a.r.c.h.i.w.u.m.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.U.s.u.D.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.U.s.u.w.a. .w.y.b.r.a.n.e. .p.l.i.k.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72140
        Entropy (8bit):4.323020183210509
        Encrypted:false
        SSDEEP:
        MD5:27A5596A47F7A1D312F1035D3E317F69
        SHA1:2690661E2220B6D99F2045A1270F0A0AE11A516B
        SHA-256:B6F10D5EF77FBFE54F6B2281DF73F1D118D3D3AA41C71E426E3384B65433289D
        SHA-512:6E08EAA7604707143AF6B5BB61088ADE46D70D7A2612521B98B77B3D4499017A6C10A9FD5EB7ACC85BC1304F8F0BC1278587B3BCE21552AD5BCDF7976A31BBA0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.u.s.s.i.a.n. .(. .C.A.A.:.8.9.).....T.r.a.n.s.l.a.t.i.o.n.=...0.2.5.;. .!.Q.<.8.=.....V.e.r.s.i.o.n.=.4...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.K.9.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.>.7.4.0.B.L. .=.>.2.K.9. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.:.@.K.B.L.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.:.@.K.B.L. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.1.0.2.8.B.L.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.1.0.2.8.B.L. .D.0.9.;.K. .2. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.#.4.0.;.8.B.L.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.#.4.0.;.8.B.L. .0.@.E.8.2.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...7.2.;.5.G.L.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...7.2.;.5.G.L. .D.0.9.;.K. .8.7. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...@.>.A.<.>.B.@.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):75992
        Entropy (8bit):4.292675299235033
        Encrypted:false
        SSDEEP:
        MD5:6C22B655A7C3279B00209D7829345527
        SHA1:24B980BEE91D893096BC6D2BC0B834E009A87657
        SHA-256:8ED7FF7555B065E2185DAD544A600E8B9FD0C36611AD977FD19A66D4091F5111
        SHA-512:9FA5B620D2065595F84DD425FF9EBEB65B3CF0ED4D0166234B576E9F2D4EEB13D027497D9EE5F63261FAE96FFAA0B558AB4358D7372C0B43822646F2CE53F922
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.#.:.@.0.W.=.A.L.:.0.....T.r.a.n.s.l.a.t.i.o.n.=...5.=.>.2.V.9. ...5.<.`.O.=.G.C.:. .(.w.w.w...u.k.r.f.a.c.e...k.i.e.v...u.a.).....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.8.9.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.B.2.>.@.8.B.8. .=.>.2.8.9. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...V.4.:.@.8.B.8.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...V.4.:.@.8.B.8. .V.A.=.C.N.G.8.9. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.B.8.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.B.8. .D.0.9.;.8. .2. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...8.4.0.;.8.B.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...8.4.0.;.8.B.8. .0.@.E.V.2.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...8.9.=.O.B.8.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...8.9.=.O.B.8. .D.0.9.;.8. .7. .0.@.E.V.2.C.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72860
        Entropy (8bit):3.9725421214205663
        Encrypted:false
        SSDEEP:
        MD5:B747F4F638380C759633D61BE5428072
        SHA1:6400AF259A9293086703CF0836A20B9109572794
        SHA-256:1C68DD5B848B8479A236967B922C730A04F368CBD23101AF9C0B16A1F37E4167
        SHA-512:3AE67443D3FDE90016A8940E06F02E6243C1B83CFBE4B1DD014E3BD82D47A072EC0BBD7C3E1C167213F3B3E765687FD0AFED816D759FBBA6A5CFA244748D5D49
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.t.i...n.g. .V.i...t.....T.r.a.n.s.l.a.t.i.o.n.=.T.h.a.n.h. .T...i. .(.t.h.a.n.h.t.a.i.2.0.0.9. .-. .h.t.t.p.:././.f.o.r.u.m...k.a.s.p.e.r.s.k.y...v.n. .-. .h.t.t.p.:././.a.f.u.b.l.o.g...c.o.m.).....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.M...i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.T...o. .m...t. .l...u. .t.r... .m...i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.M.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M... .m...t. .l...u. .t.r... ..... .c.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.T.h...m.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.T.h...m. .t...p. .t.i.n. .v...o. .l...u. .t.r.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.X.o.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.X.o.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.T.r...c.h. .x.u...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.T.r...c.h. .x.u...t. .t...p. .t.i.n. .
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):79348
        Entropy (8bit):3.585566664306648
        Encrypted:false
        SSDEEP:
        MD5:705CB330C0D5C0A1623B2899743D509B
        SHA1:E71CB66C57531FC5480F2791CA9DC51A1C6438DC
        SHA-256:D0C77918CA48064A89EB404ED47F32DCBD2F7ED5AD33FDF8F5F44DFE5EB7382B
        SHA-512:6B8DCF5F6724400352789FBCEB076B1FCDC0AC6B51C066666A1D64887DC64C539AD5A59E38961A20E7BA5CC9E75342F001D6F5B75588CBE9B4992BEA2C6BCEAC
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.n.d.o.n.e.s.i.a. .G.a.u.l.....T.r.a.n.s.l.a.t.i.o.n.=.D.a.n.i.e.l. .H.a.m.o.n.a.n.g.a.n. .(.0.1.h.i.r.a.g.a.s.a.i.t.o.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.1...0...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.B.a.r.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.N.g.e.b.u.a.t. .b.a.r.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.B.u.k.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.N.g.e.b.u.k.a. .a.r.s.i.p. .y.a.n.g. .s.u.d.a.h. .a.d.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.M.a.s.u.k.k.a.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.M.a.s.u.k.i.n. .b.e.r.k.a.s. .k.e. .d.a.l.a.m. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.k.s.t.r.a.k. .b.e.r.k.a.s. .d.a.r.i. .a.r.s.i.p.....M.a.i.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):62552
        Entropy (8bit):4.365561265632067
        Encrypted:false
        SSDEEP:
        MD5:9DDA0629C86D501CD1AD12CBE3695D7F
        SHA1:1547E80E0E1DDB2429E480A9C9617299CFC936FD
        SHA-256:8D9F5E2D16F026B73C2AF35EAD9CC1FDB2C3A179BFBD6D8443847C9F5780A26E
        SHA-512:F4F95D14C9DFD2DF52DD171B5828905DBC1AAB0F6876D5F542AAA8CA05CC0A2770752CD9CF5FB6AC8F7FD8C3EDD8DBBC917D3C7B26CD9317FDACDB1A2C343832
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.h.i.n.e.s.e.....T.r.a.n.s.l.a.t.i.o.n.=.J.A.K.E. .L.I.N... .<.j.a.k.e.-.l.i.n.@.y.a.h.o.o...c.o.m...t.w.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..^.z.ech....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..^.z.N*N.e.S).ch....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.._/T.ech....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.._/T.N*N.sX[.v.S).ch....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=..ReQ....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..ReQchHh0R.S).ch....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=. Rd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=. Rd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=..S).....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=..S).eg.S).ch..vchHh....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=..h.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..h..S).chKN.Q.vchHh....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.=..[.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):78372
        Entropy (8bit):3.645133056955063
        Encrypted:false
        SSDEEP:
        MD5:AC17D2D801C88F2DF46DC29BE7CA501F
        SHA1:352CD506A0096852D00089CD859CD5FA0A6E7EC8
        SHA-256:9FC8091E6B713FBA9981FAC96AC7B907A044326CC2926BBE72389697E45DE83C
        SHA-512:7D613E3CB2B7FD09B68E6057A24939FBF03706F8356D0DE9537F2C7027826C53EC3AAA9920B03EFEDBBC16139E65705BA4DDC1462C1660CEA1CC35E6401B98A5
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.r.e.t.o.n.....T.r.a.n.s.l.a.t.i.o.n.=.K.A.D.-.K.o.r.v.i.g.e.l.l.o... .A.n. .D.r.o.u.i.z.i.g. .(.d.r.o.u.i.z.i.g.@.d.r.o.u.i.z.i.g...o.r.g.).....V.e.r.s.i.o.n.=.3...4...1...5.........[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.e.v.e.z.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.e.v.e.l. .u.n. .D.i.e.l.l. .n.e.v.e.z.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.D.i.g.e.r.i.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.D.i.g.e.r.i... .u.n. .D.i.e.l.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.O.u.z.h.p.e.n.n.a.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.O.u.z.h.p.e.n.n.a... .R.e.s.t.r.o... .e.n. .D.i.e.l.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.D.i.l.e.m.e.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.D.i.l.e.m.e.l.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.z.t.e.n.n.a.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.z.t.e.n.n.a... .R.e.s.t.r.o... .a.d.a.l.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77114
        Entropy (8bit):3.6164095080560754
        Encrypted:false
        SSDEEP:
        MD5:565C440264C0D82C3BC04753E3D900FD
        SHA1:20E3229D57A195946D4A94AD7F141784E7471629
        SHA-256:4D1444EA94D5A02A4C27B7701E04E5DC626AB2D0491EE88056FFEE4804ACB4BB
        SHA-512:563B92B08F68F0E1DE16429974F6D95968A3F80E9071E904EEAA8302DD8CBBE41828F7DC0065CB81BDDCBFFA2F1F2B92D0D60A3E2C2D72FE4E4E7DC7467F6A2F
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .(.B.R.).....T.r.a.n.s.l.a.t.i.o.n.=.A.l.e.x. .M... .S.a.n.c.h.e.s. .<.a.m...s.a.n.c.h.e.s.@.i.g...c.o.m...b.r.>.....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.i.a.r. .u.m. .n.o.v.o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .u.m. .a.r.q.u.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.i.c.i.o.n.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.i.c.i.o.n.a.r. .a.r.q.u.i.v.o.s. .p.a.r.a. .o. .a.r.q.u.i.v.o. .c.o.m.p.a.c.t.a.d.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.i.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.i.r. .
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):80416
        Entropy (8bit):3.562987442693227
        Encrypted:false
        SSDEEP:
        MD5:DE5C2F98E0208DBA5375A59C088C99A1
        SHA1:7E34F34EF8FDC15259F82B6821A616D697BFD2D8
        SHA-256:FA81788C02A9A704A067FC32F053F2A7846A8E5A2F16F3658472C3B37421A6EB
        SHA-512:594E10664E8D7524BDBC29F6B455CC7C017CBC72BF5A3C4D27A7E351565B8C4966BF4F433417EBAB3E9DA13B29A785152968A0CF74D689FFAF31375A5D6B285B
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.t.a.l.i.a.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.L.u.c.a. .S.n.o.r.i.g.u.z.z.i.....V.e.r.s.i.o.n.=.4...2...0.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .n.u.o.v.o. .a.r.c.h.i.v.i.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.p.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.p.r.i. .u.n. .a.r.c.h.i.v.i.o. .e.s.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.g.g.i.u.n.g.i.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.g.g.i.u.n.g.i. .d.e.i. .f.i.l.e. .a.l.l.'.a.r.c.h.i.v.i.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .i. .f.i.l.e. .d.e.l.l.'.a.r.c.h.i.v.i.o. .s.e.l.e.z.i.o.n.a.t.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.s.t.r.a.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.s.t.r.a.i. .i. .f.i.l.e. .d.e.l.l.'.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):67270
        Entropy (8bit):4.28924502801033
        Encrypted:false
        SSDEEP:
        MD5:4363ECF6852366B41D94EED4AAF38F35
        SHA1:629C4C92565E56C7A7E101CB9DDF582A775DCB8E
        SHA-256:EF3035912424061BC06DD3242DF3688CEF20F3DB9B2E07FC33CB06ABBB8396FB
        SHA-512:C829B11C6AB76C9286A0E461BAE1BDAF9B804F2106C779C7826AF5A749585D2B598AC47BA1A656CDD128A9E426A731B6A0E256F3A155427DBABD35E9957781BD
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.h.e.b.r.e.w.....T.r.a.n.s.l.a.t.i.o.n.=.n.s.i.s.1.2.3. .....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=....... ............. ...........M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=....... ............. .............M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.............M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=......... ........... ...................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=....... ........... ...................M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...........M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=....... ............. .....................M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):35497
        Entropy (8bit):6.18540290363786
        Encrypted:false
        SSDEEP:
        MD5:916D341B2FEE098C4B00044E266CAD63
        SHA1:830E111C8744913AF878AA33AD8530DB23753C97
        SHA-256:EECC99911C59745E45C5144BD2D935419B9BBDCBCCAE0716BDBB0E3239F86579
        SHA-512:5A8D370B0352551E12A370FC427DA47A8C609B7A3BA014138202077EF408F6D5B5725737E6F3E0E8DFACC55DF5CD37DC4BB6192F6C55E4CE60850D0E7960099F
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Simplified Chinese..Translation=Ken(kycken@yahoo.com)&...~..wcxu21@126.com...Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=........MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...........MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=........MainForm.Close
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with very long lines (305), with CRLF, CR line terminators
        Category:dropped
        Size (bytes):80530
        Entropy (8bit):3.5912798796501697
        Encrypted:false
        SSDEEP:
        MD5:49B9AD024276A7421213C482FC79D14B
        SHA1:35583B57C6D93B627FD10C97C9D175D7C9957AFD
        SHA-256:F501922A317D7327F919BA092F0B0CB7156269EB6182F9C8F5F3B2FFC87CBD9A
        SHA-512:07AC7A9674144BD40E32EE1E20EFD2C830DC21F00EBFE6587FDCF862A81A2FEBF9A98A924403840F917463C763A5CAC0EA4C2B89935D6C6E994454D8A6A673F9
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.n.g.l.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.I.v.a.n. .Z.a.h.a.r.i.e.v. .(.I.Z.A.r.c.).....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.a.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.u.t.h.a.i.g.h. .C.a.r.t.l.a.n.n. .N.u.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.s.c.a.i.l.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.s.c.a.i.l. .C.a.r.t.l.a.n.n. .a.t... .a.n.n. .c.h.e.a.n.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.C.u.i.r. .l.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.C.u.i.r. .C.o.m.h.a.i.d. .l.e. .C.a.r.t.l.a.n.n.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.c.r.i.o.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.c.r.i.o.s.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.B.a.i.n.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.B.a.i.n. .C.o.m.h.a.i.d. ... .C.h.a.r.t.l.a.n.n.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.A.m.h.a.r.c.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77814
        Entropy (8bit):3.7504876957059246
        Encrypted:false
        SSDEEP:
        MD5:30D8BE574026EB425EEA1FEAA23FD9FE
        SHA1:7A7F684A6C5BC127AAE7B28AF5549D45969D6C3B
        SHA-256:B3FF4F1729FE8664DD251AF60405798E88942B35068AD0E42BFC6FD6C505F9F6
        SHA-512:A06539EBE70693D253F42C291FCD769425E56B0A02832F1827E8AA05A7ABEAE0BA4AF057E58A39DD2B425A9DE9A47B2C4B2591C3E52FD778E7B9B6FC4699DBAB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T...r.k...e.....T.r.a.n.s.l.a.t.i.o.n.=.N.e.z.i.r. .T.O.P.A.L.O...L.U.....V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.Y.e.n.i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.Y.e.n.i. .A.r._.i.v. .Y.a.r.a.t.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M.e.v.c.u.t. .B.i.r. .A.r._.i.v. .A.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.E.k.l.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.r._.i.v.e. .D.o.s.y.a. .E.k.l.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.i.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.i.l.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...1.k.a.r.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.A.r._.i.v. .I...i.n.d.e.n. .D.o.s.y.a. ...1.k.a.r.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.G...s.t.e.r.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.A.r._.i.v. .i...i.n.d.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):54196
        Entropy (8bit):4.478078592902462
        Encrypted:false
        SSDEEP:
        MD5:7E1EC6A6E5D4504B06A9D1430A0C042C
        SHA1:0E24231CC3268D786661233E78B0A4058D6F1628
        SHA-256:3591C27BEFCA05895A76B3B9ABCD6D778BBB9E13ECCCA50D49CF2C272F9C1015
        SHA-512:013CE9892BDA91CD729BD6A6794D759ED5F7DAA85934A570F2FB12FE096D91DF285F8DF25BCC9A1EA07824854ED262385929436A7478955B3E2CA07649017127
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.h.i.n.e.s.e. .T.r.a.d.i.t.i.o.n.a.l.....T.r.a.n.s.l.a.t.i.o.n.=...8.-.....V.e.r.s.i.o.n.=.4...1...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..e.X....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..^.z.N.P.e.v.X.~.j....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=..._U....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=..._U.N.P.]X[(W.v.X.~.j....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=..ReQ....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..ReQ.jHh0R.X.~.j....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.*Rd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.*Rd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...X.~....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...X.~.O..X.~.j..v.jHh....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=..j......M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..j...X.~.jKNgQ.v.jHh....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.=..[.....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...H.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):70436
        Entropy (8bit):4.318311304969547
        Encrypted:false
        SSDEEP:
        MD5:EB0B580DA805B80A3C60611189F7DB45
        SHA1:8EDAB325BF892A72BDAA50888C7FE8E7541FE7BD
        SHA-256:47A431291903736DEE39AAFA3DB1533EAE61138D68E343A09BF0B21E3DDD82F0
        SHA-512:5435CE338B1D51D9DFE8E309ECAEE6A934E6D427781AAA06DC99A282D8E64D96DF954DE7D94A0FB1150335DEE6AB696222DE999AE1685D2FD0A2EBFEBB786F0D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T.a.i.w.a.n.e.s.e.(.R...O...C. .i.n. .T.A.I.W.A.N.).....T.r.a.n.s.l.a.t.i.o.n.=.J.A.K.E. .L.I.N... .<.j.a.k.e.-.l.i.n.@.y.a.h.o.o...c.o.m...t.w.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...8...?...s. .).....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...8...?...@...3...s. ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...}...2.".". .).....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...}...2...@...3...{...s..... ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...[...J.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...[...J. .)...7...L. ...!.Y. .).....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...R.........M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...R.........M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...1. ...!.Y.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...1. ...!.Y...3..... ...!.Y. .).Y.8..... .)...7.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):69820
        Entropy (8bit):3.625998780279793
        Encrypted:false
        SSDEEP:
        MD5:498DB23D790B83F585D2B6A548FEA2A3
        SHA1:9B58B3AB67C2C394CE7C719F5EAE7E385953502D
        SHA-256:5ABE5A4DD6E954C3F8B3B0563ED61F08832FF6A9D2A6E11BC75A0097A47A7A4B
        SHA-512:F13909D61C770084737BA82B717189588438FC76E239804718097BFB5C720627E2CC8B510301B212E29190A335DD32F2885B5A8194D3A3D4BF1518DAE8904C00
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n.i.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.J.a.d.r.a.n. .R.u.d.e.c. .<.j.r.u.d.e.c.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.4...4. .(.T.r.a.n.s.l.a.t.e.d. .0.9...0.7...2.0.1.9.).....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.U.s.t.v.a.r.i. .n.o.v. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.d.p.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.d.p.r.i. .o.b.s.t.o.j.e... .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.j. .d.a.t.o.t.e.k.e. .v. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.I.z.b.r.i.a.i.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.I.z.b.r.i.a.i. .d.a.t.o.t.e.k.e. .i.z. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.R.a.z.a.i.r.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.R.a.z.a.i.r.i. .d.a.t.o.t.e.k.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):35403
        Entropy (8bit):6.162106045334967
        Encrypted:false
        SSDEEP:
        MD5:0E94362AFA8635B09A23AD388CD9B48D
        SHA1:4A508B12FC0B83D3ACDDF4B17C3CEC4D75ED74A6
        SHA-256:C0683512169C38C5F5B5CE7CF6C212BBA4B478D0C81BCE93815D75BC0DFEF6D2
        SHA-512:B38E72DDFA0E5DE01FCB6A2655816A9BD63960F1132D2A679FA3F4F0AA3985A6DBDBD8C2652839462D0E468EDCBBF0771B2E041E0DBCF95AF01DBBA89CC531B7
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Simplified Chinese..Translation=Ken(kycken@yahoo.com)..Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=......MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...............MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=......MainForm.CloseArchive1.Caption=......Mai
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):71426
        Entropy (8bit):4.272214609905141
        Encrypted:false
        SSDEEP:
        MD5:E73AE230FBC039A792FC38A6D924A186
        SHA1:32C51FE904B96CCB09D380E0AD25214C7DD91102
        SHA-256:49658912EBFF571FC2B6180634904AB7D90CB83C19639FF479413995246F44C6
        SHA-512:478B4EB88A761A3DF5A1D68A1A1B0926E1ECD36F092A49615CA9B499BB0FECB34704EF57F723FF8A299210DAF8C489225ECE8F23358DACD4A207A9750410B8F0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...0.:.5.4.>.=.A.:.8.....T.r.a.n.s.l.a.t.i.o.n.=.m.i.t.e.7.1.....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.>.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.!.>.7.4.0.2.0.Z.5. .=.>.2.0. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.>.@.8.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.>.@.0.Z.5. .?.>.A.B.>.5.G.:.0. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.X.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.2.0.Z.5. .4.0.B.>.B.5.:.8. .2.>. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...7.1.@.8.H.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...@.8.H.5.Z.5.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...B.?.0.:.C.2.0.X.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...B.?.0.:.C.2.0.Z.5. .4.0.B.>.B.5.:.8. .>.4. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...@.5.3.;.5.4...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72186
        Entropy (8bit):4.275483259314768
        Encrypted:false
        SSDEEP:
        MD5:179A1425CE75D75F1E4B8A8520E621EF
        SHA1:75084B67079F226DEE883829630D98F866153EA6
        SHA-256:7390747E33874C654BEA46A0A743E41330D3F5EC6F7E5C17E4106D678FD5CAF9
        SHA-512:4E583AF2B87B6A2152C0056E4FD26ECEAE448DB9B2A66D0E17D4C8400EF064F1735B75B00D9303E5B51BBB09DA5334CC283413950B07C406696441361A2BEB0D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...H.1./.......T.r.a.n.s.l.a.t.i.o.n.=.(.g.o.r.r.a.n.9.0.@.g.m.a.i.l...c.o.m.). .....1.'.F. .:...1...(.....V.e.r.s.i.o.n.=.d. ... .a. ... .g.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.F.H.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=./.1.H.3.*...1./.F... .&...1.4...A....... .F.H.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...1./.F...H.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...1./.F...H..... .&...1.4...A... .&...3.*.'.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.2...'./...1./.F.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.2...'./...1./.F... .A.'...D. .(... .F.'.H. .&...1.4...A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.3.....F...H.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.3.....F...H.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=./...1.G...F.'.F.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=./...1.G...F.'.F... .A.'...D.....'.F... .F.'.H. .&...1.4...A.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):73192
        Entropy (8bit):3.6383152167136306
        Encrypted:false
        SSDEEP:
        MD5:8D6BE8D55A175723E0A32DC55EE6389E
        SHA1:88F6115D3256CA841868DB45F3C6747644582EAF
        SHA-256:479ADF7C747416DB3C998AAC00F792F8889D3D2B1FB095215B8F697A48D5609E
        SHA-512:6CF04B264469283F1BD586F14F3988CE587E6E97125BA1B746D20DB98E6FC44B54747CA79AEF46369EFD6DC7F43C9AD508E91826818EAA065699824DA28C4A2E
        Malicious:false
        Reputation:unknown
        Preview:.. .T.r.a.n.s.l.a.t.i.o.n. .m.a.d.e. .w.i.t.h. .T.r.a.n.s.l.a.t.o.r. .1...3.2. .(.h.t.t.p.:././.w.w.w.2...a.r.n.e.s...s.i./.~.s.o.p.j.s.i.m.o./.t.r.a.n.s.l.a.t.o.r...h.t.m.l.)..... .$.T.r.a.n.s.l.a.t.o.r.:.N.L.=.%.n.:.T.B.=.%.t.........[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.e.r.b.i.a.n. .(.C.y.r.i.l.l.i.c.).....T.r.a.n.s.l.a.t.i.o.n.=.B... .J.o.t.e.v. .(.b.j.o.t.e.v.@.y.a.h.o.o...c.o.m.).....V.e.r.s.i.o.n.=.3...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.K.r.e.i.r.a.n.j.e. .n.o.v.o.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.a.r.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.a.r.a.n.j.e. .p.o.s.t.o.j.e...e.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.v.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.v.a.n.j.e. .f.a.j.l.o.v.a. .a.r.h.i.v.i.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):79822
        Entropy (8bit):3.602546837248348
        Encrypted:false
        SSDEEP:
        MD5:3D4B90085FA73FACBA260F66C105FDF4
        SHA1:625353CCC23DAA6C4CFB54DB672328CDA2BBC401
        SHA-256:12B8B6AAAE6BF6A1D861B1D89AD68AA2DE644B127EA394CA718EFF2F3B74DE00
        SHA-512:13EFD6867351559A6EFC8B08B60E1A9A0D8A21FD90D8AF93C8804C9FEB3E6B3ED16403203D9EB98DD4CF0B645B9164FC6EF535FC2D444DBF15F177277737032D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.a.t.a.l.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.P.a.u. .B.o.s.c.h. .i. .C.r.e.s.p.o. .<.p.a.u.b.c.r.e.s.p.o.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.3...8.1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .a. .a.r.x.i.u. .n.o.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.b.r.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.b.r.e. .u.n. .a.r.x.i.u. .e.x.i.s.t.e.n.t.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.f.e.g.e.i.x.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.f.e.g.e.i.x. .f.i.t.x.e.r.s. .a. .l.'.a.r.x.i.u.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.e.u.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.e.u. .f.i.t.x.e.r.s. .d.e. .l.'.a.r.x.i.u.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):75450
        Entropy (8bit):4.390962210623323
        Encrypted:false
        SSDEEP:
        MD5:273754C196D8E8817C1E678E1BD240EE
        SHA1:D4D340D2A83EFBC6024D4C42F0BAAB8D6B0A110F
        SHA-256:B7627AB556B2584BE95CA3EFBF1CB9C51CDA2437148630FDD8BDE51D23C82757
        SHA-512:5AEC57DC17EE675060AEA1DED7EF21666C88FEADD471261E1D143C1AF0AD9475E742F9346C0A3163DA003B67A97003C4FB50F200FB69BB844EBEE693D1CC4E02
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.D...".....T.r.a.n.s.l.a.t.i.o.n.=...$...4.'.1.....L. . .@.!...5...8.%.....V.e.r.s.i.o.n.=.3...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.C.+.!.H.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.*.#.I.2...@.-...*.2.#...5...-.1...C.+.!.H.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.@...4.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.@...4...@.-...*.2.#...5...-.1.....5.H.!.5.-.".9.H.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...3.@...I.2.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.@...4.H.!.D...%.L.C...@.-...*.2.#...5...-.1.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.%.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.%.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.*.H...-.-.......M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=...6...D...%.L.-.-.....2...@.-...*.2.#...5...-.1.......M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.*.3.#.'.......M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):76274
        Entropy (8bit):3.5674625988392403
        Encrypted:false
        SSDEEP:
        MD5:7D31F6D711D528404C400D0DC7456165
        SHA1:97B8DDDD8F7F316861A19139E8E7AFC87DA62010
        SHA-256:BA422E17829D9F835465CD29BA4A65D173158AE3D20DCFDE15E63A729E38A2EC
        SHA-512:EC91781D4DA6EDC32C4E78F44A150C3397F282BF1749E149D2D68F39137C3823B3D23AF982EE3E1B0D10DE6EAB84868377B76D0711A8023AF915E5D403A65592
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.a.s.t.e.l.l.a.n.o.....T.r.a.n.s.l.a.t.i.o.n.=.J.o.s... .M... .F.d.e.z.-.S.a.t.o.r.r.e. .<.j.m.@.s.a.t.o.r.r.e...e.u.>.....C.o.r.r.e.c.t.i.o.n.:.S.e.r.g.i. .M.e.d.i.n.a.....V.e.r.s.i.o.n.=.4...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=. .N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .a.r.c.h.i.v.o. .n.u.e.v.o. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.e. .u.n. .a.r.c.h.i.v.o. .c.o.m.p.r.i.m.i.d.o. .y.a. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.e. .f.i.c.h.e.r.o.s. .a.l. .a.r.c.h.i.v.o. .a.c.t.u.a.l.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .l.o.s. .a.r.c.h.i.v.o.s. .s.e.l.e.c.c.i.o.n.a.d.o.s.....M.a.i.n.F.o.r.m...t.b.E.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):66808
        Entropy (8bit):4.2388133067956275
        Encrypted:false
        SSDEEP:
        MD5:6A91B87D5EDCF48AAC55612A71B1E8C6
        SHA1:CD673F85F0EC9565E5E7142B391E4C22995BFFED
        SHA-256:1F520A0EA43845F9CB2ACFC81DE965025A54379A4591632E27B1DA9B2EDD0FD6
        SHA-512:3CD75DB705B169766F88BF5A17536E6B629FCD9E77300F28ABB596745624A26136079C94DD32860E5FDEFBD1BDEAE6B61147662A467899A5B4DC3EC8FBE757AB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.'.D.9.1.(.J.).....T.r.a.n.s.l.a.t.i.o.n.=.'.D.#.3.*.'.0. .9.H.6. .".D.-.9.'.&.6. .'.D.:.'.E./.J.....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.,./.J./.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.%.F.4.'.!. .%.1.4.J.A. .,./.J./.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.*.-.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.*.-. .%.1.4.J.A. .E.H.,.H./.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.%.6.'.A.).....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.%.6.'.A.). .E.D.A.'.*. .D.D.#.1.4.J.A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.-.0.A.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.-.0.A.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.%.3.*...1.'.,.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.%.3.*...1.'.,. .'.D.E.D.A.'.*. .E.F. .'.D.%.1.4.J.A.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.9.1.6.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.9.1.6.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77620
        Entropy (8bit):3.5689930351059145
        Encrypted:false
        SSDEEP:
        MD5:77A04A09217C143D1C0F4A06086D4855
        SHA1:75C9C598FAA987EAB3D21641DFCAEF3D5BB018E0
        SHA-256:E41D3AC59B8C450F810B2FCADF6DCFCF155CBF17C1E52835CA2E076715BB6EEB
        SHA-512:584D35B81D1B0FA6C689F7825574417850CFFE4564594E5067ED23F5396B620431FD67981F7D2946B3FADDD223230C70AF24A81E658DB3DEA05C6D05B84DB7B2
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.n.d.o.n.e.s.i.a.....T.r.a.n.s.l.a.t.i.o.n.=.N.u.r.a.h.m.a.t. .A.g.u.s.t.i.a.n.t.o.....V.e.r.s.i.o.n.=.0.3...2.0.0.7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.B.a.r.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.M.e.m.b.u.a.t. .a.r.s.i.p. .b.a.r.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.B.u.k.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.M.e.m.b.u.k.a. .a.r.s.i.p. .y.a.n.g. .s.u.d.a.h. .a.d.a.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.M.a.s.u.k.k.a.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.M.e.m.a.s.u.k.k.a.n. .b.e.r.k.a.s. .k.e. .d.a.l.a.m. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.H.a.p.u.s.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.M.e.n.g.h.a.p.u.s. .i.s.i.a.n. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.M.e.n.g.e.k.s.t.r.a.k. .b.e.r.k.a.s. .d.a.r.i. .a.r.s.i.p.....M.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):71474
        Entropy (8bit):3.7168559255201408
        Encrypted:false
        SSDEEP:
        MD5:4DB95839F5AA06A02D2B0D8B9AC0E42F
        SHA1:878C69417EB2CFEF6E93F382209DE9440D7D7895
        SHA-256:EC5E996ADC1D2BA197C247DD9BC0227E1461A038EFFFDD525E22CF5BDCD9CCB2
        SHA-512:79AF6FA7280978185A234F54757B07211D408D88A735396A758A7C913E8A7EEFF8B05EADFCEB75CE80B0CEB3F4908A1B13FE10D523CFCB09B7B868663CC26C3A
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.......T.r.a.n.s.l.a.t.i.o.n.=.O.c.c.o. .M.a.h.a.b.a.d. .(.o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.A.r._...v.e.k.e. .N... .....k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.V.e.k.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.r._...v.e.k.e. .H.e.y... .V.e.k.e. .....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L... .Z...d.e. .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.s.y.a.y... .T.e.v... .A.r._...v... .B.i.k.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.J... .B.i.b.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.J.i. .H.u.n.d.i.r... .A.r._...v... .D.o.s.y.a. .D.e.r.x.e.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.N.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):69778
        Entropy (8bit):3.6813532479991045
        Encrypted:false
        SSDEEP:
        MD5:231521907BE13DDCF185777B545C0280
        SHA1:04D609245CB23A3BBB39651C5FF33BCB78BB8F4D
        SHA-256:F64DFC5C2A930D97CE54C9A895E783B11A6F9658FE75E42BECD5C02F0B1B1DD9
        SHA-512:F55D328B6DC6EA5D3BE42D6984A1409FEA21661DAC52A597094D59A69A34E648E0E7611ECFDCC530002F5606D033AE197280AEA05801E90C2C920F80A0151ED0
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.c.e.l.a.n.d.i.c.....T.r.a.n.s.l.a.t.i.o.n.=.E.r.l.i.n.g.u.r. .J.o.n.s.s.o.n. .<.e.r.l.i.n.g.u.r.1.0.1.0.@.h.o.t.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.1...0. .B.e.t.a.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N...t.t.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.o.f.n.a. .n...t.t. .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.p.n.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.p.n.a. .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.B...t.a. .v.i.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.B...t.a. .v.i... .s.a.f.n.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.y...a.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.y...a.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.k.k.a. ...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.k.k.a. ...t. .s.k.r...m. .f.r... .s.a.f.n.i.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.S.k.o...a.....M.a.i.n.F.o.r.m.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):75112
        Entropy (8bit):3.603437804596744
        Encrypted:false
        SSDEEP:
        MD5:92D6F3904A29CD24CBECEBB1C55BE410
        SHA1:E0C5F95F1915D40E65E7DB72F8D71298969C6B89
        SHA-256:64A7769CA0C68410AF2DEE2259AC2AD3AD5F0AB36625DD62157601EC6389C449
        SHA-512:AF6728737352B311195D59B4D93235FDAEBC25EF39A870566A3E8B20B44829C112E3F416D787A0C1394C5E10880F6A1BE06D3B9FDAFA70067F864343B098DD58
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .(.P.T.).....T.r.a.n.s.l.a.t.i.o.n.=.A.n.t...n.i.o. .E.d.u.a.r.d.o. .M.a.r.q.u.e.s. .<.a.e.m.a.r.q.u.e.s.@.h.o.t.m.a.i.l...c.o.m.>. .e. .N.u.n.o. .R.e.g.o. .<.n.u.n.i.t.o...m.o.k.i.t.o.@.g.m.a.i.l...c.o.m.>.....V.e.r.s.i.o.n.=.4...1...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.i.a.r. .n.o.v.o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .a.r.q.u.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.i.c.i.o.n.a.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.i.c.i.o.n.a.r. .f.i.c.h.e.i.r.o.s. .p.a.r.a. .o. .a.r.q.u.i.v.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.A.p.a.g.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.i.r.....M.a.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77710
        Entropy (8bit):3.6485314294392848
        Encrypted:false
        SSDEEP:
        MD5:5FB3036A47BB74780FA77DF34388AD9E
        SHA1:8DAA05C9C54AE7D49CC6037D6C77040067BC7106
        SHA-256:5AC8811060318CD468222DAD984216865FBE50C7E60225D9864AF1A127690E4C
        SHA-512:9937933BC1FAA80B643EE0F382898036B3A74D997242FEB672F2D3AD72E7ED4742EEAAAED8C1E419991A5DCC651D7D531519CF57228E9039169A127012939E47
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.o.s.n.i.a.n. .(.B.o.s.a.n.s.k.i.).....T.r.a.n.s.l.a.t.i.o.n.=.F.E.D.....V.e.r.s.i.o.n.=.4...1.....[.B.o.s.n.i.a.n. .f.o.r. .I.Z.A.r.c. .4...1.].............[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.i.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.v.a.r.a.n.j.e. .n.o.v.o.g. .a.r.h.i.v.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.o.r.i. .p.o.s.t.o.j.e...i. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.D.o.d.a.j.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.D.o.d.a.v.a.n.j.e. .d.a.t.o.t.e.k.a. .u. .a.r.h.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.B.r.i.s.a.n.j.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.I.z.d.v.o.j.i.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.I.z.d.v.o.j.i. .d.a.t.o.t.e.k.e. .i.z. .a.r.h.i.v.a.....M.a.i.n.F.o.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):79752
        Entropy (8bit):3.5649943028167366
        Encrypted:false
        SSDEEP:
        MD5:661BBC05C74F58768A0551646F43FD4C
        SHA1:F9AFCEDD483BD8F2E465D31B5947F8B8655BA8D5
        SHA-256:7014E3CAB1F3A50811D89A39FEEF7B0AEA2990860547DFF11E05A78A3B3438B3
        SHA-512:C38E0C3670A5C97CFF960F667D7FDA4889DB8D63854D3E3512BC7EB8134E9C0712A3B63E57A3CE4F132355D360A6777770673D24CE3853CE65F5613E5B3F6FAB
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.p.a.n.i.s.h. .(.U.r.u.g.u.a.y.).....T.r.a.n.s.l.a.t.i.o.n.=.G.o.n.z.a.l.o. .F.e.r.r.e.i.r.a. .<.g.o.n.z.a.f.e.r.@.i.n.t.e.r.n.e.t...c.o.m...u.y.>.....V.e.r.s.i.o.n.=.3...3.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a.r. .n.u.e.v.o. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.i.r. .c.o.m.p.r.i.m.i.d.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.i.r. .a.r.c.h.i.v.o.s. .a. .c.o.m.p.r.i.m.i.d.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.B.o.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.B.o.r.r.a.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e.r. .a.r.c.h.i.v.o.s. .d.e.s.d.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):56900
        Entropy (8bit):4.544776448456302
        Encrypted:false
        SSDEEP:
        MD5:75CC94BC2E626D3AE6C4CF99803D8B18
        SHA1:D73B4901768D4A923518DDDAA0D2D8B1BF83DA90
        SHA-256:EC15EA484393CFE96EA62F8E593590EAC391685B97547E71C7606E0E4195642D
        SHA-512:23FD9646070BDD993D3F914BBE0FA2D0F4A66361189AFE8A4826D0DBE718826EE9EEDBACFC27F5D4F95842D06B20E790DAC8AAC616EB82CCC78D0C3476835424
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.o.r.e.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.S.i.n. .M.i.n.S.i.k. .(.s.i.n...m.i.n.s.i.k.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...\.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=... .U....|. ...0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.0.t. .U....|. ...0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.#.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...|.D. .U....|... .#.0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=....0.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=....0.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.U....|..... ...|. ...0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...0.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=.U....|... .... ...|. ...0.....M.a.i.n.F.o.r.m...t.b.I.n.s.t.a.l.l...C.a.p.t.i.o.n.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):71016
        Entropy (8bit):3.677226086812301
        Encrypted:false
        SSDEEP:
        MD5:A76A23B6BC1D57574EC95E76C6BF7FB1
        SHA1:F3AE884CD77E0F6FA3779C2D1CD0D05B11554A97
        SHA-256:0F75EBB230C13C4CE6D203FDA967843B2233684EFC8B810C95571F726BC6553C
        SHA-512:E7C00F5CC8F151AA1012C29661B09AE0583CDF34E6297DAC4EE312283ABF66B9F0BA5303216627794E738C4639ED81E2B8F67A625B9033833FDEC03BD035F600
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.o.m.a.n.i.a.n.....T.r.a.n.s.l.a.t.i.o.n.=.A.l.e.x.a.n.d.r.u. .B.o.g.d.a.n. .M.u.n.t.e.a.n.u. .h.t.t.p.:././.m.u.n.t.e.a.l.b...b.r.a.v.e.h.o.s.t...c.o.m./.....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.u.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.e.a.z... .o. .A.r.h.i.v... .N.o.u.......M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.D.e.s.c.h.i.d.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.D.e.s.c.h.i.d.e. .o. .A.r.h.i.v... .E.x.i.s.t.e.n.t.......M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A.d.a.u.g.......M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A.d.a.u.g... .F.i.l.e. .l.a. .A.r.h.i.v.......M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...t.e.r.g.e.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...t.e.r.g.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.g.e.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.g.e. .F.i.l.e.l.e. .d.i.n. .A.r.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72098
        Entropy (8bit):3.6261271781041784
        Encrypted:false
        SSDEEP:
        MD5:39951B0DF9613A5485CAFBD81B40A201
        SHA1:E3E26EA2FB9A5C5D08796D7D222C8F2002F962DE
        SHA-256:C731A966D48F08A87F02E2B171498E764F88794CCD6C60F20346117D5F8F2265
        SHA-512:22AF7F46793C3333FB888C90852DEC32A45E8DEDEA38272BA08258C18CCD05A3C0375720F569D2FB5B24D4AC3086077AFF2149C27FD043FC9AD9959321AE0900
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.w.e.d.i.s.h.....T.r.a.n.s.l.a.t.i.o.n.=.P.e.t.e.r. .R.u.n.e.s.s.o.n. .<.i.z.a.r.c.@.r.u.n.e.s.s.o.n...r.u.>.....V.e.r.s.i.o.n.=.4...1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.y.t.t.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.k.a.p.a. .n.y.t.t. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...p.p.n.a.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...p.p.n.a. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L...g.g. .t.i.l.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.L...g.g. .t.i.l.l. .f.i.l.e.r. .i. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.T.a. .b.o.r.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.T.a. .b.o.r.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.c.k.a. .u.p.p.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.c.k.a. .u.p.p. .f.i.l.e.r. .f.r...n. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.V.i.s.a.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
        Category:dropped
        Size (bytes):35458
        Entropy (8bit):6.17294809385724
        Encrypted:false
        SSDEEP:
        MD5:2CA5C6D630680859F86A2D2794BD18ED
        SHA1:9A4BBF8771A6ACAE2F56E2E6E3DEB3DDED9298A7
        SHA-256:48A4E02DA2DFF1337B0D1A3D38DA8A8338A70CCCEB5FDAECDA67B74A199038FD
        SHA-512:DDB91B3E93AE8074B320FD1599741C82A56C8DD037F055C736E040C677165BFB14DF9CDCCA5B538DBA500FC4D731066393BD92E0F85EC156A95201E7429ADFD8
        Malicious:false
        Reputation:unknown
        Preview:.[Info]..Language=Traditional Chinese..Translation=Ken(kycken@yahoo.com)..Version=4.0..[MainForm]..MainForm.tbNew.Caption=....MainForm.tbNew.Hint=......MainForm.tbOpen.Caption=....MainForm.tbOpen.Hint=......MainForm.tbAdd.Caption=....MainForm.tbAdd.Hint=......MainForm.tbDelete.Caption=....MainForm.tbDelete.Hint=......MainForm.tbExtract.Caption=....MainForm.tbExtract.Hint=......MainForm.tbView.Caption=....MainForm.tbView.Hint=........MainForm.tbInstall.Caption=....MainForm.tbInstall.Hint=..........MainForm.tbCheckOut.Caption=......MainForm.tbCheckOut.Hint=...............MainForm.LedRed.Hint=...........MainForm.LedGreen.Hint=.............., .........MainForm.mnFile.Caption=....MainForm.mnNew.Caption=......MainForm.mnOpen.Caption=......MainForm.CloseArchive1.Caption=......Ma
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):74130
        Entropy (8bit):3.6091352057909583
        Encrypted:false
        SSDEEP:
        MD5:7B70F96059CDB0E7A2176ABD71945CBE
        SHA1:E842F899329E961F9C79FCD9EF250400A33A094F
        SHA-256:0D567B80AD6195988B8D1D83ACA1E9FE01BF65416DA58F3A708F808981131BF0
        SHA-512:D842B856EFBF574A66D76510894DFEBBB615B52053679B8B508816A3790AD60DD0A64F2D72C28EE5A4F587AB6A46AFAEAF5CE3FC40E7D7216883F54EAB62D21D
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.N.o.r.w.e.g.i.a.n. .(.N.o.r.s.k.).....T.r.a.n.s.l.a.t.i.o.n.=.S.t.e.i.n.-.O.v.e. .B...t.h.u.n. .<.s.t.e.b.o.t.@.s.t.e.b.o.t...n.e.t.>.....V.e.r.s.i.o.n.=.3...8.1.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.y.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.O.p.p.r.e.t.t. .n.y.t.t. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...p.n.e.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...p.n.e. .e.k.s.i.s.t.e.r.e.n.d.e. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.L.e.g.g. .t.i.l.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.L.e.g.g. .t.i.l. .f.i.l.e.r. .i. .a.r.k.i.v.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.S.l.e.t.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.S.l.e.t.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.P.a.k.k. .u.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.P.a.k.k. .u.t. .f.i.l.e.r. .f.r.a. .a.r.k.i.v.e.t.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):82332
        Entropy (8bit):4.455802423614083
        Encrypted:false
        SSDEEP:
        MD5:D68A8CC8F9782BA228687A9F44F23A6F
        SHA1:CF0A0915F2EACF2F5034E2ED8E3991EF46E8FE7D
        SHA-256:2FFF4C9C7D7C8AC9D185C19F2DCC4413C155B42EE794BF86BD02F21E41F78D8B
        SHA-512:9AA42F4B06981F1CF19A3F292AEFF3521B67B663CE85E2B84A17BC66D35478FC9B00A6233A0901EF1554B43D18D6A95207868261EE7EE2707D8B1994F6A5ED87
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.H.e.l.l.e.n.i.c. .(.G.r.e.e.k.).....T.r.a.n.s.l.a.t.i.o.n.=.I.o.a.n.n.i.s. .(.P.r.o.w.l.e.r.). .Z.o.u.m.b.a.s.....V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.........................M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..................... ......................... ...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=............... ......................... ...................M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.....................M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=................. ............... ..... ....................... .................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.....................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.....................M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...................M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):77370
        Entropy (8bit):3.7438079758928153
        Encrypted:false
        SSDEEP:
        MD5:62B98BA414850D8BF457DBFD432C2A76
        SHA1:EAE1E848A57C5E5E0A5997129C4C337A8616384F
        SHA-256:BFBF96113C691BDAA546C897416896293919DF0C36AAE23ADC1641462509DF3D
        SHA-512:B0A4BD39268ACB8F44E71067455D5DFC4177362B0C006099FB8AA2AEBAA2BB9C977F0842D0D05A3EDF4FE57F31B2E7A1F2D7583BE340947D0DAEDE1795AACCD3
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.L.a.t.v.i.a.n. .(.l.a.t.v.i.e.a.u.).....T.r.a.n.s.l.a.t.i.o.n.=.A.g.r.i.s. .K.n.a.u.e.r.s.....V.e.r.s.i.o.n.=.3...1.2...8.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.J.a.u.n.s.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.I.z.v.e.i.d.o.t. .j.a.u.n.u. .a.r.h.+.v.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.t.v...r.t.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.t.v...r.t. .e.k.s.i.s.t...j.o.a.u. .a.r.h.+.v.u.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.P.i.e.v.i.e.n.o.t.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.P.i.e.v.i.e.n.o.t. .f.a.i.l.u.s. .a.r.h.+.v.a.m.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.D.z...s.t.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.D.z...s.t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.A.t.a.r.h.i.v...t.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.A.t.a.r.h.i.v...t. .f.a.i.l.u.s. .n.o. .a.r.h.+.v.a.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):72720
        Entropy (8bit):4.280644346046709
        Encrypted:false
        SSDEEP:
        MD5:63A7881572D216880919637216DAB0E5
        SHA1:5F67965549B1F193DDD806C8777C38761F6CD84B
        SHA-256:1F5970637830A67B6BA3E391269D65E2078FFB15DB20120B2ECF80E72D09E945
        SHA-512:07C04D896CE104317AB7BD167ACCDC75A246ABFEBD28EC3AB224619B1114F378CC96FB0C74BC9B09B593FCE3C8DA9A670CE3F05665B550E34577860396439F0D
        Malicious:false
        Reputation:unknown
        Preview:.. .T.r.a.n.s.l.a.t.i.o.n. .m.a.d.e. .w.i.t.h. .T.r.a.n.s.l.a.t.o.r. .1...3.2. .(.h.t.t.p.:././.w.w.w.2...a.r.n.e.s...s.i./.~.s.o.p.j.s.i.m.o./.t.r.a.n.s.l.a.t.o.r...h.t.m.l.)..... .$.T.r.a.n.s.l.a.t.o.r.:.N.L.=.%.n.:.T.B.=.%.t.........[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.e.r.b.i.a.n. .(.C.y.r.i.l.l.i.c.).....T.r.a.n.s.l.a.t.i.o.n.=.B... .J.o.t.e.v. .(.b.j.o.t.e.v.@.y.a.h.o.o...c.o.m.).....V.e.r.s.i.o.n.=.3...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=...>.2.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=...@.5.8.@.0.Z.5. .=.>.2.>.3. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...B.2.0.@.0.Z.5.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=...B.2.0.@.0.Z.5. .?.>.A.B.>.X.5.[.5.3. .0.@.E.8.2.0.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=...>.4.0.2.0.Z.5.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=...>.4.0.2.0.Z.5. .D.0.X.;.>.2.0. .0.@.E.8.2.8.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...@.8.A.0.Z.5.....M.a.i.n.F.o.r.m...t.b.D.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):67972
        Entropy (8bit):3.594786028890728
        Encrypted:false
        SSDEEP:
        MD5:945D7CDF34FFCD97EC92346555C06476
        SHA1:F48AD795BC4CAC941811B9BA48F1BA0356B98195
        SHA-256:7E349B4453EF6D2EAFB678BFA2A7B84C50033C07D9F48D40A959172F5E4AE66B
        SHA-512:7B6AC3161A31B7E49F46C7B522CB84BD3F8B1EF8D7A2BDB40F93079984A282DCD01506E912972A3333ADBC15B8B6522BDD97A8234DA0D36C056C15ECEAF8307E
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.o.s.o. .J.o.w.o.....T.r.a.n.s.l.a.t.i.o.n.=.m.a.s. .y.a.y.a.n. .(.y.a.y.a.n.p.u.j.i.@.g.m.a.i.l...c.o.m.).....V.e.r.s.i.o.n.=.4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.A.n.y.a.r.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.N.g.g.a.w.e. .a.r.s.i.p. .a.n.y.a.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.m.B.u.k.a.k.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.m.B.u.k.a.k. .a.r.s.i.p. .s.i.n.g. .w.i.s. .o.n.o.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.N.a.m.b.a.h.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.N.a.m.b.a.h. .f.i.l.e. .n.i.n.g. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.m.B.u.s.a.k.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.m.B.u.s.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.n.g.E.k.s.t.r.a.k.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.n.g.E.x.t.r.a.k. .f.i.l.e. .s.o.k.o. .a.r.s.i.p.....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):64710
        Entropy (8bit):4.484324297779564
        Encrypted:false
        SSDEEP:
        MD5:DBD92F73A4E67842BA0CCE7333079EF7
        SHA1:94A173C5776BB9B719CA16D5C0C6B5A530DA6FE7
        SHA-256:442980D4DA69281ECABE9E26690955F42248CB75D3FF55BEAB96E9441D7DF62A
        SHA-512:A55E44009665369FDAD2A1676DC21EDB1EDFE8CAAE60E38E3527DD6E44323FE9B261FB91A461065399CB3EC4C540982045583D96AB9B0B66630DBBFC8E769147
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.J.a.p.a.n.e.s.e.....T.r.a.n.s.l.a.t.i.o.n.=.c.h.i.n.Q. .(.c.h.i.n.Q.@.b.a.s.i.l...f.r.e.e.m.a.i.l...n.e...j.p.).....V.e.r.s.i.o.n.=.3...4...1...5.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=..e......M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..eW0D0.f.^.0\O.bW0~0Y0....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=...O0....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=..eX[n0.f.^.0..M0~0Y0....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=....R....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=..f.^k0.0.0.0.0.0...R'W.~W0~0Y0....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.JRd.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.JRd.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...Q....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=..f.^K0.0.0.0.0.0.0..QW0~0Y0....M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=.........M.a.i.n.F.o.r.m...t.b.V.i.e.w...H.i.n.t.=..f.^k0<h.}U0.0f0D0.0.0.0.0.0.0....W0~0Y0....M.a.i.n.F.o.r.m...t.b.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):73622
        Entropy (8bit):3.55373073443454
        Encrypted:false
        SSDEEP:
        MD5:7BB308AB48959363EBC8F6AA92403CC1
        SHA1:02B04F96BC5345DE2F2A528995384CACFFCC4679
        SHA-256:C5F864CBE68A49D206142CF78B4C6B39CFBA3B43F850DA4251F530BC32F072BE
        SHA-512:5519F820E5E40F546F282116A1A0DF0A96C8841E8D47DD1198A488B3EAF9540241B5DADC721FE44FA4A4B6B48F92A81329CDCC41733DB86D726B1C912A847986
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l.....T.r.a.n.s.l.a.t.i.o.n.=.V.i.c.t.o.r. .E.m.m.a.n.u.e.l.,. .v.i.c.o.k.o.b.y.@.g.m.a.i.l...c.o.m.....V.e.r.s.i.o.n.=.4...1...7.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.u.e.v.o.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.C.r.e.a. .u.n. .n.u.e.v.o. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.A.b.r.i.r.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.A.b.r.e. .u.n. .a.r.c.h.i.v.o. .e.x.i.s.t.e.n.t.e.....M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.A...a.d.i.r.....M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=.A...a.d.e. .f.i.c.h.e.r.o.s. .a.l. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=.E.l.i.m.i.n.a.r.....M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=.E.l.i.m.i.n.a. .f.i.c.h.e.r.o.s. .d.e.l. .a.r.c.h.i.v.o.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=.E.x.t.r.a.e.r.....M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=.E.x.t.r.a.e. .f.i.c.h.e.r.o.s. .d.e.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF, CR line terminators
        Category:dropped
        Size (bytes):76182
        Entropy (8bit):3.6207033887902766
        Encrypted:false
        SSDEEP:
        MD5:DEE3B1EF18FD88C9FFBA029D0F6A4F84
        SHA1:0C006DFD5EF0945D4AED62FDC06521149B713479
        SHA-256:9C70A7CD7BA4CC8DEE94FC041B312588B7CEEEC59F0FD4CB3BAA0DB3C0E133D0
        SHA-512:66F28D215A60C79BB39FE1FA0E7E48D34EA23F91305338B94B11D9ACF28E89D8357F68D3EA54205EA8B14A9E809607D065BF7A756B052FE42CF7D8D6971612A2
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.C.r.o.a.t.i.a.n. .(.H.r.v.a.t.s.k.i.).....T.r.a.n.s.l.a.t.i.o.n.=.S.t.e.v.a.n. .G.r.u.b.i.......V.e.r.s.i.o.n.=.1...0.....[.C.r.o.a.t.i.o.n. .f.o.r. .I.Z.A.r.c. .3...8.1. .(.B.u.i.l.d. .1.5.5.0.).].............[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=.N.o.v.a.....M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=.S.t.v.a.r.a. .n.o.v.u. .a.r.h.i.v.u.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.O.t.v.o.r.i.....M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=.O.t.v.a.r.a. .p.o.s.t.o.j.e...u. .a.r.h.i.v.u.....M.a.i.n.F.o.r.m...t.b.F.a.v.o.r.i.t.e.s...C.a.p.t.i.o.n.=.O.m.i.l.j.e.n.i. .d.i.r.......M.a.i.n.F.o.r.m...t.b.F.a.v.o.r.i.t.e.s...H.i.n.t.=.P.o.p.i.s. .a.r.h.i.v.a. .u. .V.a.a.i.m. .o.m.i.l.j.e.n.i.m. .d.i.r.e.k.t.o.r.i.j.i.m.a.....M.a.i.n.F.o.r.m...t.b.P.r.o.p.e.r.t.i.e.s...C.a.p.t.i.o.n.=.S.v.o.j.s.t.v.a.....M.a.i.n.F.o.r.m...t.b.P.r.o.p.e.r.t.i.e.s...H.i.n.t.=.P.r.i.k.a.z.u.j.e. .s.v.o.j.s.t.v.a. .a.r.h.i.v.e.....M.a.i.n.F.o.r.m.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [MainForm]
        Category:dropped
        Size (bytes):39570
        Entropy (8bit):5.291961005261564
        Encrypted:false
        SSDEEP:
        MD5:A8A1C840DF9363A30884EA0A1BFE0D1C
        SHA1:3CEC0B1D09C3B5961B0C0293CCC56CE9D4DA542C
        SHA-256:CAD586B60CB607C0721E05CB074FA82E56C6A71E143AA88BB5685C8BD3473890
        SHA-512:99A48C90BFCCA75D4C1C385D944FC9715E1EEDE9811A27A829EAAAF25344ED55FC76716DA0BEABE01874F09ED17635901D395A59992C309AD14BBFB72BC2E481
        Malicious:false
        Reputation:unknown
        Preview:[Info]..Language=Lithuanian (Lietuvi.)..Translation=Giedrius Naud.i.nas <gimp@projektas.lt>..Version=3.4.1.3..[MainForm]..MainForm.tbNew.Caption=Naujas..MainForm.tbNew.Hint=Sukurti nauj. archyv...MainForm.tbOpen.Caption=Atverti..MainForm.tbOpen.Hint=Atverti esam. archyv...MainForm.tbAdd.Caption=.traukti..MainForm.tbAdd.Hint=.traukti bylas . archyv...MainForm.tbDelete.Caption=Trinti..MainForm.tbDelete.Hint=Trinti archyv...MainForm.tbExtract.Caption=I.spausti..MainForm.tbExtract.Hint=I.spausti bylas i. archyvo..MainForm.tbView.Caption=Per.i.ra..MainForm.tbView.Hint=Per.i.r.ti byl. archyvo viduje..MainForm.tbInstall.Caption=Paleisti.....MainForm.tbInstall.Hint=Paleisti program. i. archyvo.....MainForm.tbCheckOut.Caption=Valdymas..MainForm.tbCheckOut.Hint=.traukti programin. grup. . meni. "Visos programos" su byl. i.spaudimu i. archyvo . laikin.j. aplankala ir .enkliuk. sukurimu...MainForm.LedRed.Hint=Spragtel.kite jei norite baigti .. veiksm....MainForm.LedGreen.Hint=B.senos indikatorius:
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
        Category:dropped
        Size (bytes):75134
        Entropy (8bit):4.279737202687828
        Encrypted:false
        SSDEEP:
        MD5:3222AD02502F6BE24D3D1E143778BA4D
        SHA1:0DA9488CF6FF172D4A9298745B4214CE5D0E15A4
        SHA-256:712A539CA8CA619C6F3AFC8A7511933A9899E1536565991F2836468729BBF391
        SHA-512:3C5097E9D1AE85FB1CCDF4BE1DC8DA82476187ECEB5EFD5C906FDE0E4102F368AD4752E50D8F967AE892618B5EF567541429FDFF08217D9F4A5D951D3F193F04
        Malicious:false
        Reputation:unknown
        Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.....................T.r.a.n.s.l.a.t.i.o.n.=............... ..................... .-. .............V.e.r.s.i.o.n.=.3...4...1...6.....[.M.a.i.n.F.o.r.m.].....M.a.i.n.F.o.r.m...t.b.N.e.w...C.a.p.t.i.o.n.=....... .................M.a.i.n.F.o.r.m...t.b.N.e.w...H.i.n.t.=..................... ......... ...................M.a.i.n.F.o.r.m...t.b.O.p.e.n...C.a.p.t.i.o.n.=.................M.a.i.n.F.o.r.m...t.b.O.p.e.n...H.i.n.t.=............. ....... ............... .................M.a.i.n.F.o.r.m...t.b.A.d.d...C.a.p.t.i.o.n.=.............M.a.i.n.F.o.r.m...t.b.A.d.d...H.i.n.t.=......... .................M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.D.e.l.e.t.e...H.i.n.t.=...............M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.E.x.t.r.a.c.t...H.i.n.t.=........... .................M.a.i.n.F.o.r.m...t.b.V.i.e.w...C.a.p.t.i.o.n.=...............M.a.i.n.F.o.r.m...t.b.V.i.e.w...
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 12 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B5F7F2914A7E7266641BA6727E39F749
        SHA1:9E2636B7835F99E9B1A79431370D6424DB73D1F2
        SHA-256:92FCAF10F58821F8FEE0B9E729B8D5A29313640D73A00AEFB8DDB7713A91A552
        SHA-512:2372C58C508599AADC66390ED46213939A7C74E678473E3E847EFB434E2EDDF792F848A14723BBC91CC165B42EFA89136FBA145C4EDE2FB1E2EAC3DAC55A00D6
        Malicious:false
        Reputation:unknown
        Preview:..............OW......00......h....X.. ..........}^..........(...ea...............b..00.............. ......................h...n$........ .l....)..00.... ..%..B... .... ............... .h....&...PNG........IHDR.............\r.f.. .IDATx..}m..8.l..YH...Y.. vrg%#.{%..(..TJ.....Cv.....+2#?...#...)......K>'.....,.....,.....,.....Xc..W;J}|..K.WnW...#......sL...O.y...>=.K......x.a%.....x<p..,.S..1..4.~........t.t).....)...c.....,.Lo...Y...R.'r).....|.....}o..@ee[.m..mO.<.>............R....Xm....Y..../..%...k...Tm........|.j...q.{.G,}....0.<....[..K1.^~......}.=2.{>..#V.....u.....3.J..P..Bh...........n.1J..@.wn{.A....1.sw._...P,..6~.....i_...,.......G......d.(=..T.2..l.R.}9.....r.Q.xm...m.....8.[{2..F.....v..A...Yy&.......^E....o_.....z.b..u.:..].....#..d.X9j.Z.y[............}.5.......#.rT..m...|..@..=.../.E>...oU}x....m..H.v_..^..yG.y..5...g..w.......{..[..-k....O..&.[..l..M..([.x.{..n.qTq.......=..w......w.Y...;......|..."....=...G,..S8.U^#...W.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6B876F377C0BCE233BEE634EDCA9A209
        SHA1:A9AF4CF8CD063B404A1F4776D87F92F09CA6BF0D
        SHA-256:4DC2EC12452F697397F2173712689B9842C8574B6ADA91DC5031146B35D7560B
        SHA-512:65A21971B65F57160B1D3B9616799356C53C699C80174CB6C85A406ACD2C468AE867132319BB8B95565132185360B865981196724F583CF6F10AEDA4471586AF
        Malicious:false
        Reputation:unknown
        Preview:..............(...............h....... ..........&... ..............00......h.......00.................... .h....'.. .... ......,..00.... ..%...<..(....... .........................................................................................................wp.wp..........."x..p...z...p...x.......x.p........p...x................ww...........wwwwp..x...............wwwwww......x...............x...............x...............x.........(....... ...........@................................................|~......................................................................................................................||..................cc.`II..ii..........}}.N>>.........tt.....oZZ.|ee.=22.;11.............................................^]].................................................t.843.............qfb..................................................................]..............BA@...h....................P..Q...^...v..m......
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 9 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
        Category:dropped
        Size (bytes):25214
        Entropy (8bit):5.8394872704745655
        Encrypted:false
        SSDEEP:
        MD5:6B876F377C0BCE233BEE634EDCA9A209
        SHA1:A9AF4CF8CD063B404A1F4776D87F92F09CA6BF0D
        SHA-256:4DC2EC12452F697397F2173712689B9842C8574B6ADA91DC5031146B35D7560B
        SHA-512:65A21971B65F57160B1D3B9616799356C53C699C80174CB6C85A406ACD2C468AE867132319BB8B95565132185360B865981196724F583CF6F10AEDA4471586AF
        Malicious:false
        Reputation:unknown
        Preview:..............(...............h....... ..........&... ..............00......h.......00.................... .h....'.. .... ......,..00.... ..%...<..(....... .........................................................................................................wp.wp..........."x..p...z...p...x.......x.p........p...x................ww...........wwwwp..x...............wwwwww......x...............x...............x...............x.........(....... ...........@................................................|~......................................................................................................................||..................cc.`II..ii..........}}.N>>.........tt.....oZZ.|ee.=22.;11.............................................^]].................................................t.843.............qfb..................................................................]..............BA@...h....................P..Q...^...v..m......
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows icon resource - 12 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
        Category:dropped
        Size (bytes):142074
        Entropy (8bit):7.724480674349337
        Encrypted:false
        SSDEEP:
        MD5:B5F7F2914A7E7266641BA6727E39F749
        SHA1:9E2636B7835F99E9B1A79431370D6424DB73D1F2
        SHA-256:92FCAF10F58821F8FEE0B9E729B8D5A29313640D73A00AEFB8DDB7713A91A552
        SHA-512:2372C58C508599AADC66390ED46213939A7C74E678473E3E847EFB434E2EDDF792F848A14723BBC91CC165B42EFA89136FBA145C4EDE2FB1E2EAC3DAC55A00D6
        Malicious:false
        Reputation:unknown
        Preview:..............OW......00......h....X.. ..........}^..........(...ea...............b..00.............. ......................h...n$........ .l....)..00.... ..%..B... .... ............... .h....&...PNG........IHDR.............\r.f.. .IDATx..}m..8.l..YH...Y.. vrg%#.{%..(..TJ.....Cv.....+2#?...#...)......K>'.....,.....,.....,.....Xc..W;J}|..K.WnW...#......sL...O.y...>=.K......x.a%.....x<p..,.S..1..4.~........t.t).....)...c.....,.Lo...Y...R.'r).....|.....}o..@ee[.m..mO.<.>............R....Xm....Y..../..%...k...Tm........|.j...q.{.G,}....0.<....[..K1.^~......}.=2.{>..#V.....u.....3.J..P..Bh...........n.1J..@.wn{.A....1.sw._...P,..6~.....i_...,.......G......d.(=..T.2..l.R.}9.....r.Q.xm...m.....8.[{2..F.....v..A...Yy&.......^E....o_.....z.b..u.:..].....#..d.X9j.Z.y[............}.5.......#.rT..m...|..@..=.../.E>...oU}x....m..H.v_..^..yG.y..5...g..w.......{..[..-k....O..&.[..l..M..([.x.{..n.qTq.......=..w......w.Y...;......|..."....=...G,..S8.U^#...W.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:DDBB86C4D135AFD74C13457377B396A3
        SHA1:EFD09BAE2789647E4C246A0A556F2347B5F4FA14
        SHA-256:118E2A4573E2810A37081507B6D7E2B666343E736D79CCA6BE9C964718951EF7
        SHA-512:C8536F44442EB2C4F7BD2F6509B1B42552AE8840026B10769703A2E4FEFF97A8447119D6835107B22C27EEBBE502F96787F4DCCA78DF388010CC1DC1999845B8
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................Z...".......e.......p....@.......................... ...................@......................................,...........................................................................................................CODE.....X.......Z.................. ..`DATA.........p.......^..............@...BSS.....@@...........`...................idata...............`..............@....tls.................h...................rdata...............h..............@..P.reloc...............j..............@..P.rsrc...,............p..............@..P............. ......................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A3756D8BE4E46F606DAF8F5909C4AEBD
        SHA1:FC7A5DCE902D5E4FD61D2C27759A91B998078A2F
        SHA-256:45353A89A696963E8B2E154236C9181E9CF39C80AB4F73C2665E4EA041912422
        SHA-512:12266F5C2DA0195B8B9158C7576CC7A7877C4544A4383FD813E5539403FCF5C5BC128886FF4ACD0A3F55CC75F09009C98FA182EF16C2C041F627247B32B5AA69
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................h...$......Tu............@..........................0...................@................................... ..4...........................................................................................................CODE.....g.......h.................. ..`DATA.................l..............@...BSS.....t@...........n...................idata...............n..............@....tls.................v...................rdata...............v..............@..P.reloc...............x..............@..P.rsrc...4.... ......................@..P.............0......................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:E921B65B66F927E82694559FB70FD8DF
        SHA1:4F444A67F6A0EB7D99CF86E352B157048F076F22
        SHA-256:3468DD80783D7B24B99E22D7B9360AE098B32F7B973A15F0CAE1EC53A4DCF8C2
        SHA-512:F8FC0D2C710FBB567BD0FBF129C4F32D71B009BC3BA6356888FA84AEF71C0AF13C9609DFE4E5CF2AD44123B278E49171655C2154C1CDA9E6CDE436069F8CF621
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................^...".......j.......p....@..............................................@......................................L...........................................................................................................CODE.....].......^.................. ..`DATA.........p.......b..............@...BSS.....X............d...................idata...............d..............@....tls.................l...................rdata...............l..............@..P.reloc...............n..............@..P.rsrc...L............t..............@..P....................................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:C28C2A50EB2D0C6B3D19714DF7F363FB
        SHA1:6161655C444D89535818C25E978D39875318E391
        SHA-256:7BE39D6F43386102848B4D0A702618E55D7E0E4993DC422F3676D193157DE6FE
        SHA-512:1C5A3544CED839AEC4F6EB2B1B97171734129269A444621265EC913B01E65A4CE79A0990F03FB2A939259C1DC1F3889D2D8F1271AB22B9798967598ED77943E6
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................V...".......b.......p....@.......................... ...................@......................................4...........................................................................................................CODE.....U.......V.................. ..`DATA.........p.......Z..............@...BSS.....$@...........\...................idata...............\..............@....tls.................d...................rdata...............d..............@..P.reloc...............f..............@..P.rsrc...4............l..............@..P............. .......|..............@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:8BA6C47D7B56313A2C9F0052EEE20D1D
        SHA1:CA2B6410AB0AA9C50B1DD610B00108FE596517D6
        SHA-256:DFDD28782ACDAAAE3EC5A025116908B357801B6C2D87203B79CCA5782B513D76
        SHA-512:F007B0FA880E5C256792994AEE8326C87C38C7D00F25873971BFDE0C6A5D3988BDD6666EC5226B69DBE3A4184292017B26C95546169893E777D398762C46C751
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 4%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................................................................................................................................................................................................................................................................................PE..L....K.E.................0...r...............@....@.............................................. ......................................r<...........................................................................................................text....0.......................... ..`.data....p...@.......4..............@....idata...............>..............@..@.rsrc...r<.......>...N..............@..@................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:4234AB62EA6ACBB244B6EF6EA8DC3729
        SHA1:19B9B39AA81C0367A7C538FB8FD966A447CDCFDC
        SHA-256:F26A05BAED525A6FDE41F179BAAACB8F648B227D14F0BD6164DB61D0B2C8A2C0
        SHA-512:B176CC8529EE5388E66D9195C2F1F44B422012B532E074106D3D3746F905825B34D4333E0651E1F3D70D2D2F7D9A21DC97B2F80C417D770F64857E891D6E40D2
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........%K..D%..D%..D%..[...D%.YX+..D%..[/..D%..[!..D%.TLz..D%..D$.~D%.YLx..D%..b...D%...X..D%..b/..D%..B#..D%.Rich.D%.........PE..L...18YF.........................................@......................................................................................6...........................................................................................................text............................... ..`.rdata...R.......T..................@..@.data....z... ......................@....rsrc....6.......8..................@..@........................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:7EE8F6D83BD0581F2C4A25194532A297
        SHA1:4AF186A39F102E0276F58A9475587664F59A6E60
        SHA-256:9096E13F8A1206C57020A7909C1D17E20A1B00FF68F919D3893397AD7D55B5E8
        SHA-512:2661033D7548CE1EC57241007A76B43821964011802435794E19C081DA6912E24217DAF12060C2E1B7027E808C92B5D828B827AA6F6A398F36E35D3360005FAA
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 2%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...j..H.....................L......$.............@..............................................@...................................P..^1...................@...............................0......................p................................text............................... ..`.itext.............................. ..`.data...(...........................@....bss....l0...............................idata..............................@....tls......... ...........................rdata.......0......................@..@.reloc..4....@......................@..B.rsrc...^1...P...2..................@..@.............`......................@..@................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):146944
        Entropy (8bit):6.192569358104895
        Encrypted:false
        SSDEEP:
        MD5:4234AB62EA6ACBB244B6EF6EA8DC3729
        SHA1:19B9B39AA81C0367A7C538FB8FD966A447CDCFDC
        SHA-256:F26A05BAED525A6FDE41F179BAAACB8F648B227D14F0BD6164DB61D0B2C8A2C0
        SHA-512:B176CC8529EE5388E66D9195C2F1F44B422012B532E074106D3D3746F905825B34D4333E0651E1F3D70D2D2F7D9A21DC97B2F80C417D770F64857E891D6E40D2
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........%K..D%..D%..D%..[...D%.YX+..D%..[/..D%..[!..D%.TLz..D%..D$.~D%.YLx..D%..b...D%...X..D%..b/..D%..B#..D%.Rich.D%.........PE..L...18YF.........................................@......................................................................................6...........................................................................................................text............................... ..`.rdata...R.......T..................@..@.data....z... ......................@....rsrc....6.......8..................@..@........................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):36864
        Entropy (8bit):6.33082633330158
        Encrypted:false
        SSDEEP:
        MD5:A3756D8BE4E46F606DAF8F5909C4AEBD
        SHA1:FC7A5DCE902D5E4FD61D2C27759A91B998078A2F
        SHA-256:45353A89A696963E8B2E154236C9181E9CF39C80AB4F73C2665E4EA041912422
        SHA-512:12266F5C2DA0195B8B9158C7576CC7A7877C4544A4383FD813E5539403FCF5C5BC128886FF4ACD0A3F55CC75F09009C98FA182EF16C2C041F627247B32B5AA69
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................h...$......Tu............@..........................0...................@................................... ..4...........................................................................................................CODE.....g.......h.................. ..`DATA.................l..............@...BSS.....t@...........n...................idata...............n..............@....tls.................v...................rdata...............v..............@..P.reloc...............x..............@..P.rsrc...4.... ......................@..P.............0......................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):59392
        Entropy (8bit):6.039974770680328
        Encrypted:false
        SSDEEP:
        MD5:7EE8F6D83BD0581F2C4A25194532A297
        SHA1:4AF186A39F102E0276F58A9475587664F59A6E60
        SHA-256:9096E13F8A1206C57020A7909C1D17E20A1B00FF68F919D3893397AD7D55B5E8
        SHA-512:2661033D7548CE1EC57241007A76B43821964011802435794E19C081DA6912E24217DAF12060C2E1B7027E808C92B5D828B827AA6F6A398F36E35D3360005FAA
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...j..H.....................L......$.............@..............................................@...................................P..^1...................@...............................0......................p................................text............................... ..`.itext.............................. ..`.data...(...........................@....bss....l0...............................idata..............................@....tls......... ...........................rdata.......0......................@..@.reloc..4....@......................@..B.rsrc...^1...P...2..................@..@.............`......................@..@................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):33792
        Entropy (8bit):6.250732064867198
        Encrypted:false
        SSDEEP:
        MD5:E921B65B66F927E82694559FB70FD8DF
        SHA1:4F444A67F6A0EB7D99CF86E352B157048F076F22
        SHA-256:3468DD80783D7B24B99E22D7B9360AE098B32F7B973A15F0CAE1EC53A4DCF8C2
        SHA-512:F8FC0D2C710FBB567BD0FBF129C4F32D71B009BC3BA6356888FA84AEF71C0AF13C9609DFE4E5CF2AD44123B278E49171655C2154C1CDA9E6CDE436069F8CF621
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................^...".......j.......p....@..............................................@......................................L...........................................................................................................CODE.....].......^.................. ..`DATA.........p.......b..............@...BSS.....X............d...................idata...............d..............@....tls.................l...................rdata...............l..............@..P.reloc...............n..............@..P.rsrc...L............t..............@..P....................................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):101376
        Entropy (8bit):6.23792412051907
        Encrypted:false
        SSDEEP:
        MD5:8BA6C47D7B56313A2C9F0052EEE20D1D
        SHA1:CA2B6410AB0AA9C50B1DD610B00108FE596517D6
        SHA-256:DFDD28782ACDAAAE3EC5A025116908B357801B6C2D87203B79CCA5782B513D76
        SHA-512:F007B0FA880E5C256792994AEE8326C87C38C7D00F25873971BFDE0C6A5D3988BDD6666EC5226B69DBE3A4184292017B26C95546169893E777D398762C46C751
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................................................................................................................................................................................................................................................................................PE..L....K.E.................0...r...............@....@.............................................. ......................................r<...........................................................................................................text....0.......................... ..`.data....p...@.......4..............@....idata...............>..............@..@.rsrc...r<.......>...N..............@..@................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):32768
        Entropy (8bit):6.166113224818328
        Encrypted:false
        SSDEEP:
        MD5:DDBB86C4D135AFD74C13457377B396A3
        SHA1:EFD09BAE2789647E4C246A0A556F2347B5F4FA14
        SHA-256:118E2A4573E2810A37081507B6D7E2B666343E736D79CCA6BE9C964718951EF7
        SHA-512:C8536F44442EB2C4F7BD2F6509B1B42552AE8840026B10769703A2E4FEFF97A8447119D6835107B22C27EEBBE502F96787F4DCCA78DF388010CC1DC1999845B8
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................Z...".......e.......p....@.......................... ...................@......................................,...........................................................................................................CODE.....X.......Z.................. ..`DATA.........p.......^..............@...BSS.....@@...........`...................idata...............`..............@....tls.................h...................rdata...............h..............@..P.reloc...............j..............@..P.rsrc...,............p..............@..P............. ......................@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):31744
        Entropy (8bit):6.199567638892622
        Encrypted:false
        SSDEEP:
        MD5:C28C2A50EB2D0C6B3D19714DF7F363FB
        SHA1:6161655C444D89535818C25E978D39875318E391
        SHA-256:7BE39D6F43386102848B4D0A702618E55D7E0E4993DC422F3676D193157DE6FE
        SHA-512:1C5A3544CED839AEC4F6EB2B1B97171734129269A444621265EC913B01E65A4CE79A0990F03FB2A939259C1DC1F3889D2D8F1271AB22B9798967598ED77943E6
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................V...".......b.......p....@.......................... ...................@......................................4...........................................................................................................CODE.....U.......V.................. ..`DATA.........p.......Z..............@...BSS.....$@...........\...................idata...............\..............@....tls.................d...................rdata...............d..............@..P.reloc...............f..............@..P.rsrc...4............l..............@..P............. .......|..............@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:18CC7E0E05AEC44396F09DCA56BFE7CD
        SHA1:3A41DF0F04804FE27D0BDCA430FF861EF1165595
        SHA-256:7634B05B4DE3CD3DC191BF3807BA826E7FB28F8AB45BC919135E638811A68A51
        SHA-512:6CD4BE216AD5BAB2BD08DAADCB85E8231AACF309355C99C577A2D14EB09876B722CC98A7EC9D04F6B04C54779FF6863B2E7F508BABA47BAC00BE0C3707C56D83
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D5C4B1EBF011F9D3ACD7167B5D51BB2C
        SHA1:F81ABC4E2E0C6503A0A72ED267E8A3C2B3A517E6
        SHA-256:1A9F7B2F9D1F14E55D6383216B67765CF99339E95D54993FECCEB9DBF136C877
        SHA-512:827AE94D8842EEF5EC92F6760DE4DAEDC5A25CDD856D6EEF6A5C68B613E915F7A93C2DC508985B9F46C196114BF9B23B005DE24B82338E6A6D737EA701D2DEB8
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... .............................................................................................................................................................................................................. 0..................`/.. 0.. 0.. 0.. 0.. 0.. 0..`/.......... 0........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55298, resolution 2834 x 2834 px/m, cbSize 55352, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:829F2C34B920789D36ABA057B125DEEC
        SHA1:5F2B389B352B96C2A54C2BAC6673DAD57A63EC2D
        SHA-256:03572F8811053F43BA9551E5F7540EA7C1D632D2B106475C36EFC72C61DAF9E0
        SHA-512:5DA8F07D643CF8B36563802D8BBB90E19C9E1A0306782FECD35FE00C4F66AF38F786730EFB720AF2305EB77208CD2E8C7BC8C2E65FD9689ED58812B19650D138
        Malicious:false
        Reputation:unknown
        Preview:BM8.......6...(...@... ........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................:::oqr........................................................................................................................................................................YZ[UVVEEFSTTZ[[opq.........................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 2835 x 2835 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:19D6895A0D7078832D4E101E75FEAE52
        SHA1:23B710D7699D44FE6D49F1EFA8977759BC9E1204
        SHA-256:A99FF93265084A431F237C94F5915256A1DE916C74AA48611AFB6AAA9D4510FD
        SHA-512:4981231AD2E2573E56866F7205BB4F803998C516B7770C4C72382AD5BD1B183180A309C85ABACFEF22D4D040B9DF7F4C587F9D7E01259F0AC1722109CA2B5514
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ................................................................{{{ccccccZZZRRRRRRJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ................k!s9..J..B..B.{9.{9.s9.s9.s1.s1.s1.s1.s1.s1.s1.s1.s1.k1.k1.k1.k1.k).k).k).c).c).c).c).c).J!.B!........................................................................................................................................................................................................................{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{....................................................{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{.....................................................................................................................kkk...kkkJJJJJJJJJJJJRRRJJJJ1....JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ.................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:14844441468EDF2C12DFE7A59EC20B76
        SHA1:CEED3664811A26C1424DB30F3581815927E85C2C
        SHA-256:CC466122B23884745A4B259BA94F446F48D135C33C0AD65254499E932516C8F2
        SHA-512:21DE469358750F828530C98F54E3DEF976C70AB410DDE264FD7FBD431F4E1A2DB7151AD3052C919068DB8EEA388646273D2ECD8AD06C3A5B8367CBA4D9285525
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ............................................................................................................................................................................................z...............................................................................................................................y.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 7874 x 7874 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:1CCDD9FB6B5EF26AAA84BE1FC09A9A38
        SHA1:BEDF56F65A70BE0161F3EE83334BEFA5614D07FC
        SHA-256:607D1651D7AAC37A44A00B4DB721AF196EFF99EE65BF7600685AF0561CB045C7
        SHA-512:3834318FE60984C5C0E2346B058819D07C4CBDBC74C57B483F2D60E46132B74A6AB8D0448931C94FB60677BBF2EA0431604B9D23114C1F407D32F119D9A3A1D6
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:4A8B44F768BABBC7C8D0ECB78067B13D
        SHA1:D42602FA141FE3E621EFA3A62360EEA96257120C
        SHA-256:4D8437882EE841993618D0FADD216C39C3C9F7164FBC6EE54C2BA09FFD53CA5C
        SHA-512:FBE5DFDE9E027F0664E4C4370CDA1EB965CA3FC3148BEECAAB04CAD89096A432E664E0126F7CAD6D477890A5CE183D3F474ACD50428E65CCD1878182191D5767
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................@H@.............................................................................................@H@........................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:FC6BFF5E1F8C1792ACD2A0657A67A37B
        SHA1:8ABA8D70BB63F96CB68C5A00BA1BC3D7B1E1BA96
        SHA-256:AD6EC04A8F27CA37D2382C3178690F93C7276656FC90F9C5C576257E74CC6251
        SHA-512:E15EE5BE5795BD90722CB07C8DE232E8421E20AC49224D5A80BA25E9C8C0C0AB3FBDA5B557A93E8354EE98C668D93C2526C1D5255FBE2E24AF69442E15858EBD
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:07E86923C827D99F9B222E5E5B65F8E4
        SHA1:1A9B69B59344DDEA8239377380A465D2E7EDF1EA
        SHA-256:FEC37BFB96446FD18FE553BB328D2070C92637B59E95669AB804844AFE9210EC
        SHA-512:1476D641A437E5297980222B84B9B772880CBEE8DAB25B18D40AE9B0D2FE63B901186FEBC8D112799C45DDFF35C8486CBCF3B364473610E429A0C51EE88ACEEB
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ..........................................................................................................................................................................................................................................................................................Z.. .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................jej.ab{ajs]b............................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:488EE583FA8644EB53D42E524F0F53A3
        SHA1:59318DEEC4520887C0DBDACAB5629221D2B22877
        SHA-256:C05FD76D263A5FA99AE3858E2755D0B991166C8EB80974632BA1CABEAF6BB574
        SHA-512:22B8211569DD355833EE59F07E06461ABD96CFA2FDEC01CB16B632FEBCEAE0C6E9E7B640A4EA64CB491F511A6C6E6B4A1E0650E0178DD850D3C89EE414B207D5
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................|||.|||.~~~...........................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F00145A9D1956C2629BBC59CA4DABEA8
        SHA1:C09B2E9BBB877952E1C7CD7C363560B0DE622AA0
        SHA-256:32CCEFD3711E6E125602ED66637642FE9892D17338CFF63036A0111F0FD07922
        SHA-512:D2CE0178828175C9231A2BD39B94DF1FD91CD753D8E8F1A14A53C031C7A48350E593389D45FA7078CE4AD32976904E2C5A708DF939D8C5F77B03B238E47913C8
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................gt........................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 7874 x 7874 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F0E86D86C72273CFA827066BB4F2BD4C
        SHA1:249EFEB2DBAAA77240C6545D11769FEF2EEFB732
        SHA-256:8AF4DC270AF6FA954AC4A1844C756F5E513121FBCADC734B3D46FC2A8C2B32C7
        SHA-512:6651B237B3BD290892720762C95EFAC423DC26F85D88CC010D105FB4B76B3CFC642F10D5DF631C5F6DE4E22457E009D8F5BD1F707A6FDD394EDEAC31CB4CEB0B
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:18E2AC5502871C5D5992ED7811450639
        SHA1:79E0F85D6BAA66290228D98335597C8ADAEA75D2
        SHA-256:8A280D8B87C8081C27B572026CFFAA0CC219903AA2DC0138AB3B96FEE7570D56
        SHA-512:63EC5BAD42C2AE88DD590E5897BD2392B9CBA8A9B3A5640A0AF054CB84CBFDF23D9131F713ACDE0AB8ACCFAFE148603CDAE5CC8512EC0F6275CD09CC4AF4056F
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..................................................................................................................................................................s...JZZ.RRR.sss.sss.sss.................................................................................................................................................................................................................................................pho.pXP.pXP..`_..`_..X_.pXP.`PP.PPO.PPP.oho......................................................................................................................................................................................................ss.scc.RRR.RRR..ss.......................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A01EE795750460BA80738A4D0A20B386
        SHA1:F76A3C04F94D151E5537B27241FEA2F6C9054938
        SHA-256:49D81E588D4F691C413808439F708A2A968922B8F431E42347D3C335D6BDFD7E
        SHA-512:5FD59263185999F349F249F1BE1D9F7659B115E7816B9338D137646334001C4E078D10756EC8D4E58D1AB09F3CC45934D267D6699940817F74DAF4A4A36E6538
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ss.scc.RRR.RRR..ss.......................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 3780 x 3780 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:A173B33271C5E5635AC6A1B24B76FBCC
        SHA1:7889B1D3FAD08CD8F255DC7D658ECDE9A1B4FD57
        SHA-256:39E369CDEB8D35D468B78B6D0913248486AFB96195313EB36A7ABE90323EF818
        SHA-512:472957D8F5EB092FAEDB7B40D08435EA9440F86129D0AC68744763356958E57BD68374A5DC106A7924BC4BBBAA0F4F3427182B74330B1268B64E8E5C7B1DB8B8
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:CA418F3B0D14AE2D14DF5B2C5270FBC2
        SHA1:1A6F43FF0AA2A39B9F5BC133F96A0F3D86064C76
        SHA-256:E3C961505DB9A8470ACFFA49F7836F7416A50FED802D2DB5A0ADA0609E0D2D8B
        SHA-512:578A02E9D57895E770D0297AB0E2CC90F379B0A2077540B2A608C0A1C1F938D5851987A1E32209C6F847BE931CB1A6E055B5A04F9207B8FBC0E3C76F454B362F
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 3780 x 3780 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):5.482194947492178
        Encrypted:false
        SSDEEP:
        MD5:A173B33271C5E5635AC6A1B24B76FBCC
        SHA1:7889B1D3FAD08CD8F255DC7D658ECDE9A1B4FD57
        SHA-256:39E369CDEB8D35D468B78B6D0913248486AFB96195313EB36A7ABE90323EF818
        SHA-512:472957D8F5EB092FAEDB7B40D08435EA9440F86129D0AC68744763356958E57BD68374A5DC106A7924BC4BBBAA0F4F3427182B74330B1268B64E8E5C7B1DB8B8
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 7874 x 7874 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):5.762457837422729
        Encrypted:false
        SSDEEP:
        MD5:1CCDD9FB6B5EF26AAA84BE1FC09A9A38
        SHA1:BEDF56F65A70BE0161F3EE83334BEFA5614D07FC
        SHA-256:607D1651D7AAC37A44A00B4DB721AF196EFF99EE65BF7600685AF0561CB045C7
        SHA-512:3834318FE60984C5C0E2346B058819D07C4CBDBC74C57B483F2D60E46132B74A6AB8D0448931C94FB60677BBF2EA0431604B9D23114C1F407D32F119D9A3A1D6
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):4.76526649880805
        Encrypted:false
        SSDEEP:
        MD5:FC6BFF5E1F8C1792ACD2A0657A67A37B
        SHA1:8ABA8D70BB63F96CB68C5A00BA1BC3D7B1E1BA96
        SHA-256:AD6EC04A8F27CA37D2382C3178690F93C7276656FC90F9C5C576257E74CC6251
        SHA-512:E15EE5BE5795BD90722CB07C8DE232E8421E20AC49224D5A80BA25E9C8C0C0AB3FBDA5B557A93E8354EE98C668D93C2526C1D5255FBE2E24AF69442E15858EBD
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 7874 x 7874 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):4.805669897825579
        Encrypted:false
        SSDEEP:
        MD5:F0E86D86C72273CFA827066BB4F2BD4C
        SHA1:249EFEB2DBAAA77240C6545D11769FEF2EEFB732
        SHA-256:8AF4DC270AF6FA954AC4A1844C756F5E513121FBCADC734B3D46FC2A8C2B32C7
        SHA-512:6651B237B3BD290892720762C95EFAC423DC26F85D88CC010D105FB4B76B3CFC642F10D5DF631C5F6DE4E22457E009D8F5BD1F707A6FDD394EDEAC31CB4CEB0B
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):3.7554125439614814
        Encrypted:false
        SSDEEP:
        MD5:18CC7E0E05AEC44396F09DCA56BFE7CD
        SHA1:3A41DF0F04804FE27D0BDCA430FF861EF1165595
        SHA-256:7634B05B4DE3CD3DC191BF3807BA826E7FB28F8AB45BC919135E638811A68A51
        SHA-512:6CD4BE216AD5BAB2BD08DAADCB85E8231AACF309355C99C577A2D14EB09876B722CC98A7EC9D04F6B04C54779FF6863B2E7F508BABA47BAC00BE0C3707C56D83
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... .................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):4.4179878974179445
        Encrypted:false
        SSDEEP:
        MD5:488EE583FA8644EB53D42E524F0F53A3
        SHA1:59318DEEC4520887C0DBDACAB5629221D2B22877
        SHA-256:C05FD76D263A5FA99AE3858E2755D0B991166C8EB80974632BA1CABEAF6BB574
        SHA-512:22B8211569DD355833EE59F07E06461ABD96CFA2FDEC01CB16B632FEBCEAE0C6E9E7B640A4EA64CB491F511A6C6E6B4A1E0650E0178DD850D3C89EE414B207D5
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................|||.|||.~~~...........................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):3.128250776628003
        Encrypted:false
        SSDEEP:
        MD5:D713DF602DB200D42A93FE1037CC3AE9
        SHA1:ACECBF9F83A5635FC44B9958FFC2B6FD65736B7F
        SHA-256:25565DD108133DA78FB1F6EDDDC3FB3FAAA05DF088FC08C40108301C117D594B
        SHA-512:B03097037EAB8B1BC5BC34D9EDDA0BC0116247497D1CDBB5614CDBCC38729C69C67CE755F8C91428BC173D71DF61E2CFCA0D0E8795ED276443FA67B3478FEECC
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..................................................................................................................................................................................................................................................```......................................................./.../.../.../.....................................................................................................................................................................................................................................................?8?. . .```.```.```.........................................................................................................................................................pxp.pxp.pxp.pxp.pxp...................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):4.652707485187215
        Encrypted:false
        SSDEEP:
        MD5:07E86923C827D99F9B222E5E5B65F8E4
        SHA1:1A9B69B59344DDEA8239377380A465D2E7EDF1EA
        SHA-256:FEC37BFB96446FD18FE553BB328D2070C92637B59E95669AB804844AFE9210EC
        SHA-512:1476D641A437E5297980222B84B9B772880CBEE8DAB25B18D40AE9B0D2FE63B901186FEBC8D112799C45DDFF35C8486CBCF3B364473610E429A0C51EE88ACEEB
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ..........................................................................................................................................................................................................................................................................................Z.. .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................jej.ab{ajs]b............................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55298, resolution 2834 x 2834 px/m, cbSize 55352, bits offset 54
        Category:dropped
        Size (bytes):55352
        Entropy (8bit):5.613434629061541
        Encrypted:false
        SSDEEP:
        MD5:829F2C34B920789D36ABA057B125DEEC
        SHA1:5F2B389B352B96C2A54C2BAC6673DAD57A63EC2D
        SHA-256:03572F8811053F43BA9551E5F7540EA7C1D632D2B106475C36EFC72C61DAF9E0
        SHA-512:5DA8F07D643CF8B36563802D8BBB90E19C9E1A0306782FECD35FE00C4F66AF38F786730EFB720AF2305EB77208CD2E8C7BC8C2E65FD9689ED58812B19650D138
        Malicious:false
        Reputation:unknown
        Preview:BM8.......6...(...@... ........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................:::oqr........................................................................................................................................................................YZ[UVVEEFSTTZ[[opq.........................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):3.5300591418482674
        Encrypted:false
        SSDEEP:
        MD5:B5231A4692C3E9FC1D4F7F4C1A355BD4
        SHA1:5DB15484523CC7DC3E82D0A65108425047BF656A
        SHA-256:A8846E412FD640B04C9DAD63BA8C8577B0A54930F9D3F26B0135058BE99268D4
        SHA-512:FCE7CED848C8ADA6BB543E7817B38F0636811C779899160713659C89C405EFFAC74CD685E7C0464F9262DF0AB15B15A3A8A510786694FDAD4C4FE1B2C643FE03
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... .......................................................................................................................... .. ......................................................................................................................................................................................................................................................................................................................................................................................... ............................................................................................................................. .. ......................................................................................................................... .. ................................................................................................................. ................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):4.748807751429599
        Encrypted:false
        SSDEEP:
        MD5:F00145A9D1956C2629BBC59CA4DABEA8
        SHA1:C09B2E9BBB877952E1C7CD7C363560B0DE622AA0
        SHA-256:32CCEFD3711E6E125602ED66637642FE9892D17338CFF63036A0111F0FD07922
        SHA-512:D2CE0178828175C9231A2BD39B94DF1FD91CD753D8E8F1A14A53C031C7A48350E593389D45FA7078CE4AD32976904E2C5A708DF939D8C5F77B03B238E47913C8
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................gt........................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):3.687419855580657
        Encrypted:false
        SSDEEP:
        MD5:D5C4B1EBF011F9D3ACD7167B5D51BB2C
        SHA1:F81ABC4E2E0C6503A0A72ED267E8A3C2B3A517E6
        SHA-256:1A9F7B2F9D1F14E55D6383216B67765CF99339E95D54993FECCEB9DBF136C877
        SHA-512:827AE94D8842EEF5EC92F6760DE4DAEDC5A25CDD856D6EEF6A5C68B613E915F7A93C2DC508985B9F46C196114BF9B23B005DE24B82338E6A6D737EA701D2DEB8
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... .............................................................................................................................................................................................................. 0..................`/.. 0.. 0.. 0.. 0.. 0.. 0..`/.......... 0........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):3.827315258383347
        Encrypted:false
        SSDEEP:
        MD5:4A8B44F768BABBC7C8D0ECB78067B13D
        SHA1:D42602FA141FE3E621EFA3A62360EEA96257120C
        SHA-256:4D8437882EE841993618D0FADD216C39C3C9F7164FBC6EE54C2BA09FFD53CA5C
        SHA-512:FBE5DFDE9E027F0664E4C4370CDA1EB965CA3FC3148BEECAAB04CAD89096A432E664E0126F7CAD6D477890A5CE183D3F474ACD50428E65CCD1878182191D5767
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................@H@.............................................................................................@H@........................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):5.2442920199467835
        Encrypted:false
        SSDEEP:
        MD5:CA418F3B0D14AE2D14DF5B2C5270FBC2
        SHA1:1A6F43FF0AA2A39B9F5BC133F96A0F3D86064C76
        SHA-256:E3C961505DB9A8470ACFFA49F7836F7416A50FED802D2DB5A0ADA0609E0D2D8B
        SHA-512:578A02E9D57895E770D0297AB0E2CC90F379B0A2077540B2A608C0A1C1F938D5851987A1E32209C6F847BE931CB1A6E055B5A04F9207B8FBC0E3C76F454B362F
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):4.447881940684289
        Encrypted:false
        SSDEEP:
        MD5:14844441468EDF2C12DFE7A59EC20B76
        SHA1:CEED3664811A26C1424DB30F3581815927E85C2C
        SHA-256:CC466122B23884745A4B259BA94F446F48D135C33C0AD65254499E932516C8F2
        SHA-512:21DE469358750F828530C98F54E3DEF976C70AB410DDE264FD7FBD431F4E1A2DB7151AD3052C919068DB8EEA388646273D2ECD8AD06C3A5B8367CBA4D9285525
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ............................................................................................................................................................................................z...............................................................................................................................y.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):3.3626587508854984
        Encrypted:false
        SSDEEP:
        MD5:18E2AC5502871C5D5992ED7811450639
        SHA1:79E0F85D6BAA66290228D98335597C8ADAEA75D2
        SHA-256:8A280D8B87C8081C27B572026CFFAA0CC219903AA2DC0138AB3B96FEE7570D56
        SHA-512:63EC5BAD42C2AE88DD590E5897BD2392B9CBA8A9B3A5640A0AF054CB84CBFDF23D9131F713ACDE0AB8ACCFAFE148603CDAE5CC8512EC0F6275CD09CC4AF4056F
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..................................................................................................................................................................s...JZZ.RRR.sss.sss.sss.................................................................................................................................................................................................................................................pho.pXP.pXP..`_..`_..X_.pXP.`PP.PPO.PPP.oho......................................................................................................................................................................................................ss.scc.RRR.RRR..ss.......................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 24, image size 55296, resolution 2835 x 2835 px/m, cbSize 55350, bits offset 54
        Category:dropped
        Size (bytes):55350
        Entropy (8bit):3.8318364931188325
        Encrypted:false
        SSDEEP:
        MD5:19D6895A0D7078832D4E101E75FEAE52
        SHA1:23B710D7699D44FE6D49F1EFA8977759BC9E1204
        SHA-256:A99FF93265084A431F237C94F5915256A1DE916C74AA48611AFB6AAA9D4510FD
        SHA-512:4981231AD2E2573E56866F7205BB4F803998C516B7770C4C72382AD5BD1B183180A309C85ABACFEF22D4D040B9DF7F4C587F9D7E01259F0AC1722109CA2B5514
        Malicious:false
        Reputation:unknown
        Preview:BM6.......6...(...@... ................................................................{{{ccccccZZZRRRRRRJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ................k!s9..J..B..B.{9.{9.s9.s9.s1.s1.s1.s1.s1.s1.s1.s1.s1.k1.k1.k1.k1.k).k).k).c).c).c).c).c).J!.B!........................................................................................................................................................................................................................{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{{....................................................{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{..{.....................................................................................................................kkk...kkkJJJJJJJJJJJJRRRJJJJ1....JJJJJJJJJJJJJJJJJJJJJJJJJJJJJJ.................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):73782
        Entropy (8bit):4.807529748411987
        Encrypted:false
        SSDEEP:
        MD5:A01EE795750460BA80738A4D0A20B386
        SHA1:F76A3C04F94D151E5537B27241FEA2F6C9054938
        SHA-256:49D81E588D4F691C413808439F708A2A968922B8F431E42347D3C335D6BDFD7E
        SHA-512:5FD59263185999F349F249F1BE1D9F7659B115E7816B9338D137646334001C4E078D10756EC8D4E58D1AB09F3CC45934D267D6699940817F74DAF4A4A36E6538
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................ss.scc.RRR.RRR..ss.......................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:B5231A4692C3E9FC1D4F7F4C1A355BD4
        SHA1:5DB15484523CC7DC3E82D0A65108425047BF656A
        SHA-256:A8846E412FD640B04C9DAD63BA8C8577B0A54930F9D3F26B0135058BE99268D4
        SHA-512:FCE7CED848C8ADA6BB543E7817B38F0636811C779899160713659C89C405EFFAC74CD685E7C0464F9262DF0AB15B15A3A8A510786694FDAD4C4FE1B2C643FE03
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... .......................................................................................................................... .. ......................................................................................................................................................................................................................................................................................................................................................................................... ............................................................................................................................. .. ......................................................................................................................... .. ................................................................................................................. ................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PC bitmap, Windows 3.x format, 576 x 32 x 32, image size 73728, cbSize 73782, bits offset 54
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:D713DF602DB200D42A93FE1037CC3AE9
        SHA1:ACECBF9F83A5635FC44B9958FFC2B6FD65736B7F
        SHA-256:25565DD108133DA78FB1F6EDDDC3FB3FAAA05DF088FC08C40108301C117D594B
        SHA-512:B03097037EAB8B1BC5BC34D9EDDA0BC0116247497D1CDBB5614CDBCC38729C69C67CE755F8C91428BC173D71DF61E2CFCA0D0E8795ED276443FA67B3478FEECC
        Malicious:false
        Reputation:unknown
        Preview:BM6 ......6...(...@... ..... ...... ..................................................................................................................................................................................................................................................```......................................................./.../.../.../.....................................................................................................................................................................................................................................................?8?. . .```.```.```.........................................................................................................................................................pxp.pxp.pxp.pxp.pxp...................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:C8ECE2D5385101B25FA665E670DFA408
        SHA1:0936CA6D30A636594E1F22698CB9ECE9D86ACE1A
        SHA-256:7E53CAC1D35BC9BED1E3B40B53E36BF7C5A84EE556EAABEF77BD802DE9992855
        SHA-512:147D039C38C7A72C73E883EA5A8724F38F4EA6225061F6EE21746A4F4F6B4724398F58D8CFDE5D55A7A1B8175AF12B0FB933361BB3B7D35C6FDC0B8BDA6944F6
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 2%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........W...9..9..9...5..9.'.7..9...2..9...3.<.9.[.3..9...*..9..8.!.9..3..9..2..9.c.?..9.[.=..9.Rich..9.........PE..L....@.D...........!.................$...................................................................................... ...<....@..p....................P..h0...................................................................................text............................... ..`.rdata..............................@..@.data....z.......p..................@....rsrc...p....@.......0..............@..@.reloc...8...P...@...@..............@..B................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:243B9AD419B0A6E08D53F415CED69F8F
        SHA1:0689D1CD21092D8429FC8A35161E71F2BFB6C510
        SHA-256:201CC1DE2FD6D39D6D0C5487295E0E337783D280E8AC0EEF37A6CBB1948A9767
        SHA-512:196FB4F0F2A6E18692383709F887831CCBFD68986EB13DE01EE19C9D8AD0D6CC1604315622827D1D73100BF3EDADC73B735B900D8C4B39D2C8AAC2D48A604727
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........T.x.5.+.5.+.5.+.).+.5.+.5.+.5.+.5.+.4.+.*.+.5.+.*.+.5.+q).+.5.+.*.+p5.+...+.5.+...+.5.+...+.5.+53.+.5.+...+.5.+Rich.5.+........................PE..L...../B...........!.................a.......................................P..............................................x...........x'.......................*...................................................................................text............................... ..`.rdata..'o.......p..................@..@.data........ ...@... ..............@....rsrc...x'.......0...`..............@..@.reloc..~Q.......`..................@..B........................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:ISO-8859 text, with CRLF line terminators
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:523899E2DB1A16AF25AE65CEFEB6B741
        SHA1:54029C8871B1F22364FECF0FA90E8CA9ABA63AFF
        SHA-256:FED16FC1F4075221BDD9A0617D55A60BA17AB915FFD8A4E38B966F458A7D10EB
        SHA-512:7EE15E1277843D4A8D39E265D2122132BCD4CE0D56269156C5E252569ECBC570D86A9E92A970F006072B3C1995F01E56E992997E94E0EE53C15E9FA1C4419458
        Malicious:false
        Reputation:unknown
        Preview:IZArc version 4.5..Copyright. 2022 Ivan Zahariev..All Rights Reserved..https://www.izarc.org....=========================== WHAT'S NEW ===========================..Version 4.5....-Changed some shortcut combinations in order to avoid default windows actions...* Shift+S -> Alt+S (Virus Scan)...* Shift+V -> Alt+V (Check with VirusTotal)...* Ctrl+C -> Alt+C (Convert Archive).....-Fixed deleting existing files when extract password protected archive and enter wrong password..-Fixed using the same temp folder when converting multiple archives at once..-Fixed some problems with Unicode filenames....-Updated translations....==================================================================..Version 4.4....-Fixed support for LHA archives..-Fixed some small bugs..-Removed support for ACE archives due to found security vulnerability in UNACEV2.DLL library....-Updated translations....==================================================================..Version 4.3....-Fixed error messages are not s
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:182AF2F9911B98CE18AA7B1A5AF4DA63
        SHA1:FD46E30B6DD4429A1A81C29D166223ED2F183150
        SHA-256:CA86F69295619D2F49B0E741A3DA732F2B77388511435AD5D95919C358F86FAA
        SHA-512:FCB069EFE613A673E5FDC5988D34DD05ECFE14C5F7520FBC35E8E3294769164B097FA3ABF908F784E74CA6658DBF15E07E8898B7E79B213DA07DA9F1A8A01BCD
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!Z..e;.\e;.\e;.\...\f;.\B..\.;.\B..\.;.\.4.\l;.\e;.\.;.\B..\+;.\B..\d;.\B..\d;.\B..\d;.\Riche;.\........PE..L...G..G...........!.....p..........kk...............................................t..........................................d....P.......................`..........................................@...............$............................text....n.......p.................. ..`.rdata...............t..............@..@.data....2..........................@....rsrc........P......................@..@.reloc..H&...`...(..................@..B................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:56D1932B7EDB3AB165D456944EF484DD
        SHA1:E8B40B5A267593E9B399B909A59170B219EEC8C6
        SHA-256:1514CEE215B7EE3D67FB6E8968C0AF73E4E4C970A3378EF331B2A77ED76E1A4E
        SHA-512:D44CB75C05BBFA656537D80060379ADF994DFE14066BD6ED74DAAAB032DF8582F5C165C81D503F14CC7B2D6D19436A4F915AA6EF1A60361CD57835F9B5975348
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 1%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................f...X......Xu............@.....................................................................z.......................................`...................................................................................CODE....pe.......f.................. ..`DATA.................j..............@...BSS......................................idata..............................@....edata..z...........................@..P.reloc..`...........................@..P.rsrc...............................@..P....................................@..P................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:27BA0CECB62FC7ACF0D166485BBF6A24
        SHA1:D64506692D8C565399908BE27A102066A4BE37E8
        SHA-256:921407945777EF06946B8E949B0F83BEE23C3B6DEE83B08EC2DE7214254210BB
        SHA-512:CB0C1C0C60077898778E2760599EB103201A014DADFCA422B9A13340409DFD080D1C81D66F2D3D55370E2A36D25A085078734A2796AA8D2C95EEF628436882B4
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................................................................Rich...........................PE..L.....~I...........!.....*...................@......................................................................PD.......A..(....p..............................................................HA..@............@..t............................text....(.......*.................. ..`.rdata.......@......................@..@.data........P.......4..............@....CRT.........`.......6..............@..@.rsrc........p.......8..............@..@.reloc...............>..............@..B................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:9EC7CF498F3F71E807629577C7BC2D19
        SHA1:D47D985CEDAAC980D18FF446687EDC0F9C5F2F1F
        SHA-256:ED3407EEACCC1718E0B2BC27FD3301BB3D4213821533412B2FE0F2149D0F7A8B
        SHA-512:3993E02DA2CB20C5AB389DEF865986AE4881522E291EBABA507F3ADF28C68548D249076CE555C696DFB8340771447EC9F7954B0055EE2174E8BB75A39BC240D1
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........{J...$...$...$...%...$..97...$..."...$...$...$.Rich..$.................PE..L....;@9...........#.........2.....................~.........................0.......k..........................................<............................ ......`.......................................`...D.......\............................text...M........................... ..`.data....(..........................@....rsrc...............................@..@.reloc....... ......................@..B4.D8 ...0[.8-...5.D87...........KERNEL32.dll.NTDLL.DLL.ole32.dll........................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):219224
        Entropy (8bit):6.583478447150069
        Encrypted:false
        SSDEEP:
        MD5:570E94ACBC5E43E7A3C217148291BE4C
        SHA1:684E6DC1669CC5772EA46493C17D8010554CB3D9
        SHA-256:CFC782FAFFC6FA3B602E97D2EA0D00E20873E10CC9B46160BFF7CE1B5F738C0F
        SHA-512:FB271860D7978D2CC59D2F1CA618A27248278837317D87C032469F8561A221314B9388B61DD2942BC916C388BA74CECB4517040BF3DA898BE2F85CF7ADC45AFE
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........r...................................|...........................Rich............................PE..L....5.S...........!.................2..............................................X.....@.............................p.......P....................@..X.......<...P...................................@............................................text...P........................... ..`.rdata..@@.......B..................@..@.data........ ......................@....rsrc...............................@..@.reloc..t$.......&..................@..B........................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):855713
        Entropy (8bit):6.825114620272033
        Encrypted:false
        SSDEEP:
        MD5:6E4E197E5039041B67A0F707830094FE
        SHA1:5CE9DAA32C701866C95D381C0AEA17EDAA31CF4E
        SHA-256:174C6424B87D3F6E80C6276A2188F904AC0AD08CFB487CF400386E094A9A5932
        SHA-512:F7B73B7DDC862D472413BA3EB910706A83D122C0D268E1DFEAF238EEB43269C4D9CE035E5D4EB71630BA93737FBDB53AD0E60B1E3BA95FA9C6943277272DD3D1
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................~...`....................@..............................................@...............................%.......%................... ......................................................................................CODE.....}.......~.................. ..`DATA................................@...BSS......................................idata...%.......&..................@....tls.....................................rdata..............................@..P.reloc....... ......................@..P.rsrc....%.......&..................@..P.....................T..............@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
        Category:dropped
        Size (bytes):189440
        Entropy (8bit):7.893450320949656
        Encrypted:false
        SSDEEP:
        MD5:F938C43BD841C4398E39644FAA7D6FF7
        SHA1:875637BF4215FE285CD227D516FD114D61675A03
        SHA-256:2F4E78B021DEBFF39D4339C775FD51071B603A7F3165F0B631F74D910796A05E
        SHA-512:570759BA8B5449D0E510F9AFD1EED166C78FA472C1DA7DB8428B9F910480F0D4BA425CA1ED04F74DC6F96C0A81B1A9A2DBEA5AAE46447FDE99B2327E80882CAA
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....LfM............................ .............@..............................................@..........................|...........|..........................................................................................................UPX0....................................UPX1................................@....rsrc...............................@..............................................................................................................................................................................................................................................................................................................................................................................3.05.UPX!....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows HtmlHelp Data
        Category:dropped
        Size (bytes):92048
        Entropy (8bit):7.796008335896805
        Encrypted:false
        SSDEEP:
        MD5:092E24B7B052302139111F0C65BD25AC
        SHA1:651CF2AA4F5861996B77757D7AD6CD78A8D40850
        SHA-256:B06D04139EC6B0E810AD6073C2E84EDEE7F49ACF672E09771EA3D67002DADAA4
        SHA-512:132AEBA9036860F144E38151AC60DDA4AF119D86FD4275D1551E444BB493F0D26742D75D1D66A2F3406E8AC4ACEC49ED42EE8F74DABDDB70AB003213E0D72096
        Malicious:false
        Reputation:unknown
        Preview:ITSF....`..................|.{.......".....|.{......."..`...............x.......T........................g..............ITSP....T...........................................j..].!......."..T...............PMGL)................/..../#IDXHDR...O.../#ITBITS..../#IVB.....\./#STRINGS......./#SYSTEM....../#TOPICS...O.@./#URLSTR..._.5./#URLTBL.....P./#WINDOWS...>.L./$FIftiMain...t..[./$OBJINST...5.?./$WWAssociativeLinks/..../$WWAssociativeLinks/BTree...=.L./$WWAssociativeLinks/Data.....r./$WWAssociativeLinks/Map...{../$WWAssociativeLinks/Property.... ./$WWKeywordLinks/..../$WWKeywordLinks/BTree...f.L./$WWKeywordLinks/Data...2.a./$WWKeywordLinks/Map....../$WWKeywordLinks/Property.... ./180.htm..@.l./aboutarchivefiles.htm...,.$./aboutizip.htm...P.../addfilestoanarchive.htm...m..!./checkout.htm.....;./clearhistory.htm...I.../closearchive.htm...`.5./commandlineinterface.htm......../configuration.htm......-./convertarchive.htm...K.>./convertcdimage.htm.....B./copyarchive.htm...K.X./createanewarchiv
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):275456
        Entropy (8bit):6.425984533162282
        Encrypted:false
        SSDEEP:
        MD5:93AA6A76E2F245C85C76FB4C993BC9CB
        SHA1:6D39D98588AD4623DCC423A94FCFAADBB22A0104
        SHA-256:0C19B611525E2B4FB5F04581B61F4119821A10EABDF73151F22BE18DB2C805B8
        SHA-512:35E4B4E797DDC1AF09C755ABE7D55A1F6E7053F03F2F18A5C8CF406DCFC2A8D6211A623D7A1DFAE1E58FEE6CAE4F927219E8137D9CCBD8BBE3A4AC629B8F2C43
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*o;+n.Uxn.Uxn.Ux..[xw.UxX(_xP.Ux...xo.Uxn.Tx..Ux...xi.UxX(^x..Ux.x.xy.Ux.x.xl.Ux..Sxo.Ux..Qxo.UxRichn.Ux........PE..L....S.L...........!.....F...<......U........`......................................................................p..........P....`..........................8$...................................................`..d............................text....E.......F.................. ..`.rdata..c^...`...`...J..............@..@.data...........:..................@....sxdata......P......................@....rsrc........`......................@..@.reloc...5.......6..................@..B................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
        Category:dropped
        Size (bytes):2469888
        Entropy (8bit):5.9502768947662625
        Encrypted:false
        SSDEEP:
        MD5:F64E891A69B8274CB7D011883F8B2A65
        SHA1:0EDCFCE898FBEA3AB417BE9C30C5565BBD7EC95D
        SHA-256:C79474CE574887482BC455FEE365FC4F89904102AEB1DF0D449DE5460C553D45
        SHA-512:F199958F2A1D833FA46D90B4234FA53797AF8DCB2950FAB6D77E4ACB326CD37362934E6090481001CAEA0A7CE05C3C19315A642F544CC940552990658578F8A9
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..d...q..\.........." ..........................@...............................&...................................... ................".......".6N...0&..d...p$.8.............#.Dn..................................................(.".X....."......................text............................... ..`.data........ ......................@....bss.........!.......!..................idata..6N...."..P....!.............@....didata.......".......".............@....edata........"......(".............@..@.reloc..Dn....#..p...*".............@..B.pdata..8....p$.......#.............@..@.rsrc....d...0&..d...L%.............@..@..............&.......%.............@..@................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:Generic INItialization configuration [InternetShortcut]
        Category:dropped
        Size (bytes):229
        Entropy (8bit):5.206328391359808
        Encrypted:false
        SSDEEP:
        MD5:5EDE8FD9DD6AA1C48ECBF416EBF18C7C
        SHA1:738A5A9282AB7ABD91A1A78454864E7E7FB33EC2
        SHA-256:45E78315F26D722386335DB3039C3A0BAC5C53DE2EDAD2705207AA2A2251E39F
        SHA-512:D71D68EB3C38CCDBDD8FBA426E6B89FA88941C92348976E8D00D15E7E08875DE9A43ECAC55BEF9BED5296E6580EACA3BB98B17701FAFA4792AE6E729CD34919D
        Malicious:false
        Reputation:unknown
        Preview:[DEFAULT]..BASEURL=http://izarc.org/donate.html..[InternetShortcut]..URL=https://www.izarc.org/donate..IDList=..IconFile=http://izarc.org/favicon.ico..IconIndex=1..HotKey=0..[{000214A0-0000-0000-C000-000000000046}]..Prop3=19,11..
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):214528
        Entropy (8bit):6.614329349290251
        Encrypted:false
        SSDEEP:
        MD5:182AF2F9911B98CE18AA7B1A5AF4DA63
        SHA1:FD46E30B6DD4429A1A81C29D166223ED2F183150
        SHA-256:CA86F69295619D2F49B0E741A3DA732F2B77388511435AD5D95919C358F86FAA
        SHA-512:FCB069EFE613A673E5FDC5988D34DD05ECFE14C5F7520FBC35E8E3294769164B097FA3ABF908F784E74CA6658DBF15E07E8898B7E79B213DA07DA9F1A8A01BCD
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!Z..e;.\e;.\e;.\...\f;.\B..\.;.\B..\.;.\.4.\l;.\e;.\.;.\B..\+;.\B..\d;.\B..\d;.\B..\d;.\Riche;.\........PE..L...G..G...........!.....p..........kk...............................................t..........................................d....P.......................`..........................................@...............$............................text....n.......p.................. ..`.rdata...............t..............@..@.data....2..........................@....rsrc........P......................@..@.reloc..H&...`...(..................@..B................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):258048
        Entropy (8bit):6.149953054555633
        Encrypted:false
        SSDEEP:
        MD5:243B9AD419B0A6E08D53F415CED69F8F
        SHA1:0689D1CD21092D8429FC8A35161E71F2BFB6C510
        SHA-256:201CC1DE2FD6D39D6D0C5487295E0E337783D280E8AC0EEF37A6CBB1948A9767
        SHA-512:196FB4F0F2A6E18692383709F887831CCBFD68986EB13DE01EE19C9D8AD0D6CC1604315622827D1D73100BF3EDADC73B735B900D8C4B39D2C8AAC2D48A604727
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........T.x.5.+.5.+.5.+.).+.5.+.5.+.5.+.5.+.4.+.*.+.5.+.*.+.5.+q).+.5.+.*.+p5.+...+.5.+...+.5.+...+.5.+53.+.5.+...+.5.+Rich.5.+........................PE..L...../B...........!.................a.......................................P..............................................x...........x'.......................*...................................................................................text............................... ..`.rdata..'o.......p..................@..@.data........ ...@... ..............@....rsrc...x'.......0...`..............@..@.reloc..~Q.......`..................@..B........................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):360448
        Entropy (8bit):6.3986775571990115
        Encrypted:false
        SSDEEP:
        MD5:C8ECE2D5385101B25FA665E670DFA408
        SHA1:0936CA6D30A636594E1F22698CB9ECE9D86ACE1A
        SHA-256:7E53CAC1D35BC9BED1E3B40B53E36BF7C5A84EE556EAABEF77BD802DE9992855
        SHA-512:147D039C38C7A72C73E883EA5A8724F38F4EA6225061F6EE21746A4F4F6B4724398F58D8CFDE5D55A7A1B8175AF12B0FB933361BB3B7D35C6FDC0B8BDA6944F6
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........W...9..9..9...5..9.'.7..9...2..9...3.<.9.[.3..9...*..9..8.!.9..3..9..2..9.c.?..9.[.=..9.Rich..9.........PE..L....@.D...........!.................$...................................................................................... ...<....@..p....................P..h0...................................................................................text............................... ..`.rdata..............................@..@.data....z.......p..................@....rsrc...p....@.......0..............@..@.reloc...8...P...@...@..............@..B................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Category:dropped
        Size (bytes):69632
        Entropy (8bit):5.593004615810322
        Encrypted:false
        SSDEEP:
        MD5:9EC7CF498F3F71E807629577C7BC2D19
        SHA1:D47D985CEDAAC980D18FF446687EDC0F9C5F2F1F
        SHA-256:ED3407EEACCC1718E0B2BC27FD3301BB3D4213821533412B2FE0F2149D0F7A8B
        SHA-512:3993E02DA2CB20C5AB389DEF865986AE4881522E291EBABA507F3ADF28C68548D249076CE555C696DFB8340771447EC9F7954B0055EE2174E8BB75A39BC240D1
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........{J...$...$...$...%...$..97...$..."...$...$...$.Rich..$.................PE..L....;@9...........#.........2.....................~.........................0.......k..........................................<............................ ......`.......................................`...D.......\............................text...M........................... ..`.data....(..........................@....rsrc...............................@..@.reloc....... ......................@..B4.D8 ...0[.8-...5.D87...........KERNEL32.dll.NTDLL.DLL.ole32.dll........................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):372736
        Entropy (8bit):6.588017731833523
        Encrypted:false
        SSDEEP:
        MD5:D13A7CC98FC3CBDCAC897747EB30D9E5
        SHA1:B9C6B7822674D318494ACB7F5A45BB38658C7019
        SHA-256:EACD666AD079917AEE7392F55E5F3653843AF92C2DFBBCB2EBBBE55B2B8DA1B1
        SHA-512:0E3327BBDD761D4BCD3F53E1FA32841547F4BC56167D0A2A71B3E0D82FA21FD1323784D58BA087AF1A169BB6E7D14F069D058CFE6F453429558A7D85DDF00E32
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........?K}@^%.@^%.@^%.;B).C^%.@^%.R^%.@^$.._%."A6.O^%./A..J^%..B+.[^%./A/..^%.9...t^%.F}/.S^%.F}..^^%..X#.A^%..~!.A^%.Rich@^%.........................PE..L...F..<...........!................0........ ............................................................................. ........P...%........................................................................... ..h............................text............................... ..`.rdata..q.... ....... ..............@..@.data............p..................@....rsrc....%...P...0... ..............@..@.reloc..NS.......`...P..............@..B........................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):115200
        Entropy (8bit):6.465034223261167
        Encrypted:false
        SSDEEP:
        MD5:56D1932B7EDB3AB165D456944EF484DD
        SHA1:E8B40B5A267593E9B399B909A59170B219EEC8C6
        SHA-256:1514CEE215B7EE3D67FB6E8968C0AF73E4E4C970A3378EF331B2A77ED76E1A4E
        SHA-512:D44CB75C05BBFA656537D80060379ADF994DFE14066BD6ED74DAAAB032DF8582F5C165C81D503F14CC7B2D6D19436A4F915AA6EF1A60361CD57835F9B5975348
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................f...X......Xu............@.....................................................................z.......................................`...................................................................................CODE....pe.......f.................. ..`DATA.................j..............@...BSS......................................idata..............................@....edata..z...........................@..P.reloc..`...........................@..P.rsrc...............................@..P....................................@..P................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):3420160
        Entropy (8bit):6.391749403836158
        Encrypted:false
        SSDEEP:
        MD5:6AD69B02B1A5BA995EADC7FD9CC6A705
        SHA1:0EECB19E7D06E36165D36B12A2572EF8493AF835
        SHA-256:79074936D195049D1380E7FF085221C970D7A2283EC612C40BD15B8006AEAEB4
        SHA-512:B0031AEEE86BD4C1D1D7F6B0C041C552BE662B34620EEB6E70DC017212AF319DD676468E0DB6A50BB6712645385DC32A5E1CF48A2BEFAB00DF6AAEF95855A84F
        Malicious:false
        Yara Hits:
        • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Program Files (x86)\IZArc\is-GD2P4.tmp, Author: Joe Security
        • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Program Files (x86)\IZArc\is-GD2P4.tmp, Author: Joe Security
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...~..b..................#..v......X.#.......#...@..........................p;...........@......@............................+..@............................,. i............................,.......................+..............................text...l.#.......#................. ..`.itext........#.......#............. ..`.data.........#.......#.............@....bss..........$.......$..................idata...@....+..B....$.............@....tls....H.....+.......$..................rdata........,.......$.............@..@.reloc.. i....,..j....$.............@..B.rsrc................D'.............@..@.............p;......04.............@..@................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):16896
        Entropy (8bit):5.714455474752954
        Encrypted:false
        SSDEEP:
        MD5:27BA0CECB62FC7ACF0D166485BBF6A24
        SHA1:D64506692D8C565399908BE27A102066A4BE37E8
        SHA-256:921407945777EF06946B8E949B0F83BEE23C3B6DEE83B08EC2DE7214254210BB
        SHA-512:CB0C1C0C60077898778E2760599EB103201A014DADFCA422B9A13340409DFD080D1C81D66F2D3D55370E2A36D25A085078734A2796AA8D2C95EEF628436882B4
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................................................................Rich...........................PE..L.....~I...........!.....*...................@......................................................................PD.......A..(....p..............................................................HA..@............@..t............................text....(.......*.................. ..`.rdata.......@......................@..@.data........P.......4..............@....CRT.........`.......6..............@..@.rsrc........p.......8..............@..@.reloc...............>..............@..B................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:ISO-8859 text, with CRLF line terminators
        Category:dropped
        Size (bytes):21006
        Entropy (8bit):4.896752916821742
        Encrypted:false
        SSDEEP:
        MD5:523899E2DB1A16AF25AE65CEFEB6B741
        SHA1:54029C8871B1F22364FECF0FA90E8CA9ABA63AFF
        SHA-256:FED16FC1F4075221BDD9A0617D55A60BA17AB915FFD8A4E38B966F458A7D10EB
        SHA-512:7EE15E1277843D4A8D39E265D2122132BCD4CE0D56269156C5E252569ECBC570D86A9E92A970F006072B3C1995F01E56E992997E94E0EE53C15E9FA1C4419458
        Malicious:false
        Reputation:unknown
        Preview:IZArc version 4.5..Copyright. 2022 Ivan Zahariev..All Rights Reserved..https://www.izarc.org....=========================== WHAT'S NEW ===========================..Version 4.5....-Changed some shortcut combinations in order to avoid default windows actions...* Shift+S -> Alt+S (Virus Scan)...* Shift+V -> Alt+V (Check with VirusTotal)...* Ctrl+C -> Alt+C (Convert Archive).....-Fixed deleting existing files when extract password protected archive and enter wrong password..-Fixed using the same temp folder when converting multiple archives at once..-Fixed some problems with Unicode filenames....-Updated translations....==================================================================..Version 4.4....-Fixed support for LHA archives..-Fixed some small bugs..-Removed support for ACE archives due to found security vulnerability in UNACEV2.DLL library....-Updated translations....==================================================================..Version 4.3....-Fixed error messages are not s
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:F938C43BD841C4398E39644FAA7D6FF7
        SHA1:875637BF4215FE285CD227D516FD114D61675A03
        SHA-256:2F4E78B021DEBFF39D4339C775FD51071B603A7F3165F0B631F74D910796A05E
        SHA-512:570759BA8B5449D0E510F9AFD1EED166C78FA472C1DA7DB8428B9F910480F0D4BA425CA1ED04F74DC6F96C0A81B1A9A2DBEA5AAE46447FDE99B2327E80882CAA
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....LfM............................ .............@..............................................@..........................|...........|..........................................................................................................UPX0....................................UPX1................................@....rsrc...............................@..............................................................................................................................................................................................................................................................................................................................................................................3.05.UPX!....
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:InnoSetup Log IZArc 4.5 {97C82B44-D408-4F14-9252-47FC1636D23E}, version 0x30, 14427 bytes, 287400\user, "C:\Program Files (x86)\IZArc"
        Category:dropped
        Size (bytes):14427
        Entropy (8bit):5.111962618200852
        Encrypted:false
        SSDEEP:
        MD5:B6AABD4CD2163E26C94FE77EE5828EF6
        SHA1:7DF55CD08857D7CAB70FAABFF42920625D9D8D48
        SHA-256:05BEAEEF8E356CBA736C09E39344D87EBE236E0C8B5C99204E9526AA847ECD4D
        SHA-512:0226A4C52EFA0C8D0E3FAADE6FEBAB9B797F28C34D1EBAA456DA71104B14D29368375DD32599A007597430C570A64343860734FDAFA4BCDB9295276E5FBED8DB
        Malicious:false
        Reputation:unknown
        Preview:Inno Setup Uninstall Log (b)....................................{97C82B44-D408-4F14-9252-47FC1636D23E}..........................................................................................IZArc 4.5.......................................................................................................................0.......[8..%...............................................................................................................g..........._6.......=....287400.user.C:\Program Files (x86)\IZArc...............Y.. ............IFPS.............................................................................................................BOOLEAN....................O...........!MAIN....-1.P...........GETSETUPPARAMS....8 @8..EXPANDCONSTANT......."...........DEINITIALIZEUNINSTALL....-1..UNINSTALLSILENT.......MSGBOX..........SHELLEXEC..............ISWIN64..........................`.........{param:Language|English}.....`.................`.........{param:ArcTypes|}.....`..........
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:6E4E197E5039041B67A0F707830094FE
        SHA1:5CE9DAA32C701866C95D381C0AEA17EDAA31CF4E
        SHA-256:174C6424B87D3F6E80C6276A2188F904AC0AD08CFB487CF400386E094A9A5932
        SHA-512:F7B73B7DDC862D472413BA3EB910706A83D122C0D268E1DFEAF238EEB43269C4D9CE035E5D4EB71630BA93737FBDB53AD0E60B1E3BA95FA9C6943277272DD3D1
        Malicious:false
        Reputation:unknown
        Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................~...`....................@..............................................@...............................%.......%................... ......................................................................................CODE.....}.......~.................. ..`DATA................................@...BSS......................................idata...%.......&..................@....tls.....................................rdata..............................@..P.reloc....... ......................@..P.rsrc....%.......&..................@..P.....................T..............@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):0
        Entropy (8bit):0.0
        Encrypted:false
        SSDEEP:
        MD5:570E94ACBC5E43E7A3C217148291BE4C
        SHA1:684E6DC1669CC5772EA46493C17D8010554CB3D9
        SHA-256:CFC782FAFFC6FA3B602E97D2EA0D00E20873E10CC9B46160BFF7CE1B5F738C0F
        SHA-512:FB271860D7978D2CC59D2F1CA618A27248278837317D87C032469F8561A221314B9388B61DD2942BC916C388BA74CECB4517040BF3DA898BE2F85CF7ADC45AFE
        Malicious:false
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........r...................................|...........................Rich............................PE..L....5.S...........!.................2..............................................X.....@.............................p.......P....................@..X.......<...P...................................@............................................text...P........................... ..`.rdata..@@.......B..................@..@.data........ ......................@....rsrc...............................@..@.reloc..t$.......&..................@..B........................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:13 2024, atime=Mon Feb 7 18:24:38 2022, length=92048, window=hide
        Category:dropped
        Size (bytes):1054
        Entropy (8bit):4.605319850987282
        Encrypted:false
        SSDEEP:
        MD5:76871E8736DB8A99D207BA359AF592E7
        SHA1:20BA791138883AAF00292DCBE6DB00BE0E01F1CB
        SHA-256:8ED72D668E2E6FFC53AFE539FE7B5553381BC9644C700B61DA66D1CBE839D816
        SHA-512:9D05B590263A5BF44C01152261E4AA953B04EDD2F1D08847D220B901320A3477A0609CB2E302636CB3AD19F75B1BB2346C98EE033C03790A546E862ABBE6E11F
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ......Dd...E..Dd......XX....g......................s....P.O. .:i.....+00.../C:\.....................1.....CY':..PROGRA~2.........O.ICY):....................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....\.2..g..GT.. .IZArc.chm.D......CY':CY':..............................I.Z.A.r.c...c.h.m.......U...............-.......T...........c........C:\Program Files (x86)\IZArc\IZArc.chm..5.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.I.Z.A.r.c...c.h.m...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .E..F...../....%..hT..CrF.f4... .E..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..m
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:13 2024, atime=Wed Feb 9 17:54:22 2022, length=3420160, window=hide
        Category:dropped
        Size (bytes):1126
        Entropy (8bit):4.534937449405457
        Encrypted:false
        SSDEEP:
        MD5:AA8D543FE7F59003EC5D1F20BC9F2D0C
        SHA1:62154AC50BF38A699B86845C10D6062E9DF7D363
        SHA-256:A774E2A4931011D3947ACB7F8851F983901DE707A03C3601000C476C000A7EE7
        SHA-512:551E0C46867FFB2B3FDC80CD3C287627DF4DED963DD7D3A3BE4BF86F3CA89F28CCDA10EF6B9E1348EBF923544DD927A08AB0C96242E0F5FB45E69C960E1CDAAF
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ...>\.Dd....|.Dd.....5s.....04.....................s....P.O. .:i.....+00.../C:\.....................1.....CY.:..PROGRA~2.........O.ICY.:....................V......i..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....\.2..04.IT. .IZArc.exe.D......CY':CY':....`.........................I.Z.A.r.c...e.x.e.......U...............-.......T...........c........C:\Program Files (x86)\IZArc\IZArc.exe..5.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.#.%.P.r.o.g.r.a.m.F.i.l.e.s.(.x.8.6.).%.\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .@..F...../....%..hT..CrF.f4... .@..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:13 2024, atime=Thu Oct 3 06:16:49 2024, length=855713, window=hide
        Category:dropped
        Size (bytes):1073
        Entropy (8bit):4.647486680788711
        Encrypted:false
        SSDEEP:
        MD5:D48DE15E59CB02F650920CDA6AF4EC9B
        SHA1:F6CA2BFB02A70A7669214BF0AF71E12E853004AF
        SHA-256:ADB41B9897CD906C18E082E50D6DF5D450FB2C10C4F8583B44098940094FA476
        SHA-512:EC8F5FB079502C42856F8C60A14826D13BE00255E6E1D2E517A7F77819F6CAD3E0912D3147FFCFF2948E029F384BCA6E52D082CBD34A42C0A56E756ED60D5452
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ...+..Dd...m~.Dd.....6d...........................}....P.O. .:i.....+00.../C:\.....................1.....CY':..PROGRA~2.........O.ICY):....................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....f.2.....CY.: .unins000.exe..J......CY':CY':....Z......................{@.u.n.i.n.s.0.0.0...e.x.e.......X...............-.......W...........c........C:\Program Files (x86)\IZArc\unins000.exe..8.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.u.n.i.n.s.0.0.0...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .M..F...../....%..hT..CrF.f4... .M..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:13 2024, atime=Wed Feb 9 18:03:18 2022, length=21006, window=hide
        Category:dropped
        Size (bytes):1073
        Entropy (8bit):4.631957581767967
        Encrypted:false
        SSDEEP:
        MD5:455E47B892B8D3CBAEAEC7DB201CB32A
        SHA1:2FB41E99C3B90894175B41595D067CFD85B07457
        SHA-256:93B2FF61D93110BF72C4C4DB29E1EAF0428C8924990B24DAA0B49B06D37C3F2F
        SHA-512:256D9BDE1C7C8822DB8EE6F9989EF3C270B1BD4E27B323D5D1658B3B4B77C618904EDC02BDA7056AFC372AC2301EF9C1680BDCDA09EBBD7CA0C49C04531D4592
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ...O`.Dd...O`.Dd............R......................}....P.O. .:i.....+00.../C:\.....................1.....CY':..PROGRA~2.........O.ICY):....................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....f.2..R..ITi. .WHATSNEW.TXT..J......CY':CY':.............................W.H.A.T.S.N.E.W...T.X.T.......X...............-.......W...........c........C:\Program Files (x86)\IZArc\WHATSNEW.TXT..8.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.W.H.A.T.S.N.E.W...T.X.T...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .J..F...../....%..hT..CrF.f4... .J..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.
        Process:C:\Users\user\Desktop\IZArc_4.5.exe
        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):844288
        Entropy (8bit):6.821024307107224
        Encrypted:false
        SSDEEP:
        MD5:296B3061BB1D0A1EFD08719210F3C19F
        SHA1:7A5B348627EB9A99C8B6023277542C45FC8042F8
        SHA-256:87D4223D074E3035A5959264EC9C20CBD4FC51EEA9FC8A9C83FC6414808FF9AC
        SHA-512:5C4E1D3CBC7C354A3B5A081AC47A3BF9C742C4386738D745C81EB7FCCC5D10EA51395A4959077B828AC4B80E996511515A29146392CF3A727AA61BE88744B2E5
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 4%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.................~...`....................@..............................................@...............................%.......%................... ......................................................................................CODE.....}.......~.................. ..`DATA................................@...BSS......................................idata...%.......&..................@....tls.....................................rdata..............................@..P.reloc....... ......................@..P.rsrc....%.......&..................@..P.....................T..............@..P........................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
        Category:dropped
        Size (bytes):19456
        Entropy (8bit):5.8975201046735535
        Encrypted:false
        SSDEEP:
        MD5:3ADAA386B671C2DF3BAE5B39DC093008
        SHA1:067CF95FBDB922D81DB58432C46930F86D23DDED
        SHA-256:71CD2F5BC6E13B8349A7C98697C6D2E3FCDEEA92699CEDD591875BEA869FAE38
        SHA-512:BBE4187758D1A69F75A8CCA6B3184E0C20CF8701B16531B55ED4987497934B3C9EF66ECD5E6B83C7357F69734F1C8301B9F82F0A024BB693B732A2D5760FD303
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 3%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g...#~..#~..#~...q.. ~..#~..!~......"~......+~......"~......"~..Rich#~..........................PE..L....[.L...........!.....6...........E.......P.......................................................................P.......P..(............................p.......................................................P...............................text....5.......6.................. ..`.rdata.......P.......:..............@..@.data...8....`.......<..............@....reloc.......p.......J..............@..B................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32+ executable (console) x86-64, for MS Windows
        Category:dropped
        Size (bytes):6144
        Entropy (8bit):4.289297026665552
        Encrypted:false
        SSDEEP:
        MD5:C8871EFD8AF2CF4D9D42D1FF8FADBF89
        SHA1:D0EACD5322C036554D509C7566F0BCC7607209BD
        SHA-256:E4FC574A01B272C2D0AED0EC813F6D75212E2A15A5F5C417129DD65D69768F40
        SHA-512:2735BB610060F749E26ACD86F2DF2B8A05F2BDD3DCCF3E4B2946EBB21BA0805FB492C474B1EEB2C5B8BF1A421F7C1B8728245F649C644F4A9ECC5BD8770A16F6
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....HP..........#............................@.............................`..............................................................<!.......P.......@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc........P......................@..@................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Category:dropped
        Size (bytes):23312
        Entropy (8bit):4.596242908851566
        Encrypted:false
        SSDEEP:
        MD5:92DC6EF532FBB4A5C3201469A5B5EB63
        SHA1:3E89FF837147C16B4E41C30D6C796374E0B8E62C
        SHA-256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
        SHA-512:9908E573921D5DBC3454A1C0A6C969AB8A81CC2E8B5385391D46B1A738FB06A76AA3282E0E58D0D2FFA6F27C85668CD5178E1500B8A39B1BBAE04366AE6A86D3
        Malicious:false
        Antivirus:
        • Antivirus: ReversingLabs, Detection: 0%
        • Antivirus: Virustotal, Detection: 0%, Browse
        Reputation:unknown
        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......IzJ^..$...$...$...%.".$.T87...$.[."...$...$...$.Rich..$.........................PE..L.....\;...........#..... ...4.......'.......0.....q....................................................................k...l)..<....@.../...................p..T....................................................................................text...{........ .................. ..`.data...\....0.......&..............@....rsrc..../...@...0...(..............@..@.reloc.......p.......X..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:16 2024, atime=Wed Feb 9 17:54:22 2022, length=3420160, window=hide
        Category:dropped
        Size (bytes):1132
        Entropy (8bit):4.52237434958223
        Encrypted:false
        SSDEEP:
        MD5:9C60D4F33B1D533AEDE3171B80F9CFDF
        SHA1:45B7BD294776CDDD0C495E05FFBE587E267B5A22
        SHA-256:D3958C885342AEC1CE90CE0B059E4395775C41F81D948626E38B3F83195D5F86
        SHA-512:2CA902B323319C13D172A9A9D0F0D5379D95AA8D03D9EF3153413E651568F951F7F4C182AFC24BB41439A8068A496322F6E1476B9718729E70B0C797DA3389DD
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ...>\.Dd...j..Fd.....5s.....04.....................s....P.O. .:i.....+00.../C:\.....................1.....CY':..PROGRA~2.........O.ICY):....................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....\.2..04.IT. .IZArc.exe.D......CY':CY':....`.........................I.Z.A.r.c...e.x.e.......U...............-.......T...........c........C:\Program Files (x86)\IZArc\IZArc.exe..8.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.#.%.P.r.o.g.r.a.m.F.i.l.e.s.(.x.8.6.).%.\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .@..F...../....%..hT..CrF.f4... .@..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6
        Process:C:\Users\user\AppData\Local\Temp\is-Q7QBE.tmp\IZArc_4.5.tmp
        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu Oct 3 06:17:13 2024, mtime=Thu Oct 3 06:17:16 2024, atime=Wed Feb 9 17:54:22 2022, length=3420160, window=hide
        Category:dropped
        Size (bytes):1108
        Entropy (8bit):4.5427458045593365
        Encrypted:false
        SSDEEP:
        MD5:04F8B3B678B8CF7E298D5CD8D17C1C25
        SHA1:0775931477B12FB22F24AC20B9DB33BC6BE3F095
        SHA-256:58AEC0C1F9F3571F62922D73E30BA188C5218E4D879F6AA3C8893193136041AC
        SHA-512:DC5898D36DF05AFE33B3B0BF4D741B64E6C44E03626066CE7A829BD5E8CB4BD5FB1515169EE10322B2729F2BF4997ACD79438161DA2B63FB2A1287C1A6B336FD
        Malicious:false
        Reputation:unknown
        Preview:L..................F.... ...>\.Dd......Fd.....5s.....04.....................s....P.O. .:i.....+00.../C:\.....................1.....CY':..PROGRA~2.........O.ICY):....................V........P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....P.1.....CY):..IZArc.<......CY':CY):..............................I.Z.A.r.c.....\.2..04.IT. .IZArc.exe.D......CY':CY':....`.........................I.Z.A.r.c...e.x.e.......U...............-.......T...........c........C:\Program Files (x86)\IZArc\IZArc.exe..,.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.I.Z.A.r.c.#.%.P.r.o.g.r.a.m.F.i.l.e.s.(.x.8.6.).%.\.I.Z.A.r.c.\.I.Z.A.r.c...e.x.e.........*................@Z|...K.J.........`.......X.......287400...........hT..CrF.f4... .@..F...../....%..hT..CrF.f4... .@..F...../....%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1
        File type:PE32 executable (GUI) Intel 80386, for MS Windows
        Entropy (8bit):7.995159777188471
        TrID:
        • Win32 Executable (generic) a (10002005/4) 98.73%
        • Inno Setup installer (109748/4) 1.08%
        • Windows Screen Saver (13104/52) 0.13%
        • Win16/32 Executable Delphi generic (2074/23) 0.02%
        • Generic Win/DOS Executable (2004/3) 0.02%
        File name:IZArc_4.5.exe
        File size:5'460'056 bytes
        MD5:6a3326cf6e377ffe29f946104514b9db
        SHA1:00a76e4983e1655389e70e148721c5e4bf86c3cc
        SHA256:557dc67478b7ab0fd71187de08b3e4164a6d9b8e7d432dbe06713e930df60fe0
        SHA512:956b574e3a25af9d95a1f87c942fb731fb8fdb8328f2e6a9f800cba6c2ab0273e5231e1d63ab5a951e670879a8bcfc2b26e6568439de4c25732d874a03ba8cf4
        SSDEEP:98304:JiwZzXMzwbSNv1zgepFR3JaU8sKA9xqX329JKYvjKmb2nbWbm8k1RsuaZGK:Amz8zwbEXpFR3ysKAf4m9EYveE4BRg3
        TLSH:73463309F743C03DF0A607F29B4247D55C0FAE465F35A7EE28DEEBF44A2110298DA669
        File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
        Icon Hash:0c06920363ed6d18
        Entrypoint:0x40a5f8
        Entrypoint Section:CODE
        Digitally signed:false
        Imagebase:0x400000
        Subsystem:windows gui
        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        DLL Characteristics:
        Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
        TLS Callbacks:
        CLR (.Net) Version:
        OS Version Major:1
        OS Version Minor:0
        File Version Major:1
        File Version Minor:0
        Subsystem Version Major:1
        Subsystem Version Minor:0
        Import Hash:884310b1928934402ea6fec1dbd3cf5e
        Instruction
        push ebp
        mov ebp, esp
        add esp, FFFFFFC4h
        push ebx
        push esi
        push edi
        xor eax, eax
        mov dword ptr [ebp-10h], eax
        mov dword ptr [ebp-24h], eax
        call 00007F0C2462BD83h
        call 00007F0C2462CF8Ah
        call 00007F0C2462D219h
        call 00007F0C2462D2BCh
        call 00007F0C2462F25Bh
        call 00007F0C24631BC6h
        call 00007F0C24631D2Dh
        xor eax, eax
        push ebp
        push 0040ACC9h
        push dword ptr fs:[eax]
        mov dword ptr fs:[eax], esp
        xor edx, edx
        push ebp
        push 0040AC92h
        push dword ptr fs:[edx]
        mov dword ptr fs:[edx], esp
        mov eax, dword ptr [0040C014h]
        call 00007F0C246327DBh
        call 00007F0C246323C6h
        cmp byte ptr [0040B234h], 00000000h
        je 00007F0C246332BEh
        call 00007F0C246328D8h
        xor eax, eax
        call 00007F0C2462CA79h
        lea edx, dword ptr [ebp-10h]
        xor eax, eax
        call 00007F0C2462F86Bh
        mov edx, dword ptr [ebp-10h]
        mov eax, 0040CE28h
        call 00007F0C2462BE1Ah
        push 00000002h
        push 00000000h
        push 00000001h
        mov ecx, dword ptr [0040CE28h]
        mov dl, 01h
        mov eax, 0040738Ch
        call 00007F0C246300FAh
        mov dword ptr [0040CE2Ch], eax
        xor edx, edx
        push ebp
        push 0040AC4Ah
        push dword ptr fs:[edx]
        mov dword ptr fs:[edx], esp
        call 00007F0C24632836h
        mov dword ptr [0040CE34h], eax
        mov eax, dword ptr [0040CE34h]
        cmp dword ptr [eax+0Ch], 00000000h
        NameVirtual AddressVirtual Size Is in Section
        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IMPORT0xd0000x950.idata
        IMAGE_DIRECTORY_ENTRY_RESOURCE0x110000x2451c.rsrc
        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
        IMAGE_DIRECTORY_ENTRY_BASERELOC0x100000x0.reloc
        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
        IMAGE_DIRECTORY_ENTRY_TLS0xf0000x18.rdata
        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_IAT0x00x0
        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
        CODE0x10000x9d300x9e00c3bd95c4b1a8e5199981e0d9b45fd18cFalse0.6052709651898734data6.631765876950794IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        DATA0xb0000x2500x4001ee71d84f1c77af85f1f5c278f880572False0.306640625data2.751820662285145IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        BSS0xc0000xe8c0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .idata0xd0000x9500xa00bb5485bf968b970e5ea81292af2acdbaFalse0.414453125data4.430733069799036IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .tls0xe0000x80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        .rdata0xf0000x180x2009ba824905bf9c7922b6fc87a38b74366False0.052734375data0.2044881574398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
        .reloc0x100000x8c40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
        .rsrc0x110000x2451c0x2460096c3e5775469dd43eddf38c8cba4db1fFalse0.8882557452749141data7.648561729467027IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
        NameRVASizeTypeLanguageCountryZLIB Complexity
        RT_ICON0x114d40x574fPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9970023712585566
        RT_ICON0x16c240x668Device independent bitmap graphic, 48 x 96 x 4, image size 1152EnglishUnited States0.4121951219512195
        RT_ICON0x1728c0x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.5040322580645161
        RT_ICON0x175740x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.5641891891891891
        RT_ICON0x1769c0xaa91PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9993358525134547
        RT_ICON0x221300xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsEnglishUnited States0.5692963752665245
        RT_ICON0x22fd80x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.7188628158844765
        RT_ICON0x238800x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.4869942196531792
        RT_ICON0x23de80xc66cPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9978935349240098
        RT_ICON0x304540x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.46898340248962656
        RT_ICON0x329fc0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.5328330206378987
        RT_ICON0x33aa40x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.6950354609929078
        RT_STRING0x33f0c0x2f2data0.35543766578249336
        RT_STRING0x342000x30cdata0.3871794871794872
        RT_STRING0x3450c0x2cedata0.42618384401114207
        RT_STRING0x347dc0x68data0.75
        RT_STRING0x348440xb4data0.6277777777777778
        RT_STRING0x348f80xaedata0.5344827586206896
        RT_RCDATA0x349a80x2cdata1.1818181818181819
        RT_GROUP_ICON0x349d40xaedataEnglishUnited States0.632183908045977
        RT_VERSION0x34a840x4f4dataEnglishUnited States0.2807570977917981
        RT_MANIFEST0x34f780x5a4XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.42590027700831024
        DLLImport
        kernel32.dllDeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle
        user32.dllMessageBoxA
        oleaut32.dllVariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
        advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA
        kernel32.dllWriteFile, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, Sleep, SizeofResource, SetLastError, SetFilePointer, SetErrorMode, SetEndOfFile, RemoveDirectoryA, ReadFile, LockResource, LoadResource, LoadLibraryA, IsDBCSLeadByte, GetWindowsDirectoryA, GetVersionExA, GetUserDefaultLangID, GetSystemInfo, GetSystemDefaultLCID, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetACP, InterlockedExchange, FormatMessageA, FindResourceA, DeleteFileA, CreateProcessA, CreateFileA, CreateDirectoryA, CloseHandle
        user32.dllTranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA
        comctl32.dllInitCommonControls
        advapi32.dllAdjustTokenPrivileges
        Language of compilation systemCountry where language is spokenMap
        EnglishUnited States