Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2024_04_Setup-S4-View-V4.20.13.exe

Overview

General Information

Sample name:2024_04_Setup-S4-View-V4.20.13.exe
Analysis ID:1533008
MD5:cff2c405dcf893d747b92c600d4dc26a
SHA1:95425a08cbcb8c9ed1f085b62f5c69937d253347
SHA256:d34011319c9faf5400cfb72ccfd04e445b80515bbfade3f9164d08f91b8b63d0
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64
  • 2024_04_Setup-S4-View-V4.20.13.exe (PID: 1048 cmdline: "C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe" MD5: CFF2C405DCF893D747B92C600D4DC26A)
    • 2024_04_Setup-S4-View-V4.20.13.tmp (PID: 1460 cmdline: "C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp" /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe" MD5: 832DAB307E54AA08F4B6CDD9B9720361)
      • Setup-S4-View.exe (PID: 5804 cmdline: "C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\" MD5: 6E1FA307C84ABA5C57F5C32F237DBB3B)
        • Setup-S4-View.tmp (PID: 1096 cmdline: "C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp" /SL5="$10444,15151522,57856,C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\" MD5: 832DAB307E54AA08F4B6CDD9B9720361)
          • _setup64.tmp (PID: 3184 cmdline: helper 105 0x404 MD5: E4211D6D009757C078A9FAC7FF4F03D4)
            • conhost.exe (PID: 3656 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • SNTOperationTrustZoneMigrate.exe (PID: 3632 cmdline: "C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe" MD5: DD9DD242A4F7AA3083435FCE216BCB25)
            • conhost.exe (PID: 2552 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: 2024_04_Setup-S4-View-V4.20.13.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Last update: 1 September 2023LICENSE AND ONLINE SERVICES AGREEMENTThis license and online services agreement has been signed by and between the Customer and the LACROIX group company (LACROIX) as identified in the Order. This Agreement is accepted by the Customer by signing the Order (including by clicking to accept).The Customer and LACROIX are sometimes hereinafter collectively referred to as the Parties and individually as a Party.By downloading installing and/or using the Software or the Services the Customer unconditionally and unreservedly accepts the entire Agreement and undertakes to comply with the terms and conditions thereof. If the Customer does not agree to the terms of the Agreement the Customer must not download install or use the Software or the Services.LACROIX reserves the right to modify the terms of the Agreement at any time without notice or prior information given to the Customer in order to adapt the Agreement to changes in the Software or the Services or to technical legal or case law developments. The updated version of the Agreement is brought to the attention of the Customer simply by being posted online. The Agreement is deemed to have been accepted unreservedly by the Customer which uses the Software or the Services after this posting online. The Customer is therefore advised to consult the terms of the Agreement on a regular basis to be aware of the version then in force at the moment the Customer uses the Software or the Services.1DefinitionsCapitalised terms used in the body of the Agreement whether used in the singular or plural form shall have the meanings set forth below:API means Application Programming Interface.Customer means the legal entity or natural person being a client of LACROIX pursuant to an Order placed pursuant to this Agreement and authorised by LACROIX to download install and/or use the Software and/or the Services.Order means the document (possibly available online) signed or accepted in any other way by the Customer and LACROIX identifying the Parties the Software and/or Services ordered by the Customer the volumes and prices relating thereto the duration and the geographical area. The Customer may place one or more Orders for Software licenses and/or Services under the Agreement. The Orders form an integral part of the Agreement.Agreement means this license and online services agreement the Order referencing the said license and online services agreement and the terms and conditions contained in the internet links referenced in the Agreement.Documentation means the user documentation relating to the Software or Services whatever the form and medium of this documentation including where applicable the specific conditions of use of the Software or Services.Data means a
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Last update: 1 September 2023LICENSE AND ONLINE SERVICES AGREEMENTThis license and online services agreement has been signed by and between the Customer and the LACROIX group company (LACROIX) as identified in the Order. This Agreement is accepted by the Customer by signing the Order (including by clicking to accept).The Customer and LACROIX are sometimes hereinafter collectively referred to as the Parties and individually as a Party.By downloading installing and/or using the Software or the Services the Customer unconditionally and unreservedly accepts the entire Agreement and undertakes to comply with the terms and conditions thereof. If the Customer does not agree to the terms of the Agreement the Customer must not download install or use the Software or the Services.LACROIX reserves the right to modify the terms of the Agreement at any time without notice or prior information given to the Customer in order to adapt the Agreement to changes in the Software or the Services or to technical legal or case law developments. The updated version of the Agreement is brought to the attention of the Customer simply by being posted online. The Agreement is deemed to have been accepted unreservedly by the Customer which uses the Software or the Services after this posting online. The Customer is therefore advised to consult the terms of the Agreement on a regular basis to be aware of the version then in force at the moment the Customer uses the Software or the Services.1DefinitionsCapitalised terms used in the body of the Agreement whether used in the singular or plural form shall have the meanings set forth below:API means Application Programming Interface.Customer means the legal entity or natural person being a client of LACROIX pursuant to an Order placed pursuant to this Agreement and authorised by LACROIX to download install and/or use the Software and/or the Services.Order means the document (possibly available online) signed or accepted in any other way by the Customer and LACROIX identifying the Parties the Software and/or Services ordered by the Customer the volumes and prices relating thereto the duration and the geographical area. The Customer may place one or more Orders for Software licenses and/or Services under the Agreement. The Orders form an integral part of the Agreement.Agreement means this license and online services agreement the Order referencing the said license and online services agreement and the terms and conditions contained in the internet links referenced in the Agreement.Documentation means the user documentation relating to the Software or Services whatever the form and medium of this documentation including where applicable the specific conditions of use of the Software or Services.Data means a
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX SofrelJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-ViewJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\unins000.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NA6MU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\Resources.de.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\Resources.en.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\Resources.es.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\frJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\fr\Resources.fr.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\Resources.it.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\unins001.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-2H57J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\LicencesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-GJBTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-8S8GG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-1C7FG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-QKQ6M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-AVN7T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-NBDG7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-5PU52.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-1Q05E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-RFS0L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-VA86U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-6LHTM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-8IA3J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-3JH6B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9U3EE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IBGQ4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HKM4S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EP5BO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-TQ04E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-4GNF5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-4MBH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EAKNJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0E3AN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RFN5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-VCOJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CMV4L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CO470.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MQRPV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-K8GT2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5OU1M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-24Q32.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-GJHT8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EPB0C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-PAQHC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NIACK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-AMCK3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-SAULK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LN3AI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-63MLF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HSBN8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1B2OG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-VM2NU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-6LAJA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-011JG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-A8B8O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-58KO8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-629VU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-ETP9J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-FQ7A5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-GVSU9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RAUP2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-L9SE8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-E1V4F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-R1SGO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-JC70F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-FFPA8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LKI3D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-TR8AE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DO2RS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T78QA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-6TKMN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RDUQ2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DV2L2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-64KF6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EBEI6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9CU2D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CQKPO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-UCSDM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1JODI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0KPQ7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T8JRN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CUTEF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-51Q4I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MHHC6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-07KGM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T1MUB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-8T8MU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-D15N5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-B4JIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-C7GU2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LQ48F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-F3FDQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-C93UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EM22B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-81M0T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-N6KMT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0QSN7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-B3LJV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-14EBV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-50VD7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NS71O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NPHFL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-V52PD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-G7IVF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5TC81.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-AAS65.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HCBT0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DI2GE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-KF3NS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-JH2S8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9M3EF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-3R6MR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1612U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-8SVAM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-I729J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MEJTF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-7V1V2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5CTU6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MRUE4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IJG31.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RKS5T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IO3NH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-Q18VP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-L48QA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-OMBLA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-KUKBE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-K4C6A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-639A2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5E0EU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-PEO2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5D9DG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgrJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\is-FSGCV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\ConfigJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-RACOJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-JF1PV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-9HN53.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-V46HS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\deJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-SNIS1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MTL24.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-4GV0Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-12JRF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-2PJ6V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-BKBVR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-88ROD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TSM0G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MNQB6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-Q1TBT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-QJN7L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-K9MBO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-I9EUD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-R82J1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AV8EA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-45VRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AIVQD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TETLV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-FCHG3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TIL3R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-H4HST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MSV9G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\enJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-88TKO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-HI6A6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-U9E7M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-84CMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IFV82.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-AI79O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-0OG0F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-NL5PA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N6DPP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-PI5H9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-LLIH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-O4B33.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-GU3TJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-DMU3F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-KJV73.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IO3OE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-5ITBB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-JRJN5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-39RKE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N93I3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-SGKUN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-3F4N1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLibJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLib\is-C4NEP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLib\is-R8GSR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\esJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-0I2NF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-6F11R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-REQFT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-PRAPE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-58PPC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-HF0AC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-ELILH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-DQESJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-EU6C6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9TNNB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9121E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-77VF3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4TBRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-VMG3H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9CCPB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-699DL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-TM2NE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-7FRTL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4F771.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-CMA91.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-S8MJD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-BND8G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\itJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-F83O7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-VDM61.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-UB479.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-HABQQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-CO0UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-PTTTA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2MNEP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-LRAV9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-QUNG5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-SJKRM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-NF99L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-KKVKO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2886D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7SN1T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7ITRM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-89MDT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-IR9V5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-TGF4M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-732CK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-609HG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-3ONS6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-9CSCQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSLJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-5MB86.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ODMQA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ERV37.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ROON0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-N3HU4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-7BLN2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-DCCU0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\DefaultJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-5QUK0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-8LJ27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-1SDAH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrateJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0FSQB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-IMF8J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3OCC6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-8BABE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-PE69T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-TRODH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4EQNQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RQL4I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SLB2H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-GUQFH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K1O4R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0E7KK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3F4TS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-Q2EFC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UNPN0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-833ED.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7NJPP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K8C1P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-46DM1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-347OL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-D4BNT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3MFFG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-ABPDN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SC7E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3D2U2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-F0VLA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-21NDQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-E3UTF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-54VM0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-79K3V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-KPLA1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5EA9I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UL6DE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-O3R06.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RHHQ4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-HGR93.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-G87M5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-1DV2O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5HQPS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-49F6R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7ME5S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4FDOC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-V4B91.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-I151H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K3CMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-LBT1Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-FK9BA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5BJBU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgrJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgr\is-VSC5C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\ConfigJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Config\is-ARHJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\deJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-E748F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-53UCP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-47PKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-DO4N7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-KUIC9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HMDUR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HLK9U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HFA8L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-1JF6G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\enJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-773GS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-H0RF0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-79MOU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-RPPAQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-Q5G5I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-8HSHI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-5N5CP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-VTGH2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-BTAJO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\esJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-OI13D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-5FTSU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-M8JKU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-SK564.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-AVSQ8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-TQQM6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-61UM6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-843RE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-PKRFS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\itJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-H8EP9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-RL8OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-33I6F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-MBF20.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-4JBQU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1K23T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-M9PDU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-8MTID.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1L83U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSLJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-JVI3R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-T0MCK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-SRF6Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-F14H0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-TBL85.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-KJFH8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-6NS90.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\DefaultJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-EIIIS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-LAR4K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-IAAUJ.tmpJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\LogJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Log\Sofrel.Uranus.Framework.Logger.Erreur.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9E82D52C-73A8-4180-844B-564D36F24BDE}_is1Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-10-14 #001.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\Desktop\Setup Log 2024-10-14 #001.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-10-14 #002.txtJump to behavior
Source: 2024_04_Setup-S4-View-V4.20.13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdbD} source: is-EP5BO.tmp.7.dr
Source: Binary string: {app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 4{app}\SharpDX.Direct3D9.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Logging\Src\Logging\obj\Release\Microsoft.Practices.EnterpriseLibrary.Logging.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679450866.0000000004B72000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: CertMgr.pdb source: is-FSGCV.tmp.7.dr
Source: Binary string: C:\BuildAgent\work\2a0d6c9273f701c9\WPF\Build\Lib\net47\SciChart.Charting.pdbBSJB source: is-SAULK.tmp.7.dr
Source: Binary string: CertMgr.pdbH source: is-FSGCV.tmp.7.dr
Source: Binary string: >{app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Drawing\Microsoft.Expression.Drawing.pdb source: is-IMF8J.tmp.7.dr
Source: Binary string: -{app}\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: I,*C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.dllps`C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: SharpDX.DXGI.pdb source: is-RAUP2.tmp.7.dr
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Prototyping.SketchControls\Microsoft.Expression.Prototyping.SketchControls.pdb source: is-TRODH.tmp.7.dr
Source: Binary string: {app}\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: `C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: @+{app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Desktop\Prism.Interactivity\obj\Release\Microsoft.Practices.Prism.Interactivity.pdb source: is-CO470.tmp.7.dr
Source: Binary string: {app}\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb^ source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: RC:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 1{app}\TrustZoneMigrate\SNACooperateTrustZone.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 5{app}\SharpDX.Direct3D11.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 3C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.pdb^, source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Logger\obj\Release\SUFLogger.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679080591.0000000004A52000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: =C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdbrD source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: YC:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.TlsCallback\obj\Release\SUFTlsCallback.pdbN source: is-LBT1Q.tmp.7.dr
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Common\Src\obj\Release\Microsoft.Practices.EnterpriseLibrary.Common.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679541333.0000000004BE2000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: FC:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Operation\Operation.Visualization.V8\obj\Release\SNAOperationVisualizationV8.pdb source: is-3R6MR.tmp.7.dr
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Operation\Operation.Visualization.V5\obj\Release\SNAOperationVisualizationV5.pdb source: is-JH2S8.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Security\obj\Release\SUFSecurity.pdb source: is-L48QA.tmp.7.dr
Source: Binary string: {app}\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdb source: is-EP5BO.tmp.7.dr
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Prism.Mvvm.Desktop\obj\Release\Microsoft.Practices.Prism.Mvvm.Desktop.pdb source: is-K8GT2.tmp.7.dr
Source: Binary string: C:\BuildAgent\work\2a0d6c9273f701c9\WPF\Build\Lib\net47\SciChart.Charting.pdb source: is-SAULK.tmp.7.dr
Source: Binary string: OC:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8{app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: p3{app}\SharpDX.DXGI.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: =C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\ExceptionHandling\Src\ExceptionHandling\obj\Release\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.pdbd source: is-EAKNJ.tmp.7.dr
Source: Binary string: >C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb^H source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Tools\Tools.Operation.TrustZone.Migrate\obj\Release\SNTOperationTrustZoneMigrate.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: t6{app}\SharpDX.Direct3D11.Effects.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Prism.SharedInterfaces\obj\Release\Microsoft.Practices.Prism.SharedInterfaces.pdb source: is-833ED.tmp.7.dr
Source: Binary string: p2{app}\SharpDX.Mathematics.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: >C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Controls\Microsoft.Expression.Controls.pdb source: is-9U3EE.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdbB source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\dd\WPF_1\src\wpf\src\ControlsPack\WPFToolkit\Layout\obj\Release\System.Windows.Controls.Layout.Toolkit.pdb source: is-5E0EU.tmp.7.dr
Source: Binary string: C:\dd\WPF_1\src\wpf\src\ControlsPack\WPFToolkit\Layout\obj\Release\System.Windows.Controls.Layout.Toolkit.pdbxp source: is-5E0EU.tmp.7.dr
Source: Binary string: <{app}\Microsoft.Practices.ServiceLocation.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ${app}\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Common\Src\obj\Release\Microsoft.Practices.EnterpriseLibrary.Common.pdbT source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679541333.0000000004BE2000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: {app}\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 1{app}\SharpDX.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: FC:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdbV$ source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\ExceptionHandling\Src\ExceptionHandling\obj\Release\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.pdb source: is-EAKNJ.tmp.7.dr
Source: Binary string: {app}\SharpDX.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 7{app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Environment\obj\Release\SUFEnvironment.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1678621608.0000000000B22000.00000002.00000001.01000000.00000011.sdmp, is-49F6R.tmp.7.dr
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8{app}\SharpDX.D3DCompiler.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 0{app}\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Cooperate\Cooperate.LxConnect.Service\obj\Release\SNACooperateLxConnectService.pdb source: is-0KPQ7.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.TlsCallback\obj\Release\SUFTlsCallback.pdb source: is-LBT1Q.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: OC:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb^h source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: SharpDX.DXGI.pdb X source: is-RAUP2.tmp.7.dr
Source: Binary string: C:\Users\Michelle\Documents\Visual Studio 2017\Projects\Microsoft.SDK.Expression.Blend\Microsoft.SDK.Expression.Blend\obj\Debug\Microsoft.SDK.Expression.Blend.pdb$'>' 0'_CorDllMainmscoree.dll source: is-NIACK.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Tools\Tools.Operation.TrustZone.Migrate\obj\Release\SNTOperationTrustZoneMigrate.pdb2HLH >H_CorExeMainmscoree.dll source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\Users\Michelle\Documents\Visual Studio 2017\Projects\Microsoft.SDK.Expression.Blend\Microsoft.SDK.Expression.Blend\obj\Debug\Microsoft.SDK.Expression.Blend.pdb source: is-NIACK.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.dllHK8C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\zlib-dll\Release\isunzlib.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Environment\obj\Release\SUFEnvironment.pdb\BvB hB_CorDllMainmscoree.dll source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1678621608.0000000000B22000.00000002.00000001.01000000.00000011.sdmp, is-49F6R.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Extension\obj\Release\SUFExtension.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679375530.0000000004B12000.00000002.00000001.01000000.00000013.sdmp
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.certum.pl/ca.crl0:
Source: Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.certum.pl/l3.
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.certum.pl/l3.crl0a
Source: Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: is-9U3EE.tmp.7.drString found in binary or memory: http://expression/microsoft.expression.controls.dll
Source: is-IMF8J.tmp.7.drString found in binary or memory: http://expression/microsoft.expression.drawing.dll0
Source: is-EP5BO.tmp.7.drString found in binary or memory: http://expression/microsoft.expression.interactions.dll
Source: is-TRODH.tmp.7.drString found in binary or memory: http://expression/microsoft.expression.prototyping.sketchcontrols.dll
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.certum.pl0.
Source: Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://repository.certum.pl/l3.cer0
Source: is-SAULK.tmp.7.dr, is-AAS65.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Common.Extensions
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Common.ExtensionsO
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Model.ChartSeries
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Model.ChartSeriesQ
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.Databinding
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.DatabindingR
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Visuals.TradeChart
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart%SciChart.Charting.Visuals.Annotations
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart%SciChart.Charting.Visuals.AnnotationsM
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart&SciChart.Charting.Visuals.PointMarkers
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart&SciChart.Charting.Visuals.PointMarkersY
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart(SciChart.Charting.Numerics.TickProviders
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart(SciChart.Charting.Numerics.TickProvidersG
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart)SciChart.Charting.Common.MarkupExtensions
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart)SciChart.Charting.Common.MarkupExtensionsO
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart-SciChart.Charting.Visuals.Axes.LabelProviders
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Numerics.CoordinateProviders
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Numerics.CoordinateProvidersZ
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.Axes.LogarithmicAxis
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.Axes.LogarithmicAxis_
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.TradeChart.MultiPane
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.TradeChart.MultiPaned
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Numerics.CoordinateCalculators
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxis
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxisU
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animations
Source: is-SAULK.tmp.7.drString found in binary or memory: http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animations0
Source: is-GJBTC.tmp.7.drString found in binary or memory: http://www.apache.org/licenses/
Source: is-GJBTC.tmp.7.drString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: is-CO470.tmp.7.drString found in binary or memory: http://www.codeplex.com/prism
Source: is-K8GT2.tmp.7.drString found in binary or memory: http://www.codeplex.com/prism#Microsoft.Practices.Prism.ViewModel
Source: is-CO470.tmp.7.drString found in binary or memory: http://www.codeplex.com/prism:Microsoft.Practices.Prism.Interactivity.InteractionRequest
Source: is-5E0EU.tmp.7.drString found in binary or memory: http://www.codeplex.com/wpf
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpString found in binary or memory: http://www.innosetup.com/
Source: Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.jrsoftware.org/0
Source: 2024_04_Setup-S4-View-V4.20.13.exe, is-F5IU6.tmp.2.drString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
Source: 2024_04_Setup-S4-View-V4.20.13.exe, is-F5IU6.tmp.2.drString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: is-SRF6Q.tmp.7.drString found in binary or memory: http://www.openssl.org/)
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpString found in binary or memory: http://www.remobjects.com/ps
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpString found in binary or memory: http://www.remobjects.com/psU
Source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: http://www.sofrel.com/ConfigurationVisualizationGeneralParams/
Source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmpString found in binary or memory: http://www.sofrel.com/ConfigurationVisualizationGeneralParams/T
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNACooperate/SetPasswordInput.xsdT
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNACooperate/SetPasswordInput.xsdV
Source: is-64KF6.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAIdentityCard/E
Source: is-64KF6.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAIdentityCard/T
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdT
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdV
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/V110/RestartInput.xsdT
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/V110/RestartInput.xsdd
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsdT
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsdd
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNEIdentityCard/V110/T
Source: is-9CU2D.tmp.7.drString found in binary or memory: http://www.sofrel.com/SNEIdentityCard/V110/W
Source: is-V52PD.tmp.7.drString found in binary or memory: http://www.sofrel.com/StationConnection/G
Source: is-V52PD.tmp.7.drString found in binary or memory: http://www.sofrel.com/StationConnection/T
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://fr.lacroix-group.com/vie-privee/
Source: is-6LHTM.tmp.7.drString found in binary or memory: https://github.com/jquery/jquery
Source: is-6LHTM.tmp.7.drString found in binary or memory: https://jquery.org/
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730243352.0000000002684000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729897385.0000000002164000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730282551.0000000002688000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730187996.0000000002620000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730034355.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730133469.00000000021FC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729973001.00000000021AC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359384126.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359252275.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730096712.00000000021F8000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1362003060.000000000214C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719834895.000000000215C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719193779.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719575132.0000000003310000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1361845260.0000000003110000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719478541.00000000033C4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1726050951.00000000021A4000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1685995917.0000000002098000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603142010.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1686551455.0000000002658000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1686213258.00000000025C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://lacroix-group.com/
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730243352.0000000002684000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729897385.0000000002164000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730282551.0000000002688000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730187996.0000000002620000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730034355.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730133469.00000000021FC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729973001.00000000021AC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359384126.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359252275.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730096712.00000000021F8000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1362003060.000000000214C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1471714765.0000000000839000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1407756392.000000000080C000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719834895.000000000215C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719193779.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719575132.0000000003310000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1718730811.0000000000811000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1361845260.0000000003110000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719478541.00000000033C4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1726050951.00000000021A4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1408237246.000000000080C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://lacroix-group.com/private-life/
Source: is-SAULK.tmp.7.drString found in binary or memory: https://www.c-sharpcorner.com/UploadFile/mahesh/binding-static-properties-in-wpf-4-5/
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.certum.pl/CPS0
Source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.certum.pl/repository.0
Source: is-T0MCK.tmp.7.dr, is-5MB86.tmp.7.drString found in binary or memory: https://www.openssl.org/H
Source: Setup-S4-View.tmp, 00000007.00000003.1679782768.0000000003150000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1683990301.000000000018D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://www.openssl.org/community/mailinglists.html
Source: is-SAULK.tmp.7.drString found in binary or memory: https://www.scichart.com/documentation/v4.x/webframe.html#Performance_Tips_&_Tricks.html
Source: 2024_04_Setup-S4-View-V4.20.13.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: 2024_04_Setup-S4-View-V4.20.13.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: 2024_04_Setup-S4-View-V4.20.13.tmp.0.drStatic PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: is-NA6MU.tmp.2.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-NA6MU.tmp.2.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-NA6MU.tmp.2.drStatic PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: Setup-S4-View.tmp.6.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: Setup-S4-View.tmp.6.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: Setup-S4-View.tmp.6.drStatic PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs 2024_04_Setup-S4-View-V4.20.13.exe
Source: 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs 2024_04_Setup-S4-View-V4.20.13.exe
Source: 2024_04_Setup-S4-View-V4.20.13.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engineClassification label: clean3.winEXE@13/678@0/0
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Program Files\LACROIX SofrelJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3656:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2552:120:WilError_03
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeFile created: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile read: C:\Windows\win.iniJump to behavior
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
Source: 2024_04_Setup-S4-View-V4.20.13.exeString found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeFile read: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe "C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe"
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp "C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp" /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe"
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe "C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeProcess created: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp "C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp" /SL5="$10444,15151522,57856,C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmp helper 105 0x404
Source: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmpProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe "C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe"
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp "C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp" /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe "C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeProcess created: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp "C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp" /SL5="$10444,15151522,57856,C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmp helper 105 0x404Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe "C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe"Jump to behavior
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: msxml3.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: sfc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: sfc_os.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: linkinfo.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: ntshrui.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: cscapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: version.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: wldp.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: profapi.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: netutils.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpWindow found: window name: TSelectLanguageFormJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpAutomated click: I accept the agreement
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Last update: 1 September 2023LICENSE AND ONLINE SERVICES AGREEMENTThis license and online services agreement has been signed by and between the Customer and the LACROIX group company (LACROIX) as identified in the Order. This Agreement is accepted by the Customer by signing the Order (including by clicking to accept).The Customer and LACROIX are sometimes hereinafter collectively referred to as the Parties and individually as a Party.By downloading installing and/or using the Software or the Services the Customer unconditionally and unreservedly accepts the entire Agreement and undertakes to comply with the terms and conditions thereof. If the Customer does not agree to the terms of the Agreement the Customer must not download install or use the Software or the Services.LACROIX reserves the right to modify the terms of the Agreement at any time without notice or prior information given to the Customer in order to adapt the Agreement to changes in the Software or the Services or to technical legal or case law developments. The updated version of the Agreement is brought to the attention of the Customer simply by being posted online. The Agreement is deemed to have been accepted unreservedly by the Customer which uses the Software or the Services after this posting online. The Customer is therefore advised to consult the terms of the Agreement on a regular basis to be aware of the version then in force at the moment the Customer uses the Software or the Services.1DefinitionsCapitalised terms used in the body of the Agreement whether used in the singular or plural form shall have the meanings set forth below:API means Application Programming Interface.Customer means the legal entity or natural person being a client of LACROIX pursuant to an Order placed pursuant to this Agreement and authorised by LACROIX to download install and/or use the Software and/or the Services.Order means the document (possibly available online) signed or accepted in any other way by the Customer and LACROIX identifying the Parties the Software and/or Services ordered by the Customer the volumes and prices relating thereto the duration and the geographical area. The Customer may place one or more Orders for Software licenses and/or Services under the Agreement. The Orders form an integral part of the Agreement.Agreement means this license and online services agreement the Order referencing the said license and online services agreement and the terms and conditions contained in the internet links referenced in the Agreement.Documentation means the user documentation relating to the Software or Services whatever the form and medium of this documentation including where applicable the specific conditions of use of the Software or Services.Data means a
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.Last update: 1 September 2023LICENSE AND ONLINE SERVICES AGREEMENTThis license and online services agreement has been signed by and between the Customer and the LACROIX group company (LACROIX) as identified in the Order. This Agreement is accepted by the Customer by signing the Order (including by clicking to accept).The Customer and LACROIX are sometimes hereinafter collectively referred to as the Parties and individually as a Party.By downloading installing and/or using the Software or the Services the Customer unconditionally and unreservedly accepts the entire Agreement and undertakes to comply with the terms and conditions thereof. If the Customer does not agree to the terms of the Agreement the Customer must not download install or use the Software or the Services.LACROIX reserves the right to modify the terms of the Agreement at any time without notice or prior information given to the Customer in order to adapt the Agreement to changes in the Software or the Services or to technical legal or case law developments. The updated version of the Agreement is brought to the attention of the Customer simply by being posted online. The Agreement is deemed to have been accepted unreservedly by the Customer which uses the Software or the Services after this posting online. The Customer is therefore advised to consult the terms of the Agreement on a regular basis to be aware of the version then in force at the moment the Customer uses the Software or the Services.1DefinitionsCapitalised terms used in the body of the Agreement whether used in the singular or plural form shall have the meanings set forth below:API means Application Programming Interface.Customer means the legal entity or natural person being a client of LACROIX pursuant to an Order placed pursuant to this Agreement and authorised by LACROIX to download install and/or use the Software and/or the Services.Order means the document (possibly available online) signed or accepted in any other way by the Customer and LACROIX identifying the Parties the Software and/or Services ordered by the Customer the volumes and prices relating thereto the duration and the geographical area. The Customer may place one or more Orders for Software licenses and/or Services under the Agreement. The Orders form an integral part of the Agreement.Agreement means this license and online services agreement the Order referencing the said license and online services agreement and the terms and conditions contained in the internet links referenced in the Agreement.Documentation means the user documentation relating to the Software or Services whatever the form and medium of this documentation including where applicable the specific conditions of use of the Software or Services.Data means a
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX SofrelJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-ViewJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\unins000.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NA6MU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\Resources.de.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\Resources.en.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\Resources.es.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\frJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\fr\Resources.fr.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\Resources.it.xmlJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\unins001.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-2H57J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\LicencesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-GJBTC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-8S8GG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-1C7FG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-QKQ6M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-AVN7T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-NBDG7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-5PU52.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-1Q05E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-RFS0L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-VA86U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-6LHTM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Licences\is-8IA3J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-3JH6B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9U3EE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IBGQ4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HKM4S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EP5BO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-TQ04E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-4GNF5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-4MBH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EAKNJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0E3AN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RFN5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-VCOJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CMV4L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CO470.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MQRPV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-K8GT2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5OU1M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-24Q32.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-GJHT8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EPB0C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-PAQHC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NIACK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-AMCK3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-SAULK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LN3AI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-63MLF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HSBN8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1B2OG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-VM2NU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-6LAJA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-011JG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-A8B8O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-58KO8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-629VU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-ETP9J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-FQ7A5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-GVSU9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RAUP2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-L9SE8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-E1V4F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-R1SGO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-JC70F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-FFPA8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LKI3D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-TR8AE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DO2RS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T78QA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-6TKMN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RDUQ2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DV2L2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-64KF6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EBEI6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9CU2D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CQKPO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-UCSDM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1JODI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0KPQ7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T8JRN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-CUTEF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-51Q4I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MHHC6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-07KGM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-T1MUB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-8T8MU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-D15N5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-B4JIE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-C7GU2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-LQ48F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-F3FDQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-C93UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-EM22B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-81M0T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-N6KMT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-0QSN7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-B3LJV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-14EBV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-50VD7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NS71O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-NPHFL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-V52PD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-G7IVF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5TC81.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-AAS65.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-HCBT0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-DI2GE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-KF3NS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-JH2S8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-9M3EF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-3R6MR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-1612U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-8SVAM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-I729J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MEJTF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-7V1V2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5CTU6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-MRUE4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IJG31.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-RKS5T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-IO3NH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-Q18VP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-L48QA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-OMBLA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-KUKBE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-K4C6A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-639A2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5E0EU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-PEO2L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\is-5D9DG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgrJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\is-FSGCV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\ConfigJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-RACOJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-JF1PV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-9HN53.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\Config\is-V46HS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\deJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-SNIS1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MTL24.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-4GV0Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-12JRF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-2PJ6V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-BKBVR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-88ROD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TSM0G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MNQB6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-Q1TBT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-QJN7L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-K9MBO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-I9EUD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-R82J1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AV8EA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-45VRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AIVQD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TETLV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-FCHG3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TIL3R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-H4HST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MSV9G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\enJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-88TKO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-HI6A6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-U9E7M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-84CMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IFV82.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-AI79O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-0OG0F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-NL5PA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N6DPP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-PI5H9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-LLIH1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-O4B33.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-GU3TJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-DMU3F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-KJV73.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IO3OE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-5ITBB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-JRJN5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-39RKE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N93I3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-SGKUN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-3F4N1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLibJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLib\is-C4NEP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\EntLib\is-R8GSR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\esJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-0I2NF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-6F11R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-REQFT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-PRAPE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-58PPC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-HF0AC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-ELILH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-DQESJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-EU6C6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9TNNB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9121E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-77VF3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4TBRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-VMG3H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9CCPB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-699DL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-TM2NE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-7FRTL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4F771.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-CMA91.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-S8MJD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-BND8G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\itJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-F83O7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-VDM61.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-UB479.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-HABQQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-CO0UM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-PTTTA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2MNEP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-LRAV9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-QUNG5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-SJKRM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-NF99L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-KKVKO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2886D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7SN1T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7ITRM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-89MDT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-IR9V5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-TGF4M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-732CK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-609HG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-3ONS6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-9CSCQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSLJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-5MB86.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ODMQA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ERV37.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ROON0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-N3HU4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-7BLN2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-DCCU0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\DefaultJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-5QUK0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-8LJ27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\Default\is-1SDAH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrateJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0FSQB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-IMF8J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3OCC6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-8BABE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-PE69T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-TRODH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4EQNQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RQL4I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SLB2H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-GUQFH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K1O4R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0E7KK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3F4TS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-Q2EFC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UNPN0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-833ED.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7NJPP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K8C1P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-46DM1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-347OL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-D4BNT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3MFFG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-ABPDN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SC7E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3D2U2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-F0VLA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-21NDQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-E3UTF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-54VM0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-79K3V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-KPLA1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5EA9I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UL6DE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-O3R06.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RHHQ4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-HGR93.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-G87M5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-1DV2O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5HQPS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-49F6R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7ME5S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4FDOC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-V4B91.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-I151H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K3CMC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-LBT1Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-FK9BA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5BJBU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgrJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgr\is-VSC5C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\ConfigJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Config\is-ARHJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\deJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-E748F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-53UCP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-47PKL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-DO4N7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-KUIC9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HMDUR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HLK9U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HFA8L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-1JF6G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\enJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-773GS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-H0RF0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-79MOU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-RPPAQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-Q5G5I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-8HSHI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-5N5CP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-VTGH2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-BTAJO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\esJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-OI13D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-5FTSU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-M8JKU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-SK564.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-AVSQ8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-TQQM6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-61UM6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-843RE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-PKRFS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\itJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-H8EP9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-RL8OJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-33I6F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-MBF20.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-4JBQU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1K23T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-M9PDU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-8MTID.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1L83U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSLJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-JVI3R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-T0MCK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-SRF6Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-F14H0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-TBL85.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-KJFH8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-6NS90.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\DefaultJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-EIIIS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-LAR4K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\Default\is-IAAUJ.tmpJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\LogJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeDirectory created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Log\Sofrel.Uranus.Framework.Logger.Erreur.logJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9E82D52C-73A8-4180-844B-564D36F24BDE}_is1Jump to behavior
Source: 2024_04_Setup-S4-View-V4.20.13.exeStatic file information: File size 15783365 > 1048576
Source: 2024_04_Setup-S4-View-V4.20.13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdbD} source: is-EP5BO.tmp.7.dr
Source: Binary string: {app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 4{app}\SharpDX.Direct3D9.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Logging\Src\Logging\obj\Release\Microsoft.Practices.EnterpriseLibrary.Logging.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679450866.0000000004B72000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: CertMgr.pdb source: is-FSGCV.tmp.7.dr
Source: Binary string: C:\BuildAgent\work\2a0d6c9273f701c9\WPF\Build\Lib\net47\SciChart.Charting.pdbBSJB source: is-SAULK.tmp.7.dr
Source: Binary string: CertMgr.pdbH source: is-FSGCV.tmp.7.dr
Source: Binary string: >{app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Drawing\Microsoft.Expression.Drawing.pdb source: is-IMF8J.tmp.7.dr
Source: Binary string: -{app}\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: I,*C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.dllps`C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: SharpDX.DXGI.pdb source: is-RAUP2.tmp.7.dr
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Prototyping.SketchControls\Microsoft.Expression.Prototyping.SketchControls.pdb source: is-TRODH.tmp.7.dr
Source: Binary string: {app}\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: `C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: @+{app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Desktop\Prism.Interactivity\obj\Release\Microsoft.Practices.Prism.Interactivity.pdb source: is-CO470.tmp.7.dr
Source: Binary string: {app}\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb^ source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: RC:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 1{app}\TrustZoneMigrate\SNACooperateTrustZone.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1683279345.0000000003440000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 5{app}\SharpDX.Direct3D11.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 3C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.pdb^, source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Logger\obj\Release\SUFLogger.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679080591.0000000004A52000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: =C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdbrD source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: YC:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: {app}\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.TlsCallback\obj\Release\SUFTlsCallback.pdbN source: is-LBT1Q.tmp.7.dr
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Common\Src\obj\Release\Microsoft.Practices.EnterpriseLibrary.Common.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679541333.0000000004BE2000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: FC:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Operation\Operation.Visualization.V8\obj\Release\SNAOperationVisualizationV8.pdb source: is-3R6MR.tmp.7.dr
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Operation\Operation.Visualization.V5\obj\Release\SNAOperationVisualizationV5.pdb source: is-JH2S8.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Security\obj\Release\SUFSecurity.pdb source: is-L48QA.tmp.7.dr
Source: Binary string: {app}\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Interactions\Microsoft.Expression.Interactions.pdb source: is-EP5BO.tmp.7.dr
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Prism.Mvvm.Desktop\obj\Release\Microsoft.Practices.Prism.Mvvm.Desktop.pdb source: is-K8GT2.tmp.7.dr
Source: Binary string: C:\BuildAgent\work\2a0d6c9273f701c9\WPF\Build\Lib\net47\SciChart.Charting.pdb source: is-SAULK.tmp.7.dr
Source: Binary string: OC:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8{app}\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681650165.000000000343C000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: p3{app}\SharpDX.DXGI.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: =C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\ExceptionHandling\Src\ExceptionHandling\obj\Release\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.pdbd source: is-EAKNJ.tmp.7.dr
Source: Binary string: >C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb^H source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Tools\Tools.Operation.TrustZone.Migrate\obj\Release\SNTOperationTrustZoneMigrate.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: t6{app}\SharpDX.Direct3D11.Effects.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\Projects\WorkingDir\PrismLibraryBuild\PrismLibrary\Prism.SharedInterfaces\obj\Release\Microsoft.Practices.Prism.SharedInterfaces.pdb source: is-833ED.tmp.7.dr
Source: Binary string: p2{app}\SharpDX.Mathematics.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: >C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: d:\ExprUpdate2\Blend\SDK\BlendWPFSDK\Build\Intermediate\Release\Libraries\Microsoft.Expression.Controls\Microsoft.Expression.Controls.pdb source: is-9U3EE.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdbB source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\dd\WPF_1\src\wpf\src\ControlsPack\WPFToolkit\Layout\obj\Release\System.Windows.Controls.Layout.Toolkit.pdb source: is-5E0EU.tmp.7.dr
Source: Binary string: C:\dd\WPF_1\src\wpf\src\ControlsPack\WPFToolkit\Layout\obj\Release\System.Windows.Controls.Layout.Toolkit.pdbxp source: is-5E0EU.tmp.7.dr
Source: Binary string: <{app}\Microsoft.Practices.ServiceLocation.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: ${app}\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\Common\Src\obj\Release\Microsoft.Practices.EnterpriseLibrary.Common.pdbT source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679541333.0000000004BE2000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: {app}\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 1{app}\SharpDX.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: FC:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdbV$ source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\Builds\40\EntLib\ELV6-Blocks-NuGet\src\Source\Blocks\ExceptionHandling\Src\ExceptionHandling\obj\Release\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.pdb source: is-EAKNJ.tmp.7.dr
Source: Binary string: {app}\SharpDX.pdb source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 7{app}\TrustZoneMigrate\SNTOperationTrustZoneMigrate.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Environment\obj\Release\SUFEnvironment.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1678621608.0000000000B22000.00000002.00000001.01000000.00000011.sdmp, is-49F6R.tmp.7.dr
Source: Binary string: ?C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 8{app}\SharpDX.D3DCompiler.pdb` source: Setup-S4-View.tmp, 00000007.00000003.1681668216.0000000003438000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: 0{app}\TrustZoneMigrate\SNACooperateTrustZone.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Application\Cooperate\Cooperate.LxConnect.Service\obj\Release\SNACooperateLxConnectService.pdb source: is-0KPQ7.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.TlsCallback\obj\Release\SUFTlsCallback.pdb source: is-LBT1Q.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.pdb source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: OC:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.pdb^h source: Setup-S4-View.tmp, 00000007.00000003.1652767785.0000000003168000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: SharpDX.DXGI.pdb X source: is-RAUP2.tmp.7.dr
Source: Binary string: C:\Users\Michelle\Documents\Visual Studio 2017\Projects\Microsoft.SDK.Expression.Blend\Microsoft.SDK.Expression.Blend\obj\Debug\Microsoft.SDK.Expression.Blend.pdb$'>' 0'_CorDllMainmscoree.dll source: is-NIACK.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\NPT_dev420_Operation\03_Sources\Development\Tools\Tools.Operation.TrustZone.Migrate\obj\Release\SNTOperationTrustZoneMigrate.pdb2HLH >H_CorExeMainmscoree.dll source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: C:\Users\Michelle\Documents\Visual Studio 2017\Projects\Microsoft.SDK.Expression.Blend\Microsoft.SDK.Expression.Blend\obj\Debug\Microsoft.SDK.Expression.Blend.pdb source: is-NIACK.tmp.7.dr
Source: Binary string: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.dllHK8C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.pdb source: Setup-S4-View.tmp, 00000007.00000003.1672781074.0000000003168000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1672740128.0000000003164000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: c:\zlib-dll\Release\isunzlib.pdb source: Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Environment\obj\Release\SUFEnvironment.pdb\BvB hB_CorDllMainmscoree.dll source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1678621608.0000000000B22000.00000002.00000001.01000000.00000011.sdmp, is-49F6R.tmp.7.dr
Source: Binary string: C:\Jenkins\workspace\Uranus_Release_NuGet\03_Sources\Development\Framework\Framework.Extension\obj\Release\SUFExtension.pdb source: SNTOperationTrustZoneMigrate.exe, 0000000A.00000002.1679375530.0000000004B12000.00000002.00000001.01000000.00000013.sdmp
Source: is-KF3NS.tmp.7.drStatic PE information: 0x8FF46B80 [Sat Jul 14 05:49:52 2046 UTC]
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-CMA91.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-D4BNT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-VDM61.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationUiError.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationShell.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N93I3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-DV2L2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-8BABE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Controls.Input.Toolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNFCommunicationKernel.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-VMG3H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNAOperationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Core.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateEmbS4User.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K1O4R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-4GNF5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-9M3EF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Controls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7ME5S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-8HSHI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-GU3TJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TIL3R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-SGKUN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\System.Net.Http.Formatting.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-QJN7L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-AI79O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.SketchControls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-9CU2D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-GVSU9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-JH2S8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-DO4N7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IO3OE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\is-F5IU6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-PE69T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-RL8OJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-O3R06.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-T1MUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5BJBU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnect.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3F4TS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-LN3AI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-HF0AC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\WPFToolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-7FRTL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNFHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationStation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.SDK.Expression.Blend.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.PubSubEvents.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-07KGM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-I9EUD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFSecurity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.MefExtensions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Composition.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3MFFG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-AMCK3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-21NDQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MNQB6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-9U3EE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-63MLF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-RAUP2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ODMQA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libssl-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-OI13D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-61UM6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-2PJ6V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-LLIH1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-639A2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-G87M5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-TGF4M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-LQ48F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationVersion.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-5CTU6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IFV82.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-HSBN8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_isdecmp.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-3ONS6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-45VRU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationErrorMapping.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-46DM1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-PI5H9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-KPLA1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\unins001.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0E7KK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-T8JRN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateEmbS4User.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-50VD7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNAOperationStation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K3CMC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-BKBVR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-88TKO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-CO470.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFRepository.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-AVSQ8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-699DL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationWebApiTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Drawing.DirectX.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-54VM0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4FDOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-347OL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.SharedInterfaces.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-5OU1M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-843RE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1K23T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-39RKE.tmpJump to dropped file
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeFile created: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-64KF6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.MefExtensions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-IJG31.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-H4HST.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Common.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-IBGQ4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HFA8L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-TQQM6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3OCC6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-0KPQ7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-5N5CP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-011JG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-MBF20.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-1B2OG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9CCPB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-SAULK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UL6DE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-5ITBB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-U9E7M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4TBRK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-ETP9J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Composition.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-7V1V2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-12JRF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Newtonsoft.Json.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-PTTTA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-EPB0C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AV8EA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFExtension.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-M8JKU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Mvvm.Desktop.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-TR8AE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-FCHG3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-PRAPE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-833ED.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-84CMC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-1JODI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-5FTSU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HLK9U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV3.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-33I6F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationLxConnectTransferObjects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-GUQFH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-NA6MU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-JVI3R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TSM0G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-N6KMT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\certmgr.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-58PPC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-C93UM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.SDK.Expression.Blend.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-732CK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7ITRM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Interactions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-UCSDM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV5.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFEnvironment.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-TQ04E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-0E3AN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-NL5PA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-RPPAQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-MQRPV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV5.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Prototyping.SketchControls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-GJHT8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-D15N5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-4JBQU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-CMV4L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-HI6A6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-CUTEF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-SK564.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-14EBV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Controls.DataVisualization.Toolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-DMU3F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-9CSCQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9TNNB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnectService.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-EU6C6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4EQNQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-4MBH1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-DI2GE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Controls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateTrustZone.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-E1V4F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-DQESJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-B4JIE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-PKRFS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-Q5G5I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-NIACK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-I151H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-IR9V5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationWebApiTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationChangePassword.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Charting.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationGeneralSettings.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-49F6R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-C7GU2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-G7IVF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-BND8G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-HCBT0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\openssl.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-V52PD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-HABQQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1L83U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFLogger.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-Q18VP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-0I2NF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationUiError.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-MRUE4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-6TKMN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateTrustZone.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-KUIC9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgr\is-VSC5C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Prototyping.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SLB2H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-2H57J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-ELILH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-MHHC6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-NS71O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-F3FDQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNFCommunicationKernel.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-T78QA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7SN1T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-RDUQ2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-A8B8O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-R82J1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-CO0UM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-SNIS1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV4.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\is-FSGCV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFTlsCallback.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-JRJN5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-LKI3D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2886D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-TM2NE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Newtonsoft.Json.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-FK9BA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-TRODH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-VTGH2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-EAKNJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MSV9G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-IMF8J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-EM22B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-81M0T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationChangePassword.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-E748F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-79MOU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-8MTID.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-EP5BO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-NF99L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationTheme.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-PEO2L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-47PKL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Common.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-T0MCK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RHHQ4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualization.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV8.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TETLV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-OMBLA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4F771.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-4GV0Q.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-S8MJD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV8.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7NJPP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N6DPP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-KF3NS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-609HG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-M9PDU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SC7E2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-8T8MU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-AAS65.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationErrorMapping.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-7BLN2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Interactions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Data.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-1612U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-CQKPO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-3F4N1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-UB479.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-0QSN7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SUFException.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-K9MBO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-SJKRM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-O4B33.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.Desktop.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-FFPA8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeFile created: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV4.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-53UCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RQL4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-VM2NU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-RFN5H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationService.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-F0VLA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-Q1TBT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-LBT1Q.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-EBEI6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-Q2EFC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-773GS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.PubSubEvents.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-KJV73.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-1JF6G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\sharpdx_direct3d11_1_effects_x86.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UNPN0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-H8EP9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-B3LJV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Mvvm.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-5MB86.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-LRAV9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\sharpdx_direct3d11_1_effects_x64.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3D2U2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MTL24.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-ABPDN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-L48QA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-5D9DG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-HKM4S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-89MDT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AIVQD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-I729J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libcrypto-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNFHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HMDUR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV3.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-51Q4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-F83O7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-KUKBE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-BTAJO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-REQFT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-77VF3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-V4B91.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNFMvvm.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Validation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-3R6MR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV3.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-5E0EU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-H0RF0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-5TC81.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-VCOJR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9121E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateInitValueTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-24Q32.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\is-88ROD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationValues.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0FSQB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-IO3NH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-K8GT2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\unins000.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceCore.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-KJFH8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-KKVKO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-RKS5T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-DO2RS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-K4C6A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\is-MEJTF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-QUNG5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\en\is-0OG0F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Controls.Layout.Toolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Validation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.SharedInterfaces.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2MNEP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Program Files\LACROIX Sofrel\S4-View\es\is-6F11R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-10-14 #001.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpFile created: C:\Users\user\Desktop\Setup Log 2024-10-14 #001.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-10-14 #002.txtJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LACROIX SofrelJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LACROIX Sofrel\S4-ViewJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LACROIX Sofrel\S4-View\S4-View.lnkJump to behavior
Source: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeMemory allocated: AE0000 memory reserve | memory write watchJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeMemory allocated: 2430000 memory reserve | memory write watchJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeMemory allocated: 4430000 memory reserve | memory write watchJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-CMA91.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-D4BNT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-VDM61.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationUiError.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationShell.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N93I3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-DV2L2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-8BABE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Controls.Input.Toolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNFCommunicationKernel.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNAOperationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-VMG3H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Core.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\System.Windows.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateEmbS4User.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K1O4R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-4GNF5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\openssl.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-9M3EF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Controls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7ME5S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-GU3TJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-8HSHI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TIL3R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-SGKUN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\System.Net.Http.Formatting.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-QJN7L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-AI79O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.SketchControls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-9CU2D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-GVSU9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-JH2S8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-DO4N7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IO3OE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-PE69T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-RL8OJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-O3R06.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-T1MUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-5BJBU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnect.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3F4TS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-LN3AI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-HF0AC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\WPFToolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-7FRTL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNFHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationStation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.SDK.Expression.Blend.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.PubSubEvents.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-07KGM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-I9EUD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFSecurity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.MefExtensions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Composition.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3MFFG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-AMCK3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-21NDQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MNQB6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-9U3EE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-63MLF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-RAUP2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ODMQA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libssl-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-OI13D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\libcrypto-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-61UM6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-LLIH1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-2PJ6V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-639A2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-TGF4M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-LQ48F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-5CTU6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-HSBN8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-IFV82.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_isdecmp.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-3ONS6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-45VRU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D9.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationErrorMapping.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-46DM1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-PI5H9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-KPLA1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-0E7KK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\unins001.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\libssl-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-T8JRN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateEmbS4User.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-50VD7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNAOperationStation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-K3CMC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-BKBVR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-88TKO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-CO470.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFRepository.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-AVSQ8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-699DL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationWebApiTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Drawing.DirectX.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-54VM0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4FDOC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-347OL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.SharedInterfaces.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-5OU1M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-843RE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1K23T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-39RKE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV2.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-64KF6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.MefExtensions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-H4HST.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Common.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-IJG31.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-IBGQ4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HFA8L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-TQQM6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3OCC6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-0KPQ7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFEnvironment.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-5N5CP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-011JG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-MBF20.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-1B2OG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9CCPB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-SAULK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UL6DE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-5ITBB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-U9E7M.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4TBRK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-ETP9J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Composition.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-7V1V2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Newtonsoft.Json.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-12JRF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-PTTTA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-EPB0C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AV8EA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFExtension.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-M8JKU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Mvvm.Desktop.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-TR8AE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-FCHG3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-PRAPE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-84CMC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-833ED.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.ServiceLocation.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-5FTSU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-1JODI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HLK9U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFRepository.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV3.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-33I6F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationLxConnectTransferObjects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-GUQFH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-NA6MU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-JVI3R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TSM0G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-N6KMT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\certmgr.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-58PPC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-C93UM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.SDK.Expression.Blend.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-732CK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7ITRM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Interactions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-UCSDM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV5.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFEnvironment.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-TQ04E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-0E3AN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-NL5PA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-RPPAQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-MQRPV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV5.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Prototyping.SketchControls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-GJHT8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-D15N5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-4JBQU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-CMV4L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-HI6A6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-CUTEF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-SK564.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Controls.DataVisualization.Toolkit.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-14EBV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV4.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-DMU3F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-9CSCQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-9TNNB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnectService.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-EU6C6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-4EQNQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-4MBH1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Controls.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-DI2GE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateTrustZone.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-E1V4F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-DQESJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\is-PKRFS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-B4JIE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-Q5G5I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-NIACK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV2.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-I151H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-IR9V5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationWebApiTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationChangePassword.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Charting.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.DXGI.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationGeneralSettings.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-49F6R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-C7GU2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationInterface.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-G7IVF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-BND8G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-HCBT0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\openssl.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-HABQQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-V52PD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-1L83U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFLogger.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-Q18VP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-0I2NF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Logging.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationUiError.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationVisualizationV8.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-MRUE4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-6TKMN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateTrustZone.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-KUIC9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgr\is-VSC5C.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Prototyping.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\System.Net.Http.Formatting.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SLB2H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-2H57J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-ELILH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-NS71O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-MHHC6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNFCommunicationKernel.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-F3FDQ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-T78QA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV5.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-7SN1T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateLxConnect.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-RDUQ2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-R82J1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-A8B8O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-CO0UM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-SNIS1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Drawing.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\CertMgr\certmgr.exe (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV4.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\is-FSGCV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationTransferObjectV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFTlsCallback.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFTlsCallback.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-JRJN5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-LKI3D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-2886D.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Newtonsoft.Json.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-TM2NE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-FK9BA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-TRODH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-VTGH2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-EAKNJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MSV9G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-IMF8J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-EM22B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-81M0T.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationChangePassword.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-E748F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateInitValueTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-79MOU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\System.Windows.Interactivity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV6.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-8MTID.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateLxConnectService.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationTheme.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-NF99L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-EP5BO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-PEO2L.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-47PKL.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Common.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\OpenSSL\is-T0MCK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RHHQ4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SUFInfrastructure.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualization.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationVisualizationV8.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-TETLV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFExtension.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-4F771.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-OMBLA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-4GV0Q.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-S8MJD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV8.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-N6DPP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-7NJPP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-KF3NS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV3.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-609HG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFSecurity.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-M9PDU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-SC7E2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationShell.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-8T8MU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-AAS65.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationErrorMapping.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-7BLN2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Interactions.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SciChart.Data.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-1612U.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-CQKPO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-3F4N1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-UB479.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-0QSN7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.D3DCompiler.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SUFException.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-SJKRM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-K9MBO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-O4B33.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.Desktop.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFLogger.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-FFPA8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SUFTlsCallback.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV4.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-53UCP.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-VM2NU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Mathematics.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-RQL4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationService.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-RFN5H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNFMvvm.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-F0VLA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-Q1TBT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-LBT1Q.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-EBEI6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-Q2EFC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-773GS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationVisualizationV110.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.PubSubEvents.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Expression.Effects.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\is-KJV73.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-1JF6G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SharpDX.Direct3D11.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\sharpdx_direct3d11_1_effects_x86.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\SNACooperateCommunicationUiError.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\en\SNAOperationVisualizationV6.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-UNPN0.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\it\is-H8EP9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-B3LJV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV110.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.Prism.Mvvm.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-5MB86.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-LRAV9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\sharpdx_direct3d11_1_effects_x64.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-3D2U2.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-MTL24.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-ABPDN.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-L48QA.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-5D9DG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-HKM4S.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\SNAOperationCommunicationValues.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNACooperateCommunicationTransferObject.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-89MDT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\de\is-AIVQD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNACooperateTrustZone.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-I729J.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\SNACooperateEmbS4User.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNACooperateCommunicationTransferObject.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\es\SNACooperateCommunicationChangePassword.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libcrypto-1_1.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNFHttpClient.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\de\is-HMDUR.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationServiceV3.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationStation.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-51Q4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\is-F83O7.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\it\SNAOperationGeneralSettings.resources.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\is-KUKBE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\en\is-BTAJO.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-REQFT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\es\is-77VF3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationCommunicationInfrastructure.dll (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\is-V4B91.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpDropped PE file which has not been started: C:\Program Files\LACROIX Sofrel\S4-View\SNFMvvm.dll (copy)Jump to dropped file
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe TID: 2320Thread sleep time: -922337203685477s >= -30000sJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmpProcess information queried: ProcessInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeProcess token adjusted: DebugJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmp helper 105 0x404Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmpQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFEnvironment.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFLogger.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Logging.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SUFExtension.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeQueries volume information: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\Microsoft.Practices.EnterpriseLibrary.Common.dll VolumeInformationJump to behavior
Source: C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
Windows Service
1
Windows Service
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
11
Process Injection
1
Disable or Modify Tools
LSASS Memory32
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
32
Virtualization/Sandbox Evasion
Security Account Manager2
System Owner/User Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Registry Run Keys / Startup Folder
11
Process Injection
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Timestomp
LSA Secrets12
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1533008 Sample: 2024_04_Setup-S4-View-V4.20... Startdate: 14/10/2024 Architecture: WINDOWS Score: 3 9 2024_04_Setup-S4-View-V4.20.13.exe 2 2->9         started        file3 37 C:\...\2024_04_Setup-S4-View-V4.20.13.tmp, PE32 9->37 dropped 12 2024_04_Setup-S4-View-V4.20.13.tmp 24 36 9->12         started        process4 file5 39 C:\Users\user\AppData\Local\...\is-F5IU6.tmp, PE32 12->39 dropped 41 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 12->41 dropped 43 C:\Users\user\...\Setup-S4-View.exe (copy), PE32 12->43 dropped 45 2 other files (none is malicious) 12->45 dropped 15 Setup-S4-View.exe 2 12->15         started        process6 file7 47 C:\Users\user\AppData\...\Setup-S4-View.tmp, PE32 15->47 dropped 18 Setup-S4-View.tmp 27 363 15->18         started        process8 file9 29 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 18->29 dropped 31 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 18->31 dropped 33 C:\Program Files\...\unins001.exe (copy), PE32 18->33 dropped 35 541 other files (none is malicious) 18->35 dropped 21 SNTOperationTrustZoneMigrate.exe 6 18->21         started        23 _setup64.tmp 1 18->23         started        process10 process11 25 conhost.exe 21->25         started        27 conhost.exe 23->27         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
2024_04_Setup-S4-View-V4.20.13.exe0%VirustotalBrowse
2024_04_Setup-S4-View-V4.20.13.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\certmgr.exe (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\CertMgr\is-FSGCV.tmp0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Controls.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Drawing.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Effects.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Interactions.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.Interactivity.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Prototyping.SketchControls.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Common.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Logging.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.EnterpriseLibrary.Validation.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Composition.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Interactivity.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.MefExtensions.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.Desktop.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.Mvvm.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.PubSubEvents.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.Prism.SharedInterfaces.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Practices.ServiceLocation.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.SDK.Expression.Blend.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\Newtonsoft.Json.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-5MB86.tmp0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-7BLN2.tmp0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\is-ODMQA.tmp0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libcrypto-1_1.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\libssl-1_1.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\OpenSSL\openssl.exe (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationChangePassword.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationErrorMapping.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationHttpClient.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationInterface.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationLxConnectTransferObjects.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationService.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationTransferObject.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationUiError.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateCommunicationWebApiTransferObject.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateEmbS4User.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateInitValueTransferObject.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnect.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateLxConnectService.dll (copy)0%ReversingLabs
C:\Program Files\LACROIX Sofrel\S4-View\SNACooperateTrustZone.dll (copy)0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.innosetup.com/0%URL Reputationsafe
https://www.certum.pl/CPS00%URL Reputationsafe
http://www.remobjects.com/psU0%URL Reputationsafe
https://www.openssl.org/H0%URL Reputationsafe
http://www.remobjects.com/ps0%URL Reputationsafe
http://www.codeplex.com/prism:Microsoft.Practices.Prism.Interactivity.InteractionRequest0%VirustotalBrowse
https://www.scichart.com/documentation/v4.x/webframe.html#Performance_Tips_&_Tricks.html0%VirustotalBrowse
http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdV0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart&SciChart.Charting.Visuals.PointMarkers0%VirustotalBrowse
http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdT0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxis0%VirustotalBrowse
https://github.com/jquery/jquery0%VirustotalBrowse
http://www.jrsoftware.org/00%VirustotalBrowse
http://www.sofrel.com/ConfigurationVisualizationGeneralParams/0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Visuals.TradeChart0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animations0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animations00%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Common.ExtensionsO0%VirustotalBrowse
http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU0%VirustotalBrowse
https://fr.lacroix-group.com/vie-privee/0%VirustotalBrowse
http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsdd0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart0%VirustotalBrowse
http://crl.certum.pl/l3.crl0a0%VirustotalBrowse
http://www.sofrel.com/SNAOperation/V110/RestartInput.xsdT0%VirustotalBrowse
http://www.codeplex.com/prism1%VirustotalBrowse
http://crl.certum.pl/ca.crl0:0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxisU0%VirustotalBrowse
http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsdT0%VirustotalBrowse
https://lacroix-group.com/private-life/0%VirustotalBrowse
https://www.openssl.org/community/mailinglists.html0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.Axes.LogarithmicAxis_0%VirustotalBrowse
http://www.sofrel.com/SNAIdentityCard/E0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.Databinding0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Model.ChartSeries0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart(SciChart.Charting.Numerics.TickProvidersG0%VirustotalBrowse
http://www.codeplex.com/prism#Microsoft.Practices.Prism.ViewModel1%VirustotalBrowse
http://www.sofrel.com/StationConnection/G0%VirustotalBrowse
http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.DatabindingR0%VirustotalBrowse
http://www.sofrel.com/ConfigurationVisualizationGeneralParams/T0%VirustotalBrowse
http://www.sofrel.com/StationConnection/T0%VirustotalBrowse
http://www.sofrel.com/SNAIdentityCard/T0%VirustotalBrowse
https://lacroix-group.com/0%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.codeplex.com/prism:Microsoft.Practices.Prism.Interactivity.InteractionRequestis-CO470.tmp.7.drfalseunknown
http://www.jrsoftware.org/0Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalseunknown
https://www.scichart.com/documentation/v4.x/webframe.html#Performance_Tips_&_Tricks.htmlis-SAULK.tmp.7.drfalseunknown
http://schemas.abtsoftware.co.uk/scichart&SciChart.Charting.Visuals.PointMarkersis-SAULK.tmp.7.drfalseunknown
http://www.sofrel.com/ConfigurationVisualizationGeneralParams/SNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmpfalseunknown
http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdVis-9CU2D.tmp.7.drfalseunknown
https://github.com/jquery/jqueryis-6LHTM.tmp.7.drfalseunknown
http://www.sofrel.com/SNAOperation/SetDateTimeInput.xsdTis-9CU2D.tmp.7.drfalseunknown
http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxisis-SAULK.tmp.7.drfalseunknown
http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Visuals.TradeChartis-SAULK.tmp.7.drfalseunknown
https://fr.lacroix-group.com/vie-privee/Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalseunknown
http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animationsis-SAULK.tmp.7.drfalseunknown
http://ocsp.certum.pl0.Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalse
    unknown
    http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU2024_04_Setup-S4-View-V4.20.13.exe, is-F5IU6.tmp.2.drfalseunknown
    http://www.sofrel.com/SNAOperation/V110/RestartInput.xsdTis-9CU2D.tmp.7.drfalseunknown
    http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsdTis-9CU2D.tmp.7.drfalseunknown
    http://schemas.abtsoftware.co.uk/scichart5SciChart.Charting.Visuals.RenderableSeries.Animations0is-SAULK.tmp.7.drfalseunknown
    https://www.openssl.org/community/mailinglists.htmlSetup-S4-View.tmp, 00000007.00000003.1679782768.0000000003150000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1683990301.000000000018D000.00000004.00000010.00020000.00000000.sdmpfalseunknown
    http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Common.ExtensionsOis-SAULK.tmp.7.drfalseunknown
    http://www.sofrel.com/SNAOperation/V110/UploadOutput.xsddis-9CU2D.tmp.7.drfalseunknown
    http://schemas.abtsoftware.co.uk/scichartis-SAULK.tmp.7.dr, is-AAS65.tmp.7.drfalseunknown
    http://crl.certum.pl/l3.crl0aSetup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalseunknown
    http://www.codeplex.com/prismis-CO470.tmp.7.drfalseunknown
    http://crl.certum.pl/ca.crl0:Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalseunknown
    http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Visuals.Axes.DiscontinuousAxisUis-SAULK.tmp.7.drfalseunknown
    https://lacroix-group.com/private-life/2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730243352.0000000002684000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729897385.0000000002164000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730282551.0000000002688000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730187996.0000000002620000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730034355.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730133469.00000000021FC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729973001.00000000021AC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359384126.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359252275.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730096712.00000000021F8000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1362003060.000000000214C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1471714765.0000000000839000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1407756392.000000000080C000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719834895.000000000215C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719193779.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719575132.0000000003310000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1718730811.0000000000811000.00000004.00000020.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1361845260.0000000003110000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719478541.00000000033C4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1726050951.00000000021A4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1408237246.000000000080C000.00000004.00000020.00020000.00000000.sdmpfalseunknown
    http://schemas.abtsoftware.co.uk/scichart(SciChart.Charting.Numerics.TickProvidersGis-SAULK.tmp.7.drfalseunknown
    http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.Axes.LogarithmicAxis_is-SAULK.tmp.7.drfalseunknown
    http://www.sofrel.com/SNAIdentityCard/Eis-64KF6.tmp.7.drfalseunknown
    http://www.sofrel.com/StationConnection/Tis-V52PD.tmp.7.drfalseunknown
    http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Model.ChartSeriesis-SAULK.tmp.7.drfalseunknown
    http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.Databindingis-SAULK.tmp.7.drfalseunknown
    https://lacroix-group.com/2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730243352.0000000002684000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729897385.0000000002164000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730282551.0000000002688000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730187996.0000000002620000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730034355.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730133469.00000000021FC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1729973001.00000000021AC000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359384126.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359252275.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1730096712.00000000021F8000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1362003060.000000000214C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719834895.000000000215C000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719193779.0000000002154000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719575132.0000000003310000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1361845260.0000000003110000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1719478541.00000000033C4000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000003.1726050951.00000000021A4000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1685995917.0000000002098000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603142010.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1686551455.0000000002658000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1686213258.00000000025C0000.00000004.00001000.00020000.00000000.sdmpfalseunknown
    http://www.sofrel.com/StationConnection/Gis-V52PD.tmp.7.drfalseunknown
    http://www.codeplex.com/prism#Microsoft.Practices.Prism.ViewModelis-K8GT2.tmp.7.drfalseunknown
    http://www.sofrel.com/ConfigurationVisualizationGeneralParams/TSNTOperationTrustZoneMigrate.exe, 0000000A.00000000.1673307686.0000000000292000.00000002.00000001.01000000.0000000E.sdmpfalseunknown
    http://www.sofrel.com/SNAIdentityCard/Tis-64KF6.tmp.7.drfalseunknown
    http://www.innosetup.com/2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpfalse
    • URL Reputation: safe
    unknown
    http://schemas.abtsoftware.co.uk/scichart$SciChart.Charting.Common.DatabindingRis-SAULK.tmp.7.drfalseunknown
    https://www.c-sharpcorner.com/UploadFile/mahesh/binding-static-properties-in-wpf-4-5/is-SAULK.tmp.7.drfalse
      unknown
      http://www.apache.org/licenses/LICENSE-2.0is-GJBTC.tmp.7.drfalse
        unknown
        http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Numerics.CoordinateProvidersZis-SAULK.tmp.7.drfalse
          unknown
          http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.TradeChart.MultiPanedis-SAULK.tmp.7.drfalse
            unknown
            http://www.apache.org/licenses/is-GJBTC.tmp.7.drfalse
              unknown
              http://schemas.abtsoftware.co.uk/scichart%SciChart.Charting.Visuals.Annotationsis-SAULK.tmp.7.drfalse
                unknown
                http://schemas.abtsoftware.co.uk/scichart%SciChart.Charting.Visuals.AnnotationsMis-SAULK.tmp.7.drfalse
                  unknown
                  http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline2024_04_Setup-S4-View-V4.20.13.exe, is-F5IU6.tmp.2.drfalse
                    unknown
                    http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Model.ChartSeriesQis-SAULK.tmp.7.drfalse
                      unknown
                      https://www.certum.pl/CPS0Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://schemas.abtsoftware.co.uk/scichart#SciChart.Charting.Common.Extensionsis-SAULK.tmp.7.drfalse
                        unknown
                        https://www.certum.pl/repository.0Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalse
                          unknown
                          http://schemas.abtsoftware.co.uk/scichart)SciChart.Charting.Common.MarkupExtensionsOis-SAULK.tmp.7.drfalse
                            unknown
                            http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.Axes.LogarithmicAxisis-SAULK.tmp.7.drfalse
                              unknown
                              http://www.sofrel.com/SNEIdentityCard/V110/Wis-9CU2D.tmp.7.drfalse
                                unknown
                                https://jquery.org/is-6LHTM.tmp.7.drfalse
                                  unknown
                                  http://schemas.abtsoftware.co.uk/scichart(SciChart.Charting.Numerics.TickProvidersis-SAULK.tmp.7.drfalse
                                    unknown
                                    http://www.remobjects.com/psU2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpfalse
                                    • URL Reputation: safe
                                    unknown
                                    http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Numerics.CoordinateProvidersis-SAULK.tmp.7.drfalse
                                      unknown
                                      http://www.sofrel.com/SNEIdentityCard/V110/Tis-9CU2D.tmp.7.drfalse
                                        unknown
                                        http://www.codeplex.com/wpfis-5E0EU.tmp.7.drfalse
                                          unknown
                                          https://www.openssl.org/His-T0MCK.tmp.7.dr, is-5MB86.tmp.7.drfalse
                                          • URL Reputation: safe
                                          unknown
                                          http://www.sofrel.com/SNACooperate/SetPasswordInput.xsdTis-9CU2D.tmp.7.drfalse
                                            unknown
                                            http://schemas.abtsoftware.co.uk/scichart&SciChart.Charting.Visuals.PointMarkersYis-SAULK.tmp.7.drfalse
                                              unknown
                                              http://www.openssl.org/)is-SRF6Q.tmp.7.drfalse
                                                unknown
                                                http://www.remobjects.com/ps2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1360056421.0000000002410000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.exe, 00000000.00000003.1359763477.0000000002720000.00000004.00001000.00020000.00000000.sdmp, 2024_04_Setup-S4-View-V4.20.13.tmp, 00000002.00000002.1727466827.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Setup-S4-View.exe, 00000006.00000003.1603767166.00000000026C0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.exe, 00000006.00000003.1603967138.00000000023B0000.00000004.00001000.00020000.00000000.sdmp, Setup-S4-View.tmp, 00000007.00000002.1684057553.0000000000401000.00000020.00000001.01000000.0000000A.sdmpfalse
                                                • URL Reputation: safe
                                                unknown
                                                http://www.sofrel.com/SNACooperate/SetPasswordInput.xsdVis-9CU2D.tmp.7.drfalse
                                                  unknown
                                                  http://schemas.abtsoftware.co.uk/scichart.SciChart.Charting.Visuals.TradeChart.MultiPaneis-SAULK.tmp.7.drfalse
                                                    unknown
                                                    http://schemas.abtsoftware.co.uk/scichart)SciChart.Charting.Common.MarkupExtensionsis-SAULK.tmp.7.drfalse
                                                      unknown
                                                      http://repository.certum.pl/l3.cer0Setup-S4-View.tmp, 00000007.00000003.1611964357.0000000003150000.00000004.00001000.00020000.00000000.sdmpfalse
                                                        unknown
                                                        http://schemas.abtsoftware.co.uk/scichart-SciChart.Charting.Visuals.Axes.LabelProvidersis-SAULK.tmp.7.drfalse
                                                          unknown
                                                          http://crl.certum.pl/l3.Setup-S4-View.tmp, 00000007.00000003.1611905481.0000000003444000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            unknown
                                                            http://schemas.abtsoftware.co.uk/scichart0SciChart.Charting.Numerics.CoordinateCalculatorsis-SAULK.tmp.7.drfalse
                                                              unknown
                                                              http://www.sofrel.com/SNAOperation/V110/RestartInput.xsddis-9CU2D.tmp.7.drfalse
                                                                unknown
                                                                No contacted IP infos
                                                                Joe Sandbox version:41.0.0 Charoite
                                                                Analysis ID:1533008
                                                                Start date and time:2024-10-14 09:47:24 +02:00
                                                                Joe Sandbox product:CloudBasic
                                                                Overall analysis duration:0h 6m 34s
                                                                Hypervisor based Inspection enabled:false
                                                                Report type:full
                                                                Cookbook file name:default.jbs
                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                Number of analysed new started processes analysed:17
                                                                Number of new started drivers analysed:0
                                                                Number of existing processes analysed:0
                                                                Number of existing drivers analysed:0
                                                                Number of injected processes analysed:0
                                                                Technologies:
                                                                • EGA enabled
                                                                • AMSI enabled
                                                                Analysis Mode:default
                                                                Analysis stop reason:Timeout
                                                                Sample name:2024_04_Setup-S4-View-V4.20.13.exe
                                                                Detection:CLEAN
                                                                Classification:clean3.winEXE@13/678@0/0
                                                                Cookbook Comments:
                                                                • Found application associated with file extension: .exe
                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                                                • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
                                                                • Not all processes where analyzed, report is missing behavior information
                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                No simulations
                                                                No context
                                                                No context
                                                                No context
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                C:\Program Files\LACROIX Sofrel\S4-View\Microsoft.Expression.Controls.dll (copy)OneLaunch - EarthView3D_3o3f1.exeGet hashmaliciousUnknownBrowse
                                                                  https://geteasypdf.com/Get hashmaliciousUnknownBrowse
                                                                    MDE_File_Sample_4e8af2004a77f531e655e2e5cb669c388d0655c9.zipGet hashmaliciousUnknownBrowse
                                                                      https://fastprintapp.com/lp1?channel=hud-gdn&tracking_id=142&oid=142&affid=1025&source_id=google&sub1=142imall&gclid=EAIaIQobChMI5Lzv2NSvgwMVXaOmBB3WUQkTEAEYASAAEgI9zPD_BwEGet hashmaliciousUnknownBrowse
                                                                        https://onelaunch.com/downloadGet hashmaliciousUnknownBrowse
                                                                          https://getquickmanuals.com/manuals/lp2Get hashmaliciousUnknownBrowse
                                                                            https://download.onelaunch.com/latest/Onelaunch%20Software.exeGet hashmaliciousUnknownBrowse
                                                                              https://download.onelaunch.com/latest/Onelaunch%20Software.exeGet hashmaliciousUnknownBrowse
                                                                                OneLaunch - Manuals_t5m2z.exeGet hashmaliciousUnknownBrowse
                                                                                  OneLaunch - PDF_o2u43.exeGet hashmaliciousUnknownBrowse
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):86168
                                                                                    Entropy (8bit):6.045998280536677
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:NV+Qu8/p1r+Cg0S+xik+WXZw+QQLaJNC8pNYw+WXsA9iYvYBS:ic1/gp4QQuhpNt+WXsoES
                                                                                    MD5:4CCA26E7EE11419A33960E7428E8972D
                                                                                    SHA1:86807367D7793299BBB2F558B41EE6641E2587D9
                                                                                    SHA-256:81E1FD52AD744AEBCA2E9F320FE871CCDEFC1B52210CE6F04D4EC8B9C54554B8
                                                                                    SHA-512:F7E0BF39F34E6760A7DBFB0D55379D01C2D23B6F22BB04CEA7A25708B050F4C6C1C8508F9A1E9B25DDD86A7A6A1AF47E982E13CB151A740A32A15228041C3644
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Reputation:low
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........GE...E...E....)..D....)..D....)..W....)..H...E...=....)..F....)..D....)..D...RichE...........PE..d.....JT..........".................p..........@..........................................`.......... ..................................................8Z......,........<...p..(...`...............................p................................................text...|........................... ..`.data...p(..........................@....pdata..,...........................@..@.idata..............................@..@.rsrc...8Z.......\..................@..@.reloc..(....p......................@..B................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):86168
                                                                                    Entropy (8bit):6.045998280536677
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:NV+Qu8/p1r+Cg0S+xik+WXZw+QQLaJNC8pNYw+WXsA9iYvYBS:ic1/gp4QQuhpNt+WXsoES
                                                                                    MD5:4CCA26E7EE11419A33960E7428E8972D
                                                                                    SHA1:86807367D7793299BBB2F558B41EE6641E2587D9
                                                                                    SHA-256:81E1FD52AD744AEBCA2E9F320FE871CCDEFC1B52210CE6F04D4EC8B9C54554B8
                                                                                    SHA-512:F7E0BF39F34E6760A7DBFB0D55379D01C2D23B6F22BB04CEA7A25708B050F4C6C1C8508F9A1E9B25DDD86A7A6A1AF47E982E13CB151A740A32A15228041C3644
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Reputation:low
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........GE...E...E....)..D....)..D....)..W....)..H...E...=....)..F....)..D....)..D...RichE...........PE..d.....JT..........".................p..........@..........................................`.......... ..................................................8Z......,........<...p..(...`...............................p................................................text...|........................... ..`.data...p(..........................@....pdata..,...........................@..@.idata..............................@..@.rsrc...8Z.......\..................@..@.reloc..(....p......................@..B................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):248
                                                                                    Entropy (8bit):4.931431276891108
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:JiMVBddIYaDg7zw9KLMw7HgXplMX4HBo1gAgluqmOo67:MMHddpaDp9KVAZlS4HVdXmW
                                                                                    MD5:D64FD7C733F1D2653E2DC5F0448E64AD
                                                                                    SHA1:08C64DE02AF096399B41E66E06A3A9FB68CBB1D8
                                                                                    SHA-256:7435EBFADA11DC3F913BAE8273E8CFD9E0150B773BB629B767A8298A8A5F6B6B
                                                                                    SHA-512:3CA2BBF30F046943867CEE99D7BA9DE055A505E092032685EDA0F3B32FD21603EE378B46C4C3D34DBA270B4788A33ADB925DCD0375050D8646B986F9218E0B9A
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<Communication>.. Interval de rafraichissement des communications des .quipements pour les librairies utilisant l'architecture Kernel-->.. <add key="RefreshInterval" value="1.0" />..</Communication>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):208
                                                                                    Entropy (8bit):5.185512776920795
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:BMteugQJwlxiTPD2XqmM5KAIUCyb8jMGERMQlWDq3GDx93dzRqVKFAZyVTMXK8eu:BMtxi4TPCXw3Cc8wGEbi9t93FAZy52Z
                                                                                    MD5:A0FEB3DE947508A590B0361F91A176D3
                                                                                    SHA1:E751C1A655D23486F2ADABFCBB992B0E765CD8B2
                                                                                    SHA-256:F0736AC856C218D751B33296F8A5EB811D0ECF6574D9AAD929E477BA065E35E8
                                                                                    SHA-512:952E83E58FE38D8F43F557892CDFAFF71B473FF6B4DD141AC639E9CA327E9C9D2A5FEEBE7CA4498A7E84CD8103674E8C104989D588DDBBC908C68D0484EA0E27
                                                                                    Malicious:false
                                                                                    Preview:.<environment>.. <culture Language="fr" LanguageResourceFolder="fr"/>.. <oem Company="LACROIX Sofrel" Product="Application" Copyright="Copyright (C) LACROIX Sofrel 2014-2016. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):316
                                                                                    Entropy (8bit):5.139299833202651
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:0CJOL2VUiTTPCXYaLL/XTbJRLQuCcWOM1mUi9t9VZAZy52Z:D02x+16czzO
                                                                                    MD5:205F72A8D398DD9D8F8203C3C09DABF0
                                                                                    SHA1:F3E10CF8E53340A14C7974270CEA4C6E222A06F0
                                                                                    SHA-256:D803BBBD5F50007ADB1EFAA0A6BA4519D17A29A5D7BFEDE35B026B1AECF7C000
                                                                                    SHA-512:86C5CBCBB1DB601AE5FB4438B8D05EFC982AA14956615E2A6C15617345A4B61A071CB76704F5CA00BB485348DA13AF8CE66246E085A94DE971FAE59A30273AEA
                                                                                    Malicious:false
                                                                                    Preview:<environment>... Culture et language de l'application-->...<culture Language="en" LanguageResourceFolder="en"/>... Contrainte OEM pour la personalisation lors de l'installation-->...<oem Company="LACROIX Sofrel" Product="S4-View" Copyright="Copyright (C) LACROIX Sofrel 2014-2021. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):333
                                                                                    Entropy (8bit):5.091184645617402
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:JiMVBdVdXLUtfFvVJOBJnyduqGn1V6QyLMLhj3iunduqVdT:MMHdDob6ydXGnH6QychjFdXn
                                                                                    MD5:18D74FC71EE703438E0D3BFFE4E79370
                                                                                    SHA1:B77EB06598EECB8AC809C163410E737D8E0F25F9
                                                                                    SHA-256:DD283129E8317DF5D84C43B5A0F5BB500B5C0E77F1554D0D22A499B32295A8E5
                                                                                    SHA-512:BADCBEBFA1BF5CCAD6A887FA7F9BB259C44A40A93460FB20C3DA69BF3BC6FE0FBCC69C46085A105D994A43C5185BC568C475B9DB65B4CA19DDB6D5A20682547C
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>....<Visualization>.. contr.leur de l'inactivit. de l'utilisateur sur l'application d'exploitation-->.. <add key="AutoLogOffDuration" value="10" />.. dur.e du test du module de communication RD-RTU2 (secondes)-->.. <add key="RdRtu2TestDuration" value="300" />..</Visualization>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):323
                                                                                    Entropy (8bit):5.131606066343924
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:BMth7L2VPi4TPCXw/IL/XTbJRLOCcWOM1mUi9t9VZAZy52Z:672RTI1azzO
                                                                                    MD5:65705D25741C77B55621F96CE9B45AE4
                                                                                    SHA1:B24EE24D35670D1298EFD0A0618297B802207D50
                                                                                    SHA-256:14833253161F174C22205B065BA6A56E1D5C0ED2951B1796EF08E5EC50CB402D
                                                                                    SHA-512:4BAF266D9E3E551F9F67951D52038031D16E2C8B9F2E0DDEEA4E55CA1DEB5A89A2F25CABECCDB17E42CE73A6EA16EAE789E97AA5D5F96CD0A6B1BC9D95CFD423
                                                                                    Malicious:false
                                                                                    Preview:.<environment>.. Culture et language de l'application-->.. <culture Language="fr" LanguageResourceFolder="fr"/>.. Contrainte OEM pour la personalisation lors de l'installation-->.. <oem Company="LACROIX Sofrel" Product="S4-View" Copyright="Copyright (C) LACROIX Sofrel 2014-2021. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):208
                                                                                    Entropy (8bit):5.185512776920795
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:BMteugQJwlxiTPD2XqmM5KAIUCyb8jMGERMQlWDq3GDx93dzRqVKFAZyVTMXK8eu:BMtxi4TPCXw3Cc8wGEbi9t93FAZy52Z
                                                                                    MD5:A0FEB3DE947508A590B0361F91A176D3
                                                                                    SHA1:E751C1A655D23486F2ADABFCBB992B0E765CD8B2
                                                                                    SHA-256:F0736AC856C218D751B33296F8A5EB811D0ECF6574D9AAD929E477BA065E35E8
                                                                                    SHA-512:952E83E58FE38D8F43F557892CDFAFF71B473FF6B4DD141AC639E9CA327E9C9D2A5FEEBE7CA4498A7E84CD8103674E8C104989D588DDBBC908C68D0484EA0E27
                                                                                    Malicious:false
                                                                                    Preview:.<environment>.. <culture Language="fr" LanguageResourceFolder="fr"/>.. <oem Company="LACROIX Sofrel" Product="Application" Copyright="Copyright (C) LACROIX Sofrel 2014-2016. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):248
                                                                                    Entropy (8bit):4.931431276891108
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:JiMVBddIYaDg7zw9KLMw7HgXplMX4HBo1gAgluqmOo67:MMHddpaDp9KVAZlS4HVdXmW
                                                                                    MD5:D64FD7C733F1D2653E2DC5F0448E64AD
                                                                                    SHA1:08C64DE02AF096399B41E66E06A3A9FB68CBB1D8
                                                                                    SHA-256:7435EBFADA11DC3F913BAE8273E8CFD9E0150B773BB629B767A8298A8A5F6B6B
                                                                                    SHA-512:3CA2BBF30F046943867CEE99D7BA9DE055A505E092032685EDA0F3B32FD21603EE378B46C4C3D34DBA270B4788A33ADB925DCD0375050D8646B986F9218E0B9A
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<Communication>.. Interval de rafraichissement des communications des .quipements pour les librairies utilisant l'architecture Kernel-->.. <add key="RefreshInterval" value="1.0" />..</Communication>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):333
                                                                                    Entropy (8bit):5.091184645617402
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:JiMVBdVdXLUtfFvVJOBJnyduqGn1V6QyLMLhj3iunduqVdT:MMHdDob6ydXGnH6QychjFdXn
                                                                                    MD5:18D74FC71EE703438E0D3BFFE4E79370
                                                                                    SHA1:B77EB06598EECB8AC809C163410E737D8E0F25F9
                                                                                    SHA-256:DD283129E8317DF5D84C43B5A0F5BB500B5C0E77F1554D0D22A499B32295A8E5
                                                                                    SHA-512:BADCBEBFA1BF5CCAD6A887FA7F9BB259C44A40A93460FB20C3DA69BF3BC6FE0FBCC69C46085A105D994A43C5185BC568C475B9DB65B4CA19DDB6D5A20682547C
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>....<Visualization>.. contr.leur de l'inactivit. de l'utilisateur sur l'application d'exploitation-->.. <add key="AutoLogOffDuration" value="10" />.. dur.e du test du module de communication RD-RTU2 (secondes)-->.. <add key="RdRtu2TestDuration" value="300" />..</Visualization>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2516
                                                                                    Entropy (8bit):4.850227162857249
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:3zHI+qHYMqHo7UqIqQWq65qJ2w3Yi7zHI+qHYMqHo7lqIqQ7:3zNS7UpWf5UYi7zNS7lp7
                                                                                    MD5:1AE4955549667C6FB10C34A4B6C86D03
                                                                                    SHA1:B4FC4D809C9BFECC7DDC3B97736A43E4CCA795FD
                                                                                    SHA-256:45FB740992E0FC9E567B1A16047B0DDEE9370E7BE399485CDE569724B5448E4D
                                                                                    SHA-512:7A2D3235062E031157D995DD5CB46D0C88A377A6B174102FF59FA0C3D939CBFCDC30AC405E5B58E2BAB55374FA750BB5FCA4C1A756D41FE2F3F0894981FC1B60
                                                                                    Malicious:false
                                                                                    Preview:.<exceptionHandling>.. <exceptionPolicies>.. <add name="Default">.. <exceptionTypes>.. <add type="System.Exception, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089".. postHandlingAction="ThrowNewException" name="Exception">.. <exceptionHandlers>.. <add name="Logging Handler".. type="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.LoggingExceptionHandler, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35".. logCategory="LogException" eventId="0" severity="Error" title="Exception Default".. formatterType="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.TextExceptionFormatter, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling".. priority="0" />.. <add name="DefaultWrapHandler".. exceptionMessage="{handlingInstance
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2516
                                                                                    Entropy (8bit):4.850227162857249
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:3zHI+qHYMqHo7UqIqQWq65qJ2w3Yi7zHI+qHYMqHo7lqIqQ7:3zNS7UpWf5UYi7zNS7lp7
                                                                                    MD5:1AE4955549667C6FB10C34A4B6C86D03
                                                                                    SHA1:B4FC4D809C9BFECC7DDC3B97736A43E4CCA795FD
                                                                                    SHA-256:45FB740992E0FC9E567B1A16047B0DDEE9370E7BE399485CDE569724B5448E4D
                                                                                    SHA-512:7A2D3235062E031157D995DD5CB46D0C88A377A6B174102FF59FA0C3D939CBFCDC30AC405E5B58E2BAB55374FA750BB5FCA4C1A756D41FE2F3F0894981FC1B60
                                                                                    Malicious:false
                                                                                    Preview:.<exceptionHandling>.. <exceptionPolicies>.. <add name="Default">.. <exceptionTypes>.. <add type="System.Exception, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089".. postHandlingAction="ThrowNewException" name="Exception">.. <exceptionHandlers>.. <add name="Logging Handler".. type="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.LoggingExceptionHandler, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35".. logCategory="LogException" eventId="0" severity="Error" title="Exception Default".. formatterType="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.TextExceptionFormatter, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling".. priority="0" />.. <add name="DefaultWrapHandler".. exceptionMessage="{handlingInstance
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5920
                                                                                    Entropy (8bit):5.079330515090413
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1KZBm1Er8v4mIyMRIkEcM6OQJmyYPkyLHydCwmkEw8v4RyUwmkE6H8v4RyiF4EDm:1C8g3uJZTy18gRytH8gRyozaDX
                                                                                    MD5:0AEDEC1AD24456762E0486899E3A9F12
                                                                                    SHA1:04A0D5D3D7C16F5727671475761439994B6DC1E5
                                                                                    SHA-256:ED653C096DB450BC07AE4941F4C1E534488D701899C56C0F0F5DF1BC62A08228
                                                                                    SHA-512:0A78E26A571F7A7D28CB2C9D2351F3E31D1952DA2E18C0D6C689A94451682E6825E4004A9D718F192568C3CB66DF4285815D96BE50895705B3B71D37B8226460
                                                                                    Malicious:false
                                                                                    Preview:.<loggingConfiguration name="Logging Application Block" tracingEnabled="true".. defaultCategory="LogFile" logWarningsWhenNoCategoriesMatch="true">.. <listeners>.. <add name="LogFileListener".. type="Microsoft.Practices.EnterpriseLibrary.Logging.TraceListeners.RollingFlatFileTraceListener, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35".. listenerDataType="Microsoft.Practices.EnterpriseLibrary.Logging.Configuration.RollingFlatFileTraceListenerData, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35".. fileName=".\Log\Sofrel.Uranus.Framework.Logger.log" header="" footer="".. formatter="LogFileFormatter" rollFileExistsBehavior="Overwrite".. rollInterval="None" rollSizeKB="50000" timeStampPattern="yyyyMMddfff".. maxArchivedFiles="2" filter="Information" />.. <add name="EventLogListen
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, Unicode text, UTF-8 text, with very long lines (753), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5660
                                                                                    Entropy (8bit):5.249001513006013
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:0KCRBx1d8mZyZRIkEcM6OQzmbY7yLHyddRwxku8JvRwxk8H8J345DA7OmqsO8oDc:0Z8+XnTyY8JWH8J+MUg
                                                                                    MD5:D03A6E4841675D5390822083E52F614C
                                                                                    SHA1:964F4A45747A849C76F62E5067E10C4559B1C556
                                                                                    SHA-256:11999430A1BA0CF06F13150E92FEF21119C7EAC9C1CCD055109037013943E22A
                                                                                    SHA-512:1F8EA2C853814BA9C17FCD71FD535AE9E294DB24AE07F1E688F69676C86C5B14A45E4483D9E2E95245283130601A859F85858756170673FE3FB393AD95CB0D57
                                                                                    Malicious:false
                                                                                    Preview:<loggingConfiguration name="Logging Application Block" tracingEnabled="true" defaultCategory="LogFile" logWarningsWhenNoCategoriesMatch="true">...<listeners>....<add name="LogFileListener" type="Microsoft.Practices.EnterpriseLibrary.Logging.TraceListeners.RollingFlatFileTraceListener, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" listenerDataType="Microsoft.Practices.EnterpriseLibrary.Logging.Configuration.RollingFlatFileTraceListenerData, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" fileName="C:\ProgramData\LACROIX Sofrel\S4-View\Log\Sofrel.Neptune.Framework.Logger.log" header="" footer="" formatter="LogFileFormatter" rollFileExistsBehavior="Overwrite" rollInterval="None" rollSizeKB="50000" timeStampPattern="yyyyMMddfff" maxArchivedFiles="2" filter="Information"/>.... <add name="EventLogListener" type="Microsoft.Practices.EnterpriseLibrary.Logging
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):27
                                                                                    Entropy (8bit):4.032303242743954
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:0gfJPTtlvn:0gBplv
                                                                                    MD5:11C33ECF9CC37CC85FDBB7A0CA0BF68A
                                                                                    SHA1:82C0DDF7240D1601C71170990F064C3C7DB7DE3B
                                                                                    SHA-256:F8E7507A56A4F6851CD1B3E749F9ABBB43C9D9CD77F59613917B4F68BE08C5F5
                                                                                    SHA-512:DFAA96C04BDD112ADEE57E5D206D7A68C4ABADE0C485287A5D04BED55831D4A58E49D01CE03E5E975A07616123A97B1E7FFAD44BDD75EA7055939DEFAC291141
                                                                                    Malicious:false
                                                                                    Preview:Package : V4.20.13.241602..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (946), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):10289
                                                                                    Entropy (8bit):4.62623155003621
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:LR0WP1VooUTo1xF/DFNXFE6Gz1zGf2L1CVvhz2oHqxvJbzjwLFkTGaFVHv:LFtUk1xtDv8LJ68bvNuFkTGaFt
                                                                                    MD5:2CD744D2743F496C08E97D92183E7D43
                                                                                    SHA1:E28826D4869825D9D5B17C52EE86BB46683675AF
                                                                                    SHA-256:AAF21DEA0E8C4B92B03AAC9E68F2D89F216131605B5669170BFEA4ABDE5C925F
                                                                                    SHA-512:87032261752BB08D95AE0E7F1CD962475119AF1A033FCDE6DB6168BDFBABDEF42AFE5B8C53740B38D62869AC6293DD494A84D0BAEFD34C4050271333FD547F56
                                                                                    Malicious:false
                                                                                    Preview:Version 2.0, January 2004....http://www.apache.org/licenses/....TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION....1. Definitions....."License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document....."Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License....."Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity....."You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License....."Source" form shall mea
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Non-ISO extended-ASCII text, with very long lines (514), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):9433
                                                                                    Entropy (8bit):4.87011155884007
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Fdg25o4ndmHrazdiHpAgI+V+eJlliVnc6SuGN5wcpAshFWgHSs:Y2BndmHrvHpAalliVcPFHDpAshFWgys
                                                                                    MD5:BE77F7D5220DC1186DBD9D1AC4C72FB6
                                                                                    SHA1:2BBBED575E2E531E354023724337FAF3B3CEF13C
                                                                                    SHA-256:CB362FEDBA08519971B3BBDADE04A127CE474875BA06AE72C59DB432FC9ABF76
                                                                                    SHA-512:458A37750153228F97C39B1AEE5684757F1B844D19F07E41D10C6DC0F7A179EEFAE0E3DC6989E4ACEB2F265D9090AD7D102AB26733AF7DA800750366DDA4FD05
                                                                                    Malicious:false
                                                                                    Preview:MICROSOFT SOFTWARE LICENSE TERMS......MICROSOFT .NET LIBRARY ....These license terms are an agreement between Microsoft Corporation (or based on where you live, one of its affiliates) and you. Please read them. They apply to the software named above, which includes the media on which you received it, if any. The terms also apply to any Microsoft..... updates,..... supplements,..... Internet-based services, and..... support services....for this software, unless other terms accompany those items. If so, those terms apply.....BY USING THE SOFTWARE, YOU ACCEPT THESE TERMS. IF YOU DO NOT ACCEPT THEM, DO NOT USE THE SOFTWARE.......IF YOU COMPLY WITH THESE LICENSE TERMS, YOU HAVE THE PERPETUAL RIGHTS BELOW.....1. INSTALLATION AND USE RIGHTS. ....a. Installation and Use. You may install and use any number of copies of the software to design, develop and test your programs. You may modify, copy, distribute or deploy any .js files contained in the software
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1106
                                                                                    Entropy (8bit):5.14873671945972
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:YhrDJHcH0ynYgt9qJq1hBE9QHbsUv4ek4/+daoxqmFn:m3J0lYEzBGQHbs5RTLxjFn
                                                                                    MD5:19B8D93B15D61C358EB698F45BC58134
                                                                                    SHA1:32CBAA63BD1E67583A687CA87317A96D41CCF383
                                                                                    SHA-256:3DB89794F5DFEEF43FAB474B861B5D14F7E1DE22ABD5A5DB2092B84581519ED8
                                                                                    SHA-512:BAD6A61EC70996F13BD0CD1DCC77A98FE0E6B5C6331A1DA7ECCF6F8BFFCEC656932AAF69A6AE369D5FF8E2B57808C2E6C482610E8902B12120BB93287E8AED20
                                                                                    Malicious:false
                                                                                    Preview:The MIT License (MIT)....Copyright (c) 2007 James Newton-King....Permission is hereby granted, free of charge, to any person obtaining a copy of..this software and associated documentation files (the "Software"), to deal in..the Software without restriction, including without limitation the rights to..use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of..the Software, and to permit persons to whom the Software is furnished to do so,..subject to the following conditions:....The above copyright notice and this permission notice shall be included in all..copies or substantial portions of the Software.....THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR..IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS..FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR..COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER..IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (2236), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):17599
                                                                                    Entropy (8bit):4.748870287844919
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:0ewrV6lVjZVoMWhsEFnQagPTLux5n4gf77s55LvgWz4h9Ma1WoVGQEtTQAbEuIbB:uMLBsXQ8bffwMrL1RGNTyz9/
                                                                                    MD5:EFE316D0ACB660F5CB50C62406D84689
                                                                                    SHA1:1435DDA57C999BE39227B2CDA3DEC54DA45E40D8
                                                                                    SHA-256:A0C04242CC7C639379DA24DD8E61505ED91E7BD2672467ED3A720C17B696B13E
                                                                                    SHA-512:982D63732E9FDE0BF2862B820FA356F0D667BCB44B80B0C68A60CC277A3FD85EDA06489B4D4C9592E46539A6106F3D0073E00A0058F8177413D66DB79995BDE2
                                                                                    Malicious:false
                                                                                    Preview:Microsoft patterns & practices License....patterns & practices Developer Center..This license governs use of the accompanying software. If you use the software, you accept this license. If you do not accept the license, do not use the software...1. Definitions..The terms "reproduce," "reproduction," "derivative works," and "distribution" have the same meaning here as under U.S. copyright law...A "contribution" is the original software, or any additions or changes to the software...A "contributor" is any person that distributes its contribution under this license..."Licensed patents" are a contributor's patent claims that read directly on its contribution...2. Grant of Rights..(A) Code..* Copyright Grant- Subject to the terms of this license, including the license conditions and limitations in section 3, each contributor grants you a non-exclusive, worldwide, royalty-free copyright license to reproduce its contribution, prepare derivative works of any contribution for which source code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (755), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1828
                                                                                    Entropy (8bit):5.183805962488499
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:Ws3RSt1XOOrYJkrYJzV0432sBG32s3Etm13t6THy:5BzOrYJkrYJzVn303z9ITS
                                                                                    MD5:29F266D798BDD180ACDB09EC8EF3A9A6
                                                                                    SHA1:270A555DC03FD1662AEF77B473457D1578546F15
                                                                                    SHA-256:902D90EB752212158B626109ABD54D8E927856129B3EE80DE1E62E4EB3A2447B
                                                                                    SHA-512:A2898A2DBC9412CAE95E46B1B6AECAE1F22FDFB4CAE3C5CD00E6F3D1133D36D76A3EEBF847E16D32C29736B5FF2B60751F92A4AEEE77C6FF7186FA89FDB3CEDF
                                                                                    Malicious:false
                                                                                    Preview:..The following is a BSD 2-Clause license template. To generate your own license, change the values of OWNER and YEAR from their original values as given here, and substitute your own.....Note: see also the BSD-3-Clause license.....This prelude is not part of the license.....<OWNER> = Regents of the University of California.. <YEAR> = 1998....In the original BSD license, both occurrences of the phrase "COPYRIGHT HOLDERS AND CONTRIBUTORS" in the disclaimer read "REGENTS AND CONTRIBUTORS".....Here is the license template:....Copyright (c) <YEAR>, <OWNER>.. All rights reserved.....Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:....1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.....2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ISO-8859 text, with very long lines (448), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1625
                                                                                    Entropy (8bit):4.643249827981199
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:1HMhg6y35HxebV06NpaAcEoguuiVR0f+kxykg0:1HMWJSNVBunVRRU3D
                                                                                    MD5:29DD0E3DB3E796B5B75B0414506ACB9B
                                                                                    SHA1:13D156BD4C3F449AB3C8495CAC27236A83E67077
                                                                                    SHA-256:1CAA94A20054EE9D3D05D6F83CBD84AE57A8D274D9CB3DFCEBF2C61A72876278
                                                                                    SHA-512:4BAF889EA8CCEF3FBAB6DA43858C1E8F6D299FC0F8E5BF9ED3BEC2D1BA4D9F23C9BACAA6F499ED85AB400E9FC45F465B5E659B11DE1A085D68A5CCC138DBCCE0
                                                                                    Malicious:false
                                                                                    Preview:NUnit License.... Copyright . 2002-2015 Charlie Poole.. Copyright . 2002-2004 James W. Newkirk, Michael C. Two, Alexei A. Vorontsov.. Copyright . 2000-2002 Philip A. Craig ....This software is provided 'as-is', without any express or implied warranty. In no event will the authors be held liable for any damages arising from the use of this software. ....Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to the following restrictions: ..1.The origin of this software must not be misrepresented; you must not claim that you wrote the original software. If you use this software in a product, an acknowledgment (see the following) in the product documentation is required. ....Portions Copyright . 2002-2012 Charlie Poole or Copyright . 2002-2004 James W. Newkirk, Michael C. Two, Alexei A. Vorontsov or Copyright . 2000-2002 Philip A. Craig ......2.Altered source versions must be plainly mark
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6404
                                                                                    Entropy (8bit):5.1598390009806225
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Die+xrsXrsy/QZ93OWZ762ROrsMrsSe13C3didCJ:DivrsXrsyilHo5rsMrsxdsdyCJ
                                                                                    MD5:CDAD00DCB0CE5844C78B65A3435B8567
                                                                                    SHA1:8F71D2B16416498BB416B0955402E266A1EED2AA
                                                                                    SHA-256:652884D9FCD49780FFD894235E84FD860B72F73938844581E94CFF749EF0DE23
                                                                                    SHA-512:9686A81001989F7007F25D1FB6EFACE944B39681D4367DB003138733D401E87B6ED3FDFC70C89E7B380B280BCA87E98A01A3B265E906259BC5BACA27F100E6E4
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a dual license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts. Actually both licenses are BSD-style.. Open Source licenses. In case of any license issues related to OpenSSL.. please contact openssl-core@openssl.org..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2011 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer. .. *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions an
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (405), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2697
                                                                                    Entropy (8bit):4.494004875562731
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:z9N9OvpiOF2VfEQIfFfy6GpDEqCJCBXe9USCJCh5nOxZ9U+D52nkkKvnxHgR2YPp:z9N9OQOF2xEQAFK6iFCoXe9TCE5OxTHu
                                                                                    MD5:C25777BAF9505CBF4B4360CD3FF8B01D
                                                                                    SHA1:DCFF78F571AD2D12D623097FF69744F88A9B04C2
                                                                                    SHA-256:0BE5DBEA997EF95F4736404402E5207C117CCCFDF49D05F540420A2CB65D8A30
                                                                                    SHA-512:386B562128946E48D0BE18C330AAB065ACAC1B87194CF907A8BAF037EAE22606D33B9872BC8D59272B43E2062B6E5E740DABFE034E808BB0F9D21DE51B65BAAD
                                                                                    Malicious:false
                                                                                    Preview:Microsoft Public License (Ms-PL)....Microsoft Public License (Ms-PL)....This license governs use of the accompanying software. If you use the software, you accept this license. If you do not accept the license, do not use the software.....1. Definitions....The terms "reproduce," "reproduction," "derivative works," and "distribution" have the same meaning here as under U.S. copyright law.....A "contribution" is the original software, or any additions or changes to the software.....A "contributor" is any person that distributes its contribution under this license....."Licensed patents" are a contributor's patent claims that read directly on its contribution.....2. Grant of Rights....(A) Copyright Grant- Subject to the terms of this license, including the license conditions and limitations in section 3, each contributor grants you a non-exclusive, worldwide, royalty-free copyright license to reproduce its contribution, prepare derivative works of its contribution, and distribute its contr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4696
                                                                                    Entropy (8bit):5.033873642581533
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1m5LmUW+bHiilxwnEOWOKajy4vyviXQaGYBC23zCdZuKy0iQHZoG:so0zl7hqyvaQ1+3zCdyQHZV
                                                                                    MD5:6ED93967FF0DC6DD9C8D31C17F817A06
                                                                                    SHA1:84E2137BA63C1983A1E36371FC7E08EF5D94542E
                                                                                    SHA-256:CA122F3BDA0154F692817450168CB650A7FC59EF96C93582ACD2E7A744D464D3
                                                                                    SHA-512:FAFA264E25460771DB0B01D6F900A51401A6A76CAAAEB46C109F2EC938AFA24FA3D0D8F063F85D751965477081F96796C5EF94C5B4E2972D12C7C09342242509
                                                                                    Malicious:false
                                                                                    Preview:Copyright (c) <dates>, <Copyright Holder> (<URL|email>),..with Reserved Font Name <Reserved Font Name>...Copyright (c) <dates>, <additional Copyright Holder> (<URL|email>),..with Reserved Font Name <additional Reserved Font Name>...Copyright (c) <dates>, <additional Copyright Holder> (<URL|email>).....This Font Software is licensed under the SIL Open Font License, Version 1.1...This license is copied below, and is also available with a FAQ at:..http://scripts.sil.org/OFL......-----------------------------------------------------------..SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007..-----------------------------------------------------------....PREAMBLE..The goals of the Open Font License (OFL) are to stimulate worldwide..development of collaborative font projects, to support the font creation..efforts of academic and linguistic communities, and to provide a free and..open framework in which fonts may be shared and improved in partnership..with others.....The OFL allows the licen
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):237
                                                                                    Entropy (8bit):4.544581128384236
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:e/JOXFVvrPhnvvFN4gOzZLpLtyEsKjMKvvGFKdm:e/gXFVZF2LLpLOK1XSKdm
                                                                                    MD5:E5668C83AD9F78877520F1947380E63C
                                                                                    SHA1:FFF6BB190AB3713A263A219F27904DE2742E9CDC
                                                                                    SHA-256:EA7F978F0E632710786E6E88F116F6B96CEBF629FE4CF7A3524C92D93AAD8FEA
                                                                                    SHA-512:FE2D7DF143BE8C9D1A310BB8CCA1670B1F75C3D01B758A2BC733AB0DE42F4069BF7CDC31B278911F72D0267F299D7096E9E9558D3B45348C74C8D56FD5B070C8
                                                                                    Malicious:false
                                                                                    Preview:Telerik installer packages are created using the WiX toolset version 3.8, licensed under the Microsoft Reciprocal License (MS-RL). ....The license and source code for the WiX toolset can be found at: http://wixtoolset.org/about/license/.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (2236), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):17599
                                                                                    Entropy (8bit):4.748870287844919
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:0ewrV6lVjZVoMWhsEFnQagPTLux5n4gf77s55LvgWz4h9Ma1WoVGQEtTQAbEuIbB:uMLBsXQ8bffwMrL1RGNTyz9/
                                                                                    MD5:EFE316D0ACB660F5CB50C62406D84689
                                                                                    SHA1:1435DDA57C999BE39227B2CDA3DEC54DA45E40D8
                                                                                    SHA-256:A0C04242CC7C639379DA24DD8E61505ED91E7BD2672467ED3A720C17B696B13E
                                                                                    SHA-512:982D63732E9FDE0BF2862B820FA356F0D667BCB44B80B0C68A60CC277A3FD85EDA06489B4D4C9592E46539A6106F3D0073E00A0058F8177413D66DB79995BDE2
                                                                                    Malicious:false
                                                                                    Preview:Microsoft patterns & practices License....patterns & practices Developer Center..This license governs use of the accompanying software. If you use the software, you accept this license. If you do not accept the license, do not use the software...1. Definitions..The terms "reproduce," "reproduction," "derivative works," and "distribution" have the same meaning here as under U.S. copyright law...A "contribution" is the original software, or any additions or changes to the software...A "contributor" is any person that distributes its contribution under this license..."Licensed patents" are a contributor's patent claims that read directly on its contribution...2. Grant of Rights..(A) Code..* Copyright Grant- Subject to the terms of this license, including the license conditions and limitations in section 3, each contributor grants you a non-exclusive, worldwide, royalty-free copyright license to reproduce its contribution, prepare derivative works of any contribution for which source code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6404
                                                                                    Entropy (8bit):5.1598390009806225
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Die+xrsXrsy/QZ93OWZ762ROrsMrsSe13C3didCJ:DivrsXrsyilHo5rsMrsxdsdyCJ
                                                                                    MD5:CDAD00DCB0CE5844C78B65A3435B8567
                                                                                    SHA1:8F71D2B16416498BB416B0955402E266A1EED2AA
                                                                                    SHA-256:652884D9FCD49780FFD894235E84FD860B72F73938844581E94CFF749EF0DE23
                                                                                    SHA-512:9686A81001989F7007F25D1FB6EFACE944B39681D4367DB003138733D401E87B6ED3FDFC70C89E7B380B280BCA87E98A01A3B265E906259BC5BACA27F100E6E4
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a dual license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts. Actually both licenses are BSD-style.. Open Source licenses. In case of any license issues related to OpenSSL.. please contact openssl-core@openssl.org..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2011 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer. .. *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions an
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ISO-8859 text, with very long lines (448), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1625
                                                                                    Entropy (8bit):4.643249827981199
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:1HMhg6y35HxebV06NpaAcEoguuiVR0f+kxykg0:1HMWJSNVBunVRRU3D
                                                                                    MD5:29DD0E3DB3E796B5B75B0414506ACB9B
                                                                                    SHA1:13D156BD4C3F449AB3C8495CAC27236A83E67077
                                                                                    SHA-256:1CAA94A20054EE9D3D05D6F83CBD84AE57A8D274D9CB3DFCEBF2C61A72876278
                                                                                    SHA-512:4BAF889EA8CCEF3FBAB6DA43858C1E8F6D299FC0F8E5BF9ED3BEC2D1BA4D9F23C9BACAA6F499ED85AB400E9FC45F465B5E659B11DE1A085D68A5CCC138DBCCE0
                                                                                    Malicious:false
                                                                                    Preview:NUnit License.... Copyright . 2002-2015 Charlie Poole.. Copyright . 2002-2004 James W. Newkirk, Michael C. Two, Alexei A. Vorontsov.. Copyright . 2000-2002 Philip A. Craig ....This software is provided 'as-is', without any express or implied warranty. In no event will the authors be held liable for any damages arising from the use of this software. ....Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to the following restrictions: ..1.The origin of this software must not be misrepresented; you must not claim that you wrote the original software. If you use this software in a product, an acknowledgment (see the following) in the product documentation is required. ....Portions Copyright . 2002-2012 Charlie Poole or Copyright . 2002-2004 James W. Newkirk, Michael C. Two, Alexei A. Vorontsov or Copyright . 2000-2002 Philip A. Craig ......2.Altered source versions must be plainly mark
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (587), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5463
                                                                                    Entropy (8bit):5.139311854015483
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:gaIn9MFxo3naLEMtycgPsrQHnoJ+dExeAdUlKwHlPsrQHnowzwPsrQHnow8dHaM6:jo9Mro3aLE0ycjQHnVWKlKwH0QHnnzQJ
                                                                                    MD5:1A295FFC9295C0A0F481B77A49EC08FE
                                                                                    SHA1:540CE96ADB516B6BC7B29A891DDC719E6A51D0F4
                                                                                    SHA-256:C2824BBFAD69A08FD5BFA3F18AC7ACD133746659A4E2746476A26D3C807F4CC6
                                                                                    SHA-512:DDF4264A357EC64CE2B03D0E3C50C2D2D467BEA0F6F6CD63171C200348B476127247A4B56ED6B67CD78382510643625CEBE450FBE80EFA75CC50281E533A580F
                                                                                    Malicious:false
                                                                                    Preview:.Telerik UI for ASP.NET Core by Progress v2016....Copyright . 2016 Telerik AD. All rights reserved.....Portions of the Product include certain open source and commercial third party components listed below (.Third Party Components.). The authors of the Third Party Components require Telerik AD (.Telerik.) to include the following notices and additional licensing terms as a condition of Telerik.s use of such Third Party Components. You acknowledge that the authors of the Third Party Components have no obligation to provide support to you for the Third Party Components or the Product. You hereby undertake to comply with all licenses related to the applicable Third Party Components.....1..Special Notices Regarding Open Source Third Party Components incorporated in the Product:....(1) .MIT-style Licenses:....(a) Telerik UI for ASP.NET Core by Progress v2016 incorporates..JQuery. Such technology is subject to the following terms and conditions:..Copyright jQuery Foundation a
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):237
                                                                                    Entropy (8bit):4.544581128384236
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:e/JOXFVvrPhnvvFN4gOzZLpLtyEsKjMKvvGFKdm:e/gXFVZF2LLpLOK1XSKdm
                                                                                    MD5:E5668C83AD9F78877520F1947380E63C
                                                                                    SHA1:FFF6BB190AB3713A263A219F27904DE2742E9CDC
                                                                                    SHA-256:EA7F978F0E632710786E6E88F116F6B96CEBF629FE4CF7A3524C92D93AAD8FEA
                                                                                    SHA-512:FE2D7DF143BE8C9D1A310BB8CCA1670B1F75C3D01B758A2BC733AB0DE42F4069BF7CDC31B278911F72D0267F299D7096E9E9558D3B45348C74C8D56FD5B070C8
                                                                                    Malicious:false
                                                                                    Preview:Telerik installer packages are created using the WiX toolset version 3.8, licensed under the Microsoft Reciprocal License (MS-RL). ....The license and source code for the WiX toolset can be found at: http://wixtoolset.org/about/license/.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5838
                                                                                    Entropy (8bit):5.185323286286133
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:pChMty3WPbKQHdrbM5gZELOQHFocvWLOQHFocf1aqBsLOQHFoL:60y3dQHdfM5gJQHFj5QHFjsqBvQHFi
                                                                                    MD5:A8027788375AA81D6D81AEDE3F649701
                                                                                    SHA1:2DD2A4BAEF2824C46568D4295D8324DFD16EE3AF
                                                                                    SHA-256:6AC7FCAA219F658D72C33B55F40413396C67A58E3CB8D013450956A20FC13D17
                                                                                    SHA-512:912B1734052AEBAA5D50D59C02E55D18755A70C47831B558CFB6F63B156BF459D73AB8578746CCA7FF0143607A6D7250017C88C5F31E6BB122C41530AA290626
                                                                                    Malicious:false
                                                                                    Preview:The following open source libraries are used in Kendo UI....--------------------------------------------------------------------------------..jQuery JavaScript library....Copyright jQuery Foundation and other contributors, https://jquery.org/....This software consists of voluntary contributions made by many..individuals. For exact contribution history, see the revision history..available at https://github.com/jquery/jquery....The following license applies to all parts of this software except as..documented below:....====....Permission is hereby granted, free of charge, to any person obtaining..a copy of this software and associated documentation files (the.."Software"), to deal in the Software without restriction, including..without limitation the rights to use, copy, modify, merge, publish,..distribute, sublicense, and/or sell copies of the Software, and to..permit persons to whom the Software is furnished to do so, subject to..the following conditions:....The above copyright notice a
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1106
                                                                                    Entropy (8bit):5.14873671945972
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:YhrDJHcH0ynYgt9qJq1hBE9QHbsUv4ek4/+daoxqmFn:m3J0lYEzBGQHbs5RTLxjFn
                                                                                    MD5:19B8D93B15D61C358EB698F45BC58134
                                                                                    SHA1:32CBAA63BD1E67583A687CA87317A96D41CCF383
                                                                                    SHA-256:3DB89794F5DFEEF43FAB474B861B5D14F7E1DE22ABD5A5DB2092B84581519ED8
                                                                                    SHA-512:BAD6A61EC70996F13BD0CD1DCC77A98FE0E6B5C6331A1DA7ECCF6F8BFFCEC656932AAF69A6AE369D5FF8E2B57808C2E6C482610E8902B12120BB93287E8AED20
                                                                                    Malicious:false
                                                                                    Preview:The MIT License (MIT)....Copyright (c) 2007 James Newton-King....Permission is hereby granted, free of charge, to any person obtaining a copy of..this software and associated documentation files (the "Software"), to deal in..the Software without restriction, including without limitation the rights to..use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of..the Software, and to permit persons to whom the Software is furnished to do so,..subject to the following conditions:....The above copyright notice and this permission notice shall be included in all..copies or substantial portions of the Software.....THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR..IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS..FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR..COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER..IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (946), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):10289
                                                                                    Entropy (8bit):4.62623155003621
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:LR0WP1VooUTo1xF/DFNXFE6Gz1zGf2L1CVvhz2oHqxvJbzjwLFkTGaFVHv:LFtUk1xtDv8LJ68bvNuFkTGaFt
                                                                                    MD5:2CD744D2743F496C08E97D92183E7D43
                                                                                    SHA1:E28826D4869825D9D5B17C52EE86BB46683675AF
                                                                                    SHA-256:AAF21DEA0E8C4B92B03AAC9E68F2D89F216131605B5669170BFEA4ABDE5C925F
                                                                                    SHA-512:87032261752BB08D95AE0E7F1CD962475119AF1A033FCDE6DB6168BDFBABDEF42AFE5B8C53740B38D62869AC6293DD494A84D0BAEFD34C4050271333FD547F56
                                                                                    Malicious:false
                                                                                    Preview:Version 2.0, January 2004....http://www.apache.org/licenses/....TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION....1. Definitions....."License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document....."Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License....."Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity....."You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License....."Source" form shall mea
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (755), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1828
                                                                                    Entropy (8bit):5.183805962488499
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:Ws3RSt1XOOrYJkrYJzV0432sBG32s3Etm13t6THy:5BzOrYJkrYJzVn303z9ITS
                                                                                    MD5:29F266D798BDD180ACDB09EC8EF3A9A6
                                                                                    SHA1:270A555DC03FD1662AEF77B473457D1578546F15
                                                                                    SHA-256:902D90EB752212158B626109ABD54D8E927856129B3EE80DE1E62E4EB3A2447B
                                                                                    SHA-512:A2898A2DBC9412CAE95E46B1B6AECAE1F22FDFB4CAE3C5CD00E6F3D1133D36D76A3EEBF847E16D32C29736B5FF2B60751F92A4AEEE77C6FF7186FA89FDB3CEDF
                                                                                    Malicious:false
                                                                                    Preview:..The following is a BSD 2-Clause license template. To generate your own license, change the values of OWNER and YEAR from their original values as given here, and substitute your own.....Note: see also the BSD-3-Clause license.....This prelude is not part of the license.....<OWNER> = Regents of the University of California.. <YEAR> = 1998....In the original BSD license, both occurrences of the phrase "COPYRIGHT HOLDERS AND CONTRIBUTORS" in the disclaimer read "REGENTS AND CONTRIBUTORS".....Here is the license template:....Copyright (c) <YEAR>, <OWNER>.. All rights reserved.....Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:....1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer.....2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Non-ISO extended-ASCII text, with very long lines (514), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):9433
                                                                                    Entropy (8bit):4.87011155884007
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Fdg25o4ndmHrazdiHpAgI+V+eJlliVnc6SuGN5wcpAshFWgHSs:Y2BndmHrvHpAalliVcPFHDpAshFWgys
                                                                                    MD5:BE77F7D5220DC1186DBD9D1AC4C72FB6
                                                                                    SHA1:2BBBED575E2E531E354023724337FAF3B3CEF13C
                                                                                    SHA-256:CB362FEDBA08519971B3BBDADE04A127CE474875BA06AE72C59DB432FC9ABF76
                                                                                    SHA-512:458A37750153228F97C39B1AEE5684757F1B844D19F07E41D10C6DC0F7A179EEFAE0E3DC6989E4ACEB2F265D9090AD7D102AB26733AF7DA800750366DDA4FD05
                                                                                    Malicious:false
                                                                                    Preview:MICROSOFT SOFTWARE LICENSE TERMS......MICROSOFT .NET LIBRARY ....These license terms are an agreement between Microsoft Corporation (or based on where you live, one of its affiliates) and you. Please read them. They apply to the software named above, which includes the media on which you received it, if any. The terms also apply to any Microsoft..... updates,..... supplements,..... Internet-based services, and..... support services....for this software, unless other terms accompany those items. If so, those terms apply.....BY USING THE SOFTWARE, YOU ACCEPT THESE TERMS. IF YOU DO NOT ACCEPT THEM, DO NOT USE THE SOFTWARE.......IF YOU COMPLY WITH THESE LICENSE TERMS, YOU HAVE THE PERPETUAL RIGHTS BELOW.....1. INSTALLATION AND USE RIGHTS. ....a. Installation and Use. You may install and use any number of copies of the software to design, develop and test your programs. You may modify, copy, distribute or deploy any .js files contained in the software
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with very long lines (405), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2697
                                                                                    Entropy (8bit):4.494004875562731
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:z9N9OvpiOF2VfEQIfFfy6GpDEqCJCBXe9USCJCh5nOxZ9U+D52nkkKvnxHgR2YPp:z9N9OQOF2xEQAFK6iFCoXe9TCE5OxTHu
                                                                                    MD5:C25777BAF9505CBF4B4360CD3FF8B01D
                                                                                    SHA1:DCFF78F571AD2D12D623097FF69744F88A9B04C2
                                                                                    SHA-256:0BE5DBEA997EF95F4736404402E5207C117CCCFDF49D05F540420A2CB65D8A30
                                                                                    SHA-512:386B562128946E48D0BE18C330AAB065ACAC1B87194CF907A8BAF037EAE22606D33B9872BC8D59272B43E2062B6E5E740DABFE034E808BB0F9D21DE51B65BAAD
                                                                                    Malicious:false
                                                                                    Preview:Microsoft Public License (Ms-PL)....Microsoft Public License (Ms-PL)....This license governs use of the accompanying software. If you use the software, you accept this license. If you do not accept the license, do not use the software.....1. Definitions....The terms "reproduce," "reproduction," "derivative works," and "distribution" have the same meaning here as under U.S. copyright law.....A "contribution" is the original software, or any additions or changes to the software.....A "contributor" is any person that distributes its contribution under this license....."Licensed patents" are a contributor's patent claims that read directly on its contribution.....2. Grant of Rights....(A) Copyright Grant- Subject to the terms of this license, including the license conditions and limitations in section 3, each contributor grants you a non-exclusive, worldwide, royalty-free copyright license to reproduce its contribution, prepare derivative works of its contribution, and distribute its contr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4696
                                                                                    Entropy (8bit):5.033873642581533
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1m5LmUW+bHiilxwnEOWOKajy4vyviXQaGYBC23zCdZuKy0iQHZoG:so0zl7hqyvaQ1+3zCdyQHZV
                                                                                    MD5:6ED93967FF0DC6DD9C8D31C17F817A06
                                                                                    SHA1:84E2137BA63C1983A1E36371FC7E08EF5D94542E
                                                                                    SHA-256:CA122F3BDA0154F692817450168CB650A7FC59EF96C93582ACD2E7A744D464D3
                                                                                    SHA-512:FAFA264E25460771DB0B01D6F900A51401A6A76CAAAEB46C109F2EC938AFA24FA3D0D8F063F85D751965477081F96796C5EF94C5B4E2972D12C7C09342242509
                                                                                    Malicious:false
                                                                                    Preview:Copyright (c) <dates>, <Copyright Holder> (<URL|email>),..with Reserved Font Name <Reserved Font Name>...Copyright (c) <dates>, <additional Copyright Holder> (<URL|email>),..with Reserved Font Name <additional Reserved Font Name>...Copyright (c) <dates>, <additional Copyright Holder> (<URL|email>).....This Font Software is licensed under the SIL Open Font License, Version 1.1...This license is copied below, and is also available with a FAQ at:..http://scripts.sil.org/OFL......-----------------------------------------------------------..SIL OPEN FONT LICENSE Version 1.1 - 26 February 2007..-----------------------------------------------------------....PREAMBLE..The goals of the Open Font License (OFL) are to stimulate worldwide..development of collaborative font projects, to support the font creation..efforts of academic and linguistic communities, and to provide a free and..open framework in which fonts may be shared and improved in partnership..with others.....The OFL allows the licen
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5838
                                                                                    Entropy (8bit):5.185323286286133
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:pChMty3WPbKQHdrbM5gZELOQHFocvWLOQHFocf1aqBsLOQHFoL:60y3dQHdfM5gJQHFj5QHFjsqBvQHFi
                                                                                    MD5:A8027788375AA81D6D81AEDE3F649701
                                                                                    SHA1:2DD2A4BAEF2824C46568D4295D8324DFD16EE3AF
                                                                                    SHA-256:6AC7FCAA219F658D72C33B55F40413396C67A58E3CB8D013450956A20FC13D17
                                                                                    SHA-512:912B1734052AEBAA5D50D59C02E55D18755A70C47831B558CFB6F63B156BF459D73AB8578746CCA7FF0143607A6D7250017C88C5F31E6BB122C41530AA290626
                                                                                    Malicious:false
                                                                                    Preview:The following open source libraries are used in Kendo UI....--------------------------------------------------------------------------------..jQuery JavaScript library....Copyright jQuery Foundation and other contributors, https://jquery.org/....This software consists of voluntary contributions made by many..individuals. For exact contribution history, see the revision history..available at https://github.com/jquery/jquery....The following license applies to all parts of this software except as..documented below:....====....Permission is hereby granted, free of charge, to any person obtaining..a copy of this software and associated documentation files (the.."Software"), to deal in the Software without restriction, including..without limitation the rights to use, copy, modify, merge, publish,..distribute, sublicense, and/or sell copies of the Software, and to..permit persons to whom the Software is furnished to do so, subject to..the following conditions:....The above copyright notice a
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (587), with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):5463
                                                                                    Entropy (8bit):5.139311854015483
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:gaIn9MFxo3naLEMtycgPsrQHnoJ+dExeAdUlKwHlPsrQHnowzwPsrQHnow8dHaM6:jo9Mro3aLE0ycjQHnVWKlKwH0QHnnzQJ
                                                                                    MD5:1A295FFC9295C0A0F481B77A49EC08FE
                                                                                    SHA1:540CE96ADB516B6BC7B29A891DDC719E6A51D0F4
                                                                                    SHA-256:C2824BBFAD69A08FD5BFA3F18AC7ACD133746659A4E2746476A26D3C807F4CC6
                                                                                    SHA-512:DDF4264A357EC64CE2B03D0E3C50C2D2D467BEA0F6F6CD63171C200348B476127247A4B56ED6B67CD78382510643625CEBE450FBE80EFA75CC50281E533A580F
                                                                                    Malicious:false
                                                                                    Preview:.Telerik UI for ASP.NET Core by Progress v2016....Copyright . 2016 Telerik AD. All rights reserved.....Portions of the Product include certain open source and commercial third party components listed below (.Third Party Components.). The authors of the Third Party Components require Telerik AD (.Telerik.) to include the following notices and additional licensing terms as a condition of Telerik.s use of such Third Party Components. You acknowledge that the authors of the Third Party Components have no obligation to provide support to you for the Third Party Components or the Product. You hereby undertake to comply with all licenses related to the applicable Third Party Components.....1..Special Notices Regarding Open Source Third Party Components incorporated in the Product:....(1) .MIT-style Licenses:....(a) Telerik UI for ASP.NET Core by Progress v2016 incorporates..JQuery. Such technology is subject to the following terms and conditions:..Copyright jQuery Foundation a
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71808
                                                                                    Entropy (8bit):6.302233040356993
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BZb60QnEfniRuc4MG7uKMgM1lBa/0jSNgDWcLbtNnstX1Ac:BZcEfni4c4MG7vKFLLjwX1T
                                                                                    MD5:391166F9D5D40EE90F0744982177F4AB
                                                                                    SHA1:F7DFF35B30DE2E02BCB3A7EFE45334E1B5D7C8FE
                                                                                    SHA-256:FA36ED1236CDA36DFA34BE757A791EC94011D43D19E73D0BD9D0F9F802473A22
                                                                                    SHA-512:700FBE5FD992F678C83CCA1170F68593149C04E314402F7505B8A640FA89CD24633426ECB3548057E7AF14F0342301E66B5785F01F7FDD64ED2AF13614CD98EE
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Joe Sandbox View:
                                                                                    • Filename: OneLaunch - EarthView3D_3o3f1.exe, Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: MDE_File_Sample_4e8af2004a77f531e655e2e5cb669c388d0655c9.zip, Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: , Detection: malicious, Browse
                                                                                    • Filename: OneLaunch - Manuals_t5m2z.exe, Detection: malicious, Browse
                                                                                    • Filename: OneLaunch - PDF_o2u43.exe, Detection: malicious, Browse
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`."Q...........!..................... ........... .......................@......2.....`.....................................W........................>... ....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........t...w...........]..0...P .......................................v.{....On..O.w..-t..x<P....e.@0v.bY>.7. %c.\.h.J....MW......P.w.J...(...3^.....>M.............(WIH....1..../O}.}...gOm...{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.*6..(.........*.*.*.*.0...........-.r...ps....z..2...o....o....2.r...ps....z..2...o....2.r)..ps....z.o....,..o....o....-.s....z.o.....o......o....,..o....o....-..*.o....-.s.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144496
                                                                                    Entropy (8bit):6.219127874938619
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:0RZlEOzBzB3yZwUDXSNhB+IIx3zUOEF7xQQwQQQQQQTreulTnXGZFfHjKUhcweTo:0RUONhhUDyhB1IRUOEoUjHBhT/nLN
                                                                                    MD5:5BD39A82AACF1AA423E6EEEEDA696EEA
                                                                                    SHA1:B7971F9807520DAC9523BFD1185A7DCC9E5CC77C
                                                                                    SHA-256:1D69EAF538008E0FE1A7EB2CE0124A49B95C491797749640C8351ED4643F5C97
                                                                                    SHA-512:CBD255E7323A7E82D8B9443E8CE67BEF88F88BF46E525333E4017024A31952656F61F93334B3957D85FB0E422E561197C0ADB1366653DA007C9667651B1F37B1
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[."Q...........!..................... ... ....... .......................`......a.....`.....................................W.... ..................p>...@....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......$...h...............c...P ...............................................\.E..-.....A.}.8.p. 0AF@4.....T.P\...S.aEf.....$..m..G.h......Q.,.2....N..jE...QD.V..<i<(*".\q.7_..;.ge. Q[..P..{....*"..}....*F.o....r...p(....*..0..C........(......~....-....7...s.........~....(...+(...+(.....(1.....o....&*F.~....(....t....*6.~.....(....*F.~....(....t....*6.~.....(....*F.~....(.....j...*J.~......j...(....*F.~....(.........*J.~..........(....*F.~....(.........*J.~......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):139888
                                                                                    Entropy (8bit):7.142634633787823
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:TNZyjlo+Ib/RorkWhl/pNODb6lwztxdbbDFlkYUo8:TNYAb/2rk2l/jkb6uzj5Qo8
                                                                                    MD5:18DB3E02D95A16FD502C7C091C0361D9
                                                                                    SHA1:AB2D700306E0A0A3D094A0BC856FF1FFAD916C49
                                                                                    SHA-256:34843CFEA24B713B1B5FD9A93C61D7C6D3FA320DBB84DF60D9D48C5560C79452
                                                                                    SHA-512:6DE8751ABED256BCC381F69248F33AAE551A17966EFBC0ABB5C1DC98865B46E3924202C1347E0EC6949F1719E1D282817838815E99E68E7B1381A6B204C95416
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...]."Q...........!..................... ........... .......................@............`.....................................K.......................p>... ......X................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......X....K...........M..._..P ......................................Du..l..O..(|.n.....z.fj.W4.mc....f...>e..~.V....<../..}....1$q.7@r..3w..JQ....._C(S....C. .Z.Pt..d,......f-..]..".SO.7.4...x.0..:........(.....s......r...p(M...o.....(.....~....(.....~....(....*F.~....(.........*J.~..........(....*F.~....(.....+...*J.~......+...(....*.0..,.......s.......(....o......(....o......(....o.....*F.~....(.....+...*J.~......+...(....*....0..3........t.......(...............#..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):108168
                                                                                    Entropy (8bit):6.179559450110609
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:hf+YSZc1rj0oek7u05g3XG5rs+eUvNL3NX5S8caZkvsd65FAU9Qyx1NElSJK/Tr:R4ZYrj0oeOg325ragNDNP+AUzqSJMr
                                                                                    MD5:3034CC0D5CF3731ED90153AA616F3F59
                                                                                    SHA1:AACE8D26358D9829F0E6632BDDF183534ACFEC0D
                                                                                    SHA-256:63CD5E8A60D77D1007352538A4285C60C0C3EFB9C771035589105A284E4F63A9
                                                                                    SHA-512:88589B022D713D565342E331394ED5600D1FE346AA788E45E16CF51221CE898F10BD28C6A09FDC44D9AD94F25B4ED22C6F0EB28FA832863C01732DEF5B6C6086
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X."Q...........!.....^..........n}... ........... ..............................C.....`..................................}..O....................h...>...........{............................................... ............... ..H............text...t]... ...^.................. ..`.rsrc................`..............@..@.reloc...............f..............@..B................P}......H.......L...................1...P ......................................Am.........C.....7.7....|..........,...w?..T....A.e......I}.#N..E....~...y. x`E......C`A&P.....Y.....A..J......#.p..).uGkJ1:.(......}....*:.(......}....*...0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*"..(....*"..(....*..*..{....,..{.....o....*.{....o....*2.~....(....*6.~.....(....*F.~....(....td...*6.~.....(....*J.(.....s ...}....*F.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):62160
                                                                                    Entropy (8bit):6.394651976589669
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Lu5fLsPcyp/79lGhbTfpp6tpJbox15i4R5we/MvSKi0cOEwC7:y5fQLMhbTfpp6tpJsx1R2eMqK2WC7
                                                                                    MD5:B5BBEE69523810F8AA9D92E3D3ECB896
                                                                                    SHA1:9A45F181AC22B5C633EED421B59F5FE9D12D6A7C
                                                                                    SHA-256:BF99695470075C4E2C906BE4567F1D0AB3A6D85D31EC1D8F6B4139015C48A2B3
                                                                                    SHA-512:9EEFF3BA247793163FD091FB26D8E620C99A8CB1B510F26EA7C31EB9EC27F2DE9E92F14CA470852C84FF1DCCF5FBCBAED8C93EA2F05C6515E2C078776C62BA7E
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...a."Q...........!..................... ........... ....................... ............`.................................@...K.......`................>........................................................... ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B................p.......H.......PE...............D......P .......................................xk.r..E. z.aD.-$..}...=..+<%...Z....x.N.,..D...nA*....1T. 6./n.`j..."q..rE........44.(..a...\..>...~.......9.M.).#..c.0..W.......(....s.........(.........~.....(....,+(....~....~.....o....t>........~....(....&*(....*j~....%-.&~....~.....o....*.......*2~.....(....*Z~....(.....o.....?...*Z~....(.....o.....?...*.(....,.(....,.~....(.....o....&*(....*.(....,.(....,.~....(.....o....&*(....*Z(....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48344
                                                                                    Entropy (8bit):6.53421522959476
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:4L/YzwmxRqw+4aECjhmUYVmePi+6bYKN4:aMxRqF4BCjhmHPZiYKN4
                                                                                    MD5:06296D204C279118CB8863F07E3DE4E1
                                                                                    SHA1:175553C011BA3B50322833477F095142F1C3D699
                                                                                    SHA-256:CEB0E446953833CAA54BC01E84B787281CF6712BA7DB65D4C9A664413E95CEFB
                                                                                    SHA-512:BFA4479554B841A17969D124FD69701DC1313E8F24EAD667C45002AE8D60C3F615D8D484D1334C87E5C93F1FB30B8217A0CBD528125EDFFEF050B898BDC1598A
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."Q...........!.....t............... ........... ..............................~H....`.................................l...O.......`............~...>..........4................................................ ............... ..H............text....s... ...t.................. ..`.rsrc...`............v..............@..@.reloc...............|..............@..B........................H........p..L!...........0..&@..P ........................................9q.}..;q._^.X.A...&Y..n._=....*...%...'.Dc...S)..C....W.....k.Q......l.U.v.%...l...."ITo.Z".w..|-:.L%5g..cy':....=.6..Z.bF.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*..{....*"..}....*..{....*"..}....*"..}....*..{....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):211632
                                                                                    Entropy (8bit):5.3707738806905905
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:3TdnDzOb56Xp6kGijb7N5KH+KnklI7o5UuL8J:3TdnDCbgX4ecoY
                                                                                    MD5:B8ACA033D81112E38EEA7B9525F1BD56
                                                                                    SHA1:7428C64C3E68DD45E89FDFEBA08F75F1D3A49B29
                                                                                    SHA-256:D750B661263AEFCBE961942D15C2DC507DA6361748A8E65426963274B5744EE7
                                                                                    SHA-512:045E2D152DD2AB8AB64BCF0B32ACBEDC2700018A354E26C9ADB2D26C7390D648A51903DFA33FC61CDDAF2DE6B5DC38D3F0745D37AB8BDB9328566EE48806892E
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ......~.... ... ....... .......................`......q.....`.................................,...O.... ............... .......@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):51888
                                                                                    Entropy (8bit):4.733153779202759
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:nwO5mYXPEmIeNc0jh+9fzLkguHw+n6xLVC65qMARM0Juu9sKDPMimhk8l+YGAIxG:nydeNBjhEfzLkguHw+DaNgzK151v8ix
                                                                                    MD5:2FCEF68860A27342DB0BEC3CF32188DD
                                                                                    SHA1:9135DF90FA78D08A6ADAD7926724D92D024CA74C
                                                                                    SHA-256:65CA3103E4DBDF334CC663313BA61025ED7125F59C21BB1463B27E8DB1BB8478
                                                                                    SHA-512:25C346CCFB22FB506195CE8EE362AE70A98BFE77C30BED6C96235610D80C29FD000AB2E9FF908CA845D8C697DC70B79F81E7DBD70E3478B5F8BC7A8A389CB16A
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ........... ........... ...............................k....`.................................`...K.......(...........................(................................................ ............... ..H............text....p... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):113328
                                                                                    Entropy (8bit):5.212181591929611
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:z9o2x9/b+S5QunlLrFV8FLjpnAwYxFBGPiV1uDxp454qd5kymiDuYszyW9EJP3fo:5UunVryVSFBGpBqfkzcWcxfr8vN
                                                                                    MD5:62D60CFC697E83E6646D5BD6E4CB1E51
                                                                                    SHA1:9F5F78A3738729D1D721E02CF31BED62DA27BFEB
                                                                                    SHA-256:01BA1D6A7EAF5CF39E33724B4EBA05BDFB4507B581E4789DEB59F1C473997690
                                                                                    SHA-512:F0069EEFB65762040E0C16AAC2768A7B459910E02554B4BB9E26C9EFC3892C5946F72B23D381CADCAD9A164907E3FDCF85903AA27C741FEDC854C4A2C40266DB
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....p... ........... ........... ...................................`.................................<...O.................................................................................... ............... ..H............text....e... ...p.................. ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):415408
                                                                                    Entropy (8bit):5.573182313694346
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:fXvGO+uec6A3HQ0nHajgLx+lkMPSDt2nb+6PVM0H+ULFpUKiw9OBTj1ESZ31W:fOO+66OCoMna6PV/H+UE1xZ31W
                                                                                    MD5:4DDB62841065A6587A5CF72944AA996B
                                                                                    SHA1:A437A112A19F4220E18A6C8E764D73E315F47ADA
                                                                                    SHA-256:AD18F28213EBC685A4E6F38CEA549F85DEA2E51025F4D08F672EFCE128FF105F
                                                                                    SHA-512:161A169FA60CFED2D67F135E0DBB6932FCFCA0676B6E7BEACF4BA9FCE35E887DE0AA3BBBA76EABE173CBBCD060ED8325E0C732BCFBA9E486445D5E516F5CFE8A
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....2...........P... ...`....... .............................."G....`..................................P..K....`...............<..............hO............................................... ............... ..H............text....0... ...2.................. ..`.rsrc........`.......4..............@..@.reloc...............:..............@..B.................P......H....... ;..H...........x....2..P .......................................q.+.$.~..n.P..8\.^._.v)..&Y$..".....-.]%..^...Xjf'...D......m..,e74.n..O.-X~h....%:$U=.....A+........v..g....P..u.....Rs..O.]..(-...*&...(....*.(....s/...z^.(......9...(2...o3...*J...9...(2...(....*.s....*..(-...*&...(....*.(....s/...z^.(......Y...(2...o3...*:.r...p..(....*....Y...(2...(......(......(....*F.r...p(4........*J.r...p......(5...*F.r9..p(4...t....*6.r9..p.(5...*..o7...*..o7....(....~....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):368816
                                                                                    Entropy (8bit):5.365214438266103
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:KrNvoFXHxeLeKdwU1SzZiZ5pbC7K4vQg7wwhFQSamkV8EvA3PXiD3fm553inDg8I:KxPeRiZ5nqwSuzvAsu5Jiq
                                                                                    MD5:37742E95B192B5B3F8707C2487A70BB0
                                                                                    SHA1:74F0A74F1E8F1513FFF13CD4D7A60658F59DC856
                                                                                    SHA-256:B410452B0A9BDBB8C860169F669A8E051AFB51FA53030D31E8667E5FC1B9C445
                                                                                    SHA-512:174F5DFD8DDD1C31D707F8EC0EAB29B9E563DE7DEC85A1F32BCB658E43309CE48F0BACF75964C1CDB24AFB5014D17E0DA252B7C2C7B585A9BB8430792A87EEE5
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....|..........>.... ........... ...............................5....`....................................O.................................................................................... ............... ..H............text...D{... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B................ .......H........+...m..........(...._..P .......................................G.x7tf...r|-.}...)e{.@.[......y.P...Rt...@...a..o..%9 ..n...!.M<...u...QM........l..MVNU:G.D...5#u....b$.3N_...'.....EZ.r. v.s!...}.....s"...}.....(!...*...0..6........x...(#...............o$.................(%...tP.....*...0...........s&.....*2.~'...o...+*...0..m............{....%....((....{.......o)...,.....A...(a.....(c....o.........(a...o*.....{......o+......,...(,.....*..*...........Y]........-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):140432
                                                                                    Entropy (8bit):6.059133240260085
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:z5cEGcPGEuEz6C62cxocEt+7f0YuuriDjNcYEhPoBj2bRViOsPKJKPfqIn37nNfv:z4ciEl6pJ7f0YuuAKA2XcnCyKY+8rz
                                                                                    MD5:4CBC7B9D057E89C6A5BA313F6C2F036C
                                                                                    SHA1:BE57AE313DE841F987D0AE4CF9632E5F155955BE
                                                                                    SHA-256:EB8F7CECA9DFCA2080A8A9C30EBF49298778743F288A289970846D02074C5322
                                                                                    SHA-512:63077C81B1C0379FD86BC88571F8AEF227B449693C0B015BEEEABD99C3033C644F17AB089BBC55594C0FF98BD302C503C435B992DD7E83876CCB2111483CF902
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!..................... ... ....... .......................`...........`.....................................S.... ..`....................@....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B........................H............I..............%..P .......................................f.>dT.j.P..s..K..K...|"Y...r...^. ....}1k..mu...Q'Y......4..;b0.....\Y;....W...1..I...{...8...9M..-....,.......x...vG.IQ2..{....*"..}....*..{....*"..}....*..{....*"..}....*.sI...*"..o....*.s....*.*B.e...((...(u...*....0..........()...o...+..o....*...0..^.......()...o...+..,N......((...()...o...+o..........((...()...o...+o..........((...()...o...+o.....*...0..........()...o...+..9.....r...p.<...((..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27792
                                                                                    Entropy (8bit):6.1321477705881335
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:FBg0ucz9tgkgZWJkkgZWvvwKuk4WBul+S2vKURa5kMac1WkrzvXS9//0GftpBjBh:FBgbch/vxnRakBcbr+8iN
                                                                                    MD5:8AD746D4BB9B64AC5F0CE29896162259
                                                                                    SHA1:79041040D9CC0070B9DCE4026466B195BFF78EB4
                                                                                    SHA-256:F4043D2182666F67ACF71449EA60477DBDC577B1A09574ED6562A5C3FA6C42A9
                                                                                    SHA-512:D38CA6AE2133F231E89E15A7470E24D477F9D1DF7838E793FA427E048EBBADE1618EB08CDA30FFEC72080ED4EBF2EE2A897AB9D575C205EFBC4FCA92C88E0456
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....H...........f... ........... ...............................<....`.................................`f..K.......h............R..............(e............................................... ............... ..H............text....F... ...H.................. ..`.rsrc...h............J..............@..@.reloc...............P..............@..B.................f......H........7..............P-......P .......................................(>..P.^+..Vf.......y..Cd.^....kL*.C..d.....J.4.3..P3.}..1z...9...a>..uF..XR.o.(k.:.C3.R....:...../K%n..........e.S..(...........s....}............s....}....*..{....*..0..@........{....,..{.....{....o......}.....{....,..{.....{....o.....o....*..{....*^.{.........}.....o....*Z.{....o....u.........*..0..J........(.........-...( .....(!...*.("...,%.(........("....(#...o$.........o%...*..o....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):41616
                                                                                    Entropy (8bit):6.118366181712053
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:/1UUBVS1yKegy8XiOYgzECu0WIbHzVfQ+t9yIor+8ie4:tUTy8XVnzECTWILufr+8u
                                                                                    MD5:7A271CE5582DDCC325732581A533D8BE
                                                                                    SHA1:5FA2C5390EE84BF975C861AFA361D2E17AC9F625
                                                                                    SHA-256:9202C7E903172AE1855AB96EE5D80248292B86100A843DDCC6DB664CD6EDD1B6
                                                                                    SHA-512:43F575A8FDB98565358C7C5C3FECA78A9154CDDAE6BDD1AEF1A2B108B0650059257F8983B9A1E544C12586807303D2C4F440AF0171295EA284C8F7347D24BE70
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....~..........>.... ........... ...............................&....`....................................S.......h............................................................................ ............... ..H............text...D|... ...~.................. ..`.rsrc...h...........................@..@.reloc..............................@..B................ .......H........:..._...........1......P .........................................%]..?.....V.AJ3Z^f.6g.u4.5cJ...+8.j....c;...PP8......6...T...9..kA.u;+U.na6\.......I.c(.J..L.....h.K[.!....s!Sdr.Q><S.&.0..*........-.r...ps....z.(......sG.....o.....o.....*...0..........s.....(......o....o......8......o......o....o......8......o.........o....o......+S..o........o....o......+#..o........o.....o.....(....-....+...o ...-.....,...o!......o ...-.....,...o!......-...o"...-...o#.....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14496
                                                                                    Entropy (8bit):6.327509765949796
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:rb6Oaxhqm1st8jjMfGkqWx/zB//0GftpBjcc3:rCwUQ8jjenj8i53
                                                                                    MD5:964AB2C3520B8A735329F0BE577C5850
                                                                                    SHA1:968EAB9103EC64A0DD4657582F28BB6FE9644209
                                                                                    SHA-256:DA3ABFEE09DDE110E4E9A0321F7223F7380A1052CB506313F44947E32F09BB5F
                                                                                    SHA-512:0BF393D15E64FB1A2BC0BEF663DD760E3ACDFDA503AEA185A83B904B01D612FA3AFFE7FFEC8780C23274D9B8E182B29CDD906CF8A0825569AB02ABBF4DE0AA61
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....="S...........!................>4... ...@....... ...................................`..................................3..O....@.......................`.......2............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 4......H.......(#...............!..X...P ......................................;.)%.6.h..q..O(-.`......&7.q.G..G1..J...S1.&..f....H.....bl....W(.E).K.RI..............8&Q.b......H+!df-.f..3h.H..h7|.]...(....*.0..3.......~.....(...., r...p.....(....o....s...........~....*.~....*.......*V(....ry..p~....o....*.0...........u!.....-.r...ps....z.(....*Z.,..~....o.....$...*.*V.,..~......$...o....*.r...p.$...(.........(......$..........s ...s!...("........*...T..............lSystem.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31376
                                                                                    Entropy (8bit):6.161352322277959
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:r27oPj3ZdGnwIDMIMoMMMIMIM408PUugN+8ik:rEorPGpUnN+8r
                                                                                    MD5:5C9985D31E098BF7DF031171E046D67E
                                                                                    SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                                                    SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                                                    SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):22768
                                                                                    Entropy (8bit):6.201382004474863
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:PF5AZ+le8+2KCYTzs2um7GH9SJSWcGvXS9//0GftpBjE4u:PF52+le8gR7GH9yok+8iyf
                                                                                    MD5:7C08EA125D8054BFA6057104590A7F83
                                                                                    SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                                                    SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                                                    SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):12432
                                                                                    Entropy (8bit):6.213812838430843
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:C349VlDs8a3XUVW2itvXS9nMTI/s/nGfe4pBjS735:Cq83XUVWNvXS9//0GftpBjU
                                                                                    MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                                                    SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                                                    SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                                                    SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18120
                                                                                    Entropy (8bit):6.226050809869831
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:U0xk42ZtyyslnQyrgbPyIH/rFzsX+cAW++2Wx1q//0GftpBjIc0:DVegwRe+c3S8iC/
                                                                                    MD5:E834E45855E8D220B0C5D0C1CAC24E44
                                                                                    SHA1:D8AAF831CF5B90A206EE9348386A72498AF0C0EE
                                                                                    SHA-256:78AC70411C71B7A0C68FE8746EDD3F3A8CD3F72044B329A40AB53C57891BE37D
                                                                                    SHA-512:F91A3FA6D522AD5F977AF744618D5ADC1A6CAEA0645D870E10962E00C03534CC3A9FA1D82001627F5B6FC3186BD51E3E69D16DD689C5E7CD4D84AC66AE9A63F3
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......R...........!....."...........A... ...`....... ....................................@..................................A..O....`...............,..............T@............................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........&..d............$..O...P ............................................V.{..(.;.X5..b.2X..L.{.z7t.P1).qf...w.g....ik..:.5a..J.FK.e..mSgn9.cQM..9.B..ZLSy@..j.e...Z.......6..c.'...m1.{....(....*"..(....*&...(....*v(....-.(#...s....z~....o....*.......*2~..........*&...o....*&...o....*...0.............o............o.....s....z.*...................0............o...........o.....s....z.*................^......(.....o.........*^......(.....o.........*.0..<.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*47 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):24064
                                                                                    Entropy (8bit):2.8139684302156573
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:GDwjVAfAm3ACA4C+9p80/v/z+fyvx/ZsbwZ9SWCNHn3bmEPl33dD446DAE/f5ek/:GDwjsI+rHzhVxl7
                                                                                    MD5:1B0B75EA764B048A27B3205970D2FA0B
                                                                                    SHA1:2865C064AFD9CF51B7B5916E321870EB3FDAF952
                                                                                    SHA-256:2130C737EB69EB79A9ABC74DCD9BE2A733AAFD43174FB9C177601935A08A43F8
                                                                                    SHA-512:0012D14AFE49AE0A59ABE5451AC2A705E090311A4DA5AEB3A87DD6DB4982A26747AD18DB6421E9D500F4687D4AD5399C068037C4712606334608384FF2FC060D
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS.........../...........,...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.488842171019742
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6fhZMjDlMDH5lpoJDLYNMTwCRXQtPyqE4Ev/mZWjH1AglkAqVwAK5W1AxF:UoDlUbmJfzwCRXQtqqE4zWjugRuXaWu
                                                                                    MD5:23E59CC67C075C315F717770D46B00A6
                                                                                    SHA1:260D18B0BDBB8ADABB1A6D8565ACA14CCC462CB2
                                                                                    SHA-256:1E2636B145C0C69E30DB1492950EE23D02458DFE6DAC69EA51D865BA15FA0FDE
                                                                                    SHA-512:36128BAE654D5C58053FEF3EB8DCD54B7671DACB5CEA6F26C5340E0BC38579667064F169FE7FA744FDB40DEBAAA4CA040D749C1DA803A139594DF9E7D1D42284
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Y.........." ..0.............N'... ...@....... ....................................`..................................&..O....@..8....................`.......%............................................... ............... ..H............text...T.... ...................... ..`.rsrc...8....@......................@..@.reloc.......`......................@..B................0'......H.......P ..t...........................................................BSJB............v4.0.30319......l...|...#~......P...#Strings....8.......#US.<.......#GUID...L...(...#Blob......................3..................................................y.....@.....>.....h.................`.....,.....E...........T.....2...............................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........#.....,.....K...#.T...+.x...3.x...;.~...C.T...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):711952
                                                                                    Entropy (8bit):5.967185619483575
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:GBja5bBvR8Q0TE2HB0WLmvXbsVG1Gw03RzxNHgKhwFBkjSHXP36RMGy1NqTUO:GBjk38WuBcAbwoA/BkjSHXP36RMG/
                                                                                    MD5:195FFB7167DB3219B217C4FD439EEDD6
                                                                                    SHA1:1E76E6099570EDE620B76ED47CF8D03A936D49F8
                                                                                    SHA-256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
                                                                                    SHA-512:56EB7F070929B239642DAB729537DDE2C2287BDB852AD9E80B5358C74B14BC2B2DDED910D0E3B6304EA27EB587E5F19DB0A92E1CBAE6A70FB20B4EF05057E4AC
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...p$?..........." ..0.............B.... ........... ....................... ............`....................................O......................../.......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................$.......H.......x...(9............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X..+....b....aX....X.....2.....cY.....cY....cY..|....(......._..{........+,..{|....3...{{......(....,...{{...*..{}.......-..*...0...........-.r...ps....z.o......-.~....*.~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6246
                                                                                    Entropy (8bit):5.169925801769785
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:4itmxrs1rsy/QZ93OWZ7u2dOrsMrsSC13C3dinCY:4i2rs1rsyilHcPrsMrspdsdWCY
                                                                                    MD5:CD010DA4CF5B82714DBC32F3E05DF760
                                                                                    SHA1:C52F4AE980AF344F6C98DF74AA8117F6A2C7903C
                                                                                    SHA-256:15B8E85F410B23610E424681C010E1B2833C9805F977131713AD6F7DECF3FE90
                                                                                    SHA-512:8AA6FC03C353A83BCAB9E65D30C69B5393F1AC6C0181C0B8E357C85CC3A15C63C57D4FBC8082EB8DD539BC885B5AC2808A294ADC42A541EBDC6B06BAB5357CB1
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a double license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2019 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer... *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions and the following disclaimer in.. * the documentation and/or other materials provided with the.. * distribution... *.. * 3. All advertising materials
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3251
                                                                                    Entropy (8bit):4.82055320948653
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:nAf0rWOC0pAvwIHg28vx22nK5cHGg8czKVSpxsNxddItK+4WlA1QIFL:nAyo0pT28vx2iK+HGg8cnnAtpWl2
                                                                                    MD5:54548B258AC71839F1D1BA7A0CA19FB5
                                                                                    SHA1:428202CB596D72333B3852DC1367E8A18C297521
                                                                                    SHA-256:25F242473F5CF6BCDB0192F071EC9E78A6CB4E1E6CB887AD33002BA2EC1EBA6D
                                                                                    SHA-512:FF17E5A6C40976B7881B09B4BBD480423DF27441FB51366F7F4390D2E9A99243FE75FABF2F70F8AC267AC370D34FA1391398E98EAEC003FB00820FA438366A5B
                                                                                    Malicious:false
                                                                                    Preview:.. OpenSSL 1.1.1h 22 Sep 2020.... Copyright (c) 1998-2020 The OpenSSL Project.. Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson.. All rights reserved..... DESCRIPTION.. -----------.... The OpenSSL Project is a collaborative effort to develop a robust,.. commercial-grade, fully featured, and Open Source toolkit implementing the.. Transport Layer Security (TLS) protocols (including SSLv3) as well as a.. full-strength general purpose cryptographic library..... OpenSSL is descended from the SSLeay library developed by Eric A. Young.. and Tim J. Hudson. The OpenSSL toolkit is licensed under a dual-license (the.. OpenSSL license plus the SSLeay license), which means that you are free to.. get and use it for commercial and non-commercial purposes as long as you.. fulfill the conditions of both licenses..... OVERVIEW.. --------.... The OpenSSL toolkit includes:.... libssl (with platform specific naming):.. Provides the client and server-side implementations for SSLv3 and TLS..... lib
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2419320
                                                                                    Entropy (8bit):6.634464050699479
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:HKJtezQ9MBR+qYP6dpF3KYyRm1h1dqQyadLONZUFIJEgf4PiixK7oq/N//id/Xp6:weKoAPuL3KYyRm1h1dqladLONZUFIJEA
                                                                                    MD5:5E7C712BA09DB83021F48DC4D9FFEF6F
                                                                                    SHA1:DE5398106F724236866D228B1C2896D6D2936868
                                                                                    SHA-256:D86EF526F0092A95F0A2F3A16D9E183403DB3E910B4E396DA36AA43F28B7AB91
                                                                                    SHA-512:B3F4BC1921AB8C8BE858BEA24945605B3B84C0CC0874ADAE5E8A36829F940D7225CA9F4A0A85A36CD9144A1E7EE41B90047B805E4D988E0639B61F9368BDBD50
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#......$..B........... ....@k.........................p%.......%...@... ......................@".Y....@$.......$...............$.x.....$.x.............................!.....................$C$..............................text...8...........................`..`.data........ ....... ..............@.`..rdata......0.......0..............@.`@.bss.....A....!.......................`..edata..Y....@".......!.............@.0@.idata.......@$.......#.............@.0..CRT....,....`$.......#.............@.0..tls.........p$.......#.............@.0..rsrc.........$.......#.............@.0..reloc..x.....$.......#.............@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):689272
                                                                                    Entropy (8bit):6.414399173082945
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:J0HnHbJM/BqUu+Agrp2a1Rvj6Xiww6RIR7Q491DfU0:J0HnHbJM/BqT+rp2a1Rr6Xiw1R87Q49h
                                                                                    MD5:01AE7F7D23BCD591E058B987AFB0A163
                                                                                    SHA1:38474D773CB05BF18FE40DB270E7EEE45B2552E7
                                                                                    SHA-256:B2F449BC5F448287271C7F27E773B4FECF644553EC60B21DA0E5A6655F3AD20D
                                                                                    SHA-512:C830B7FDB3A92AE3D6138FA3A4B75FCC17CD7B018450E0E80747C27ACF43A7A5D2184A780E0B0204E3244F4DF25B9B8471E85F38FCA6B9700F9F5E7C3207DA2F
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...............#.`...r..."...........p....@.......................................@... .........................N...........p...............v..x.......@~..........................$6......................X................................text...._.......`..................`.P`.data....e...p...f...d..............@.`..rdata...g.......h..................@.`@.bss....T ...P........................`..edata..N............2..............@.0@.idata..............4..............@.0..CRT....4....P......................@.0..tls.........`......................@.0..rsrc........p......................@.0..reloc..@~..........................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3251
                                                                                    Entropy (8bit):4.82055320948653
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:nAf0rWOC0pAvwIHg28vx22nK5cHGg8czKVSpxsNxddItK+4WlA1QIFL:nAyo0pT28vx2iK+HGg8cnnAtpWl2
                                                                                    MD5:54548B258AC71839F1D1BA7A0CA19FB5
                                                                                    SHA1:428202CB596D72333B3852DC1367E8A18C297521
                                                                                    SHA-256:25F242473F5CF6BCDB0192F071EC9E78A6CB4E1E6CB887AD33002BA2EC1EBA6D
                                                                                    SHA-512:FF17E5A6C40976B7881B09B4BBD480423DF27441FB51366F7F4390D2E9A99243FE75FABF2F70F8AC267AC370D34FA1391398E98EAEC003FB00820FA438366A5B
                                                                                    Malicious:false
                                                                                    Preview:.. OpenSSL 1.1.1h 22 Sep 2020.... Copyright (c) 1998-2020 The OpenSSL Project.. Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson.. All rights reserved..... DESCRIPTION.. -----------.... The OpenSSL Project is a collaborative effort to develop a robust,.. commercial-grade, fully featured, and Open Source toolkit implementing the.. Transport Layer Security (TLS) protocols (including SSLv3) as well as a.. full-strength general purpose cryptographic library..... OpenSSL is descended from the SSLeay library developed by Eric A. Young.. and Tim J. Hudson. The OpenSSL toolkit is licensed under a dual-license (the.. OpenSSL license plus the SSLeay license), which means that you are free to.. get and use it for commercial and non-commercial purposes as long as you.. fulfill the conditions of both licenses..... OVERVIEW.. --------.... The OpenSSL toolkit includes:.... libssl (with platform specific naming):.. Provides the client and server-side implementations for SSLv3 and TLS..... lib
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6246
                                                                                    Entropy (8bit):5.169925801769785
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:4itmxrs1rsy/QZ93OWZ7u2dOrsMrsSC13C3dinCY:4i2rs1rsyilHcPrsMrspdsdWCY
                                                                                    MD5:CD010DA4CF5B82714DBC32F3E05DF760
                                                                                    SHA1:C52F4AE980AF344F6C98DF74AA8117F6A2C7903C
                                                                                    SHA-256:15B8E85F410B23610E424681C010E1B2833C9805F977131713AD6F7DECF3FE90
                                                                                    SHA-512:8AA6FC03C353A83BCAB9E65D30C69B5393F1AC6C0181C0B8E357C85CC3A15C63C57D4FBC8082EB8DD539BC885B5AC2808A294ADC42A541EBDC6B06BAB5357CB1
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a double license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2019 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer... *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions and the following disclaimer in.. * the documentation and/or other materials provided with the.. * distribution... *.. * 3. All advertising materials
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):1826
                                                                                    Entropy (8bit):4.899761808548488
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQL3GkhUtDl5/QpkwNFMRR0/KbgtTU3AqxvZTdfb:50tiD3Wl4kwNFMH0/OgtTuFXz
                                                                                    MD5:4C61442851631947B8E5A11372B882C8
                                                                                    SHA1:0C1BF1444A5AB40F89EBB7C8A67D36A7F4DAD6BB
                                                                                    SHA-256:71D777064B33AD0E385513B0AED25477B40B18FDA2E28B7D79883A7FA6B4CDC1
                                                                                    SHA-512:46C0036D511FF727A6345E5D4128EB8B4D631C4DD18DEA2D0A03BE4121697FB8D3AB4B4536944D4F653091898B9C6F82F62C2ED1A6A954FD11273654CB08C47E
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825..[ ca_policy ].countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.commonName = supplied.emailAddress = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_distinguished_name ].countryName...= Nom du pays (code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):513656
                                                                                    Entropy (8bit):6.172388711561625
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:cDyeZzW7DBllO13YGZ1NBbzlRxgMd5hXgeHqQilbSu1UYaoq42:cDyeZzW7DBllO13YGrNxzlRxgK5hQeHN
                                                                                    MD5:7153055A99046DAA1230D9D67DA74927
                                                                                    SHA1:1FF082EC15238E50A776B76A3B8B2B12C3D38694
                                                                                    SHA-256:856F9E94D4B91CECFA9970CF3C80F4E383C6005A2BCD3141AE0DEDEF08C4905A
                                                                                    SHA-512:E89201AF0AB6A9722A45AEB5553AD55467515A3884624FE5E0CB87EC5AA125CDEB35DEBFE75447F6DB7534B16261A533F2BCFA3CFF3B021CB6E25EDA9C1DB714
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#...........................j.........................0.......7....@... ......................0..3@.......>......................x........?...................................................................................text...$...........................`.P`.data...D,..........................@.`..rdata..X...........................@.`@.bss....P.... ........................`..edata..3@...0...B..................@.0@.idata...>.......@...@..............@.0..CRT....,...........................@.0..tls................................@.0..rsrc...............................@.0..reloc...?.......@..................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):2225
                                                                                    Entropy (8bit):4.915897180346394
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQzLM3GkJtDl5/QDL3AqWkwNFMRR0/KbgtTRfhBYftRl7Zw1:50ti7Q3VlqTGkwNFMH0/OgtTRMPl7w
                                                                                    MD5:6B5E01439440855F115B20FF421BCE72
                                                                                    SHA1:A352BD13D8EE4E83CA0CDBCE99985A10157334B3
                                                                                    SHA-256:D0612B570F81C3C2D76E8DDA92FE6508D7C01A41852ADA1222AC5A6FDAC9C10F
                                                                                    SHA-512:A5ABFAA427F543331AFDA8A22C0BB8DC6D3F021E5A3E784EAAD3B1E19E94DDB06ABE83377DC834D3A08E8C1E87535F44085C60FA999F179AF6F469A3F97B9FD1
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825.crl_extensions = crl_ext..[ ca_policy ].commonName = supplied.countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.emailAddress = optional.serialNumber = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_disti
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2419320
                                                                                    Entropy (8bit):6.634464050699479
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:HKJtezQ9MBR+qYP6dpF3KYyRm1h1dqQyadLONZUFIJEgf4PiixK7oq/N//id/Xp6:weKoAPuL3KYyRm1h1dqladLONZUFIJEA
                                                                                    MD5:5E7C712BA09DB83021F48DC4D9FFEF6F
                                                                                    SHA1:DE5398106F724236866D228B1C2896D6D2936868
                                                                                    SHA-256:D86EF526F0092A95F0A2F3A16D9E183403DB3E910B4E396DA36AA43F28B7AB91
                                                                                    SHA-512:B3F4BC1921AB8C8BE858BEA24945605B3B84C0CC0874ADAE5E8A36829F940D7225CA9F4A0A85A36CD9144A1E7EE41B90047B805E4D988E0639B61F9368BDBD50
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#......$..B........... ....@k.........................p%.......%...@... ......................@".Y....@$.......$...............$.x.....$.x.............................!.....................$C$..............................text...8...........................`..`.data........ ....... ..............@.`..rdata......0.......0..............@.`@.bss.....A....!.......................`..edata..Y....@".......!.............@.0@.idata.......@$.......#.............@.0..CRT....,....`$.......#.............@.0..tls.........p$.......#.............@.0..rsrc.........$.......#.............@.0..reloc..x.....$.......#.............@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):513656
                                                                                    Entropy (8bit):6.172388711561625
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:cDyeZzW7DBllO13YGZ1NBbzlRxgMd5hXgeHqQilbSu1UYaoq42:cDyeZzW7DBllO13YGrNxzlRxgK5hQeHN
                                                                                    MD5:7153055A99046DAA1230D9D67DA74927
                                                                                    SHA1:1FF082EC15238E50A776B76A3B8B2B12C3D38694
                                                                                    SHA-256:856F9E94D4B91CECFA9970CF3C80F4E383C6005A2BCD3141AE0DEDEF08C4905A
                                                                                    SHA-512:E89201AF0AB6A9722A45AEB5553AD55467515A3884624FE5E0CB87EC5AA125CDEB35DEBFE75447F6DB7534B16261A533F2BCFA3CFF3B021CB6E25EDA9C1DB714
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#...........................j.........................0.......7....@... ......................0..3@.......>......................x........?...................................................................................text...$...........................`.P`.data...D,..........................@.`..rdata..X...........................@.`@.bss....P.... ........................`..edata..3@...0...B..................@.0@.idata...>.......@...@..............@.0..CRT....,...........................@.0..tls................................@.0..rsrc...............................@.0..reloc...?.......@..................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):2225
                                                                                    Entropy (8bit):4.915897180346394
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQzLM3GkJtDl5/QDL3AqWkwNFMRR0/KbgtTRfhBYftRl7Zw1:50ti7Q3VlqTGkwNFMH0/OgtTRMPl7w
                                                                                    MD5:6B5E01439440855F115B20FF421BCE72
                                                                                    SHA1:A352BD13D8EE4E83CA0CDBCE99985A10157334B3
                                                                                    SHA-256:D0612B570F81C3C2D76E8DDA92FE6508D7C01A41852ADA1222AC5A6FDAC9C10F
                                                                                    SHA-512:A5ABFAA427F543331AFDA8A22C0BB8DC6D3F021E5A3E784EAAD3B1E19E94DDB06ABE83377DC834D3A08E8C1E87535F44085C60FA999F179AF6F469A3F97B9FD1
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825.crl_extensions = crl_ext..[ ca_policy ].commonName = supplied.countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.emailAddress = optional.serialNumber = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_disti
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):1826
                                                                                    Entropy (8bit):4.899761808548488
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQL3GkhUtDl5/QpkwNFMRR0/KbgtTU3AqxvZTdfb:50tiD3Wl4kwNFMH0/OgtTuFXz
                                                                                    MD5:4C61442851631947B8E5A11372B882C8
                                                                                    SHA1:0C1BF1444A5AB40F89EBB7C8A67D36A7F4DAD6BB
                                                                                    SHA-256:71D777064B33AD0E385513B0AED25477B40B18FDA2E28B7D79883A7FA6B4CDC1
                                                                                    SHA-512:46C0036D511FF727A6345E5D4128EB8B4D631C4DD18DEA2D0A03BE4121697FB8D3AB4B4536944D4F653091898B9C6F82F62C2ED1A6A954FD11273654CB08C47E
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825..[ ca_policy ].countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.commonName = supplied.emailAddress = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_distinguished_name ].countryName...= Nom du pays (code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):689272
                                                                                    Entropy (8bit):6.414399173082945
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:J0HnHbJM/BqUu+Agrp2a1Rvj6Xiww6RIR7Q491DfU0:J0HnHbJM/BqT+rp2a1Rr6Xiw1R87Q49h
                                                                                    MD5:01AE7F7D23BCD591E058B987AFB0A163
                                                                                    SHA1:38474D773CB05BF18FE40DB270E7EEE45B2552E7
                                                                                    SHA-256:B2F449BC5F448287271C7F27E773B4FECF644553EC60B21DA0E5A6655F3AD20D
                                                                                    SHA-512:C830B7FDB3A92AE3D6138FA3A4B75FCC17CD7B018450E0E80747C27ACF43A7A5D2184A780E0B0204E3244F4DF25B9B8471E85F38FCA6B9700F9F5E7C3207DA2F
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...............#.`...r..."...........p....@.......................................@... .........................N...........p...............v..x.......@~..........................$6......................X................................text...._.......`..................`.P`.data....e...p...f...d..............@.`..rdata...g.......h..................@.`@.bss....T ...P........................`..edata..N............2..............@.0@.idata..............4..............@.0..CRT....4....P......................@.0..tls.........`......................@.0..rsrc........p......................@.0..reloc..@~..........................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.347287743366354
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:6oN4JUNanMSU/JU7r299nL2kSDtHAvCp3me0PfRnCe8SfVq6X8RRga5Rf7NjNfft:im6ab7exE0
                                                                                    MD5:DFF6850E8B2FA1D6FD14773AD9F6F150
                                                                                    SHA1:EB41A2AE0FD2BCA2D0E4E857D02BDD2245A698AB
                                                                                    SHA-256:B4453E1AB70758E8B08F1F9CC6947A18DB2519075B494C4CD8D6E1E020A68A0E
                                                                                    SHA-512:2743D550CFF83639E2D6ABCD4A1AE4C055C5A8B5FA459EB5ACE005A68CE08D83B31E296DA120ACA04FAD190F60AD0565912FEC64C79233B9414E7BF42EC3AB92
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e.........." ..0..P...........n... ........... ....................................`..................................m..O.................................................................................... ............... ..H............text....N... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B.................m......H........'...............V................................................(........s....}.....~....}....*2.{....o....*"..}....*^.{......{........o....*2.{....o....*2.{....o....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r`..p~....o....*V(....r...p~....o....*V(....rP..p~....o....*V(....r...p~....o....*V(....rI..p~....o....*V(....r...p~....o....*V(....r/..p~....o....*V(....r...p~....o....*V(....r4..p~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14336
                                                                                    Entropy (8bit):4.9314244617466665
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:FzP9VECr49b0mHsP86g8n6ZhMv11wE7uDzfpK2Ft/GjX3:dP9VL208sU6qniwEqjF1qX3
                                                                                    MD5:1F2D54F48C615F086E1CB19DD44FD97C
                                                                                    SHA1:1B97539D5AC39B7C989D8CD5CF8D71D6745287B4
                                                                                    SHA-256:3ED0A4217517B17E1459D649E4C3811865A4838E71508A953D777B2F9E16A4C3
                                                                                    SHA-512:6178AB1ED7D626186E879FDFCCF3833B68B47915D715AE9177DACEFB4B7B53869CBF8D2E8852079E5A8586E8E8DA8CE40D7DB1A4AF4D1A6372741228AAFAEFAA
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............L... ...`....... ....................................`.................................dL..O....`............................................................................... ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................L......H........&..|%...........................................................0..H........o......-..*.o......u!...,...*.u"...,..*.u#...,..*.u$...,..*.u%...,..*.*..{!...*:.(......}!...*b..3..*......3...*.,..*.*~.-.r...pr...p.(.....*.o.......*..-.r9..pr...p.(.....s....*.o.....(....*.0..y.........c1..........*.E............#...A..._.......}...............8.....rc..p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r8..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):42496
                                                                                    Entropy (8bit):5.5460008425063325
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:CETA40NKvv4nPD4l86OZIc+pojjAluxoKoadYDw185InG8RS:+/ZIcgFlJKmw1AI3RS
                                                                                    MD5:1ABEEEB32F3AEF62ADA309A297E3AA33
                                                                                    SHA1:51C5D5953A457AE988D108C3DCC2B592C3F6BA12
                                                                                    SHA-256:F5B5C57DF2ACE9999308E4B95E58ACD9386F80C163599F87711D7DF826DB8215
                                                                                    SHA-512:94395CF514C4B65B613182549045B4B24FABE4D8987E49FB0A11BB6EBB058C50774CF2D566EA83474C0EE56F0B3CF8F03701D1AA6A8436ECA62070AE5A43D8D9
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.................. ........... ....................................`.................................H...O.................................................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................|.......H........T...f............................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. j... )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%q.........-.&.+.......o.....%..{.......%q.........-.&.+.......o.....(....*..(....*...0..C........(....r]..pr...p........(.....(....s....%.o ............s!...}....*..0..........("...o#......~$....rz..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):4.35096535887655
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:HDbZgmWgUGOBlTGYI+eQ6/70dRbSA3oO4OHPbPa:fKQU6/70dRj4O4Oz
                                                                                    MD5:BAF74BAB27F9EF9F3857B4DBBB215FB7
                                                                                    SHA1:2D2068477DD2AD2C1747E08CC0BD2EB6B9E0516D
                                                                                    SHA-256:E851DD88BF9EB69383017E1211B9DD2826F94ACF3FFD345A539228DF52E9492E
                                                                                    SHA-512:20F04A0D5D8F8F8A21E84A5AC266143E151AE84C45172D45C4187A7E4D361295220B0F701FA4FF68EDC3A0097641A7C1E889F7F88A5E36C5208A97881605455F
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............0... ...@....... ....................................`.................................d0..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........ ................................................................{....*"..}....*N..(.....(....(....*>..(......(....*..{....*"..}....*:.(......(....*...BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob...........W..........3..................................................................................................................................!.................t.....U.................<.?.....Y...........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71680
                                                                                    Entropy (8bit):5.601875671857578
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:PEEZIJuG4d/Slr8w4a90F61j1lcl7XhQeQxWrlBOz8sXrygGkh9b9+nxX+CIERBV:PZ3lFQeQ0a3Xryg8xlNuEOkZVz/7odc
                                                                                    MD5:FD8DD506BA3A8ED35E5E2C6FFD39766C
                                                                                    SHA1:65695DF981FB2D78015ED4279AF7D19258F76E5C
                                                                                    SHA-256:A39C597D0F5896A490A7F2A7104EDB85486CDDA2C505940F938CA1E14B3E6DF5
                                                                                    SHA-512:3857ABB429069658227A0881D8FEE1DC192727C8459886E3FDCB8E91633B54E8BF05A45B51334834110031714243562CDDF0E389D46F3E2353B9512E8A75E1ED
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............J-... ...@....... ....................................`..................................,..O....@.......................`.......+..8............................................ ............... ..H............text...P.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................+-......H........O..0.............................................................(....*..(......(......(......(.......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..(......(.....,...(...+(...+(......(....*..(......(.....,...(...+(...+(......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*V.(......(......(....*..{....*"..}....*..{....*"..}....*..(....*V.(......(......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):32256
                                                                                    Entropy (8bit):5.509801431083607
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:Q4+hvEDyN2j1LwCgWX4KxupnIZUCYXUQ4kfiVZBEaacR9mw7LbO6hY:G5EDyN2jxZ4KxPqCYZ0ZcomiLC
                                                                                    MD5:8E6A0501C3193D8CAC1C971DE3FDA562
                                                                                    SHA1:4FE5BB62C445EB6FD49AFBF437DAEA8B4A3C12AE
                                                                                    SHA-256:C7AF158CD6D3E617231224AD713A98228972E23E4C7D524808FB2789D2EF8D64
                                                                                    SHA-512:2973735866D7686A4AF01A2372A5ADE5B39874B9E017C74A21F10FE6ACB37C4961E50FA0CEBC7976DE30060C200B4AD15F4C3BFB858E3F5878E5D61CA2E376D9
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..t............... ........... ....................................`.....................................O.................................................................................... ............... ..H............text...0r... ...t.................. ..`.rsrc................v..............@..@.reloc...............|..............@..B.......................H........>...S............................................................{....*"..}....*....0..1.......s.........+...o.......o......X...o....2....(....*....0..3.......sf......}-.....}......}/......g...s.....{/...(...+*..0............(...+...(....,...(.....+r.o.......d....e."+A.r...p.o.....P...(.....(......+?.r[..p.o.....P...(.....(.......+..r...p.o.....P...(.....(.......*..(....*..{....*"..}....*6.{.....o....*6.{.....o....*6.{.....o2...*..{....*..{....*..{....*..{....*..s...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18944
                                                                                    Entropy (8bit):5.123452606388303
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:y0sI9oCUN+uMVZFZfZ9gNe5nlpW85s2wmQs56TtmOjXis0j7XcyFXcXPXrfX2H0r:xsf+5FCNepkmuTtmOrX/y
                                                                                    MD5:B2690A6C3C2E97FA8A89F1DEF550D53B
                                                                                    SHA1:E2811A4F491D9833C1D7880AE28F7755EF179BD0
                                                                                    SHA-256:8B64B6FF4274103A919C08DADDB8E295772F38582A098E0DA097CAA632A7083E
                                                                                    SHA-512:AECC9ED7F6E57D231A4362346BF38BC094495AA5A1131508466C9DBA34A67A2F83A15CBF420C646A28A52AC444EE4E6B16B8426531CFEE0F773F65934BFF5E0F
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..@...........^... ...`....... ....................................`.................................d^..O....`............................................................................... ............... ..H............text....>... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B.................^......H........'.../...........W..............................................F.-.*.(.....(....*...0...........o@...-........oA....o@....i.1.*.........+ ..s....%..Xo....%r...po.......X...7..o@......+........o..........Y%.......X....i2...oA...*....0...........o>...-........o?....o>....i..1.*..........+ ..sV...%..XoS...%r...poU......X....7..o>......+........oR.........Y%.......X....i2...o?...*.0.......... ....s........,/..,+..i.....(........+..o....&....(......X...2..,>..,:..i...,..o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.509347235200524
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WBX0TqVWFUM3HmOFs8mXXiA+L3Ad8DUntPKeUELxK2Yj7uIt:+ayIWmp2YeU4x5suIt
                                                                                    MD5:3684F924B38D4FB23DE40554ADFB1537
                                                                                    SHA1:E4FB7143ED7DFD2CAD2E379703808CEF429882BF
                                                                                    SHA-256:702444FCDE9AC6550E636A32678493E6835B247D8D8D344E2F803184F9F0EA45
                                                                                    SHA-512:8ACAED49F0204B8BEC8DD92D759F0E7913B447A53D0962FAE290A40EE36A20435EE7508E813EDCBD5A6BA1638385D235C64C1643052EDCA890D218DE3453606C
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..0...........N... ...`....... ....................................`..................................M..O....`............................................................................... ............... ..H............text...$.... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......p$...............A..@...........................................r.(......}......}......}....*....0..T........-..+.(......(.....r...pr'..p...(.....(.....{.....(....-.(....+....{.....{....o....**....(....*..0...........(....-.(....+.....YE............!.../...=...K...Y...g...u.......................................8......(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):5.0948277461097105
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:TVoCUNaG+BIfUngxRU2nhgLrGPAyuqMzDZOikYmPj5nwrf5:CbfkWLZYVz9OHt2f5
                                                                                    MD5:894D75122FC4DFE34BF56484C361612C
                                                                                    SHA1:6FD416A2EDA7881D67E93F88E5081FBB0260E7C7
                                                                                    SHA-256:94AB68CFEE90C1D0D36DA3BD9A4679B490F2347826333F5BFAC57F9903A16992
                                                                                    SHA-512:1E75609E04F40EE523A297E1921AB733E8E9E8CE940373476FB07173339BE1A97ABBCEB19ACCE156DDA292FD5D49B45B86DC93DC1DED66135922A5C097B7498D
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..*...........I... ...`....... ....................................`..................................H..O....`............................................................................... ............... ..H............text....)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B.................H......H........#.. %............................................................{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{ ...*"..} ...*..{!...*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.865639255366771
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:akOKSRVDKCJRCNdLnRWpnipnuncpt2JbJH0qV28xqNK7I2yd1u7qAGxhrGTEZmlR:akONl3eRngpnipnuncpMJbx0qV28xtCa
                                                                                    MD5:8576099B78B5A2B4371F5607C1CC4B56
                                                                                    SHA1:56959AF98B01B360DBBF247F0B01DDE4CE8D5C9E
                                                                                    SHA-256:A3F1B2DF20581CB7D64B008692939AEC45F4D7F6D8037F29F34D58AA14C2BD84
                                                                                    SHA-512:1717169904BB82D28B9B48DA167C960CE417B6F6983380ECD40B32418149B94AED3B6DA97F87FDDF47F887D0BA334F6A1109F750C87D81A0624B3ECFA21A48D5
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e.........." ..0.."...........A... ...`....... ....................................`..................................@..O....`............................................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........"..h...........d<..X............................................0..r.......s......s.......+V..]..E............*...+:.r...p.(....o....&+&.rk..p.(....o....&+..r...p.(....o....&..X...2..o....*...0............o....o.......o....*....0...........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....,.(.........s....*r...ps.....o....o....-.(.........s....*~....*....0..b........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....-.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):17408
                                                                                    Entropy (8bit):5.340203016866838
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:ZuR5umKg7LDcJf/l64+p91nuQiS0Mw+f+Sb+jkyNr1rSeUu:K3X91uQiUje6E
                                                                                    MD5:711BDB4B08A5CA012F0E0042B800C113
                                                                                    SHA1:9FD08016EC0B720A8ADE512FF0A8147299C51719
                                                                                    SHA-256:2B32B674479391074476F65B73523ECB90C38F1E2FBE5CD2F05138CB07430FB3
                                                                                    SHA-512:C31607E1112CD9CE964CF070A0BFC3E892993191BACB53FC1C1DE68609378BE407F3DD5D31706DE7A4C18E58CEDBA32A7A857C9CD028886943571361812D21E6
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..:...........X... ...`....... ....................................`.................................XX..O....`............................................................................... ............... ..H............text....8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B.................X......H.......h"..P............<................................................(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*^.(.......}......;}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......}......}....*..{....*"..}....*..{....*"..}....*..{....*".
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):32256
                                                                                    Entropy (8bit):5.5805424459907345
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VRDROHaea45sA5AJibBCN/46XRWswufCFvF88MAhBK0ePnaSuTpz8/kk0dbXn7iN:VDOHaea5iB3TVvzamB5yqPOxXB
                                                                                    MD5:3630B889474F16781C307E814AA85292
                                                                                    SHA1:E7870ACED20FC325D6FB6E97E586F63909A02092
                                                                                    SHA-256:C8B37479A066F7332F584BE5CB100D4461A4C5399D9BED901EB815830416149A
                                                                                    SHA-512:1D391CDEC2E5DED0FB747A5BCE1D1D8B930B76F2471DA6EED2C694CBCB33AFC8ECD0A1D408B88E3C60289968705E21E2142C54DDDF48C9CAA3DFBCBB55A0D270
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....X..........." ..0..t............... ........... ....................................`.................................1...O...................................P...8............................................ ............... ..H............text....s... ...t.................. ..`.rsrc................v..............@..@.reloc...............|..............@..B................e.......H........2...M............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.s%...%.o ...%~ ...o"...%r...po$...*.s....*..{....*V.(......}......}....*..sW...*..{....*...0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):79872
                                                                                    Entropy (8bit):5.414166396089919
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:7OuYsC7iQ8gtO98NotMSyxNSYxl0uZhctTJIc+mBVD7D3mBnJIc8r:7HQE98NKmX6TmfuD7D3OmH
                                                                                    MD5:8B397B9E6D81D29B38CCF252B22526E5
                                                                                    SHA1:B1CA02779A70C89D0737637B6ECB167CE345DA6E
                                                                                    SHA-256:30007B209C850405F29FC1B67163E5136B54D77923189C0A560C2C133155952B
                                                                                    SHA-512:2256724A91F877F98C7B8A48592F37BB7788B3E791BE6E48045776B655DB32B83C10DEC029E981C90EC707756E7992B2398E7EB4DE1108CAF83E569B59E1F1AB
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....O............" ..0..............M... ...`....... ....................................`.................................xM..O....`...............................L..8............................................ ............... ..H............text....-... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................M......H........\..4...........PG..8.............................................s....}.....(.....#.....@.@s....}.....{...........s....o....*...0..........s.......}.....{....,.*..}...........(......{....~....%-.&~..........s....%.....(...+s....}.......,..(......{...........s....o......}....*.........!.?`......2.{....o ...*J.{....o!....(....*.0..5..............(.....{.....o"...,....{.....o#......,..(.....*...........&*.......0...........o#...~....%-.&~..........s$...%.....(...+,..o/.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):87040
                                                                                    Entropy (8bit):5.4554148178321675
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:nDsxiI7pW/tZrszqJBWDnvSYT3VeArUOXeeu:nJI7pW/tZrseyf3fjXeeu
                                                                                    MD5:EAEDE0361F15C2EB139C7E2FC6C6AB71
                                                                                    SHA1:DBC9F9DC7E158538C0FFDEE9AA536C33868EF693
                                                                                    SHA-256:8C8B835E81010D99B0F240E598D65951D4A50771A4B4D85CB74E513FDF169E36
                                                                                    SHA-512:3575D111C742C8D2B56BBC0EAEF1B3E95CE0AB31100047A8EAFE87E91D063BA4D420D7BB7BBD332EAC34BCE6B8DAFCED7AD7E81CEEA830394805A3F61293F40E
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Vu..........." ..0..J...........h... ........... ....................................`.................................ih..O....................................g..8............................................ ............... ..H............text....H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........V..............X...0I.........................................."..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23552
                                                                                    Entropy (8bit):5.296076848221744
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:J7ZrPZfvaob5PqTMGdAkNh5RgnlrSwH+JzO:fPZfAgPkP52nlrZ+Y
                                                                                    MD5:39EFF900514B54508575FAB39599FB25
                                                                                    SHA1:A5D527AC87B3A8D7D7C7CC2E1BF12E2448067962
                                                                                    SHA-256:392EC5F7DCEF0EFB95C4382637E46537ABDCE389C2499758F564DA16867D99F0
                                                                                    SHA-512:AD370CAF8B2FAAAF9F11176A19357BC6283FB1A6DDD5BC4597472077243053EE1B9273C62D91BB9495CF68898EA2B475B39E468D2B9B713A347ED3679F928628
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..R..........>q... ........... ....................................`..................................p..O.................................................................................... ............... ..H............text...DQ... ...R.................. ..`.rsrc................T..............@..@.reloc...............Z..............@..B................ q......H............A............................................................(....*.0..7........(....r...p...o...../3....o........s........s....}....*..0..;........(....r...p...o...../3....o........s............s....}....*N.{....r1..p..o...+*..0..7........(....ru..p...o...../3....o........s........s....}....*..0..;........(....ru..p...o...../3....o........s............s....}....*N.{....r...p..o...+*..0..7........(....r...p...o...../3....o........s........s....}....*..0..;.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.893431167436209
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:j3L1ossT+tBSTXrIJOGqjTcfeEXs8zfH2yxJi:j3L1MBTXrIJrqLEXTWyTi
                                                                                    MD5:1A15932E3DDA65E9FBCC696A51C891E7
                                                                                    SHA1:DBA73103CB5FB8EE38718E1E000C9E18D82D1204
                                                                                    SHA-256:D8DDB54F93A12DAEE51ED36FC735B56C67C01294E3493FA71B81C4C731E237FF
                                                                                    SHA-512:E4FB92ABB58EFE9534ECAA5A6E3435ED2DEA7CB0C63CBCA4422C1F81921D20857AF050F6F3E51DCD68249E879DF3EA14C9A289BB7A24D92208BE14DE0DA5C821
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text...4 ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........&..T.............................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*J.(.....s....(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.~....*.......*.~....*.......*.~....*.......*....0..7........(....(....(....(....r...p(....(......(....(.....(....*N.(.....(.....(....*..0..L.......s....(....(....(....:....(....(....9.........(....s.....(......s .....s!...%....o"...t....o....o#.....+e..o$.....(......o.....,.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27648
                                                                                    Entropy (8bit):5.660667298583979
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:mxUvyu7KjpBJ+lwRn+MRMg+GZZm6Y98WHh7xfRZDivn2PQhomXu4VPwL:mxUvF2j0lQn+zg++7W1xfRZ22BG0
                                                                                    MD5:7D9CEA1B51F03CC56C1C3540222CA32F
                                                                                    SHA1:F2FC1A279B52B24702AE478C56C37307DC5E2F7C
                                                                                    SHA-256:B7E37C69C521CC0001A76346125B4076599D54167BC7D5CCBE129B23968DCF03
                                                                                    SHA-512:87A9E1395F8296DED9F8869D0DEFB84979465D17362B513FF8B94744FCFCC8DD000D66C75806A85A6318CB9EBA097994993FEFD2D94AACD6EA97FDCD35F2F860
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0..b............... ........... ....................................`.................................D...O.................................................................................... ............... ..H............text....a... ...b.................. ..`.rsrc................d..............@..@.reloc...............j..............@..B................x.......H.......X(...X............................................................{....*"..}....*>..(......(....*>..(......(....*..{....*"..}....*>..(......(....*>..(......(....*..{....*"..}....*..{....*"..}....*Z..(......(&.....((...*Z..(......(&.....((...*..{....*"..}....*>..(......(,...*>..(......(,...*..{....*"..}....*>..(......(0...*>..(......(0...*..{....*"..}....*>..(......(=...*>..(......(=...*..{....*"..}....*>..(......(A...*>..(......(A...*..{....*"..}....*>..(......(E...*>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.514935440551161
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YjuR5/lqHudrQZ+6ouOAG2R4cd6wTmK0GEIy/o6W1A2Tk:PnoeUlRbd6mH1Aq
                                                                                    MD5:BD6803706AA2B094D3E4763867900201
                                                                                    SHA1:DF2FFFA4E269AD792EBF57C231AF07E46F62B3E7
                                                                                    SHA-256:74258BFB810371CFAADC3395151B76352723ABD26FA08561134D3AE411854741
                                                                                    SHA-512:71C416301A18F87440058E8C2856CC71A4FC9EF455AB33100E00488368A418F66423088FD1B8DFBD6E7538A9BED4C46FA6160C57F2AEB3087177228889F843B2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0..............6... ...@....... ....................................`.................................06..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B................d6......H........!..$.............................................................(....*.s....%......r...po....%......r...po....%......r...po....."...*B(....r...po....*J. ....Z. ....ZX.X*.~+...*...+...*...0..2.......(....r?..po...+..(....,.(....o......(.......(....*..BSJB............v4.0.30319......l...t...#~......t...#Strings....T...T...#US.........#GUID.......l...#Blob...........W..........3................0...............-...................................................*.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):187904
                                                                                    Entropy (8bit):5.64211166818044
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:mtqaFU/ky6445SGWPW0s1sIsssx9JmaN5a0KRYq:m4a+/kyvja0
                                                                                    MD5:4D386FCD91A7AD05221D8E6C744F9857
                                                                                    SHA1:91C4571FB654E9ED5AE4E2C714D41B6CAEC5322B
                                                                                    SHA-256:D4554C86F065556C69295D382702CFE5A6FE8B7DD90E9E295DF50484A926E38B
                                                                                    SHA-512:4365EEA6A227C52A01C626B63D7C2F0CB4ED9B462B184ABDF855E8D929179902785B282F60C3A519584BCA0FB6CAAC7FE03AEFD37DC6BF6D5553A11EE3CD3244
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0.............z.... ........... .......................@............`.................................(...O............................ ....................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................\.......H.........................................................................{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0.._........-.r...pra..p.(....*.o....- r...pr...p.o.........(.....(.....{....,..{......o......(.....(....*~r...pr1..p.(......(......(....*br5..pr1..p.(......(....*.0..........(....r...po....,"(....r...po....,.(....r...p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):49152
                                                                                    Entropy (8bit):5.480020840457158
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:7q8U/PCFUeQ8QRoGuUHMUfUCFCMUTUv4Y40kZUfUURUOodJ4uZtRc/NjSVNG6Tvv:I8K5CUodDZPokVNppllGRTS
                                                                                    MD5:79EBB46AB8A5C3B161ED49FC14608257
                                                                                    SHA1:A1C5908F0872C2A2746D9FFA8E70564A1A04AC73
                                                                                    SHA-256:C0C98B750914CC930AE576861DCC35BEFFCCBA42D899685C1E2DFE94D5854B67
                                                                                    SHA-512:D639A58C2658F4CA51DE2E01CB73312CC414C2B77986E89D0593CA5E2ADD34343BE69D1D197A469F66FFEA366B13E87CB55B78DAD12C4D829733D887F36C4B7A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............N.... ........... ....................... ............`.....................................O.................................................................................... ............... ..H............text...T.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B................0.......H........K..,.............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..(......(......(............s...........s....s....}....*..-.r...pra..p.(....*.{.....o......(.....(....*~r...pr...p.(......(......(....*br...pr...p.(......(....*..(....*.0..;.........Y...%.r...p.%.r...p.%.r...p..s....%.o......(.....(....o......H..r2..p..(......(.........s....(...........r2..p..(......s....(.........(...+,..r2..p(...+.....s....(..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):30720
                                                                                    Entropy (8bit):5.487658724802801
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:RrQiGJJgNIuhP8h1Oz0pQL8HCrR4ZOSrRTyEuu6eAEdBddFM:lBGJEc1OztL2C4NBpk
                                                                                    MD5:EAAB4BF6F12E7C8CE83079125D46D1CF
                                                                                    SHA1:A66EA182E9315289A6D73D2B7882642486B04261
                                                                                    SHA-256:B5A14083B406290E5E1FB1C7C209B24C13933B96F797CFF3BCD7118B0EBA2126
                                                                                    SHA-512:830C0A1A7930A8AC1C13461726988C5AB59AF3DB5A0E2401BF0DAF92CFC2ED85D941C0979304DA17F3D3A0D2BF5465BAE565C63B6049C0033F4A987F47A96328
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0..n............... ........... ....................................`.................................P...O.................................................................................... ............... ..H............text....m... ...n.................. ..`.rsrc................p..............@..@.reloc...............v..............@..B........................H.......,=..$P............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*.(....r...po....,...(....(....*r!..pr...p.(....*...0..J.......s....%.o....o......(.....(....o......H..r...p..(......(.........s....(...........r...p..(......s....(..........(...+,..r...p(...+.....s....(....*.o......-.r...pr[..p.(....*(....r...po....-.r...pr...pr...p( ....(....*(....r...po...+..-.r...prG..p.(....*s"..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):43008
                                                                                    Entropy (8bit):5.5092202549262455
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:6aw3APZKsp8Us47hcl2WY65cpTS41404TrgwvIcW414Q4I:6a22ZKk7oLbIcB
                                                                                    MD5:80C441CC31210C4C6843EA5FD05316C0
                                                                                    SHA1:CA4799AA1E55DD995F6C0070944A6E74E026DB5B
                                                                                    SHA-256:BBBBC9FD5A8B674A0985A3FBD73C3F86EA43020EE227D2F730F901407D837018
                                                                                    SHA-512:7C7CAC148A9189CA43780351CB3205BD7ACFCB5AA7C6E6C77AC79BB91AF80C407DFC39AF797C7291C9268DEC4989C1C4FC979B0D9FC056300839A8FA08C04500
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0.............&.... ........... ....................................`....................................O.................................................................................... ............... ..H............text...T.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........B..@y............................................................{....*"..}....*..{....*"..}....*...0...........(......(......(......(......(,.....(......(......(!.....(............s...........s....s....}............s...........s....s....}........&...s.......'...s....s....}........1...s.......2...s....s....}....*..0..3.......sd......}3.....}4.....}5......e...s.....{5...(...+*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..-.r...pru..p.(!...*.{.....o"....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):16896
                                                                                    Entropy (8bit):5.272173882144138
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:HGL26y5LNCzgMxHtY7LfP/vzL1D7dvWkI9F9iJBvs:HdbNNCsMJKHzLXvWkciPvs
                                                                                    MD5:41E6678FDFD8CC38B8946AF5EA334C00
                                                                                    SHA1:9E1846138BAA23BE3FE68BBA52583D4C07DE18E8
                                                                                    SHA-256:8BD7A4AA6EDCD88A13D2582E22A4C5595DBA764CA61C739D2D0269F03D80989A
                                                                                    SHA-512:68433F4AAB72547F7FBDE21EB55B908CC258EE11611EB4210866B86FF1F7F87687FC77CF9CBEEE159F35B38996BD94A40B5D2B153D5C15C8E574387C45B4E9C9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..8..........vW... ...`....... ....................................`.................................$W..O....`............................................................................... ............... ..H............text...|7... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B................XW......H.......L(..............................................................6.(.....o....*..(....*..{....*"..}....*..(....(....,.(....o....(....(.....s....(....*..(.....(.....(.....(......(...........s....s....o....*.0..........r...prS..p.(....+[( .....(!...o"...,..(!...o#....($...o%...,..($...o&....('...o(...,..('...o)......(*...(+....(,...,.(....,.(....o....r...pr...p.(....*..0..r.......r...pr...p.(.....(-...o....8%...( .....(/...o0...,..(/...o1....(-...o2...,..(-...o3....(4...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):21504
                                                                                    Entropy (8bit):5.2523419066901695
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:wVUPc2OSIHAh+iiEMWSgn+pkZ4xRV+ralP8Xbws:YUCHAh+PRmoP0
                                                                                    MD5:8E7AC891272DC243C274EA9E451B34EE
                                                                                    SHA1:F38DAC6C573F8C1825A6CEC7C49E18D33991378E
                                                                                    SHA-256:C763B7E3B8CFE8475E23D3DF25FF6714EC604B577593CAB2530C985A11E53A28
                                                                                    SHA-512:1BE234DB923F1CEC88D4A267C3968220493C989CD7927AC8ABF2E753F348E7F91F8FB1AF4245B120C9551ACAE59383CE1C76BEDC560BD879A643280739F5FF00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..J..........2h... ........... ....................................`..................................g..O.................................................................................... ............... ..H............text...8H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........+...<............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..~........-.r...prm..p.(....*.o....->.o....-.r...pr...p.(....*r...pr...p.o....o.........(.....(.....{....,..{......o......(......(....*~r?..pr...p.(......(......(....*br...pr...p.(......(....*..0..J.......(....r...po.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.357923587403832
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:RjVpfnzRJQH1NEiNJ0yIac6kWXrBD414UNZ414+WM:DtnzRK/EiE2V5N4140414S
                                                                                    MD5:76FABC663514D1A59D7179A5302A4B7B
                                                                                    SHA1:B040C021F3F4F33F38CD55EC2CEBA83E2BF9D416
                                                                                    SHA-256:97ED2B5838BD07AB63DB59081E5686AF7355994B3A48F5418358CD6B5A71F9C7
                                                                                    SHA-512:DAB153D0F6449437D32026CAE16DEC80C5E691DF488B25DC0B0D68600EC2A1A913F9D07564CF2F03D8D7813A9E27DB339B3649E634F347BF1AD621D4485AA611
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..P..........fn... ........... ....................................`..................................n..O.................................................................................... ............... ..H............text...lN... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B................Hn......H........,..DA............................................................{....*"..}....*..(......(......(............s...........s....s....}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..-.r...pru..p.(....*.{.....o......(.....(....*.0..........r...prJ..p.(.....-.r...prN..p.(....*.o....-.r...pr...p.(....*.s....(.....o.....+...(......(.....o......(....-...........o.......(......(....*.........O.!p......br...prJ..p.(......(....*....0..........(....rM..po ...-
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):21504
                                                                                    Entropy (8bit):5.3805904454188225
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:TlGvUdvdFxVXl825RaL7+nNcnvY7OazcIZJZaGlMOrXYnpvg:0vY/xV18YMf+c4PzhaGlMkXYpI
                                                                                    MD5:35062F3A377A0DF03E3C2D5643341518
                                                                                    SHA1:545C2835538A0FA84B9F905224F2AFC5033B16C0
                                                                                    SHA-256:7F2C26BE3F655B23C0A74ED2E2C1859B1CB77F3B9AE8FAA08E1FB1934DFDA5D5
                                                                                    SHA-512:60EEA1F6ED2B05E1189DF010F3C7FF61154E816281B57EAFD0E39B429188B213272CB68E3D535D9CD8AF738B6B7BA2CB2514CADF15BFD9980B5EECBD7703DDEB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..J...........h... ........... ....................................`..................................h..O.................................................................................... ............... ..H............text....I... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H.......p(..8@............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*....0...............(.....(.........(........ ...%.r...p.%...%.r...p.%..(.....%.r-..p.%..(.....%.rA..p.%..(.....%.rU..p.%...(.......(.....%..rq..p.%....(.....(.......(.....%..r...p.%....(.....(.......(.....%..r...p.%....(.....(.......(.....(....*..._...*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*".
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8192
                                                                                    Entropy (8bit):4.686310790005849
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:lKrvY5r86vkbfsPnZBlkeakXNvDQGYar8lgPoqIe9xF9xpHneTQDU:Yrw9KsPZBlQkXNFYK8CPo49BbHeTQD
                                                                                    MD5:E333CB2180A294D8B0B820FD307ED582
                                                                                    SHA1:D38D57248847E23C474A86B2448E15EB1FF0C71B
                                                                                    SHA-256:566919740B196E00049AA6826805F9E40F8A7E7AEF27A17CDD8BE9F5C9EF2B87
                                                                                    SHA-512:ACEE7E93C97B7A1C54A998BCDF13086FBC4616CA0A7EE522B1336E04D0EF1A3858F1E6B60DBAE93E6C41347031817557844E10D5FE5DC9C8AB535D431FF499E6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0.............R5... ...@....... ....................................`..................................5..O....@.......................`....................................................... ............... ..H............text...X.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................45......H........!..T.............................................................{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*BSJB............v4.0.30319......l.......#~..........#Strings
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6656
                                                                                    Entropy (8bit):4.505709054960742
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Fap+7OssnvRymQuQedb0sWFNFbiphORQ9FTegrDv:r7sMsyZFmpsRQ9F6grD
                                                                                    MD5:34A60A6A68B81056A0E6C61DB469166B
                                                                                    SHA1:0CEFC433427FE075FF69CBD5152FD04DEF521E31
                                                                                    SHA-256:91FD46A63FFAF1E09F25E919E620EE4F282CC15939FA3AE8859F2705D42F250B
                                                                                    SHA-512:845935EF25A5B8AB7A5002EFAF2C7E47EA2F396152933F24239988CF8EAF85B46FC5274CE254A42368C5AF156B6272F7DC87B9FE820060018662F16BC80E6B01
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0............../... ...@....... ....................................`................................../..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................./......H.......$!..`.............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*BSJB............v4.0.30319......l.......#~..H.......#Strings....d.......#US.h.......#GUID...x.......#Blob...........W..........3................................2...................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.068586044047949
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6q+lyNQslz1XmemhRzS9a3OSuHMRLElgvdMDfhLtJrjRq5qFu3nR7PPWguGkRWgW:Eyj/SAaebsmlg6Jpxef8Do
                                                                                    MD5:70C073A948BC973B1171218D085E9CC7
                                                                                    SHA1:1711231084690BCDEC24AFF68850845EE400ED94
                                                                                    SHA-256:7C45748F60320FA22A01A70336C80CCDB4EDBA9940B4647C68A6F96B51DAB676
                                                                                    SHA-512:F9B2650E49BD04BEA4A494B310A09FAA5BC09426E6C8A572A53B986682EFB735496549847F6802930ACE6C2541FD918A3A292EF8C3E89F2752A68F9B40968F51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..............)... ...@....... ....................................`.................................`)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ................................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.BSJB............v4.0.30319......l.......#~.. .......#Strings............#US.........#GUID...(.......#Blob...........W..........3......................................................................y...~.y...b.G.........e.....1.....J...........@.......................v.Z...2.Z.................y.........................M...A.........#.....&.....).
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.967993823220595
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:vnskGvPbslkoobHmpTUiiwZk1Llywb2HezdtJazF7NtDS:vqvMa7m+YZqLlyiCS
                                                                                    MD5:F927988E1BC92A9FD9A9A9FC280359A9
                                                                                    SHA1:91061B23ADFB6BD850527C3CD9CB404AEFBE947C
                                                                                    SHA-256:95CFC1492297ADDB93C4A5321C8203B21739B6765DF5C515196B3BCB6D487AB8
                                                                                    SHA-512:87B8123FE9F71C9148C687F030D5C7D336BB493142507C7D4251CF721B258B54BCC3028D869DD9A96AD7587108B67D39C0FD98EC0C59468BDEE80C172B6FAE06
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..0...........N... ...`....... ....................................`..................................N..O....`............................................................................... ............... ..H............text........ ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......L"...$..........,G..`.............................................(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rJ..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r>..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rB..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rR..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):78848
                                                                                    Entropy (8bit):5.940078992456604
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:RyP1jNOd3IEdih9JyPptMaHWKOZmR2obefWXT3eDFkpFL0w13MDzOfa0BUKTifB+:RyvGZUAaQQmR2k2KpFL0w13Iz5xkWQ
                                                                                    MD5:38F6FC962A2EC0F82CC82B92A7E1505F
                                                                                    SHA1:4A9954206350CC37F1C4C4C87EC2A1DB960C6B7D
                                                                                    SHA-256:665F15A83B027DA51C5071B81FF787BB6CDC89A7DC35E744F61326E55B12882C
                                                                                    SHA-512:373D5466C3CC9BD7DE2AD1AC269ACACD24709865688A8A44C0640E2A34341ED7F54C3A30F4403CBE497442C102D4EC5F97590A2D3AB9F6A3912A79CF2044F9D9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..*..........>H... ...`....... ....................................`..................................G..O....`............................................................................... ............... ..H............text...D(... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................ H......H.......\5................................................................{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27136
                                                                                    Entropy (8bit):5.62370208146286
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:QWacd6CBYTN80lL1Wgh1v9OkEO05YzBElfhpfpx02Vb0Q7RB7lenx+CghxXZ1:QAd6C2nt1Ey2hpxx9xFX7
                                                                                    MD5:A93A19288FB79D9B782E03901ADE875F
                                                                                    SHA1:9CE82E8B91922CE5E9FC03138DA7F77A1219AAFB
                                                                                    SHA-256:496863F170A41A8DD6712EF2A4D88B9253B96D253B6A5F47B745E3BE41D16D5D
                                                                                    SHA-512:5A833B569EEF73531038A9ADB4825966FA16ADECD325AA85A44DF86F526F96ED5C7EAEF334279CF0E3A8CBEA3309786013AB9561D874706C95BFA17282EF599C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...TH............" ..0..`............... ........... ....................................`.....................................O....................................~..8............................................ ............... ..H............text...._... ...`.................. ..`.rsrc................b..............@..@.reloc...............h..............@..B........................H........,...A...........n..(..........................................."..}....*..{....*Fr...pr?..p.(....*..(....*..0..e........(......}......}.......}.......rm..pr...pr...pr...pr...pr%..ps.....~....s....}.......s#...s....}....*....0..........s.......}....rC..prw..p.(.....s....}.....{.....s....%r...p(...+o ...%.o!...%r...p(...+o"...%r...p(...+o#...%r...p(...+o$...o.....{....o.....(......{....o%...}.....{.....{........o&....{.....{....o.....{....o'.....{....o(....../...s)...o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7680
                                                                                    Entropy (8bit):4.609043127953718
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:4x/lg1lEFiC83HY+z63w6n9HdDBFeK9R303inq6ncYZCl6lSWn:4Dg1sovz6AiDYKTDnbchMlSW
                                                                                    MD5:56E7B6DDF9FA1BB2363D5813120674A4
                                                                                    SHA1:92745E5EE779EEC4C4E2021FFA59E3FFF6242DC7
                                                                                    SHA-256:816C7FA679B7B5E529FA8274ABBC75FD56E73C1244B79EA90B552F31AC6C219D
                                                                                    SHA-512:A315110A1CB434914B37373DEB36D669EE1CF3A9B6269927F8C2D49AD2C1991560748D64F63DC1F1E2F9ED5BC01EE621EDCDC1F851F942FFB734129695173996
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............~3... ...@....... ....................................`.................................,3..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`3......H....... !..............................................................~r...p(....r...p(....(.........*.0..T........(.......}.......}.......}.......}.......}......}......}.......}.......}......}....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*BSJB............v4.0.30319......l.......#~..L...D...#Strings............#US.........#GUID.......X...#Blob...........W..........3..................................................................A.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):6.240327973349802
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrpCNNFMAxMOzchOCKePlLTK1LDq8NGl35uDZzysgL9qYIl4v0v:b/iAWYsOCKePlvK1CL3OYPLQYIllv
                                                                                    MD5:5C20E161C0B81DA188BAA9F109CD08C2
                                                                                    SHA1:1720030BC13999DAA12153073A2740C6742DA6E1
                                                                                    SHA-256:F0F9FB8BDD503F64ECE5E2286A1528044F2F2B85D288504E1ED28F07E610CF96
                                                                                    SHA-512:089F263F9DED8B635E8AD72D96286D5630309912C55597A850A4EE8CEEC876DFB61FA1C0996BA37107ED8619D8B0FA76A1CF8104C6EF01768F80CCFECE6844E0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........."...0..Z..........ny... ........@.. .......................@............`..................................y..O............................ ....................................................... ............... ..H............text...tY... ...Z.................. ..`.rsrc................\..............@..@.reloc....... ......................@..B................Py......H........(...8...........a..P...........................................F.(....r...p(....*...0..........sH....(...........s....o............s....( ....(!...}.....{....o"...(#......i.1;....I...s$...(...+o&.....(....,....(....&.(....&('...o(...*()...(*...o+...()...(,...o-...s....o......(/...*..0...........o0.....(1...&..o2.....(....*....0...........o3...u......(1...&..(....*..0..H.......s+...%(C...(...+(5...o-...%(B...(...+(5...o/...%.o3...s"...(6...&.(7...*.0..$........{....,.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2918
                                                                                    Entropy (8bit):5.175878718806986
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:3C2zyqG+qOs+qW+qJlZVxY3UXYzHXTYzH5wC7h+qm4gZ727RgdOgX8g51gXFro:4n+//+wHxY3HzszZwe46ro
                                                                                    MD5:61CD0483AC419DC130EF626C11A2BECB
                                                                                    SHA1:C314A5E97CA58E0378D3314FB68AC4EA614B1738
                                                                                    SHA-256:B7BE7495FD719A4F25D61EA6326126687845B91A0966C36D3218171F4D2D83DE
                                                                                    SHA-512:A073688A35B50C96F2F1D3043BA4CDC426EF3C06EAADF752D3BB29FAD8FC4E35CE2A4F2B60CB19C868A0BF680B9C907A9B7F457F8758D35EBB83478860A99167
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>....<configuration>.. <configSections>.. <section name="loggingConfiguration" type="Microsoft.Practices.EnterpriseLibrary.Logging.Configuration.LoggingSettings, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" requirePermission="true" />.. <section name="exceptionHandling" type="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Configuration.ExceptionHandlingSettings, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" />.. <section name="environment" type="Sofrel.Uranus.Framework.Environment.Configuration.EnvironmentSettings, SUFEnvironment" />.. <section name="Visualization" type="System.Configuration.DictionarySectionHandler, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" />.. <section name="Communication" type="System.Configuration.DictionarySectionHandler,
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):56832
                                                                                    Entropy (8bit):5.690835792827563
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:DkXuiukTFT3hvhZUq5UkA33mSIZ0lt+DDNXspw9IwL+P:DQu1kTFlhmq6kAnSKlt+nVuwGvP
                                                                                    MD5:BBA60FC073D9CBF5CB5658BC4DCD8A3F
                                                                                    SHA1:9CFBD36334B9404B3E7E8042C4F15B7F01391441
                                                                                    SHA-256:133B772B48EADF9F2FA51296A508EE0BC7B71CAB84C699F23B10B8B55F310550
                                                                                    SHA-512:CCF5DE9F317B734AF85D34FB3BD264DAEF1C326CDCEEBE6569590473F68914EF333631D15628021474494BA07F8A40EE20DB46F1C6C0F8C9D63E0295BAF36027
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............n.... ........... .......................@............`.....................................O.......p.................... ....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...p...........................@..@.reloc....... ......................@..B................P.......H........A...x..........t....8............................................{....*"..}....*..{....*"..}....*..(!...*..{....*"..}....*..0........................("...o#...(....*...0......................(....*...0...........(!...r...pr7..p.($......}.......}.......}.....{......o%.....}......s#...}.....{......s&...%r...p.(U...s'...o(...o'....s ...}.....{.....{....o).....s3...}............s....}......o).....{....o).........sg...}....*f.{.....{....o(...._o9...*.*..(....*..{.....{...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4170752
                                                                                    Entropy (8bit):6.81456353807605
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:psmQ1qsmn1285Ar5l53yTOrYC0r5h3CkicAiDQs2cAfDhx:s1e1/5O5QscA3bcAFx
                                                                                    MD5:88CD35BFFA2B7F0A2DEA256245873BCD
                                                                                    SHA1:FD218530A53ADF8470FB3365987210BF3FC59460
                                                                                    SHA-256:D35FB22B4E841029511ADB45367B0A739EE7C131A58937EC64F8A9C7B5A14596
                                                                                    SHA-512:63D74DA9292FC9C8F64920747E689C3F6F4CB15EDE06C560BB2A516F9DB7EC610205BD036E287950929D68133E0824BA1D1B4190FD8ECC4A2C5840B2E0E6619B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...{R.e.........." ..0...?..........?.. ....?...... ........................@...........`.................................p.?.O.....?.`.....................?...................................................... ............... ..H............text....?.. ....?................. ..`.rsrc...`.....?.......?.............@..@.reloc........?.......?.............@..B..................?.....H........ ...............@...x?..........................................0..'..............,.r...ps....z.~..........o.....*..0..)..............,.r...ps....z.~....o..........+..*.r...p.....(.........(..........s....(.........*...BSJB............v4.0.30319......l.......#~......<...#Strings........$...#US.........#GUID...........#Blob...........W..........3................J...............I.....................................h.....h...Q.h...".6.........8.................a.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.799493422443734
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:zyNyhhFi/zagE8FZMhywyrB4Mg5BK1QCF:Hti/zagE8jMhywyN455BK1QCF
                                                                                    MD5:D75047A487A327C213220C5F7285599E
                                                                                    SHA1:D81438AFABD3A7C7E9AC82FB3A451D2D8889B233
                                                                                    SHA-256:AE006EF5A57225B73F3BA810548193AD1EFB7AAC1C066C93224F120E5F828C69
                                                                                    SHA-512:BBCA0B6B015E7A94BDF3B8BF814BC5FD1988933FB6D689CD1C6C16C2DB8CD2D1D9624362715FE8E9B2A02AAE887461DFAA7DB9A8D48C93720B85F4EA1FECCA15
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0............."9... ...@....... ....................................`..................................8..O....@.......................`....................................................... ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H........"................................................................(....r...prK..p.(.....s....}.....{.....o....*Fr...pr...p.(....*....0..B.......s.......}.....{...........s....(...+..-..*..o....o....}.....{....*V.{....,..{.....o....*..(....*"..(....*&...(....*..{....*"..}....*rr...pr...p.(.....(....o ...*..(....*....0..a..............%...(!....(....,..(....(...+-.r...ps....z..(....~....%-.&~..........s#...%.....(...+(....*..{....*"..}....*2.(....o%...*..(....*^.o&...o'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):549376
                                                                                    Entropy (8bit):5.964237858388747
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:oh57NfiIVOaoTWg3kEnZ+NpOHiVcDj/ICvIMwmIjiV49JjAfNHo7dlKoQ/:oh5wtT1kEZ+2Hi6WhvJQ/
                                                                                    MD5:98FF049A39021CED91144D20E8A46E75
                                                                                    SHA1:E9FAA61EF57109DF25E0E04F20A0158B42A9A04F
                                                                                    SHA-256:27672D1050DC906DEFE6668F9E8966706231DB707D4D7E2D7103C1F276753DD0
                                                                                    SHA-512:8B0CEF90E10B9E375C66B61BFB9F553BE26315EB675723ACDA12474ACFF2005B73DEC3B5FD0C4D4CFBE05C760D4FC03F9848705E84E77C86FD659AE20AA1E2F9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..X...........v... ........... ....................................`..................................u..O.................................................................................... ............... ..H............text....V... ...X.................. ..`.rsrc................Z..............@..@.reloc...............`..............@..B.................u......H.......pQ..|O..........................................................0...........(#.....}......}.......}.......}......}.......}......r...pr...ps$...}.......rA..pr...ps%...}......{.....{.....s=...}.....s&...}.....s'...}.....s(...}....*..{ ...*..{....*..{....*..{....*..{....*...0...........{....o).....,...s3...}....+...}......s<...}.....s5...}.....{.....(....o4....{....o3...o*....(....(...+&.{....o3..........s,...o-....{.....{....o.....(....*.0../.......r_..p(...+r...p(...+
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144384
                                                                                    Entropy (8bit):5.844902667019692
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:RBl45K8NHxwWqEPr2Pvuy5RIh+7s5j2H6JzV7rNx/E8/+8zMma/v8GK8V2/j/h8J:eauy5Rs+7LH6JzV7hPMmmJ6mT
                                                                                    MD5:0537BD9641501778C62A1392DD5C78A6
                                                                                    SHA1:02B058E6E30EC22BA6A0AFF616EE6A51E3C4F43C
                                                                                    SHA-256:08D55AF73DF042926B0BF49B99678B00E118EA4FD140BEEB209B1AE15BD4E52A
                                                                                    SHA-512:935D73825F73C6E009A67E55C88A09DF1841432643572C334EBAEE5B9B141A6A213C2F291EAF804D9E20AB14120B84B3F1CB47612D48D45AD4CDABB008D9BB45
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..*...........I... ...`....... ....................................`..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B.................H......H........b..$............Z..............................................V......tq.......(....*2.(....t....*...(.....(.....(.....(.....(....sk...*..(....*"..(....*&...(....*..(....*.~....-.r...p.....( ...o!...s"........~....*.~....*.......*V(....r...p~....o#...*V(....r...p~....o#...*V(....r>..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*V(....rZ..p~....o#...*V(....r...p~....o#...*V(....r,..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31744
                                                                                    Entropy (8bit):5.659269598716413
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:85o05vARIetCM94LfgbMPmyfgN6v1qGO4rLF:d0NetCM94LfOMVVv1qGOo
                                                                                    MD5:73D5A44E1A9627AC01BC22B6BE269887
                                                                                    SHA1:7CB9B3D105AD9AECC9F3252B38D5870C4AB39708
                                                                                    SHA-256:749734C73806CBD24898CD4FE9DBEF882CCE96A5FD3CA94C5CA246C9F9DA99F8
                                                                                    SHA-512:E5D43A9056CB07F6FA66C8EDCFD43A0F174D3432F00D2653173490F3F0FD062CFEC86F1F8FF3BD373812B2495206D0FC9AE2AD1BCA43F826A92FA3E06323A67C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..r............... ........... ....................................`.................................D...O.................................................................................... ............... ..H............text....q... ...r.................. ..`.rsrc................t..............@..@.reloc...............z..............@..B................x.......H........-...J..........<x.....................................................tE.......(....r...prG..p.(....*2.(....t....*b.(.....(.....(....s....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r:..p~....o....*V(....rp..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r:..p~....o....*V(....r...p~....o....*V(....r...p~....o....*>..tI.....( ...*2.(!...t....*b.(.....("....(#...s....*>..tI.....($...*2.(%...t....*f..(.....(&....('...s....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):52736
                                                                                    Entropy (8bit):5.808970555867579
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:R+M1eCjCIrV3Qb2io4UOi15pO/V/R1WpiBqCF:x0CjTV2UOi1PO/V/R1WiZ
                                                                                    MD5:C26777BE282E371083A6FDAF09C9973C
                                                                                    SHA1:4593FC1E827B9B9E1FBA578CBE1C47CAFA87ADDD
                                                                                    SHA-256:A2D6DBDDF64917C29601957C542780B4BAE82D576AC8AF47870489AC61C45F48
                                                                                    SHA-512:F784444C9787FA7E097CFD4EDC86435C61455653D48B7677769BDDE67C7F526F16D16D0D6B6AD5127457F10E639A157F906BCCABC27BE33A5864DEC0BFC0ED8B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....k..........." ..0.............F.... ........... .......................@............`.....................................O............................ ..........8............................................ ............... ..H............text...|.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................&.......H........4...s.............(9..........................................V......th.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*"..(....*&...(....*..(....*.~....-.r...p.....( ...o!...s"........~....*.~....*.......*V(....r...p~....o#...*V(....r...p~....o#...*V(....r:..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*.~....*..($...*Vs....(%...t.........*V....to.........(&...*2.('...t....*z.((....(.....()....(*...s....*b.(.....()....((...sn...*F..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):16896
                                                                                    Entropy (8bit):5.247338576691855
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:vdJ3IjBFsPlq0IBDDH2ACrgB6v2nJx9Q37/CkJGrW/6kTjWAz9hiumRKD1lXx24w:lxIjBFsPlq0IojWAPFDw4x+SWdNF
                                                                                    MD5:02CE84F4413B727980DE576904D03FD1
                                                                                    SHA1:81240B2E213AE2A4517B425B72D01A8DDC72A398
                                                                                    SHA-256:B1200417D0AA644E06CE037D3816881912623B4A7BADF6D45960C11A05515925
                                                                                    SHA-512:E634134E1FF45C9FB5F2110166D6E1D29685D6A96AAF52F8126BFC3DFF582319EEA930A3E4AD0B3DAA5976CE9C2158F8A71B5954B9A07CBE427E043B01980EB5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....v..........." ..0..8...........V... ...`....... ....................................`..................................U..O....`...............................T..8............................................ ............... ..H............text...46... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................V......H.......($.../...........S..@...........................................V......t7.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*"..(....*&...(....*..(....*.~....-.r...p.....(....o ...s!........~....*.~....*.......*V(....r...p~....o"...*V....t7.........(#...*2.($...t....*z.(%....(.....(&....('...s....*..0..s.............(....((....)...(*...tB...(+....,...(*...tB...(+...(...+(...+(...+..o0....o1...,..(2....()...o,....(3...(...+*F...t7......(5...*2.(6...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55808
                                                                                    Entropy (8bit):5.775367059131953
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:VHCwr/Irm+5HZfetnHSvnAimB4Y7FtIQh9baSoC61VtCK28bnEsF:VCwjAm+5ZfynHSvn6g4oC61VtCl8r
                                                                                    MD5:73295A2768DC84259D3C2B9EA4AECF8E
                                                                                    SHA1:B85D251AC6A173DAE37430A9C6A61FE902A3D657
                                                                                    SHA-256:3845D947E5DB1A7C3F4EFD509EE35BC29ACB2393FD865D9244986C9424187D24
                                                                                    SHA-512:D7BD59F4E97C06363EAB2C1BEF1D52455939A820D2849E7651507CA04B7D4EC22C4B05DB0340A079EACE206C4AFEE619D444E0D039BECD961BB38D1C1443FA26
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....J..........." ..0.................. ........... .......................@............`.................................v...O............................ ..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........8...u.......... ...h?..........................................V......td.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*z.(.....(.....(.....(....s-...*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o ...*V(....r...p~....o ...*V(....r2..p~....o ...*V(....r...p~....o ...*V(....r@..p~....o ...*V(....rr..p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....rL..p~....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):26112
                                                                                    Entropy (8bit):5.504870778700713
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:tMsUagR+NCVz3IU/oulvE+5LE1jqXR+EL54L2aYUNTWmeF:tJgTIUwG1XR1a8UQmeF
                                                                                    MD5:08E71FF89AEF2C04D1DD93A9314AF78A
                                                                                    SHA1:B19A9EEFA06112F83F7BAB1B5BFA4F7A072721EB
                                                                                    SHA-256:5885FF0727652243CB1544B3AAE4E31352E749E78436EAC3A6BA318A5CF1585C
                                                                                    SHA-512:B9A38F05719E4FD0DB696D0923F5B0FCA0EE36E8339EB6E042FE9EF0CA4A66A626471D12B0118C25606263F9591549E8F4432C550A5009FEDC9E20D90F8DBDC3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....G..........." ..0..\..........Fz... ........... ....................................`..................................y..O....................................y..8............................................ ............... ..H............text...LZ... ...\.................. ..`.rsrc................^..............@..@.reloc...............d..............@..B................&z......H.......`%..l>...........c..8...........................................V......tI.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V....tI.........( ...*2.(!...t....*b.(.....("....(#...s/...*z.(#....(.....("....($...s....*F...tI......(%...*2.(&...t....*..('....((...o).....(*....(.....(+....(,...s%...*2.(-...t....*V......tI.......(....*..(/....(0....(1....(.....(2...s....*2.(3...t....*N......tI...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.8771212955964223
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6T+UQDKnHslyxqLF0Fy9X7qG2VGABb81iEOaETjbU0jfjqtqQ/NVbnQXmtG87KG8:GoKnHOyQFmy2t9E1yU0PWPbdzLFY
                                                                                    MD5:3EF03FB5F6D6A63E8FD67FBF144135BA
                                                                                    SHA1:4AE9461926FAB8AA9F8D2FC4FADA25A28BF8727D
                                                                                    SHA-256:EE6590FB47A18B2EFBD8EE70B1BFDEA1318DA6AB7DBF802B6C434F449FA9BD32
                                                                                    SHA-512:8353AE4BB8C815C2A2E14534EC74CC910BFD070312CDE1E13054A6F35227E3252BF68C00F1572DE75D78E0DBC8BDF2AA42A035D6488F5854E8A869B099B6A45B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............2*... ...@....... ....................................`..................................)..O....@.......................`....................................................... ............... ..H............text...8.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......| ..d...........................................................>..(......}....*J......(.....(....*..{....*.BSJB............v4.0.30319......l.......#~.. ...T...#Strings....t.......#US.x.......#GUID...........#Blob...........W..........3..............................................................................Z...........2.....A.................4.......!.................................O.x.........A.................r.....-.......S...F.....................h...M.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.762661257689725
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zRWAtSQqSbmIl3kn75fCN7RHQSFl+ouzQLxdETbSqNNDZ+GclRq3zQ6SfJtkinNu:tWwSf6mw3k7yFqhzNNiRTkin6gNb69d
                                                                                    MD5:C7F090DF56B4B7F00FBC30BE93E19CB5
                                                                                    SHA1:762A1352B78DA7970367094C4EA1DE2119BA03A0
                                                                                    SHA-256:A0B5A4E0D399D0E848A8B2CE2C9DEB3B8F2ADF0411C4BAFB066CF4646595512C
                                                                                    SHA-512:EBB747416375D393BC981D7A7C3182A4FA6A29D675C8C7366A0A1E2EED2A5D60BFBA6194C8C6AEA6291456EB6048C69CC1557DD3FFA1E330B55E36431A0DF61F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text.... ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................?......H........$................................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*...0..+.......r...p..(....,.r...p.r#..p..(....(....s....*..{....*"..}....*..{....*"..}....*J.(.....s....(....*.0..O.......s.........+...o.......o......X...o....2.......r1..p.r1..p(.........,..o.......*.........<B.......0..M.......s.........+...o.......o......X...o....2.........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):19968
                                                                                    Entropy (8bit):5.327502630579932
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:WR1TB+EYvodkn5OeUq5gCS1x9UQflcltvlVyUWY5FVRsp5GiPjcVuGk/6uQKztku:WZYvoy5OeUqp2UhLs9P4VBXuQK+u
                                                                                    MD5:CCF6F3D56977D1AFBF4A3EC884D1A32E
                                                                                    SHA1:D29EFBCC5AB0F6C7403BE0DDE5EC202D61FF410F
                                                                                    SHA-256:2129BCD055F493FE34B7E44AEE5F8175CF9D43D7AC037D742E6070A58AFE1266
                                                                                    SHA-512:329607A495E0DAEC735F81A15B8B92C4DF84F71015D9AB762967CCC664714BC2C883BD321255FDCDFAFA04BF5C24DED92B98FC940DFF30A36D72E2831A2AE012
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...XR.e.........." ..0..D...........c... ........... ....................................`.................................dc..O.................................................................................... ............... ..H............text....C... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B.................c......H........0...2............................................................(....*"..(....*&...(....*&...(....*....0..e........(.....s....}......}......}......}......%-.&s......%o...........s....(....t....o...............(....*....0...........{.........o....&.,....o.....{.......o.......(...+(!...}.....{.....o"....{..........xXs#...o$....,..{....o%...o&...r...ps'...o(.....(....*...0..|.......~)....~)....s*.......~)...~)... .........o+...-6.(,...,..(,...,.r...prm..p.(-....(,...-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):269824
                                                                                    Entropy (8bit):6.248597977496272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:w9hcO7H2po0qDQh/mLJ2e4NY647eS56K2K+p637RArP1CKlF:w9hn0Cus+c32
                                                                                    MD5:761C33DCFD02AF3A9B60C3A307362989
                                                                                    SHA1:636D766B076E05DBEAB1FC9117F1B0931DC33A8D
                                                                                    SHA-256:B17012332BC4B2745349101AEEB02501E68F1E8D470CFCF316CA3AD13A2356E6
                                                                                    SHA-512:414F48F3FC381078A5B8E0D49F8D822BF1BD9B36EF944B3A7B2FCFFBCBF2F547108FC7002179EF2DF4021F499FE23E4D87BBAE5CB83B236AAFCEFBA23C7044F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e.........." ..0.............j2... ...@....... ....................................`..................................2..O....@.......................`....................................................... ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................L2......H....... ...................hV............................................(%...*..(&...*z...(.....-.r...ps'...z..}....*..((....-.r...ps'...z..}......}....*^.{....,..{.....o)...*.*6.{.....o*...*....0...........u......-.*...(+...o,....o-......o......o....*6.~.....o/...*.s0...%.o1...%.o2...%.o....%.o,...*.r!..p.....(3........(3..........s4...s5...(6........*....0..#.......s.......}.............s7....o8...&*..0..?.......s.......}.....(.......o9...,..{....o:...*.........s7....o8..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11776
                                                                                    Entropy (8bit):4.956614026804989
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WCvPuFqE/nQ+L9XRy/z/J0pD+zcNwlClvhMHJaOHuM:TZEfQa9I/Jy+4ZWROM
                                                                                    MD5:0A0505AFC1C5AF06E4383DF3032D0674
                                                                                    SHA1:6242B357013B9E1B6423DCB5482B2D0EB510A4D5
                                                                                    SHA-256:A902F1790B60C1177301073CC1FDA983B4E3186FD6EC247335B115A41A3786E2
                                                                                    SHA-512:F7A471192BE900AC14B4C39B39CCA5EAE1ED35A04E1BC70B50AAB2867DDCBA9428EA431F00B5E05B96AEE05DBE70F2673C286752F05776BDC54192364054C1FA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..$...........B... ...`....... ...............................0....`.................................4B..O....`..\............................@............................................... ............... ..H............text...."... ...$.................. ..`.rsrc...\....`.......&..............@..@.reloc...............,..............@..B................hB......H........%......................|@........................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.0..S.......s....r...p......%..(..........%..(..........%..(..........%..(..........(....o....*..(....*V(+...o,...o$...s....*.(....*.(....*B(+...o,...o$...*.0..(.......(+...o,...o%....(......(....-...(......*B(+...o-...o'...*B(+...o-...o(...*B(+...o-...o)...*..0..F.......(....o....o.....s....%.o....o....%.o....o....%.o ...o....%.o!...o...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):10752
                                                                                    Entropy (8bit):4.8225604790518455
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:/ySWVk7AJnE0J5nMuoT4Ylzpz6dPGadIce8R+az+SvdlkGYwGsnoSjM6BKMqVXLY:/Mk7eyTXz6dPXVZnblKzVbFp
                                                                                    MD5:0E5CB0025D94586D87103A9BC42D8300
                                                                                    SHA1:64700DAD9F08F73385DBE0C98FE07776F4689AC5
                                                                                    SHA-256:3B4EE52569911F5CC967B8EE9EE405353244D01A3F43A4816498F2BF1D276FCC
                                                                                    SHA-512:F5C7DF798A6431A6A62F8805F3625EA6DC6CFDFA04FB5193BECE0E8DC791E65D0C76F5895FDB7C805DF385D14E8C4775D6FF3819E67C340788A59E6F49CF4CAA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.. ...........>... ...@....... ....................................`..................................=..O....@.......................`.......<............................................... ............... ..H............text... .... ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................=......H.......X#.......................<........................................o....-.r...p.o....(....*r%..p.o....o.....o....(....(....*..0..A........o....-.rQ..p.o.....o....(....*r...p.o.....o.....o....(....(....*2.r...p(....*6.r...p.(....*.0..............(....*...0..........s$......}.....-.r...pr...ps....z.{....(....,.rC..pr...ps....z.(....o........(....r...p.o....(.....s....z.o.......%...s....(...+,...r...p.o!...*...{.....o!...*........>..K.......0..............(....*...0..M...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.0786290349934315
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Cf8wjVl9lOPAmVqzzNBdu3DPxXEvLCiDfp6wZ8ETV56hjRUA8qbC/We3nebPLqX:TjGImk/5Q1EewZ82Vwjc2Ceu5O
                                                                                    MD5:649DFD82FE2569BC5873F0715AA545CB
                                                                                    SHA1:9D2A506C841D233C32DCF39506D5EAC7EE60B97B
                                                                                    SHA-256:7411B7C9E368E1CEE613FE97728D504E31D5F2091D11951A4DBEB88A9551BCAE
                                                                                    SHA-512:217FCADEF712A7DE2DCDF7A1036EB50AE47EC752400A1A7EFA3BB4A49F7276E3BDDCA03FA5044513DC06378EE1AEE1527498DCC534AA9D16A4873DCDCBDC5C00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..............,... ...@....... ...............................>....`..................................+..O....@..4....................`......|*............................................... ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................+......H........ .......................)........................................o.....o....o...........(.....o...........*.0...........(...+..,..o....*.o....*.0..E.........o...........X%..o....2..*..+ ...o...........X%..o....2..*..X...2..*...BSJB............v4.0.30319......l.......#~..(...x...#Strings............#US.........#GUID.......T...#Blob...........G..........3..............................................................5...............K.................1...........k.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):24576
                                                                                    Entropy (8bit):5.439852939293774
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:zbXOwhwMrAfN2/hkBwkGa2+dWLG4ZfAcION/65Hld2qFKNk8qluGLRqOunsWsrj:PhhwMrsek2+I95shhJRXiJs/
                                                                                    MD5:74E7BEBF2E462C337B1280A3E98D0B35
                                                                                    SHA1:0DF183BA4D1C4E13073581E56564F95AC5CB3254
                                                                                    SHA-256:F55761468B9B0CE16C70A2F011C486DFF07948D35EAE3E67B092D610C381F368
                                                                                    SHA-512:870D44A95CC69D694189A702DDFCEA6D98F8DD25BB0DAD78AA7259E73E328946B68160215FF209EFF93AD40DD19B34752E9E15217E78298E4C696712F0F2DF49
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..V...........t... ........... ...................................`.................................dt..O...................................,s............................................... ............... ..H............text....T... ...V.................. ..`.rsrc................X..............@..@.reloc...............^..............@..B.................t......H.......@2...=...........o.......r.......................................0..G.........(....}.......}.......}.......}.......}......|......(...+..|....( ...*..(!....s"...}....r...pr...p.(#...*......(....*...0.................{....o$...o%....+9.o&.......o'....j3&...r'..pr=..p..A....o(...()....(#......o*...-....,..o+.....9.....o,...o-.....8......o........o/...r...p(0...,t..o1...o2....3e..-...o3...-7...o4.....r...po5...r'..pr...p..A....(6...()....(#...+.r'..pr...p..A...(7....(#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):20480
                                                                                    Entropy (8bit):5.12438911804574
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:9/raLgzj2a2VtNY6gA2NGiQEt1u2UUAxT:J6Ba2Vs+intc2U
                                                                                    MD5:4E14602466E04BA26B85799C7B583135
                                                                                    SHA1:35BA198DFBEDD4E9E2A14315EDC985518011E5AE
                                                                                    SHA-256:E4382B9036CC9A50558992245D5AEDEA247567FD87E24D2CC318AA47A0898B34
                                                                                    SHA-512:054A8FD1F6218D1F2E85C46244EE2C9EA7C5D93353EA615A7F2D32317FFF7EDB6A2612270CB8621D9DA76634F8645A459FC075CFB970D028EBBD9C00DC131238
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..F...........d... ........... ..............................@.....`..................................d..O...................................tc............................................... ............... ..H............text....E... ...F.................. ..`.rsrc................H..............@..@.reloc...............N..............@..B.................d......H.......X-...5...................b.......................................0..............(......-i..o(....o......(....,.r...pr...p....6...(.....(....+R..r...pr...p......%...%...%...%...6....(.....(....+...r...pr...p...6...(.....(.....*...0..8.........(.....o(....o....(.....r...pr...p....6...(.....(.....*.0..............(......-i..o(....o......(....,.r...pr...p....:...(.....(....+R..r...pr...p......%...%...%...%...:....(.....(....+...r...pr1..p...:...(.....(.....*...0..8.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.627470324915964
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:ZnRxqFcduFzlbKYTQA7sGzaM+vgh3DQqQy6B3rqWsuYXATXjLdGC/au/z:NqFHpboA7sGeM4cv23rqiYXATXV/au/
                                                                                    MD5:852BF0289D774738CFB036A8BB5C6B11
                                                                                    SHA1:98F4D60BE0EE949346AD95BC6234D677E1C7D389
                                                                                    SHA-256:BB3AB16E765F17C784DE9CDB0C35D1B6A299ABAB476FE2F9CA1B39528A629B8F
                                                                                    SHA-512:CFDF0079C9C42D2870FA18BDC92AAD49F16481744B0AB3B296DEA4F258FDF3A6A64B419943E61173D17D3FE8A9A6BAE728AC9F245E6196770BDC77DF5B55AD30
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.............V7... ...@....... ....................................`..................................7..O....@..T....................`.......5............................................... ............... ..H............text...\.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`....... ..............@..B................87......H.......($..$...................L5......................................:.(......}....**....(....**....(....*....0...........-.s....%.o....%(....o.......{....(....&.....(....s......{.....(..............o....r...pr...p.{....(.....(.......r[..p.(.........,..o......*.*........E.+p........E.;........0..............(....&.....r...pr...p.o ...(!....(.......b.r...pr...p.o ...(!....(.......B.r...pr...p.o ...(!....(......."..r...pr...p..o ...(!....(.........*..4......... ........./.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):61440
                                                                                    Entropy (8bit):5.4953592987125335
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:v1P9PM1EO9m30XOgj6sogR/nho16ATIdYOrvQ7NR6KfgB1XxLP8uQ9O3rJt/EjBc:9PVM1i0XlhLATIdY1z5gBMuQ9On/Ky
                                                                                    MD5:E520C02EE6A83ACFE58CD9EDB296E392
                                                                                    SHA1:665A83902C560C610F1F34108742551F1E4F7BCA
                                                                                    SHA-256:A729B344885A5F7F7F09A6D6EF2B9AE86E643BBC118EA60B27CB08AE0991705C
                                                                                    SHA-512:E6EA3148DBB182909790BADF66EE0C9F4BFD5B3B624BAAE13AE4EE85CA89A44A4C1C39D4A25A72A53C1BD55DE647E9D0081DCB6AF82F05D566C300D53D831E0E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.................. ... ....... .......................`...... h....`.................................t...O.... ..,....................@......<................................................ ............... ..H............text........ ...................... ..`.rsrc...,.... ......................@..@.reloc.......@......................@..B........................H........c..8............................................................0......................(....*...0..+.......r...p(......,....r...p.......(.....(....&.*.(2.....(4......(5..._...........(...._*..0..........................(....*...0............................(....*.0..(.........r...p(......,....r...p........(......*.0..).......(2.....(4.......(5..._............(...._*N......rQ..p..(....*R......rQ..p...(....*B..........(....*F...........(....*F...........(....*J........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):5.073320023485428
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VP3bjfBuBX39tYew3jhC4h9Xx8P3RV2ReWBP3lYen:RfBg39Cew3oKihGce
                                                                                    MD5:A1D2A38772AE525ED4C0A165C3197187
                                                                                    SHA1:5EAF512F42F0DCEF235F914F104FE0696C4310B7
                                                                                    SHA-256:CF3803BC5985B65888BA30261E93E366E1C8E76AF91B6E40F36FB14812F57BF2
                                                                                    SHA-512:6D3AC43928F8A6E6F93C6C64A20B2C1E512A045979F8C2C29A584C56CF29B14477FC7DF954C4EB0F1D34F9381ABEE3C238AE7868DEA6FCDD175DB364A633D098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..0..........*N... ...`....... ..............................j.....`..................................M..O....`..@............................L............................................... ............... ..H............text...0.... ...0.................. ..`.rsrc...@....`.......2..............@..@.reloc...............8..............@..B.................N......H........+...............G...... L.......................................0...........r...p.r...p..................(........Q..+..*...0..2........r...p.r...p..................(........Q...Q..+..*...0...............~....Q..~....Qs.............,3.(......~..........(.....*...(........Q...Q...8n....o....o.....r...p.....,.....*...(.......o....&............(........,$.(.......o....(........Q...Q...8......,.....+......9......o......Yo....o........o....o .........o....o ...(!.......,t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2213888
                                                                                    Entropy (8bit):5.810653063534655
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:69sJESAufFG0oe9ZrRSSuUKPgDMmrsZhT7UYCwOYhNVs7VonU337g023hQrK:69sJpoe9GSuJPsRYCwOCNCpAUH77ST
                                                                                    MD5:47ACD42F6F2B1476758C927A9ECAA95D
                                                                                    SHA1:4299A5BCDCAC17AEF569D26A03DD0F7A4D497656
                                                                                    SHA-256:7EF96C71C8DAD6DBCB9AB0104E840ACA915554740A8CFE12AA0556FD5BD5A782
                                                                                    SHA-512:3FE6A3E66AD90EDFC754A1F3FB3873EB0584050CADEE8E3A1A6845F0AFCF414E267F9AC675BF91227D41717EE7C2DBFAE976EB7E695EE278BB773C48C44C5BEA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0...!...!.....Z.!.. ....!...@.. ....................... "......_"...`...................................!.W.....".......................!......y............................................... ............... ..H............text...`.!.. ....!................. ..`.reloc........!.......!.............@..B.rsrc.........".......!.............@..@................<.!.....H.......dz...K..................`y......................................".(:....*....0...........(a...*..0........... 4......(b...*..0................oc...*.0..................od...*...0..0........oe...%&r[..p $.......$...%...%....of...%&t....*.0.............og...*....0...........(h...*..0...........(i.....}....*...0...........{.....t{.....#........oj...%&*..0...........(k.....}......}....*....0...........{....*..0...........{....*..0..........r{..p.....r...p.d...(l........(l
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):326144
                                                                                    Entropy (8bit):6.034873314751499
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:giUW6EA3+SZowHFnNyE2TNz4GkF4a6y8iWFucu0yMUveDOrmVpfuyw:0WVA3+SZowDp2WD8ip2D
                                                                                    MD5:FB791F993AC67F4A462DBCB66FF14BF4
                                                                                    SHA1:35EE2C6A213E324F0A7A9C9451A10CFABF427545
                                                                                    SHA-256:39A80B657B1191A017B17E5908DCE5C68D9A1A2E737CBAD67B7337CB2FC44A10
                                                                                    SHA-512:80E1FE9C5F5C6C1BF29AC1CC4F49114EA1067E71E22F63FF8F654A60FAAE9118CFDA9D4F367667E7D3F474C0C2A528189587FDF1E5DFF8B91821AB3E0A5C57B0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ... ....@.. .......................`......v`....`.................................h...W....@....................... ......|................................................ ............... ..H............text........ ...................... ..`.reloc....... ......................@..B.rsrc........@......................@..@........................H...........lz...........V..x=..........................................6.(\...(.....*...0...........4............u...%.a...(0.........u...%.b...(0.........u...%.c...(0.........u...%.d...(0.........u...%.e...(0.........u...%.f...(0.........u...%.g...(0.........u...%.h...(0.........u...%.i...(0..........u...%.j...(0..........u...%.k...(0..........u...%.l...(0..........u...%.m...(0..........u...%.n...(0..........u...%.o...(0..........u...%.p...(0..........u...%.q...(0..........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4824576
                                                                                    Entropy (8bit):7.776304506864257
                                                                                    Encrypted:false
                                                                                    SSDEEP:98304:WOrDbgLR3nV/30BnLce2emqSwF3/HJ7f/kRLHCVUhY:BsV3nV/0BH2emqDFPHJ7nkRuCY
                                                                                    MD5:FD7A9437356762EE30088DDAF1B56ED5
                                                                                    SHA1:0426B255F4307498E6F531BFEB1135937E008863
                                                                                    SHA-256:C056E932DC3AFF16E8FDB56500E952C696A60A4CA22566C1B5BFC00C49756ED8
                                                                                    SHA-512:5705EC681E1BD00FB3FEEF1775737CD3053B0BD5F1724E78F5305BE31C8AFE02148FBDA9B02453D8621CAD40EB6250ED69EC20B6BAD8736E6B15BA43E81A6541
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0...I...I.....N.I.. ....I...@.. ........................J.....pTJ...`...................................I.W.....I.......................I.....8.D.............................................. ............... ..H............text...T.I.. ....I................. ..`.reloc........I.......I.............@..B.rsrc.........I.......I.............@..@................0.I.....H.........D.<...............(S7...D.....................................6.(....(l....*...0............*..0...........(&...*..0...........('...*..0..>........{.........((...%&t(.....|......(...+...3..E.........-......&*...0..)........{.........(*...t(.....|......(...+...3.*....0............s+...(....*....0..............s*...(....*..0..0.........(.....|....(,...%&.d1...}.....r[..ps+...(....*.0............(....*.0..&........{......,..E.........-......&...o-...*...0..K.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):173568
                                                                                    Entropy (8bit):6.12032044473592
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:QdkbCx9M2UJtDEbsJgNhnTK2Gu6asmzjewiZc7YgaxYU9:QqC24bs3YEAU
                                                                                    MD5:E47489D595CCD60356287B98BA2588BF
                                                                                    SHA1:7FA67EC95AF6D9AC4AAFBD296D7BA11DB9F1524C
                                                                                    SHA-256:5DAA9E04010A89BF749FDA2BAB4395F0A9449F8EF780D78D602E48B2DC61FEFA
                                                                                    SHA-512:34A12BF7DEC1A752E106B862F144FB32CCEB26D4DFC2CB13A239763CA1784B0EAE8673C2E47492CD1FA5A3F8D7E75DA686F19325F4F527805AC699B2A6C8385D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ........@.. ...................................`.................................D...W.......4............................................................................ ............... ..H............text........ ...................... ..`.reloc..............................@..B.rsrc...4...........................@..@........................H.......D................$..(...8.......................................".(E....*....0...........(....*..0..@.......~....-3.E.........-......&r[..p.....(....%&o....s.........~....*.0..........~....*...0................*..0...........(....*..0...........( ...*..0..........s....(!...%&t.........*..0..........~....*...0..G........(......}"....s#...%|$.........}%....{%....{%...}&....{%....{%...}'...*..0............{%....((...*...0..}........{&........{$........,1.E.........-.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1101824
                                                                                    Entropy (8bit):5.023302066642073
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:zKzbh1ndx6nAsUfoFoo9VCrh58feUpM+:zQlyosVih50pM+
                                                                                    MD5:0532E0660453C89AF5955445972E5D5B
                                                                                    SHA1:C0907DDFE071EF98A26D9EDEEFD2D83139C17CE9
                                                                                    SHA-256:C341D62E5343E77BF0420433D9B1FA493115422C8FC8E5512CDDAC382C1FA51C
                                                                                    SHA-512:FEA07DBA3695006B90449769264649EAC018CE203457A25C06F2A04C8CA299B9F64687F54EEE301585715401523572B3EB91880A194FE8A91BA36D22000881E1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ........@.. .......................@.......D....`.................................p...W.... ..<...........................hW............................................... ............... ..H............text........ ...................... ..`.reloc..............................@..B.rsrc...<.... ......................@..@........................H........W..............@>.......V......................................6.(....(.....*...0..$........(-.....}......}/.....}0......}1...*.0...........{....*..0...........{/...*..0...........{0...*..0...........{1...*..0...........u......9.....E.........-......&(2...%&.{.....{....o3...%&,U(4...%&.{/....{/...o5...,;(6...%&.{0....{0...o7...,!.E........(8....{1....{1...o9...*.*..0..j....... ...n )UU.Z(2...%&.{....o:...%&X )UU.Z(4...%&.{/...o;...X )UU.Z(6....{0...o<...X )UU.Z(8....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):5.916274515752421
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:VbFZAPoGIjmU9ZMPVNOhTJCj+775suxTvJREFhtK4shNeYJub4h8ZGdwv1PmQYEQ:Vm9SXGunREFhtKhNeA+4h8Md81VYExO
                                                                                    MD5:66AEAABA0629DAF8544AFC8008079386
                                                                                    SHA1:1E09E5D24E1AA3D1700B265C6FF94B7524813F4D
                                                                                    SHA-256:268B44A78354F7A225E5B1567223179C7B73453C0A27EB4BF18BB57D7A8E08D9
                                                                                    SHA-512:DD2CD1DF484600E6CC3E686E64559C3447F255F723B5F57CD51F76A838A79416BF68B7A7B380467BCE172FC3EC868EB54A0D754108926782D31BB0CBD66F5A54
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...y(.............!..................... ........@.. .......................@............`.....................................S............................ ......p...8............................................ ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......\h.......................g........................................(....**....(....*2.-..*.o....*J.-..+..o....(....*:.(......(....*...0..............i..(.....*...0..............i..(.....*...0..-............(.......(....,..,...(....s....z.s....z.*2.(....(....*:.~......(....*......(....*....0..............(.....(.....o....*"..(....*Z.~....(....-..s....*.*...0.............(.....*...0..h.......~.....~......{...........{....M........ZXM)....(.....~....(....,...sO...Q+...Q.~
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):21652
                                                                                    Entropy (8bit):4.849878167461133
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:OXwP73y8HB6AreJkS9RBbwX/QreSLG1UI43I6Y3Ix:OXmyiB6hkSVsoFI60Ix
                                                                                    MD5:3C7CE2802DAEE6DBA9E39970995C4069
                                                                                    SHA1:4FB7A312CC269CB44487B0FEE6B94695024A6B0B
                                                                                    SHA-256:226F82B448C2F8700CA5C9F3658A0808A251F98D8543753E6231BC41B2A2053C
                                                                                    SHA-512:203B5F374AE63AD4F9A3F926D8D0AFD351F2886D6B3A1FF6D0356C080980E850B9934B875B34ACCAB8EB0382A69B168C3497484BD2CE9F2F4B23B5230D751AC6
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....#..#~..t#......#Strings....P).. ...#GUID...p)..8%..#Blob....N..x...#Pdb..................?....3........1...T...S...........E...M...........e...r...................Q...Z... ...)...................................................g...p...U...b.................b...n...u...............................*.......................?...............I...p...................:...F...i...v...~.......................I...u...............5...=...D...K...\...m...........................................o...........................>...O...o...|...............0...]...j...r...........................+...9...Q..._...w.......................h...............................1...]...f...............................a...{.......................%...:...P...^...s...........................5...`...........................................-...T...a...............&.......;...C...K...S...[...c...k...s...........................=...`...................................+...8...X.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):148480
                                                                                    Entropy (8bit):6.125792384388118
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:x/xP0dmNHRIfvXyTjUxk0+8shTbRqpzMA1JhkrIAcFpZMD9hVRg5bT+02nBJdbea:x/OSSfP60kpVxbUuZKq/4qaTXc
                                                                                    MD5:D2EDDE626C241549EAB636AA87FB5D38
                                                                                    SHA1:8D836FEBD477B3EC44CC37F4F0AECDAA1D7DB788
                                                                                    SHA-256:BC0243134C93C55EA105D0E9C2A43B6030E973290D0A061CF3A61986A2268A88
                                                                                    SHA-512:490878E20ED764E81E42B8F43FAF2ADC0810DCD2F65D36F6D6980411617FAE9543F0D7B6F110E5363BE494097BA3B30DCF3695AEA41314FBE19C6A59A55538D1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....-.............!.....:..........NX... ........@.. ....................................`..................................W..S....`...............................W..8............................................ ............... ..H............text...T8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B................0X......H..............................X........................................(....*..0..8.......s.......o......(....~....(....(....-..,...o....+..o....*.0..............(....*...0................(......(....*J......(.....(....*...0............(.....(.......(....*...0..............(.......(.....*..0..-.............(....~....(....(....-..,..o......X.+..*"..(4...*Z.~....(....-..s....*.*....0.............(.....*...0..F.......~......{.........{....M........ZXM)....(.....~....(....,...s
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):34752
                                                                                    Entropy (8bit):4.846700052298754
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:JNne+E628lTYV+5Puni3MKW6kqQ9aRrwytEc8nl0FXGwxXl3kKjF2kCkB72KRleh:je+E628lv5Gi3MKWNqR928ksF2t4lg
                                                                                    MD5:44E3CF00D4EDA7F4AA38044D578AA537
                                                                                    SHA1:D73E59804E3EE494A4612185771F7F67B2FD64AE
                                                                                    SHA-256:ADC6991011DA455E001F537DB1970B2208D960BA7E66D4D4A534D293235B4463
                                                                                    SHA-512:B83080B7968E5B32DD7B1BE70EB7F9BDE797DE248A5B4C5C94EEA6EC0342AD8FA78B4FF46E63835EDCA340C3F3B254044F0348BC84F728EDD37DB1EC223030DD
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....B..#~...C......#Strings.....J.. ...#GUID....J..45..#Blob...........#Pdb................../....3....#.../...............4...<..................................................."...+...........O...X...........e...n...I...R...........'...0...x...............{.......................&.../...'...0...................b...k...........7...@...................................6...?............ ..& ...,...,........Q...........................-...9...@...L...m...................t...............................................9...u...............E...e...............................@...G...T...\...d...q...~...........................$...m...y........................... ...O...........................!...)...K...............................J...j...........................g...}...........................$...+...2...9...@...V...^...f...x...............E...R...Z...m...z...............................2...Z...g...y...............................,...>...P...b.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):5.818260075879258
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:p3Bz9k7imvWiznlHnixQJhXbfMM/yTDl5GwiVmQD8HEIPCMBxQRxSfsxmAIi37vr:Nh9wimh5GObfn/yTJIhGkma37NwU
                                                                                    MD5:40A0212AF1723D130234B7BBCAA0D582
                                                                                    SHA1:851CF72667EE5A7906DC832762E4B73A0BD34487
                                                                                    SHA-256:0D3DBDCE73FF02E14B507944525DE062895E5F9D1961CE9D6BDCE5E02318371A
                                                                                    SHA-512:01329798A4146BC4C6B9F4897D04F9517CB5FE067FFDEBA36C06ABDE55C3F0717C4B708F4239C3301584F383311606A0460DC72A3DE76101F424EBDA6025E5F1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!................n.... ........@.. .......................@.......*....`.....................................O............................ ..........8............................................ ............... ..H............text...t.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................P.......H.......0z..|....................y........................................(....*.0..\.......~.......(.....(.....3...(......o.......(.....+...(......o.......(........o.....(......(....*.0..9........(.....%.,...i-....+...........(......i(.........(......*"..(....*Z.~....(....-..s....*.*..(....*....0.............(.....*...0.............(.....*..(....*..(....*z.{.....{....M........ZXM)....*....0..N.......~......{........{....M........ZXM)....(......~....(....,...s....Q+...Q..(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):26556
                                                                                    Entropy (8bit):4.728335524596591
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:dltvbTSU47YPo0nLcZ6zE06PoPfqVnuv1tD/Xb0gnlf+BWRHmIFcM:9zg0nLcZ6zE0bPSVnu6BWRHmgcM
                                                                                    MD5:B0372EDDCE04EBA949E87B05788FE144
                                                                                    SHA1:8511A2A3E02B0AEDE1FF5B77043094A6E7ABDE0E
                                                                                    SHA-256:E294D347CB9FB7CE6E7A83B96943D5EC51DD59991D0496BBB99F6573767EF5CD
                                                                                    SHA-512:8C1B14D048D5600C8B8E163D20E4E3EF3920ED9CF8EBACDE33214D11B8F3731A0F8225EB2EBA1B84C23822325418633CAAFF1B49B7FA2428C1A0476F95C3EF28
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....4..#~...5......#Strings.....7.. ...#GUID....7...,..#Blob....d..|...#Pdb................../....3........................H...P...........\...i...................................................2...?............... ...........U...^.......'...........|.......................7...@.................e...............~...........................................3..._...................'...I...u................... ...-...5...\...y.......................6...S...f...............................)...P...............2...t...........................................................0...=...E...e...........................1...L...g.......................................%...2...?...L...Y...g.......................)...I...k...................T...a...........5...A...N...V...}.......................%...6...D...L...i...............)...s...z.......................<...O...[...g...n...........................................$...1...C...P...X...k...~...........................#.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):283136
                                                                                    Entropy (8bit):6.00665871292273
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:zTlyoOCGOd8DxSEjnhkHTI4A2j4xBJz+gM5w9HDAVvbLvm5KhgeeCjDrgvmjG0Wz:N3n2lB+xQyUeklXAknj1ur
                                                                                    MD5:07137E5CC4D5ECC95CA267C9DCE042D4
                                                                                    SHA1:D82F5E3D718BC9172FCFE0E8C50CB20251762058
                                                                                    SHA-256:56F525E33494F4CD2A560A71CDF237303A3FB54A8FA44E1693EBA35C9245C60A
                                                                                    SHA-512:9D1D6EB2887653260B62A24D3AB2C358BF15B89F68A1A3A1104F1EB5362725EB535218B9A53211F9CDB67D7793CE346C520A289D66C3EDF786B0DA5DB7C39F0C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Y.............!.....H...........f... ........@.. ...................................`..................................e..S...................................Pe..8............................................ ............... ..H............text....F... ...H.................. ..`.rsrc................J..............@..@.reloc...............P..............@..B.................e......H.......\....J...........................................................(....*..(....*V.~....(........o....*"..(....*Z.~....(....-..s....*.*....0.............(.....*...0..8.......................{........{....M........ZXM).......(....*V.~....(........o....*"..(....*Z.~....(....-..s....*.*...0.............(.....*...0..8.......................{........{....M........ZXM).......(....*.0.....................(....}.......(....}........(.......+r...<....(....}.......<....}.......<.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):78220
                                                                                    Entropy (8bit):5.051201187467832
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:CpHzmX5+N9aIcSyP6JFzIocUNX290MKc7P9tOaZQTZH:CpyTmyiJFzvNX29frPaTZH
                                                                                    MD5:1600D8ADB3E99F85C1E9719E59828559
                                                                                    SHA1:A2259A45EA284247B3AA65EC9C1DBEBD47FE208F
                                                                                    SHA-256:BBA95514FB062788C9AEC9CD7BC553CF47843C42CA5EB572814FF4B7C82CE7FD
                                                                                    SHA-512:DD967AB0F86D77FEF2E09830C00F318020B519205DD6F8BE70FB5D07FD5F6B988ACE83487B56EE49973216B385DCAF802408223AA0FD6D9F6203DAC6066BCC00
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p......#~..4.......#Strings........ ...#GUID...,...4...#Blob...`#......#Pdb..................?....3....K...........R.......,...=...E...........................0...;...........................}...............f...o...........E...N...........I...R...................................................7...@...........................@'..I'..m)..v).../.../...1...1...3...3..b9..k9...;...;...;...;...<...<..S=..\=...=...>..w>...>...>...>...B...B...C...C..8E..CE...E...E...E...E.."F..-F...F...F...F...F..OG..ZG...G...G..TH.._H...H...H..SI..^I...I...I...I...I..MJ..XJ...J...J.._K..jK..NL..YL...L...L...M..&M...M...M...M...M...N...N..%O..0O...O...O..BP..MP..YQ..dQ..%R..0R...S...S...S...S..:T..ET...T...T..kU..vU...U...U..RV..]V..9_..F_............Z...................#...4...A...I...V...........P...X...`...h...........?...m...u...}.......................*...@...V...m...........................+...P...........................+...8...Y...s.....................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):338944
                                                                                    Entropy (8bit):5.8207026443713925
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:KDjDsu4bFgg64r+85o5LQciAiQ7qKC26EX3:mjYu4bFlkQc1
                                                                                    MD5:52F43683B23D23EE15E3A6423D1B5793
                                                                                    SHA1:8B4176792BC3A3C3BE21077B5D2C8052FF4D99A9
                                                                                    SHA-256:6A5CCD1A4EF6B026A8ADBC9F36394287AF49097152D57C036DD7697C06BE549B
                                                                                    SHA-512:11B3AE3217F2CAB7C8D044A24F29C30A862AE981BA0F0DF0C536EFDA386C9BED81A4B9F9910E5CB4625E4CFAFE9949692B4E634C3601AB923AD4AC9B9F5C659C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$.............!....."...........@... ........@.. ...............................d....`..................................?..O....`..............................d?..8............................................ ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H.......................................................................(w...*b(.....3...(....*..(....*j(.....3....(....*...(....*:..-..+..(....*..(....*...0../........s....(......+..(......s#...o......X...o....2.**.{&......*...0..C........{ ....0ci ...._.{ .... ci ...._.{ .....ci ...._.{ ...i ...._s....*..0..L........{&...,>.{&...../ .....{&.....cX.{&... ...._.c.{&... ...._s....*~....*~....*..(!...*.0...........|'.........(.... ....(....}........|'.........(.... ....(....}.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):120616
                                                                                    Entropy (8bit):4.8681605086520445
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:93cL13tS8RDNugFR/6yi52SX08caJPwrV:yFtXRAgn3iwS1cYg
                                                                                    MD5:C5429024EF37DB3D20E09B8033CCAE2A
                                                                                    SHA1:FCF4C53ABF79CC196CC356D624A86FFDFF387AE8
                                                                                    SHA-256:E077F4ED5B7791708D4854B5CA290910168427767E3C02F118BDA767B5099561
                                                                                    SHA-512:6B376B5C5D0D157B87645C4FC7AD1B697C55DD16C2BB84CA3980A2E0192E552D8C03454EFB9903615036EB69058B7F730AD7B9A4A26EE101217179A3786AD521
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p.......#~..d.......#Strings....d... ...#GUID...........#Blob...........#Pdb................../....3....:...............9...;...C...%.../........... ...,...<...F...............(.......................!...$.......................N...X...................k...u...e,..o,..j/..t/...1...1...2...2...3.. 3..p3..z3..24..<4...4...4...9...9...;..);...;...;..1=..;=...=...>..U>.._>...>...>...@...A...j...j...o...o...s...s..]v..iv..Gy..Sy..Sz.._z.....................:...F.......%...................^...j...........4...@..........................u....................P...\...........9...E.............................X.......................................................................D...............A...V...............[.......................................=.......X..._...f...m...t...{...........................................%...2...D...Q...^...k...x.......................)...Z...................'...D...R...j...........................:...\...~.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):215552
                                                                                    Entropy (8bit):5.480542089734276
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:BW+i1u3AZ2YRCPJ4e3qHKSOZ53ZSOUE5Cgil7MEcR5hpGO5wZ+iEZUn1Bt+ZknSB:BdAZDCziyEs5Pib+ZknSTpc
                                                                                    MD5:50E6524B7EE9C2C93F5210B63CB1CA54
                                                                                    SHA1:3E296EC3BB24750833EA80515E6FB4C73874C91A
                                                                                    SHA-256:4C9615496970EA84320E2A6E99F8FB828E3C7790384DF5585D93FC368885D94E
                                                                                    SHA-512:F9D3B296E14D72F4BFF727ACFDCFB520AE1436BA5DED03BE04A559F493D4A8F9F915C0A2F498214309D0B84D6B3AE29750186615AE3250AD218AEB09DD7175AB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&w............!.....@..........~_... ........@.. ..............................ff....`.................................$_..W....`...............................^..8............................................ ............... ..H............text....?... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B................`_......H............>..................x........................................0..Z.........}.....E................$...+/..(....}....*..(....}....*..}....*..(....}....*."....}....*F..}.......[}....*.0..A........{....l#...`.!.@(....k.."..I.5.."...@X.+.."..I@6.."...@Y...}....*....0..*........{...."...@]..l#........4.."...@X...}....*2.{....(....*6..(....}....*2.{....(....*6..(....}....*.0..:........{....(......"....4..l(....k...Y"..pBZ*.l(....k...Y"..pBZ*...0..*........{....(....l(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):95788
                                                                                    Entropy (8bit):4.75506671884912
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:1ernxRpKZkJklUHHIWNVXVxYGGGGGGGjQYXHEmM7F7MlXZE747fBL/zdx:cbKK1NVXJTXkt7F78e747fBLJx
                                                                                    MD5:2056464074215066D3D06ABBBA1A0519
                                                                                    SHA1:C2D459A790CB21AA1C8FA92F55B96804AEFB78AA
                                                                                    SHA-256:CA3492F46E271C70182D04783B4731C6A6EAD3659FFA22EC02A758B3905E8508
                                                                                    SHA-512:EEDEF1F1DCEAD2F15928D24028C62B518F7F6B89A4E739B64C3C1FAE0B1123DC9C1A6CE024187CF2656CF5620CA670858435AB6D9C34EF9A99E283B1C14BCDF9
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p.......#~..$.......#Strings........ ...#GUID...4.......#Blob...<t..|...#Pdb..................?....3....$...C...................?...G...........=...F...................[...d...3...<....!...!...$...$...(...(...-...-..Z4..c4..p5..y5..36..<6...7..!7..,8..58...9...9...<...<...@...@...A...A...[...[..|b...b..0r..;r...z...z..............................^...i..................M...X................................\...............3...;...H...P...]...~...........................$...,...9...A...I...Q...Y...a...i...q...y.......................................................................'.../...7...?...G...O...W..._...................................$...w.......................................(...I...~.......................................................[...y...............................................................%...-...5...=...E...M...................................$...6...>...P...X...`...h...................................................%.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):274944
                                                                                    Entropy (8bit):6.122733859346656
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:IyfsmUCs3Zchh2UBSFKu033XbEUsHBEAT0C:Iy7UCs3Z22UXuwbkHBX
                                                                                    MD5:C52A44933D17D576D4C97B4CB0545841
                                                                                    SHA1:092696FDCC034910AA02C94A5C93F4E1E86E0C50
                                                                                    SHA-256:A0AF255EA4B09A8CDB995B8C6FD1075E46F098E23C2351C974E6DED9B8B620CF
                                                                                    SHA-512:8273DDB86A54C4834D469BBC856D1793C86F2577E21411F30083D4E597427170FD9CA38DA2E86F081D284043D5EA4A6D3330037EEDEDD17E37AA885927D0A76D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!.....(...........G... ........@.. ....................................`.................................8G..S....`...............................F..8............................................ ............... ..H............text....'... ...(.................. ..`.rsrc........`.......*..............@..@.reloc...............0..............@..B................pG......H..............................L........................................(....(....*..(....*..,..(....&*.0..1........{......-.r...ps....z.|......X.(.......3...X*..+.....0..9........{......|......Y.(.......3...3..%o....o.....o......Y*..+.....0..9........o....t........q....og.....M~....(....,.~B...(P...*~;...*..{....*"..}....*:..}.....(....*....0..[........(......}.....~....}.....{....,:..i........}......(...+Z..(....}......+......(......X...2.*..(...........}......(...+Z..(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):42824
                                                                                    Entropy (8bit):5.092626203240039
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:wIla9Y6ZBiygU1v+cALYbshPln6wWxwAU/fHKcnLQ8:CO0zWcQEIlnxF66
                                                                                    MD5:2883C3A35927E62EBE1871C130E93F31
                                                                                    SHA1:1A7C10AA582CCEEBFFD9BC77A11353AAAE6417E9
                                                                                    SHA-256:4109CFFF6E17D9BD2EFDC7FD52A4F544B5C66C9743C9E8CCF7D8A2F6CFC23EB7
                                                                                    SHA-512:9BC6CDAE59163756F9110867353E513CF53003A2C171E9458D920D83A8D025AB9DCFFC3278309223E9BA257B88CDB3F7F5C23BA78BB8CA4168B74F91DACE8658
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....M..#~..0N......#Strings.....T..0...#GUID....U...M..#Blob...........#Pdb.......................3....P...l...H...;.......T...........4...<......."................................... ...)...6...?...........*...3...................$...-...a...j...............&...........G...P...k...t...................{.......V..._...................................p...y...................................c...l............'...(..=(..H(...(...(..6*..A*...,...,..r-..}-...-...-..........B/..M/.../.../...2...2...3...3...4...4...5...5...6...7...8...8...:...;..R;..];..@>..K>...?...?...@...@..UA..hA...A...A...A...B..JB..]B..}B...B...B...B...B...B..EC..XC...C...C...C...C...D...D..gD..zD...D...D...D...E..$E..7E..]E..lE.._F..nF...H...H..5H..DH...H...H...I...I...I...I...I...J...J...J...M...M............Q...........................7.......................................,...9...A...N...V...c...k...s.......................%...6...Q...]...j.......................................,...l.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4435
                                                                                    Entropy (8bit):5.041234547281355
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JdJo8oHeJk+Okv3AvtiI6jS0rw4I0tHBS/NGudf/81/K31JMJ2NeXvSnT/4l6O1o:3u8E+jrc2t/D6YKIlDqarA
                                                                                    MD5:93A53B2B4B8B91292CE112E3EC1749DE
                                                                                    SHA1:CF42645FFDE1A4BF2309006E9C17CFF76B521B74
                                                                                    SHA-256:F94FC0202B9CA55F73B589108955F878AE37ADF275792CF3FF650DE5C6F90159
                                                                                    SHA-512:8F1F0353504CAA44C72980411960064A7D7319B0B4B162A0574B076C47ED40E8D43D7EF7709E768FCBD004B6F42F7097648C1398368D094E52595548BBB9F287
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="UTF-8"?>..<ArrayOfSerialNumberDescription xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.... <SerialNumberDescription Product="3100" Model="S4W 8-0-0 GSM-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.... <SerialNumberDescription Product="3101" Model="S4W 8-2-2 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescription Product="3102" Model="S4W 12-2-4 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="4" DiCount="12"/>.... <SerialNumberDescription Product="3103" Model="S4W 16-4-4 GSM-XIO" Market="1" AoCount="0" AiCount="4" DoCount="4" DiCount="16"/>... <SerialNumberDescription Product="3104" Model="S4W 8-0-0 4G-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.. <SerialNumberDescription Product="3105" Model="S4W 8-2-2 4G-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescriptio
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):185544
                                                                                    Entropy (8bit):6.1143984102987075
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:I8eNPCLiHSIZ8gcAx081w88sss9wNACJ1xZ7iOo7EM22PBdc:xeF5HSIwHACRVS9P8
                                                                                    MD5:589E1B764C0DC53BF645054960626AB1
                                                                                    SHA1:A5616537CA4E4AD5EB0BEB48863AE65E9EA91080
                                                                                    SHA-256:1C7FA94DE5E727852934387B6B0094ABC16F660C6C91B38FB3F5BC580CFBDC1F
                                                                                    SHA-512:DFD6924DD7BAF7EB1B8D3CC862FD7FB4A311818EE5684C7A85E3106EAD0F3DAE2A79956AAD9B5404C88A1D2607CAD627D0EFD729E9A9C1C1425B907884FBD1D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...E..T...........!..................... ........... ....................... ............`.....................................K...................................h................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H......../..............p...u2..P ......................................d.G..n.y=.v..].....Y...wE...#.".q[...f..N....k.:sj.D...q.`6o.........A..zt..P.6.+..{8....(...'_L[...X....~..yr....Z>/..t.8..0............i...X.........o.............*..0...........u......-..(...+..*..0..$........u......,..*.u......-..s......s....*.0...........u......,..*.s....*..0..$........u......,..*.u......,..o....*.s....*B...o.....Yo ...*....0..<........o!.....E............+..........*..o".....*.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):278872
                                                                                    Entropy (8bit):6.160790996358575
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:W8VV2gG5QRPQiIK+58lx3F4ZSnDdNbOFZxAK8Jy5TALKSLm/sHOjrBFC95:W62TqBaKC8lBgSnDdNomKvSLCsujrW
                                                                                    MD5:6813EBECD58E557E1D65C08E2B1030AF
                                                                                    SHA1:4DC95C499CBE862D4C6A4FCCDE71B2869F07E279
                                                                                    SHA-256:895819BDE598F710ED62CEE50E8BAC05EEFD42DDA64DE60E7D8DE8898082CAE4
                                                                                    SHA-512:0BC8B0AF27D565F604F49733BF5BF643F360F1C78FC29335F3415329C93DFAF4CDBC2923DCD1D3025249A64291C112893468B3DDD7BBF2050F8E671AA7ECC96E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!..... ...........?... ...@....@.. ...............................D....@..................................?..K....@...............*..X....`.......>............................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................?......H.......,....U..............9d..P ........................................./T.#<..G.M...&tuW..|.......5...n.NB...6S.&}I.......$I..7.....g....g.....8.t'..@K9...0g[.6~.l.2...m...e2...iN.qO7...<...>...Y.0......................#........(.....*Z.........(......(....*..{....*"..}....*..{....*"..}....*....0..7................(.....(......r...ps....z.(.........(....(....*..0..`........u....-..*.........(.....w....(.....w...(....-...(.....w....(.....w...(....,...(.....(....3..*.*R...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):109400
                                                                                    Entropy (8bit):6.071956198915581
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:G+s08khkhGbYzCripb/8JExywW9lGW7MPSXfciFTd95:G308khN8IExyrSWGKv
                                                                                    MD5:9722713E648F42B57299E9D2CF3D5C1A
                                                                                    SHA1:A4D0DC4F09CE84A33F1AA3E0C5CB4AE131F9FB0C
                                                                                    SHA-256:BC3A78EB4DF2FD5B39244FA0586CC0A82FE3D0E185D151E6C340C53072A61872
                                                                                    SHA-512:F6BB5724DFC46476E94448ECB4650AD23197CA21965EDF923E5D8BF51A31A707C058BCA6CBAC8E40E324BB54944DA4129659DC2D2FC965E260BD40123A8AEEBB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!..................... ........@.. ..............................~`....@.....................................W.......0...............X............................................................ ............... ..H............text........ ...................... ..`.rsrc...0...........................@..@.reloc..............................@..B.......................H.......l...............0~..9<..P ..............................................~.mM.z..L..#....K...L.eY$.....R.1.........wSn./.\fl.........h..../..U9..$$.......... .....e.TY.y><".#/M......"..s!...*..{#...*"..}#...*..{$...*"..}$...*V.(%.....(&.....('...*F.~....(*....d...*J.~......d...(+...*...0...........t......o....*..(6...*..{....*"..}....*..{....*"..}....*F.~....(*....e...*J.~......e...(+...*....0...........u.......(,....e......o....*.0..m........./.(....s-...z.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):95064
                                                                                    Entropy (8bit):6.069925755579635
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:ejt4SdWiPPH+PhqaEMN+3esQG0AZGblWfp8/x1il5OvNYXBTfciwN9rHUj:ejt1Yi8KUblWfpqwdXBfciwN9o
                                                                                    MD5:22D9D032858972B8EE628FA818AB04DB
                                                                                    SHA1:6EEAE133E394292C6C349F838114C2A39DFE8357
                                                                                    SHA-256:E3D7F794442D9DBE99F5D578C0BC8D9E3198FE4055CF5581FC1DE78085967C50
                                                                                    SHA-512:6899B2650AAFD1E88049303C7EE26FF7E0DFE201D8A7188386EF2354DEEB32F611BB4B73A02BE9127FC96D5B4D37CAB9BDBEC3CFCB3BF4CADA43170AC4349E0F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!.....R...........p... ........@.. ..............................0j....@.................................Pp..K.......8............\..X............o............................................... ............... ..H............text....P... ...R.................. ..`.rsrc...8............T..............@..@.reloc...............Z..............@..B.................p......H.......L...`...........xr...I..P ......................................g......o..g.Y...O.*....o.d....y.R2@...C.l0.HI..UV..U.(..K32[.`[@J&%~*&.;...+.n8...I[b.w.....KT.'y..j7=!p9R9<.u..........h."..(....*..{....*"..}....*..{....*"..}....*F.~....(.....Y...*...}.....~......Y...( .....}....*...0..-........t......{....-....(!....Y...o....(....s"...z*..{....*....0..F........{....,..{...........s#...o$.....}.....{....,..{...........s#...o%...*F.~....(....u]...*6.~.....( ...*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55904
                                                                                    Entropy (8bit):6.299047178318044
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BYQaIZaEmaOQxn6JxKjtlMZAnuETAV+w4:aIhOQcSLAj4
                                                                                    MD5:580244BC805220253A87196913EB3E5E
                                                                                    SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
                                                                                    SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
                                                                                    SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):86168
                                                                                    Entropy (8bit):6.045998280536677
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:NV+Qu8/p1r+Cg0S+xik+WXZw+QQLaJNC8pNYw+WXsA9iYvYBS:ic1/gp4QQuhpNt+WXsoES
                                                                                    MD5:4CCA26E7EE11419A33960E7428E8972D
                                                                                    SHA1:86807367D7793299BBB2F558B41EE6641E2587D9
                                                                                    SHA-256:81E1FD52AD744AEBCA2E9F320FE871CCDEFC1B52210CE6F04D4EC8B9C54554B8
                                                                                    SHA-512:F7E0BF39F34E6760A7DBFB0D55379D01C2D23B6F22BB04CEA7A25708B050F4C6C1C8508F9A1E9B25DDD86A7A6A1AF47E982E13CB151A740A32A15228041C3644
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........GE...E...E....)..D....)..D....)..W....)..H...E...=....)..F....)..D....)..D...RichE...........PE..d.....JT..........".................p..........@..........................................`.......... ..................................................8Z......,........<...p..(...`...............................p................................................text...|........................... ..`.data...p(..........................@....pdata..,...........................@..@.idata..............................@..@.rsrc...8Z.......\..................@..@.reloc..(....p......................@..B................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):86168
                                                                                    Entropy (8bit):6.045998280536677
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:NV+Qu8/p1r+Cg0S+xik+WXZw+QQLaJNC8pNYw+WXsA9iYvYBS:ic1/gp4QQuhpNt+WXsoES
                                                                                    MD5:4CCA26E7EE11419A33960E7428E8972D
                                                                                    SHA1:86807367D7793299BBB2F558B41EE6641E2587D9
                                                                                    SHA-256:81E1FD52AD744AEBCA2E9F320FE871CCDEFC1B52210CE6F04D4EC8B9C54554B8
                                                                                    SHA-512:F7E0BF39F34E6760A7DBFB0D55379D01C2D23B6F22BB04CEA7A25708B050F4C6C1C8508F9A1E9B25DDD86A7A6A1AF47E982E13CB151A740A32A15228041C3644
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........GE...E...E....)..D....)..D....)..W....)..H...E...=....)..F....)..D....)..D...RichE...........PE..d.....JT..........".................p..........@..........................................`.......... ..................................................8Z......,........<...p..(...`...............................p................................................text...|........................... ..`.data...p(..........................@....pdata..,...........................@..@.idata..............................@..@.rsrc...8Z.......\..................@..@.reloc..(....p......................@..B................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):316
                                                                                    Entropy (8bit):5.139299833202651
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:0CJOL2VUiTTPCXYaLL/XTbJRLQuCcWOM1mUi9t9VZAZy52Z:D02x+16czzO
                                                                                    MD5:205F72A8D398DD9D8F8203C3C09DABF0
                                                                                    SHA1:F3E10CF8E53340A14C7974270CEA4C6E222A06F0
                                                                                    SHA-256:D803BBBD5F50007ADB1EFAA0A6BA4519D17A29A5D7BFEDE35B026B1AECF7C000
                                                                                    SHA-512:86C5CBCBB1DB601AE5FB4438B8D05EFC982AA14956615E2A6C15617345A4B61A071CB76704F5CA00BB485348DA13AF8CE66246E085A94DE971FAE59A30273AEA
                                                                                    Malicious:false
                                                                                    Preview:<environment>... Culture et language de l'application-->...<culture Language="en" LanguageResourceFolder="en"/>... Contrainte OEM pour la personalisation lors de l'installation-->...<oem Company="LACROIX Sofrel" Product="S4-View" Copyright="Copyright (C) LACROIX Sofrel 2014-2021. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text
                                                                                    Category:dropped
                                                                                    Size (bytes):312
                                                                                    Entropy (8bit):5.162603522244943
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:BMtdh0OL2V1i4TPCXoULL/XTbJRL5uCcWOM1mUi9t9VZAZh2E:6V002THTfu1fczzQB
                                                                                    MD5:CF49C77F36FB96C2E95103D6D287442A
                                                                                    SHA1:B122847FA16103B2F315E6E2A0BE004F38668892
                                                                                    SHA-256:106BC8F7CABC7945C59185F89B333E324D2571DEF21340497A4C8B7DC3981829
                                                                                    SHA-512:94C463EA72B9E329413D0BE071A93A09C7810AFFCD578AA1E76DE9BA1826D2177B9F9DDC4F6429F357AA2486B91CA67D7538A43F189D1A8DA56A49A8E599E7F7
                                                                                    Malicious:false
                                                                                    Preview:.<environment>.. Culture et language de l'application-->..<culture Language="fr" LanguageResourceFolder="fr"/>.. Contrainte OEM pour la personalisation lors de l'installation-->..<oem Company="LACROIX Sofrel" Product="S4-View" Copyright="Copyright (C) LACROIX Sofrel 2014-2021. (France)"/>.</environment>
                                                                                    Process:C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):858
                                                                                    Entropy (8bit):5.276224357412578
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:4gYhAVBEdfsgPoAVBmdfsgPoAVBhdfsgPoAVBAdfsgPoAVB8wZdfL:4XhAV2FaAVwFaAVfFaAV6FaAV6wZFL
                                                                                    MD5:FE0FE2F2CB394E541F1AD17110913AA2
                                                                                    SHA1:ECE65CD44C016AB41E1C283F6B4238E9A47FBD0A
                                                                                    SHA-256:26A0A16782692C30C716E76106E652D084B137F9BBEFEF8D65DE01813150B94D
                                                                                    SHA-512:47D319EB2E6A18F6CB651BDA6389592077E3FB885D03BCCFEF7BB5C655BB2A2596C12AD29C5E26AFA6C844C7F78AAD300AD571EAE4BD1B2AFA6AD362BA907B37
                                                                                    Malicious:false
                                                                                    Preview:NO CONFIG TRACE 2024-10-14 03:48:49.879..Error.TrustZoneMigration.The expected directory located at C:\Users\All Users\AppData\Local\LACROIX Sofrel\S4-View does not exist...NO CONFIG TRACE 2024-10-14 03:48:49.910..Error.TrustZoneMigration.The expected directory located at C:\Users\Default\AppData\Local\LACROIX Sofrel\S4-View does not exist...NO CONFIG TRACE 2024-10-14 03:48:49.910..Error.TrustZoneMigration.The expected directory located at C:\Users\Default User\AppData\Local\LACROIX Sofrel\S4-View does not exist...NO CONFIG TRACE 2024-10-14 03:48:49.910..Error.TrustZoneMigration.The expected directory located at C:\Users\Public\AppData\Local\LACROIX Sofrel\S4-View does not exist...NO CONFIG TRACE 2024-10-14 03:48:49.910..Error.TrustZoneMigration.The expected directory located at C:\Users\user\AppData\Local\LACROIX Sofrel\S4-View does not exist...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71808
                                                                                    Entropy (8bit):6.302233040356993
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BZb60QnEfniRuc4MG7uKMgM1lBa/0jSNgDWcLbtNnstX1Ac:BZcEfni4c4MG7vKFLLjwX1T
                                                                                    MD5:391166F9D5D40EE90F0744982177F4AB
                                                                                    SHA1:F7DFF35B30DE2E02BCB3A7EFE45334E1B5D7C8FE
                                                                                    SHA-256:FA36ED1236CDA36DFA34BE757A791EC94011D43D19E73D0BD9D0F9F802473A22
                                                                                    SHA-512:700FBE5FD992F678C83CCA1170F68593149C04E314402F7505B8A640FA89CD24633426ECB3548057E7AF14F0342301E66B5785F01F7FDD64ED2AF13614CD98EE
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`."Q...........!..................... ........... .......................@......2.....`.....................................W........................>... ....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........t...w...........]..0...P .......................................v.{....On..O.w..-t..x<P....e.@0v.bY>.7. %c.\.h.J....MW......P.w.J...(...3^.....>M.............(WIH....1..../O}.}...gOm...{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.*6..(.........*.*.*.*.0...........-.r...ps....z..2...o....o....2.r...ps....z..2...o....2.r)..ps....z.o....,..o....o....-.s....z.o.....o......o....,..o....o....-..*.o....-.s.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144496
                                                                                    Entropy (8bit):6.219127874938619
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:0RZlEOzBzB3yZwUDXSNhB+IIx3zUOEF7xQQwQQQQQQTreulTnXGZFfHjKUhcweTo:0RUONhhUDyhB1IRUOEoUjHBhT/nLN
                                                                                    MD5:5BD39A82AACF1AA423E6EEEEDA696EEA
                                                                                    SHA1:B7971F9807520DAC9523BFD1185A7DCC9E5CC77C
                                                                                    SHA-256:1D69EAF538008E0FE1A7EB2CE0124A49B95C491797749640C8351ED4643F5C97
                                                                                    SHA-512:CBD255E7323A7E82D8B9443E8CE67BEF88F88BF46E525333E4017024A31952656F61F93334B3957D85FB0E422E561197C0ADB1366653DA007C9667651B1F37B1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[."Q...........!..................... ... ....... .......................`......a.....`.....................................W.... ..................p>...@....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......$...h...............c...P ...............................................\.E..-.....A.}.8.p. 0AF@4.....T.P\...S.aEf.....$..m..G.h......Q.,.2....N..jE...QD.V..<i<(*".\q.7_..;.ge. Q[..P..{....*"..}....*F.o....r...p(....*..0..C........(......~....-....7...s.........~....(...+(...+(.....(1.....o....&*F.~....(....t....*6.~.....(....*F.~....(....t....*6.~.....(....*F.~....(.....j...*J.~......j...(....*F.~....(.........*J.~..........(....*F.~....(.........*J.~......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):139888
                                                                                    Entropy (8bit):7.142634633787823
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:TNZyjlo+Ib/RorkWhl/pNODb6lwztxdbbDFlkYUo8:TNYAb/2rk2l/jkb6uzj5Qo8
                                                                                    MD5:18DB3E02D95A16FD502C7C091C0361D9
                                                                                    SHA1:AB2D700306E0A0A3D094A0BC856FF1FFAD916C49
                                                                                    SHA-256:34843CFEA24B713B1B5FD9A93C61D7C6D3FA320DBB84DF60D9D48C5560C79452
                                                                                    SHA-512:6DE8751ABED256BCC381F69248F33AAE551A17966EFBC0ABB5C1DC98865B46E3924202C1347E0EC6949F1719E1D282817838815E99E68E7B1381A6B204C95416
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...]."Q...........!..................... ........... .......................@............`.....................................K.......................p>... ......X................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......X....K...........M..._..P ......................................Du..l..O..(|.n.....z.fj.W4.mc....f...>e..~.V....<../..}....1$q.7@r..3w..JQ....._C(S....C. .Z.Pt..d,......f-..]..".SO.7.4...x.0..:........(.....s......r...p(M...o.....(.....~....(.....~....(....*F.~....(.........*J.~..........(....*F.~....(.....+...*J.~......+...(....*.0..,.......s.......(....o......(....o......(....o.....*F.~....(.....+...*J.~......+...(....*....0..3........t.......(...............#..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):108168
                                                                                    Entropy (8bit):6.179559450110609
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:hf+YSZc1rj0oek7u05g3XG5rs+eUvNL3NX5S8caZkvsd65FAU9Qyx1NElSJK/Tr:R4ZYrj0oeOg325ragNDNP+AUzqSJMr
                                                                                    MD5:3034CC0D5CF3731ED90153AA616F3F59
                                                                                    SHA1:AACE8D26358D9829F0E6632BDDF183534ACFEC0D
                                                                                    SHA-256:63CD5E8A60D77D1007352538A4285C60C0C3EFB9C771035589105A284E4F63A9
                                                                                    SHA-512:88589B022D713D565342E331394ED5600D1FE346AA788E45E16CF51221CE898F10BD28C6A09FDC44D9AD94F25B4ED22C6F0EB28FA832863C01732DEF5B6C6086
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X."Q...........!.....^..........n}... ........... ..............................C.....`..................................}..O....................h...>...........{............................................... ............... ..H............text...t]... ...^.................. ..`.rsrc................`..............@..@.reloc...............f..............@..B................P}......H.......L...................1...P ......................................Am.........C.....7.7....|..........,...w?..T....A.e......I}.#N..E....~...y. x`E......C`A&P.....Y.....A..J......#.p..).uGkJ1:.(......}....*:.(......}....*...0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*"..(....*"..(....*..*..{....,..{.....o....*.{....o....*2.~....(....*6.~.....(....*F.~....(....td...*6.~.....(....*J.(.....s ...}....*F.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):62160
                                                                                    Entropy (8bit):6.394651976589669
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Lu5fLsPcyp/79lGhbTfpp6tpJbox15i4R5we/MvSKi0cOEwC7:y5fQLMhbTfpp6tpJsx1R2eMqK2WC7
                                                                                    MD5:B5BBEE69523810F8AA9D92E3D3ECB896
                                                                                    SHA1:9A45F181AC22B5C633EED421B59F5FE9D12D6A7C
                                                                                    SHA-256:BF99695470075C4E2C906BE4567F1D0AB3A6D85D31EC1D8F6B4139015C48A2B3
                                                                                    SHA-512:9EEFF3BA247793163FD091FB26D8E620C99A8CB1B510F26EA7C31EB9EC27F2DE9E92F14CA470852C84FF1DCCF5FBCBAED8C93EA2F05C6515E2C078776C62BA7E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...a."Q...........!..................... ........... ....................... ............`.................................@...K.......`................>........................................................... ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B................p.......H.......PE...............D......P .......................................xk.r..E. z.aD.-$..}...=..+<%...Z....x.N.,..D...nA*....1T. 6./n.`j..."q..rE........44.(..a...\..>...~.......9.M.).#..c.0..W.......(....s.........(.........~.....(....,+(....~....~.....o....t>........~....(....&*(....*j~....%-.&~....~.....o....*.......*2~.....(....*Z~....(.....o.....?...*Z~....(.....o.....?...*.(....,.(....,.~....(.....o....&*(....*.(....,.(....,.~....(.....o....&*(....*Z(....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48344
                                                                                    Entropy (8bit):6.53421522959476
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:4L/YzwmxRqw+4aECjhmUYVmePi+6bYKN4:aMxRqF4BCjhmHPZiYKN4
                                                                                    MD5:06296D204C279118CB8863F07E3DE4E1
                                                                                    SHA1:175553C011BA3B50322833477F095142F1C3D699
                                                                                    SHA-256:CEB0E446953833CAA54BC01E84B787281CF6712BA7DB65D4C9A664413E95CEFB
                                                                                    SHA-512:BFA4479554B841A17969D124FD69701DC1313E8F24EAD667C45002AE8D60C3F615D8D484D1334C87E5C93F1FB30B8217A0CBD528125EDFFEF050B898BDC1598A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."Q...........!.....t............... ........... ..............................~H....`.................................l...O.......`............~...>..........4................................................ ............... ..H............text....s... ...t.................. ..`.rsrc...`............v..............@..@.reloc...............|..............@..B........................H........p..L!...........0..&@..P ........................................9q.}..;q._^.X.A...&Y..n._=....*...%...'.Dc...S)..C....W.....k.Q......l.U.v.%...l...."ITo.Z".w..|-:.L%5g..cy':....=.6..Z.bF.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*..{....*"..}....*..{....*"..}....*"..}....*..{....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):211632
                                                                                    Entropy (8bit):5.3707738806905905
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:3TdnDzOb56Xp6kGijb7N5KH+KnklI7o5UuL8J:3TdnDCbgX4ecoY
                                                                                    MD5:B8ACA033D81112E38EEA7B9525F1BD56
                                                                                    SHA1:7428C64C3E68DD45E89FDFEBA08F75F1D3A49B29
                                                                                    SHA-256:D750B661263AEFCBE961942D15C2DC507DA6361748A8E65426963274B5744EE7
                                                                                    SHA-512:045E2D152DD2AB8AB64BCF0B32ACBEDC2700018A354E26C9ADB2D26C7390D648A51903DFA33FC61CDDAF2DE6B5DC38D3F0745D37AB8BDB9328566EE48806892E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ......~.... ... ....... .......................`......q.....`.................................,...O.... ............... .......@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):415408
                                                                                    Entropy (8bit):5.573182313694346
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:fXvGO+uec6A3HQ0nHajgLx+lkMPSDt2nb+6PVM0H+ULFpUKiw9OBTj1ESZ31W:fOO+66OCoMna6PV/H+UE1xZ31W
                                                                                    MD5:4DDB62841065A6587A5CF72944AA996B
                                                                                    SHA1:A437A112A19F4220E18A6C8E764D73E315F47ADA
                                                                                    SHA-256:AD18F28213EBC685A4E6F38CEA549F85DEA2E51025F4D08F672EFCE128FF105F
                                                                                    SHA-512:161A169FA60CFED2D67F135E0DBB6932FCFCA0676B6E7BEACF4BA9FCE35E887DE0AA3BBBA76EABE173CBBCD060ED8325E0C732BCFBA9E486445D5E516F5CFE8A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....2...........P... ...`....... .............................."G....`..................................P..K....`...............<..............hO............................................... ............... ..H............text....0... ...2.................. ..`.rsrc........`.......4..............@..@.reloc...............:..............@..B.................P......H....... ;..H...........x....2..P .......................................q.+.$.~..n.P..8\.^._.v)..&Y$..".....-.]%..^...Xjf'...D......m..,e74.n..O.-X~h....%:$U=.....A+........v..g....P..u.....Rs..O.]..(-...*&...(....*.(....s/...z^.(......9...(2...o3...*J...9...(2...(....*.s....*..(-...*&...(....*.(....s/...z^.(......Y...(2...o3...*:.r...p..(....*....Y...(2...(......(......(....*F.r...p(4........*J.r...p......(5...*F.r9..p(4...t....*6.r9..p.(5...*..o7...*..o7....(....~....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):368816
                                                                                    Entropy (8bit):5.365214438266103
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:KrNvoFXHxeLeKdwU1SzZiZ5pbC7K4vQg7wwhFQSamkV8EvA3PXiD3fm553inDg8I:KxPeRiZ5nqwSuzvAsu5Jiq
                                                                                    MD5:37742E95B192B5B3F8707C2487A70BB0
                                                                                    SHA1:74F0A74F1E8F1513FFF13CD4D7A60658F59DC856
                                                                                    SHA-256:B410452B0A9BDBB8C860169F669A8E051AFB51FA53030D31E8667E5FC1B9C445
                                                                                    SHA-512:174F5DFD8DDD1C31D707F8EC0EAB29B9E563DE7DEC85A1F32BCB658E43309CE48F0BACF75964C1CDB24AFB5014D17E0DA252B7C2C7B585A9BB8430792A87EEE5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....|..........>.... ........... ...............................5....`....................................O.................................................................................... ............... ..H............text...D{... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B................ .......H........+...m..........(...._..P .......................................G.x7tf...r|-.}...)e{.@.[......y.P...Rt...@...a..o..%9 ..n...!.M<...u...QM........l..MVNU:G.D...5#u....b$.3N_...'.....EZ.r. v.s!...}.....s"...}.....(!...*...0..6........x...(#...............o$.................(%...tP.....*...0...........s&.....*2.~'...o...+*...0..m............{....%....((....{.......o)...,.....A...(a.....(c....o.........(a...o*.....{......o+......,...(,.....*..*...........Y]........-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):140432
                                                                                    Entropy (8bit):6.059133240260085
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:z5cEGcPGEuEz6C62cxocEt+7f0YuuriDjNcYEhPoBj2bRViOsPKJKPfqIn37nNfv:z4ciEl6pJ7f0YuuAKA2XcnCyKY+8rz
                                                                                    MD5:4CBC7B9D057E89C6A5BA313F6C2F036C
                                                                                    SHA1:BE57AE313DE841F987D0AE4CF9632E5F155955BE
                                                                                    SHA-256:EB8F7CECA9DFCA2080A8A9C30EBF49298778743F288A289970846D02074C5322
                                                                                    SHA-512:63077C81B1C0379FD86BC88571F8AEF227B449693C0B015BEEEABD99C3033C644F17AB089BBC55594C0FF98BD302C503C435B992DD7E83876CCB2111483CF902
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!..................... ... ....... .......................`...........`.....................................S.... ..`....................@....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B........................H............I..............%..P .......................................f.>dT.j.P..s..K..K...|"Y...r...^. ....}1k..mu...Q'Y......4..;b0.....\Y;....W...1..I...{...8...9M..-....,.......x...vG.IQ2..{....*"..}....*..{....*"..}....*..{....*"..}....*.sI...*"..o....*.s....*.*B.e...((...(u...*....0..........()...o...+..o....*...0..^.......()...o...+..,N......((...()...o...+o..........((...()...o...+o..........((...()...o...+o.....*...0..........()...o...+..9.....r...p.<...((..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27792
                                                                                    Entropy (8bit):6.1321477705881335
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:FBg0ucz9tgkgZWJkkgZWvvwKuk4WBul+S2vKURa5kMac1WkrzvXS9//0GftpBjBh:FBgbch/vxnRakBcbr+8iN
                                                                                    MD5:8AD746D4BB9B64AC5F0CE29896162259
                                                                                    SHA1:79041040D9CC0070B9DCE4026466B195BFF78EB4
                                                                                    SHA-256:F4043D2182666F67ACF71449EA60477DBDC577B1A09574ED6562A5C3FA6C42A9
                                                                                    SHA-512:D38CA6AE2133F231E89E15A7470E24D477F9D1DF7838E793FA427E048EBBADE1618EB08CDA30FFEC72080ED4EBF2EE2A897AB9D575C205EFBC4FCA92C88E0456
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....H...........f... ........... ...............................<....`.................................`f..K.......h............R..............(e............................................... ............... ..H............text....F... ...H.................. ..`.rsrc...h............J..............@..@.reloc...............P..............@..B.................f......H........7..............P-......P .......................................(>..P.^+..Vf.......y..Cd.^....kL*.C..d.....J.4.3..P3.}..1z...9...a>..uF..XR.o.(k.:.C3.R....:...../K%n..........e.S..(...........s....}............s....}....*..{....*..0..@........{....,..{.....{....o......}.....{....,..{.....{....o.....o....*..{....*^.{.........}.....o....*Z.{....o....u.........*..0..J........(.........-...( .....(!...*.("...,%.(........("....(#...o$.........o%...*..o....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):41616
                                                                                    Entropy (8bit):6.118366181712053
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:/1UUBVS1yKegy8XiOYgzECu0WIbHzVfQ+t9yIor+8ie4:tUTy8XVnzECTWILufr+8u
                                                                                    MD5:7A271CE5582DDCC325732581A533D8BE
                                                                                    SHA1:5FA2C5390EE84BF975C861AFA361D2E17AC9F625
                                                                                    SHA-256:9202C7E903172AE1855AB96EE5D80248292B86100A843DDCC6DB664CD6EDD1B6
                                                                                    SHA-512:43F575A8FDB98565358C7C5C3FECA78A9154CDDAE6BDD1AEF1A2B108B0650059257F8983B9A1E544C12586807303D2C4F440AF0171295EA284C8F7347D24BE70
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....~..........>.... ........... ...............................&....`....................................S.......h............................................................................ ............... ..H............text...D|... ...~.................. ..`.rsrc...h...........................@..@.reloc..............................@..B................ .......H........:..._...........1......P .........................................%]..?.....V.AJ3Z^f.6g.u4.5cJ...+8.j....c;...PP8......6...T...9..kA.u;+U.na6\.......I.c(.J..L.....h.K[.!....s!Sdr.Q><S.&.0..*........-.r...ps....z.(......sG.....o.....o.....*...0..........s.....(......o....o......8......o......o....o......8......o.........o....o......+S..o........o....o......+#..o........o.....o.....(....-....+...o ...-.....,...o!......o ...-.....,...o!......-...o"...-...o#.....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14496
                                                                                    Entropy (8bit):6.327509765949796
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:rb6Oaxhqm1st8jjMfGkqWx/zB//0GftpBjcc3:rCwUQ8jjenj8i53
                                                                                    MD5:964AB2C3520B8A735329F0BE577C5850
                                                                                    SHA1:968EAB9103EC64A0DD4657582F28BB6FE9644209
                                                                                    SHA-256:DA3ABFEE09DDE110E4E9A0321F7223F7380A1052CB506313F44947E32F09BB5F
                                                                                    SHA-512:0BF393D15E64FB1A2BC0BEF663DD760E3ACDFDA503AEA185A83B904B01D612FA3AFFE7FFEC8780C23274D9B8E182B29CDD906CF8A0825569AB02ABBF4DE0AA61
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....="S...........!................>4... ...@....... ...................................`..................................3..O....@.......................`.......2............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 4......H.......(#...............!..X...P ......................................;.)%.6.h..q..O(-.`......&7.q.G..G1..J...S1.&..f....H.....bl....W(.E).K.RI..............8&Q.b......H+!df-.f..3h.H..h7|.]...(....*.0..3.......~.....(...., r...p.....(....o....s...........~....*.~....*.......*V(....ry..p~....o....*.0...........u!.....-.r...ps....z.(....*Z.,..~....o.....$...*.*V.,..~......$...o....*.r...p.$...(.........(......$..........s ...s!...("........*...T..............lSystem.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31376
                                                                                    Entropy (8bit):6.161352322277959
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:r27oPj3ZdGnwIDMIMoMMMIMIM408PUugN+8ik:rEorPGpUnN+8r
                                                                                    MD5:5C9985D31E098BF7DF031171E046D67E
                                                                                    SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                                                    SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                                                    SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):22768
                                                                                    Entropy (8bit):6.201382004474863
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:PF5AZ+le8+2KCYTzs2um7GH9SJSWcGvXS9//0GftpBjE4u:PF52+le8gR7GH9yok+8iyf
                                                                                    MD5:7C08EA125D8054BFA6057104590A7F83
                                                                                    SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                                                    SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                                                    SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):12432
                                                                                    Entropy (8bit):6.213812838430843
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:C349VlDs8a3XUVW2itvXS9nMTI/s/nGfe4pBjS735:Cq83XUVWNvXS9//0GftpBjU
                                                                                    MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                                                    SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                                                    SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                                                    SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18120
                                                                                    Entropy (8bit):6.226050809869831
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:U0xk42ZtyyslnQyrgbPyIH/rFzsX+cAW++2Wx1q//0GftpBjIc0:DVegwRe+c3S8iC/
                                                                                    MD5:E834E45855E8D220B0C5D0C1CAC24E44
                                                                                    SHA1:D8AAF831CF5B90A206EE9348386A72498AF0C0EE
                                                                                    SHA-256:78AC70411C71B7A0C68FE8746EDD3F3A8CD3F72044B329A40AB53C57891BE37D
                                                                                    SHA-512:F91A3FA6D522AD5F977AF744618D5ADC1A6CAEA0645D870E10962E00C03534CC3A9FA1D82001627F5B6FC3186BD51E3E69D16DD689C5E7CD4D84AC66AE9A63F3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......R...........!....."...........A... ...`....... ....................................@..................................A..O....`...............,..............T@............................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........&..d............$..O...P ............................................V.{..(.;.X5..b.2X..L.{.z7t.P1).qf...w.g....ik..:.5a..J.FK.e..mSgn9.cQM..9.B..ZLSy@..j.e...Z.......6..c.'...m1.{....(....*"..(....*&...(....*v(....-.(#...s....z~....o....*.......*2~..........*&...o....*&...o....*...0.............o............o.....s....z.*...................0............o...........o.....s....z.*................^......(.....o.........*^......(.....o.........*.0..<.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*47 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):24064
                                                                                    Entropy (8bit):2.8139684302156573
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:GDwjVAfAm3ACA4C+9p80/v/z+fyvx/ZsbwZ9SWCNHn3bmEPl33dD446DAE/f5ek/:GDwjsI+rHzhVxl7
                                                                                    MD5:1B0B75EA764B048A27B3205970D2FA0B
                                                                                    SHA1:2865C064AFD9CF51B7B5916E321870EB3FDAF952
                                                                                    SHA-256:2130C737EB69EB79A9ABC74DCD9BE2A733AAFD43174FB9C177601935A08A43F8
                                                                                    SHA-512:0012D14AFE49AE0A59ABE5451AC2A705E090311A4DA5AEB3A87DD6DB4982A26747AD18DB6421E9D500F4687D4AD5399C068037C4712606334608384FF2FC060D
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS.........../...........,...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.488842171019742
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6fhZMjDlMDH5lpoJDLYNMTwCRXQtPyqE4Ev/mZWjH1AglkAqVwAK5W1AxF:UoDlUbmJfzwCRXQtqqE4zWjugRuXaWu
                                                                                    MD5:23E59CC67C075C315F717770D46B00A6
                                                                                    SHA1:260D18B0BDBB8ADABB1A6D8565ACA14CCC462CB2
                                                                                    SHA-256:1E2636B145C0C69E30DB1492950EE23D02458DFE6DAC69EA51D865BA15FA0FDE
                                                                                    SHA-512:36128BAE654D5C58053FEF3EB8DCD54B7671DACB5CEA6F26C5340E0BC38579667064F169FE7FA744FDB40DEBAAA4CA040D749C1DA803A139594DF9E7D1D42284
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Y.........." ..0.............N'... ...@....... ....................................`..................................&..O....@..8....................`.......%............................................... ............... ..H............text...T.... ...................... ..`.rsrc...8....@......................@..@.reloc.......`......................@..B................0'......H.......P ..t...........................................................BSJB............v4.0.30319......l...|...#~......P...#Strings....8.......#US.<.......#GUID...L...(...#Blob......................3..................................................y.....@.....>.....h.................`.....,.....E...........T.....2...............................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........#.....,.....K...#.T...+.x...3.x...;.~...C.T...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):711952
                                                                                    Entropy (8bit):5.967185619483575
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:GBja5bBvR8Q0TE2HB0WLmvXbsVG1Gw03RzxNHgKhwFBkjSHXP36RMGy1NqTUO:GBjk38WuBcAbwoA/BkjSHXP36RMG/
                                                                                    MD5:195FFB7167DB3219B217C4FD439EEDD6
                                                                                    SHA1:1E76E6099570EDE620B76ED47CF8D03A936D49F8
                                                                                    SHA-256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
                                                                                    SHA-512:56EB7F070929B239642DAB729537DDE2C2287BDB852AD9E80B5358C74B14BC2B2DDED910D0E3B6304EA27EB587E5F19DB0A92E1CBAE6A70FB20B4EF05057E4AC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...p$?..........." ..0.............B.... ........... ....................... ............`....................................O......................../.......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................$.......H.......x...(9............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X..+....b....aX....X.....2.....cY.....cY....cY..|....(......._..{........+,..{|....3...{{......(....,...{{...*..{}.......-..*...0...........-.r...ps....z.o......-.~....*.~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2
                                                                                    Entropy (8bit):1.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:+:+
                                                                                    MD5:96A3BE3CF272E017046D1B2674A52BD3
                                                                                    SHA1:DDFE163345D338193AC2BDC183F8E9DCFF904B43
                                                                                    SHA-256:938DB8C9F82C8CB58D3F3EF4FD250036A48D26A712753D2FDE5ABD03A85CABF4
                                                                                    SHA-512:7B3E2F9860391685C2FF6785AB60541BB0DB11A20B7E511BF020F4B3073053CC36B647D82F520C5A1C323E853F4BB110FCE8210BA409FA42069AB4BF0B0D39E1
                                                                                    Malicious:false
                                                                                    Preview:01
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6246
                                                                                    Entropy (8bit):5.169925801769785
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:4itmxrs1rsy/QZ93OWZ7u2dOrsMrsSC13C3dinCY:4i2rs1rsyilHcPrsMrspdsdWCY
                                                                                    MD5:CD010DA4CF5B82714DBC32F3E05DF760
                                                                                    SHA1:C52F4AE980AF344F6C98DF74AA8117F6A2C7903C
                                                                                    SHA-256:15B8E85F410B23610E424681C010E1B2833C9805F977131713AD6F7DECF3FE90
                                                                                    SHA-512:8AA6FC03C353A83BCAB9E65D30C69B5393F1AC6C0181C0B8E357C85CC3A15C63C57D4FBC8082EB8DD539BC885B5AC2808A294ADC42A541EBDC6B06BAB5357CB1
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a double license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2019 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer... *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions and the following disclaimer in.. * the documentation and/or other materials provided with the.. * distribution... *.. * 3. All advertising materials
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3251
                                                                                    Entropy (8bit):4.82055320948653
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:nAf0rWOC0pAvwIHg28vx22nK5cHGg8czKVSpxsNxddItK+4WlA1QIFL:nAyo0pT28vx2iK+HGg8cnnAtpWl2
                                                                                    MD5:54548B258AC71839F1D1BA7A0CA19FB5
                                                                                    SHA1:428202CB596D72333B3852DC1367E8A18C297521
                                                                                    SHA-256:25F242473F5CF6BCDB0192F071EC9E78A6CB4E1E6CB887AD33002BA2EC1EBA6D
                                                                                    SHA-512:FF17E5A6C40976B7881B09B4BBD480423DF27441FB51366F7F4390D2E9A99243FE75FABF2F70F8AC267AC370D34FA1391398E98EAEC003FB00820FA438366A5B
                                                                                    Malicious:false
                                                                                    Preview:.. OpenSSL 1.1.1h 22 Sep 2020.... Copyright (c) 1998-2020 The OpenSSL Project.. Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson.. All rights reserved..... DESCRIPTION.. -----------.... The OpenSSL Project is a collaborative effort to develop a robust,.. commercial-grade, fully featured, and Open Source toolkit implementing the.. Transport Layer Security (TLS) protocols (including SSLv3) as well as a.. full-strength general purpose cryptographic library..... OpenSSL is descended from the SSLeay library developed by Eric A. Young.. and Tim J. Hudson. The OpenSSL toolkit is licensed under a dual-license (the.. OpenSSL license plus the SSLeay license), which means that you are free to.. get and use it for commercial and non-commercial purposes as long as you.. fulfill the conditions of both licenses..... OVERVIEW.. --------.... The OpenSSL toolkit includes:.... libssl (with platform specific naming):.. Provides the client and server-side implementations for SSLv3 and TLS..... lib
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3251
                                                                                    Entropy (8bit):4.82055320948653
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:nAf0rWOC0pAvwIHg28vx22nK5cHGg8czKVSpxsNxddItK+4WlA1QIFL:nAyo0pT28vx2iK+HGg8cnnAtpWl2
                                                                                    MD5:54548B258AC71839F1D1BA7A0CA19FB5
                                                                                    SHA1:428202CB596D72333B3852DC1367E8A18C297521
                                                                                    SHA-256:25F242473F5CF6BCDB0192F071EC9E78A6CB4E1E6CB887AD33002BA2EC1EBA6D
                                                                                    SHA-512:FF17E5A6C40976B7881B09B4BBD480423DF27441FB51366F7F4390D2E9A99243FE75FABF2F70F8AC267AC370D34FA1391398E98EAEC003FB00820FA438366A5B
                                                                                    Malicious:false
                                                                                    Preview:.. OpenSSL 1.1.1h 22 Sep 2020.... Copyright (c) 1998-2020 The OpenSSL Project.. Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson.. All rights reserved..... DESCRIPTION.. -----------.... The OpenSSL Project is a collaborative effort to develop a robust,.. commercial-grade, fully featured, and Open Source toolkit implementing the.. Transport Layer Security (TLS) protocols (including SSLv3) as well as a.. full-strength general purpose cryptographic library..... OpenSSL is descended from the SSLeay library developed by Eric A. Young.. and Tim J. Hudson. The OpenSSL toolkit is licensed under a dual-license (the.. OpenSSL license plus the SSLeay license), which means that you are free to.. get and use it for commercial and non-commercial purposes as long as you.. fulfill the conditions of both licenses..... OVERVIEW.. --------.... The OpenSSL toolkit includes:.... libssl (with platform specific naming):.. Provides the client and server-side implementations for SSLv3 and TLS..... lib
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):2225
                                                                                    Entropy (8bit):4.915897180346394
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQzLM3GkJtDl5/QDL3AqWkwNFMRR0/KbgtTRfhBYftRl7Zw1:50ti7Q3VlqTGkwNFMH0/OgtTRMPl7w
                                                                                    MD5:6B5E01439440855F115B20FF421BCE72
                                                                                    SHA1:A352BD13D8EE4E83CA0CDBCE99985A10157334B3
                                                                                    SHA-256:D0612B570F81C3C2D76E8DDA92FE6508D7C01A41852ADA1222AC5A6FDAC9C10F
                                                                                    SHA-512:A5ABFAA427F543331AFDA8A22C0BB8DC6D3F021E5A3E784EAAD3B1E19E94DDB06ABE83377DC834D3A08E8C1E87535F44085C60FA999F179AF6F469A3F97B9FD1
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825.crl_extensions = crl_ext..[ ca_policy ].commonName = supplied.countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.emailAddress = optional.serialNumber = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_disti
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2419320
                                                                                    Entropy (8bit):6.634464050699479
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:HKJtezQ9MBR+qYP6dpF3KYyRm1h1dqQyadLONZUFIJEgf4PiixK7oq/N//id/Xp6:weKoAPuL3KYyRm1h1dqladLONZUFIJEA
                                                                                    MD5:5E7C712BA09DB83021F48DC4D9FFEF6F
                                                                                    SHA1:DE5398106F724236866D228B1C2896D6D2936868
                                                                                    SHA-256:D86EF526F0092A95F0A2F3A16D9E183403DB3E910B4E396DA36AA43F28B7AB91
                                                                                    SHA-512:B3F4BC1921AB8C8BE858BEA24945605B3B84C0CC0874ADAE5E8A36829F940D7225CA9F4A0A85A36CD9144A1E7EE41B90047B805E4D988E0639B61F9368BDBD50
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#......$..B........... ....@k.........................p%.......%...@... ......................@".Y....@$.......$...............$.x.....$.x.............................!.....................$C$..............................text...8...........................`..`.data........ ....... ..............@.`..rdata......0.......0..............@.`@.bss.....A....!.......................`..edata..Y....@".......!.............@.0@.idata.......@$.......#.............@.0..CRT....,....`$.......#.............@.0..tls.........p$.......#.............@.0..rsrc.........$.......#.............@.0..reloc..x.....$.......#.............@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):689272
                                                                                    Entropy (8bit):6.414399173082945
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:J0HnHbJM/BqUu+Agrp2a1Rvj6Xiww6RIR7Q491DfU0:J0HnHbJM/BqT+rp2a1Rr6Xiw1R87Q49h
                                                                                    MD5:01AE7F7D23BCD591E058B987AFB0A163
                                                                                    SHA1:38474D773CB05BF18FE40DB270E7EEE45B2552E7
                                                                                    SHA-256:B2F449BC5F448287271C7F27E773B4FECF644553EC60B21DA0E5A6655F3AD20D
                                                                                    SHA-512:C830B7FDB3A92AE3D6138FA3A4B75FCC17CD7B018450E0E80747C27ACF43A7A5D2184A780E0B0204E3244F4DF25B9B8471E85F38FCA6B9700F9F5E7C3207DA2F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...............#.`...r..."...........p....@.......................................@... .........................N...........p...............v..x.......@~..........................$6......................X................................text...._.......`..................`.P`.data....e...p...f...d..............@.`..rdata...g.......h..................@.`@.bss....T ...P........................`..edata..N............2..............@.0@.idata..............4..............@.0..CRT....4....P......................@.0..tls.........`......................@.0..rsrc........p......................@.0..reloc..@~..........................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):6246
                                                                                    Entropy (8bit):5.169925801769785
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:4itmxrs1rsy/QZ93OWZ7u2dOrsMrsSC13C3dinCY:4i2rs1rsyilHcPrsMrspdsdWCY
                                                                                    MD5:CD010DA4CF5B82714DBC32F3E05DF760
                                                                                    SHA1:C52F4AE980AF344F6C98DF74AA8117F6A2C7903C
                                                                                    SHA-256:15B8E85F410B23610E424681C010E1B2833C9805F977131713AD6F7DECF3FE90
                                                                                    SHA-512:8AA6FC03C353A83BCAB9E65D30C69B5393F1AC6C0181C0B8E357C85CC3A15C63C57D4FBC8082EB8DD539BC885B5AC2808A294ADC42A541EBDC6B06BAB5357CB1
                                                                                    Malicious:false
                                                                                    Preview:.. LICENSE ISSUES.. ==============.... The OpenSSL toolkit stays under a double license, i.e. both the conditions of.. the OpenSSL License and the original SSLeay license apply to the toolkit... See below for the actual license texts..... OpenSSL License.. ---------------..../* ====================================================================.. * Copyright (c) 1998-2019 The OpenSSL Project. All rights reserved... *.. * Redistribution and use in source and binary forms, with or without.. * modification, are permitted provided that the following conditions.. * are met:.. *.. * 1. Redistributions of source code must retain the above copyright.. * notice, this list of conditions and the following disclaimer... *.. * 2. Redistributions in binary form must reproduce the above copyright.. * notice, this list of conditions and the following disclaimer in.. * the documentation and/or other materials provided with the.. * distribution... *.. * 3. All advertising materials
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):513656
                                                                                    Entropy (8bit):6.172388711561625
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:cDyeZzW7DBllO13YGZ1NBbzlRxgMd5hXgeHqQilbSu1UYaoq42:cDyeZzW7DBllO13YGrNxzlRxgK5hQeHN
                                                                                    MD5:7153055A99046DAA1230D9D67DA74927
                                                                                    SHA1:1FF082EC15238E50A776B76A3B8B2B12C3D38694
                                                                                    SHA-256:856F9E94D4B91CECFA9970CF3C80F4E383C6005A2BCD3141AE0DEDEF08C4905A
                                                                                    SHA-512:E89201AF0AB6A9722A45AEB5553AD55467515A3884624FE5E0CB87EC5AA125CDEB35DEBFE75447F6DB7534B16261A533F2BCFA3CFF3B021CB6E25EDA9C1DB714
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#...........................j.........................0.......7....@... ......................0..3@.......>......................x........?...................................................................................text...$...........................`.P`.data...D,..........................@.`..rdata..X...........................@.`@.bss....P.... ........................`..edata..3@...0...B..................@.0@.idata...>.......@...@..............@.0..CRT....,...........................@.0..tls................................@.0..rsrc...............................@.0..reloc...?.......@..................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):1826
                                                                                    Entropy (8bit):4.899761808548488
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQL3GkhUtDl5/QpkwNFMRR0/KbgtTU3AqxvZTdfb:50tiD3Wl4kwNFMH0/OgtTuFXz
                                                                                    MD5:4C61442851631947B8E5A11372B882C8
                                                                                    SHA1:0C1BF1444A5AB40F89EBB7C8A67D36A7F4DAD6BB
                                                                                    SHA-256:71D777064B33AD0E385513B0AED25477B40B18FDA2E28B7D79883A7FA6B4CDC1
                                                                                    SHA-512:46C0036D511FF727A6345E5D4128EB8B4D631C4DD18DEA2D0A03BE4121697FB8D3AB4B4536944D4F653091898B9C6F82F62C2ED1A6A954FD11273654CB08C47E
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825..[ ca_policy ].countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.commonName = supplied.emailAddress = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_distinguished_name ].countryName...= Nom du pays (code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2419320
                                                                                    Entropy (8bit):6.634464050699479
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:HKJtezQ9MBR+qYP6dpF3KYyRm1h1dqQyadLONZUFIJEgf4PiixK7oq/N//id/Xp6:weKoAPuL3KYyRm1h1dqladLONZUFIJEA
                                                                                    MD5:5E7C712BA09DB83021F48DC4D9FFEF6F
                                                                                    SHA1:DE5398106F724236866D228B1C2896D6D2936868
                                                                                    SHA-256:D86EF526F0092A95F0A2F3A16D9E183403DB3E910B4E396DA36AA43F28B7AB91
                                                                                    SHA-512:B3F4BC1921AB8C8BE858BEA24945605B3B84C0CC0874ADAE5E8A36829F940D7225CA9F4A0A85A36CD9144A1E7EE41B90047B805E4D988E0639B61F9368BDBD50
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#......$..B........... ....@k.........................p%.......%...@... ......................@".Y....@$.......$...............$.x.....$.x.............................!.....................$C$..............................text...8...........................`..`.data........ ....... ..............@.`..rdata......0.......0..............@.`@.bss.....A....!.......................`..edata..Y....@".......!.............@.0@.idata.......@$.......#.............@.0..CRT....,....`$.......#.............@.0..tls.........p$.......#.............@.0..rsrc.........$.......#.............@.0..reloc..x.....$.......#.............@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):513656
                                                                                    Entropy (8bit):6.172388711561625
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:cDyeZzW7DBllO13YGZ1NBbzlRxgMd5hXgeHqQilbSu1UYaoq42:cDyeZzW7DBllO13YGrNxzlRxgK5hQeHN
                                                                                    MD5:7153055A99046DAA1230D9D67DA74927
                                                                                    SHA1:1FF082EC15238E50A776B76A3B8B2B12C3D38694
                                                                                    SHA-256:856F9E94D4B91CECFA9970CF3C80F4E383C6005A2BCD3141AE0DEDEF08C4905A
                                                                                    SHA-512:E89201AF0AB6A9722A45AEB5553AD55467515A3884624FE5E0CB87EC5AA125CDEB35DEBFE75447F6DB7534B16261A533F2BCFA3CFF3B021CB6E25EDA9C1DB714
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...........#...#...........................j.........................0.......7....@... ......................0..3@.......>......................x........?...................................................................................text...$...........................`.P`.data...D,..........................@.`..rdata..X...........................@.`@.bss....P.... ........................`..edata..3@...0...B..................@.0@.idata...>.......@...@..............@.0..CRT....,...........................@.0..tls................................@.0..rsrc...............................@.0..reloc...?.......@..................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):2225
                                                                                    Entropy (8bit):4.915897180346394
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQzLM3GkJtDl5/QDL3AqWkwNFMRR0/KbgtTRfhBYftRl7Zw1:50ti7Q3VlqTGkwNFMH0/OgtTRMPl7w
                                                                                    MD5:6B5E01439440855F115B20FF421BCE72
                                                                                    SHA1:A352BD13D8EE4E83CA0CDBCE99985A10157334B3
                                                                                    SHA-256:D0612B570F81C3C2D76E8DDA92FE6508D7C01A41852ADA1222AC5A6FDAC9C10F
                                                                                    SHA-512:A5ABFAA427F543331AFDA8A22C0BB8DC6D3F021E5A3E784EAAD3B1E19E94DDB06ABE83377DC834D3A08E8C1E87535F44085C60FA999F179AF6F469A3F97B9FD1
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825.crl_extensions = crl_ext..[ ca_policy ].commonName = supplied.countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.emailAddress = optional.serialNumber = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_disti
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text
                                                                                    Category:dropped
                                                                                    Size (bytes):1826
                                                                                    Entropy (8bit):4.899761808548488
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:7GcROkSieQL3GkhUtDl5/QpkwNFMRR0/KbgtTU3AqxvZTdfb:50tiD3Wl4kwNFMH0/OgtTuFXz
                                                                                    MD5:4C61442851631947B8E5A11372B882C8
                                                                                    SHA1:0C1BF1444A5AB40F89EBB7C8A67D36A7F4DAD6BB
                                                                                    SHA-256:71D777064B33AD0E385513B0AED25477B40B18FDA2E28B7D79883A7FA6B4CDC1
                                                                                    SHA-512:46C0036D511FF727A6345E5D4128EB8B4D631C4DD18DEA2D0A03BE4121697FB8D3AB4B4536944D4F653091898B9C6F82F62C2ED1A6A954FD11273654CB08C47E
                                                                                    Malicious:false
                                                                                    Preview:default_ca = CA_default..[ CA_default ].dir = ../AppData.new_certs_dir = $dir.unique_subject = no.#certificate = Config/ca.crt.#private_key = Config/ca.key.database = $dir/index.txt.serial = $dir/serial.txt.crlnumber = $dir/crlnumber.txt.default_days = 365.default_md = sha256.policy = ca_policy.copy_extensions = copy.default_crl_days = 1825..[ ca_policy ].countryName = optional.stateOrProvinceName = optional.localityName = optional.organizationName = optional.organizationalUnitName = optional.commonName = supplied.emailAddress = optional..[ ca_extensions ].basicConstraints = critical, CA:true.keyUsage = critical, cRLSign, keyCertSign.subjectKeyIdentifier = hash.authorityKeyIdentifier = keyid:always,issuer.# Lien vers la liste de revocation, uniquement si PKI Standard.# crlDistributionPoints = URI:http://example.com/root.crl..[ req ].distinguished_name.= req_distinguished_name.default_md = sha256.req_extensions = req_ext..[ req_distinguished_name ].countryName...= Nom du pays (code
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):689272
                                                                                    Entropy (8bit):6.414399173082945
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:J0HnHbJM/BqUu+Agrp2a1Rvj6Xiww6RIR7Q491DfU0:J0HnHbJM/BqT+rp2a1Rr6Xiw1R87Q49h
                                                                                    MD5:01AE7F7D23BCD591E058B987AFB0A163
                                                                                    SHA1:38474D773CB05BF18FE40DB270E7EEE45B2552E7
                                                                                    SHA-256:B2F449BC5F448287271C7F27E773B4FECF644553EC60B21DA0E5A6655F3AD20D
                                                                                    SHA-512:C830B7FDB3A92AE3D6138FA3A4B75FCC17CD7B018450E0E80747C27ACF43A7A5D2184A780E0B0204E3244F4DF25B9B8471E85F38FCA6B9700F9F5E7C3207DA2F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...+.i_...............#.`...r..."...........p....@.......................................@... .........................N...........p...............v..x.......@~..........................$6......................X................................text...._.......`..................`.P`.data....e...p...f...d..............@.`..rdata...g.......h..................@.`@.bss....T ...P........................`..edata..N............2..............@.0@.idata..............4..............@.0..CRT....4....P......................@.0..tls.........`......................@.0..rsrc........p......................@.0..reloc..@~..........................@.0B................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.347287743366354
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:6oN4JUNanMSU/JU7r299nL2kSDtHAvCp3me0PfRnCe8SfVq6X8RRga5Rf7NjNfft:im6ab7exE0
                                                                                    MD5:DFF6850E8B2FA1D6FD14773AD9F6F150
                                                                                    SHA1:EB41A2AE0FD2BCA2D0E4E857D02BDD2245A698AB
                                                                                    SHA-256:B4453E1AB70758E8B08F1F9CC6947A18DB2519075B494C4CD8D6E1E020A68A0E
                                                                                    SHA-512:2743D550CFF83639E2D6ABCD4A1AE4C055C5A8B5FA459EB5ACE005A68CE08D83B31E296DA120ACA04FAD190F60AD0565912FEC64C79233B9414E7BF42EC3AB92
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e.........." ..0..P...........n... ........... ....................................`..................................m..O.................................................................................... ............... ..H............text....N... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B.................m......H........'...............V................................................(........s....}.....~....}....*2.{....o....*"..}....*^.{......{........o....*2.{....o....*2.{....o....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r`..p~....o....*V(....r...p~....o....*V(....rP..p~....o....*V(....r...p~....o....*V(....rI..p~....o....*V(....r...p~....o....*V(....r/..p~....o....*V(....r...p~....o....*V(....r4..p~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14336
                                                                                    Entropy (8bit):4.9314244617466665
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:FzP9VECr49b0mHsP86g8n6ZhMv11wE7uDzfpK2Ft/GjX3:dP9VL208sU6qniwEqjF1qX3
                                                                                    MD5:1F2D54F48C615F086E1CB19DD44FD97C
                                                                                    SHA1:1B97539D5AC39B7C989D8CD5CF8D71D6745287B4
                                                                                    SHA-256:3ED0A4217517B17E1459D649E4C3811865A4838E71508A953D777B2F9E16A4C3
                                                                                    SHA-512:6178AB1ED7D626186E879FDFCCF3833B68B47915D715AE9177DACEFB4B7B53869CBF8D2E8852079E5A8586E8E8DA8CE40D7DB1A4AF4D1A6372741228AAFAEFAA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............L... ...`....... ....................................`.................................dL..O....`............................................................................... ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................L......H........&..|%...........................................................0..H........o......-..*.o......u!...,...*.u"...,..*.u#...,..*.u$...,..*.u%...,..*.*..{!...*:.(......}!...*b..3..*......3...*.,..*.*~.-.r...pr...p.(.....*.o.......*..-.r9..pr...p.(.....s....*.o.....(....*.0..y.........c1..........*.E............#...A..._.......}...............8.....rc..p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r8..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):4.35096535887655
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:HDbZgmWgUGOBlTGYI+eQ6/70dRbSA3oO4OHPbPa:fKQU6/70dRj4O4Oz
                                                                                    MD5:BAF74BAB27F9EF9F3857B4DBBB215FB7
                                                                                    SHA1:2D2068477DD2AD2C1747E08CC0BD2EB6B9E0516D
                                                                                    SHA-256:E851DD88BF9EB69383017E1211B9DD2826F94ACF3FFD345A539228DF52E9492E
                                                                                    SHA-512:20F04A0D5D8F8F8A21E84A5AC266143E151AE84C45172D45C4187A7E4D361295220B0F701FA4FF68EDC3A0097641A7C1E889F7F88A5E36C5208A97881605455F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............0... ...@....... ....................................`.................................d0..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........ ................................................................{....*"..}....*N..(.....(....(....*>..(......(....*..{....*"..}....*:.(......(....*...BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob...........W..........3..................................................................................................................................!.................t.....U.................<.?.....Y...........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18944
                                                                                    Entropy (8bit):5.123452606388303
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:y0sI9oCUN+uMVZFZfZ9gNe5nlpW85s2wmQs56TtmOjXis0j7XcyFXcXPXrfX2H0r:xsf+5FCNepkmuTtmOrX/y
                                                                                    MD5:B2690A6C3C2E97FA8A89F1DEF550D53B
                                                                                    SHA1:E2811A4F491D9833C1D7880AE28F7755EF179BD0
                                                                                    SHA-256:8B64B6FF4274103A919C08DADDB8E295772F38582A098E0DA097CAA632A7083E
                                                                                    SHA-512:AECC9ED7F6E57D231A4362346BF38BC094495AA5A1131508466C9DBA34A67A2F83A15CBF420C646A28A52AC444EE4E6B16B8426531CFEE0F773F65934BFF5E0F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..@...........^... ...`....... ....................................`.................................d^..O....`............................................................................... ............... ..H............text....>... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B.................^......H........'.../...........W..............................................F.-.*.(.....(....*...0...........o@...-........oA....o@....i.1.*.........+ ..s....%..Xo....%r...po.......X...7..o@......+........o..........Y%.......X....i2...oA...*....0...........o>...-........o?....o>....i..1.*..........+ ..sV...%..XoS...%r...poU......X....7..o>......+........oR.........Y%.......X....i2...o?...*.0.......... ....s........,/..,+..i.....(........+..o....&....(......X...2..,>..,:..i...,..o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.509347235200524
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WBX0TqVWFUM3HmOFs8mXXiA+L3Ad8DUntPKeUELxK2Yj7uIt:+ayIWmp2YeU4x5suIt
                                                                                    MD5:3684F924B38D4FB23DE40554ADFB1537
                                                                                    SHA1:E4FB7143ED7DFD2CAD2E379703808CEF429882BF
                                                                                    SHA-256:702444FCDE9AC6550E636A32678493E6835B247D8D8D344E2F803184F9F0EA45
                                                                                    SHA-512:8ACAED49F0204B8BEC8DD92D759F0E7913B447A53D0962FAE290A40EE36A20435EE7508E813EDCBD5A6BA1638385D235C64C1643052EDCA890D218DE3453606C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..0...........N... ...`....... ....................................`..................................M..O....`............................................................................... ............... ..H............text...$.... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......p$...............A..@...........................................r.(......}......}......}....*....0..T........-..+.(......(.....r...pr'..p...(.....(.....{.....(....-.(....+....{.....{....o....**....(....*..0...........(....-.(....+.....YE............!.../...=...K...Y...g...u.......................................8......(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.865639255366771
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:akOKSRVDKCJRCNdLnRWpnipnuncpt2JbJH0qV28xqNK7I2yd1u7qAGxhrGTEZmlR:akONl3eRngpnipnuncpMJbx0qV28xtCa
                                                                                    MD5:8576099B78B5A2B4371F5607C1CC4B56
                                                                                    SHA1:56959AF98B01B360DBBF247F0B01DDE4CE8D5C9E
                                                                                    SHA-256:A3F1B2DF20581CB7D64B008692939AEC45F4D7F6D8037F29F34D58AA14C2BD84
                                                                                    SHA-512:1717169904BB82D28B9B48DA167C960CE417B6F6983380ECD40B32418149B94AED3B6DA97F87FDDF47F887D0BA334F6A1109F750C87D81A0624B3ECFA21A48D5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e.........." ..0.."...........A... ...`....... ....................................`..................................@..O....`............................................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........"..h...........d<..X............................................0..r.......s......s.......+V..]..E............*...+:.r...p.(....o....&+&.rk..p.(....o....&+..r...p.(....o....&..X...2..o....*...0............o....o.......o....*....0...........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....,.(.........s....*r...ps.....o....o....-.(.........s....*~....*....0..b........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....-.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):87040
                                                                                    Entropy (8bit):5.4554148178321675
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:nDsxiI7pW/tZrszqJBWDnvSYT3VeArUOXeeu:nJI7pW/tZrseyf3fjXeeu
                                                                                    MD5:EAEDE0361F15C2EB139C7E2FC6C6AB71
                                                                                    SHA1:DBC9F9DC7E158538C0FFDEE9AA536C33868EF693
                                                                                    SHA-256:8C8B835E81010D99B0F240E598D65951D4A50771A4B4D85CB74E513FDF169E36
                                                                                    SHA-512:3575D111C742C8D2B56BBC0EAEF1B3E95CE0AB31100047A8EAFE87E91D063BA4D420D7BB7BBD332EAC34BCE6B8DAFCED7AD7E81CEEA830394805A3F61293F40E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Vu..........." ..0..J...........h... ........... ....................................`.................................ih..O....................................g..8............................................ ............... ..H............text....H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........V..............X...0I.........................................."..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*439 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):224768
                                                                                    Entropy (8bit):4.138821035130012
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:OYZrzdzRISZ/hCzBv1hLHfTYxk8mC6MNpMrptsuFkC6TvhkAjwYVNpwAj:tI2/huBv1hLHfEm8mkMrptsuFkC0hX
                                                                                    MD5:B2EBA7F35E2DEF32749E36A6C181BA0B
                                                                                    SHA1:4EF2027C1E03BFC948457AECCD5E77A45C78CA7B
                                                                                    SHA-256:52BACFD1EE622B668CFEC91321A95552B9D7ED2FCDA10AE31A433F650E0E8184
                                                                                    SHA-512:23359C79495A26D7E39EAF652D734CC8AA1D8ED90EC38C225C329C590453343E08BE3BF7CB923F09D243856F8D97526DF48B4428E3D5634C8D4A6BECAAAFAD8A
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS...............T................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................_..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7680
                                                                                    Entropy (8bit):4.609043127953718
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:4x/lg1lEFiC83HY+z63w6n9HdDBFeK9R303inq6ncYZCl6lSWn:4Dg1sovz6AiDYKTDnbchMlSW
                                                                                    MD5:56E7B6DDF9FA1BB2363D5813120674A4
                                                                                    SHA1:92745E5EE779EEC4C4E2021FFA59E3FFF6242DC7
                                                                                    SHA-256:816C7FA679B7B5E529FA8274ABBC75FD56E73C1244B79EA90B552F31AC6C219D
                                                                                    SHA-512:A315110A1CB434914B37373DEB36D669EE1CF3A9B6269927F8C2D49AD2C1991560748D64F63DC1F1E2F9ED5BC01EE621EDCDC1F851F942FFB734129695173996
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............~3... ...@....... ....................................`.................................,3..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`3......H....... !..............................................................~r...p(....r...p(....(.........*.0..T........(.......}.......}.......}.......}.......}......}......}.......}.......}......}....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*BSJB............v4.0.30319......l.......#~..L...D...#Strings............#US.........#GUID.......X...#Blob...........W..........3..................................................................A.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):686
                                                                                    Entropy (8bit):5.095369395177209
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:MMHdGzNFF7ap+5KJf/2/DXFip+5NJf/2/qKFicYo4xT:JduPF7NyH2/5V3H2/qo9y
                                                                                    MD5:1C692F9907BB6FCD97ECA18D587E5B87
                                                                                    SHA1:C6021EA19B5F88925AB27FB2E65C3CB47A6601AB
                                                                                    SHA-256:EF01791FD533C9B51F2F279D21A6CA4B6F935C1AFE6D4A24E75DB91E568C6404
                                                                                    SHA-512:15195678CF637D7E19445523F9B39604FDA221D3D5F530FF5F6090C0AF22BC9D46C3936811D02F20BB133ACA210575F6C860247B63ED1574EE9EAAC4725B3F5D
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):56832
                                                                                    Entropy (8bit):5.690835792827563
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:DkXuiukTFT3hvhZUq5UkA33mSIZ0lt+DDNXspw9IwL+P:DQu1kTFlhmq6kAnSKlt+nVuwGvP
                                                                                    MD5:BBA60FC073D9CBF5CB5658BC4DCD8A3F
                                                                                    SHA1:9CFBD36334B9404B3E7E8042C4F15B7F01391441
                                                                                    SHA-256:133B772B48EADF9F2FA51296A508EE0BC7B71CAB84C699F23B10B8B55F310550
                                                                                    SHA-512:CCF5DE9F317B734AF85D34FB3BD264DAEF1C326CDCEEBE6569590473F68914EF333631D15628021474494BA07F8A40EE20DB46F1C6C0F8C9D63E0295BAF36027
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............n.... ........... .......................@............`.....................................O.......p.................... ....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...p...........................@..@.reloc....... ......................@..B................P.......H........A...x..........t....8............................................{....*"..}....*..{....*"..}....*..(!...*..{....*"..}....*..0........................("...o#...(....*...0......................(....*...0...........(!...r...pr7..p.($......}.......}.......}.....{......o%.....}......s#...}.....{......s&...%r...p.(U...s'...o(...o'....s ...}.....{.....{....o).....s3...}............s....}......o).....{....o).........sg...}....*f.{.....{....o(...._o9...*.*..(....*..{.....{...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1180
                                                                                    Entropy (8bit):5.055540465344216
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JduPF7NhOXrRH2/dVyH2/5VEH2/qoV3H2/qo9y:327O7Rgd8g5OgX1gXw
                                                                                    MD5:131D63E86E45EC3D3A831BF1F7FECFEA
                                                                                    SHA1:41BFCDDD7C6C7A011693DA8956F7415D7219371A
                                                                                    SHA-256:318E8D19BEE652FFD2B8AEE736E9C3C537979043365E079A95C0DA758B8558C8
                                                                                    SHA-512:CAE1254C31E947A9BA8560974BBE9D9DF082234D954C1AB5D649437343D3302715E19B4DED6AD8853A727E37F49805D7C8A4B69F24E5C8488577370EBD8BDBF9
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFInfrastructure" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutra
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.762661257689725
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zRWAtSQqSbmIl3kn75fCN7RHQSFl+ouzQLxdETbSqNNDZ+GclRq3zQ6SfJtkinNu:tWwSf6mw3k7yFqhzNNiRTkin6gNb69d
                                                                                    MD5:C7F090DF56B4B7F00FBC30BE93E19CB5
                                                                                    SHA1:762A1352B78DA7970367094C4EA1DE2119BA03A0
                                                                                    SHA-256:A0B5A4E0D399D0E848A8B2CE2C9DEB3B8F2ADF0411C4BAFB066CF4646595512C
                                                                                    SHA-512:EBB747416375D393BC981D7A7C3182A4FA6A29D675C8C7366A0A1E2EED2A5D60BFBA6194C8C6AEA6291456EB6048C69CC1557DD3FFA1E330B55E36431A0DF61F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text.... ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................?......H........$................................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*...0..+.......r...p..(....,.r...p.r#..p..(....(....s....*..{....*"..}....*..{....*"..}....*J.(.....s....(....*.0..O.......s.........+...o.......o......X...o....2.......r1..p.r1..p(.........,..o.......*.........<B.......0..M.......s.........+...o.......o......X...o....2.........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):19968
                                                                                    Entropy (8bit):5.327502630579932
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:WR1TB+EYvodkn5OeUq5gCS1x9UQflcltvlVyUWY5FVRsp5GiPjcVuGk/6uQKztku:WZYvoy5OeUqp2UhLs9P4VBXuQK+u
                                                                                    MD5:CCF6F3D56977D1AFBF4A3EC884D1A32E
                                                                                    SHA1:D29EFBCC5AB0F6C7403BE0DDE5EC202D61FF410F
                                                                                    SHA-256:2129BCD055F493FE34B7E44AEE5F8175CF9D43D7AC037D742E6070A58AFE1266
                                                                                    SHA-512:329607A495E0DAEC735F81A15B8B92C4DF84F71015D9AB762967CCC664714BC2C883BD321255FDCDFAFA04BF5C24DED92B98FC940DFF30A36D72E2831A2AE012
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...XR.e.........." ..0..D...........c... ........... ....................................`.................................dc..O.................................................................................... ............... ..H............text....C... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B.................c......H........0...2............................................................(....*"..(....*&...(....*&...(....*....0..e........(.....s....}......}......}......}......%-.&s......%o...........s....(....t....o...............(....*....0...........{.........o....&.,....o.....{.......o.......(...+(!...}.....{.....o"....{..........xXs#...o$....,..{....o%...o&...r...ps'...o(.....(....*...0..|.......~)....~)....s*.......~)...~)... .........o+...-6.(,...,..(,...,.r...prm..p.(-....(,...-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):269824
                                                                                    Entropy (8bit):6.248597977496272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:w9hcO7H2po0qDQh/mLJ2e4NY647eS56K2K+p637RArP1CKlF:w9hn0Cus+c32
                                                                                    MD5:761C33DCFD02AF3A9B60C3A307362989
                                                                                    SHA1:636D766B076E05DBEAB1FC9117F1B0931DC33A8D
                                                                                    SHA-256:B17012332BC4B2745349101AEEB02501E68F1E8D470CFCF316CA3AD13A2356E6
                                                                                    SHA-512:414F48F3FC381078A5B8E0D49F8D822BF1BD9B36EF944B3A7B2FCFFBCBF2F547108FC7002179EF2DF4021F499FE23E4D87BBAE5CB83B236AAFCEFBA23C7044F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e.........." ..0.............j2... ...@....... ....................................`..................................2..O....@.......................`....................................................... ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................L2......H....... ...................hV............................................(%...*..(&...*z...(.....-.r...ps'...z..}....*..((....-.r...ps'...z..}......}....*^.{....,..{.....o)...*.*6.{.....o*...*....0...........u......-.*...(+...o,....o-......o......o....*6.~.....o/...*.s0...%.o1...%.o2...%.o....%.o,...*.r!..p.....(3........(3..........s4...s5...(6........*....0..#.......s.......}.............s7....o8...&*..0..?.......s.......}.....(.......o9...,..{....o:...*.........s7....o8..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):686
                                                                                    Entropy (8bit):5.095369395177209
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:MMHdGzNFF7ap+5KJf/2/DXFip+5NJf/2/qKFicYo4xT:JduPF7NyH2/5V3H2/qo9y
                                                                                    MD5:1C692F9907BB6FCD97ECA18D587E5B87
                                                                                    SHA1:C6021EA19B5F88925AB27FB2E65C3CB47A6601AB
                                                                                    SHA-256:EF01791FD533C9B51F2F279D21A6CA4B6F935C1AFE6D4A24E75DB91E568C6404
                                                                                    SHA-512:15195678CF637D7E19445523F9B39604FDA221D3D5F530FF5F6090C0AF22BC9D46C3936811D02F20BB133ACA210575F6C860247B63ED1574EE9EAAC4725B3F5D
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.8275707319309165
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Fifvs56GFPy0GPVcRQoN5E6ZmOGZX36uE5daEy:Ks56GxHG9gu6e
                                                                                    MD5:DD9DD242A4F7AA3083435FCE216BCB25
                                                                                    SHA1:F86E801E1A13A8087B9CB1330C9B0B2D91AD9B05
                                                                                    SHA-256:6A272F121B0F098DEE2519C19C8EB150141D8533D4CD49459B84BD58EA9B42A3
                                                                                    SHA-512:F7FD0C104D6B27BCB1006469C3011623A7F0999CCFFFFBD7FCC830C48C7C70AEE97BFD4CA48124D76C2D8E8A907212B11433049862A6047AB829F980BE4F9E7D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....7..........."...0..*..........^H... ...`....@.. ....................................`..................................H..O....`..\...........................$G..8............................................ ............... ..H............text...d(... ...*.................. ..`.rsrc...\....`.......,..............@..@.reloc...............4..............@..B................>H......H........%..L!............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.r...p.....*...0...........((....(....%-.&.+.o......-.r/..prU..p.(.....*.(.......+G......&...%...%.r...p.%.r...p.%.(.....%.(.....(.....s....o....(......X....i2..*.0...........(....-.r/..pr...p.(.....(....*.(....,.r/..pr...p.(.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):760
                                                                                    Entropy (8bit):5.024737792359112
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:TMHdGPa9V9l2K4r3e5f3VOcreI9GakSNFF7ap+5v5OXrRf/2//FicYo4xT:2dz9V9rY36rZPF7NhOXrRH2/d9y
                                                                                    MD5:30F4A541A4542DFD2761089C573AA534
                                                                                    SHA1:871F7FA84886F6697A268D393C8F706894820C99
                                                                                    SHA-256:64E51DCC54AB9C10E197389CCB5FCA50FA419E7108623F6C2FE261BB623EC6E2
                                                                                    SHA-512:3FD8808268718FA1E00A7C8C5AE724374F2E3F9130E939EBB635E0304D86FB68FB5C8EF08A050DAD54648B3A8301CA9D56BBFCF6BC81D3DEDB825408EB54EB59
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <section name="environment" type="Sofrel.Uranus.Framework.Environment.Configuration.EnvironmentSettings, SUFEnvironment" />.. </configSections>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <environment configSource="Config\Environment.config" />.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*67 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):34304
                                                                                    Entropy (8bit):3.2335417829239637
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:YPMAPuAPVwAPuAPVdAPoEC5ELMNfK1exhUubzAk9vO6bq/jcPWY4tx0EfTVv9ptR:EzR1RsoE9Lt1erxsFmoE7v2
                                                                                    MD5:5BA7CC3B868063DBF7B76EC9E8B4D7D6
                                                                                    SHA1:3F7196D56077DDD8DEB6B8DFA0F4D84C41D43274
                                                                                    SHA-256:33879940E55C62FA5353E04552111E47950699D3AE1CB4C0A16D4FD06211A941
                                                                                    SHA-512:9170ECDD06EBAEF196CEEE68168A6F39928099692A219087353BD7B808855D330F44243C70DDF302C03EB209B43EA6FE0674E23E989A3878480AD8CB78FB7A91
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS...........C...........B...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11776
                                                                                    Entropy (8bit):4.956614026804989
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WCvPuFqE/nQ+L9XRy/z/J0pD+zcNwlClvhMHJaOHuM:TZEfQa9I/Jy+4ZWROM
                                                                                    MD5:0A0505AFC1C5AF06E4383DF3032D0674
                                                                                    SHA1:6242B357013B9E1B6423DCB5482B2D0EB510A4D5
                                                                                    SHA-256:A902F1790B60C1177301073CC1FDA983B4E3186FD6EC247335B115A41A3786E2
                                                                                    SHA-512:F7A471192BE900AC14B4C39B39CCA5EAE1ED35A04E1BC70B50AAB2867DDCBA9428EA431F00B5E05B96AEE05DBE70F2673C286752F05776BDC54192364054C1FA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..$...........B... ...`....... ...............................0....`.................................4B..O....`..\............................@............................................... ............... ..H............text...."... ...$.................. ..`.rsrc...\....`.......&..............@..@.reloc...............,..............@..B................hB......H........%......................|@........................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.0..S.......s....r...p......%..(..........%..(..........%..(..........%..(..........(....o....*..(....*V(+...o,...o$...s....*.(....*.(....*B(+...o,...o$...*.0..(.......(+...o,...o%....(......(....-...(......*B(+...o-...o'...*B(+...o-...o(...*B(+...o-...o)...*..0..F.......(....o....o.....s....%.o....o....%.o....o....%.o ...o....%.o!...o...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.0786290349934315
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Cf8wjVl9lOPAmVqzzNBdu3DPxXEvLCiDfp6wZ8ETV56hjRUA8qbC/We3nebPLqX:TjGImk/5Q1EewZ82Vwjc2Ceu5O
                                                                                    MD5:649DFD82FE2569BC5873F0715AA545CB
                                                                                    SHA1:9D2A506C841D233C32DCF39506D5EAC7EE60B97B
                                                                                    SHA-256:7411B7C9E368E1CEE613FE97728D504E31D5F2091D11951A4DBEB88A9551BCAE
                                                                                    SHA-512:217FCADEF712A7DE2DCDF7A1036EB50AE47EC752400A1A7EFA3BB4A49F7276E3BDDCA03FA5044513DC06378EE1AEE1527498DCC534AA9D16A4873DCDCBDC5C00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..............,... ...@....... ...............................>....`..................................+..O....@..4....................`......|*............................................... ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................+......H........ .......................)........................................o.....o....o...........(.....o...........*.0...........(...+..,..o....*.o....*.0..E.........o...........X%..o....2..*..+ ...o...........X%..o....2..*..X...2..*...BSJB............v4.0.30319......l.......#~..(...x...#Strings............#US.........#GUID.......T...#Blob...........G..........3..............................................................5...............K.................1...........k.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):24576
                                                                                    Entropy (8bit):5.439852939293774
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:zbXOwhwMrAfN2/hkBwkGa2+dWLG4ZfAcION/65Hld2qFKNk8qluGLRqOunsWsrj:PhhwMrsek2+I95shhJRXiJs/
                                                                                    MD5:74E7BEBF2E462C337B1280A3E98D0B35
                                                                                    SHA1:0DF183BA4D1C4E13073581E56564F95AC5CB3254
                                                                                    SHA-256:F55761468B9B0CE16C70A2F011C486DFF07948D35EAE3E67B092D610C381F368
                                                                                    SHA-512:870D44A95CC69D694189A702DDFCEA6D98F8DD25BB0DAD78AA7259E73E328946B68160215FF209EFF93AD40DD19B34752E9E15217E78298E4C696712F0F2DF49
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..V...........t... ........... ...................................`.................................dt..O...................................,s............................................... ............... ..H............text....T... ...V.................. ..`.rsrc................X..............@..@.reloc...............^..............@..B.................t......H.......@2...=...........o.......r.......................................0..G.........(....}.......}.......}.......}.......}......|......(...+..|....( ...*..(!....s"...}....r...pr...p.(#...*......(....*...0.................{....o$...o%....+9.o&.......o'....j3&...r'..pr=..p..A....o(...()....(#......o*...-....,..o+.....9.....o,...o-.....8......o........o/...r...p(0...,t..o1...o2....3e..-...o3...-7...o4.....r...po5...r'..pr...p..A....(6...()....(#...+.r'..pr...p..A...(7....(#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):20480
                                                                                    Entropy (8bit):5.12438911804574
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:9/raLgzj2a2VtNY6gA2NGiQEt1u2UUAxT:J6Ba2Vs+intc2U
                                                                                    MD5:4E14602466E04BA26B85799C7B583135
                                                                                    SHA1:35BA198DFBEDD4E9E2A14315EDC985518011E5AE
                                                                                    SHA-256:E4382B9036CC9A50558992245D5AEDEA247567FD87E24D2CC318AA47A0898B34
                                                                                    SHA-512:054A8FD1F6218D1F2E85C46244EE2C9EA7C5D93353EA615A7F2D32317FFF7EDB6A2612270CB8621D9DA76634F8645A459FC075CFB970D028EBBD9C00DC131238
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..F...........d... ........... ..............................@.....`..................................d..O...................................tc............................................... ............... ..H............text....E... ...F.................. ..`.rsrc................H..............@..@.reloc...............N..............@..B.................d......H.......X-...5...................b.......................................0..............(......-i..o(....o......(....,.r...pr...p....6...(.....(....+R..r...pr...p......%...%...%...%...6....(.....(....+...r...pr...p...6...(.....(.....*...0..8.........(.....o(....o....(.....r...pr...p....6...(.....(.....*.0..............(......-i..o(....o......(....,.r...pr...p....:...(.....(....+R..r...pr...p......%...%...%...%...:....(.....(....+...r...pr1..p...:...(.....(.....*...0..8.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.627470324915964
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:ZnRxqFcduFzlbKYTQA7sGzaM+vgh3DQqQy6B3rqWsuYXATXjLdGC/au/z:NqFHpboA7sGeM4cv23rqiYXATXV/au/
                                                                                    MD5:852BF0289D774738CFB036A8BB5C6B11
                                                                                    SHA1:98F4D60BE0EE949346AD95BC6234D677E1C7D389
                                                                                    SHA-256:BB3AB16E765F17C784DE9CDB0C35D1B6A299ABAB476FE2F9CA1B39528A629B8F
                                                                                    SHA-512:CFDF0079C9C42D2870FA18BDC92AAD49F16481744B0AB3B296DEA4F258FDF3A6A64B419943E61173D17D3FE8A9A6BAE728AC9F245E6196770BDC77DF5B55AD30
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.............V7... ...@....... ....................................`..................................7..O....@..T....................`.......5............................................... ............... ..H............text...\.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`....... ..............@..B................87......H.......($..$...................L5......................................:.(......}....**....(....**....(....*....0...........-.s....%.o....%(....o.......{....(....&.....(....s......{.....(..............o....r...pr...p.{....(.....(.......r[..p.(.........,..o......*.*........E.+p........E.;........0..............(....&.....r...pr...p.o ...(!....(.......b.r...pr...p.o ...(!....(.......B.r...pr...p.o ...(!....(......."..r...pr...p..o ...(!....(.........*..4......... ........./.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):61440
                                                                                    Entropy (8bit):5.4953592987125335
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:v1P9PM1EO9m30XOgj6sogR/nho16ATIdYOrvQ7NR6KfgB1XxLP8uQ9O3rJt/EjBc:9PVM1i0XlhLATIdY1z5gBMuQ9On/Ky
                                                                                    MD5:E520C02EE6A83ACFE58CD9EDB296E392
                                                                                    SHA1:665A83902C560C610F1F34108742551F1E4F7BCA
                                                                                    SHA-256:A729B344885A5F7F7F09A6D6EF2B9AE86E643BBC118EA60B27CB08AE0991705C
                                                                                    SHA-512:E6EA3148DBB182909790BADF66EE0C9F4BFD5B3B624BAAE13AE4EE85CA89A44A4C1C39D4A25A72A53C1BD55DE647E9D0081DCB6AF82F05D566C300D53D831E0E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.................. ... ....... .......................`...... h....`.................................t...O.... ..,....................@......<................................................ ............... ..H............text........ ...................... ..`.rsrc...,.... ......................@..@.reloc.......@......................@..B........................H........c..8............................................................0......................(....*...0..+.......r...p(......,....r...p.......(.....(....&.*.(2.....(4......(5..._...........(...._*..0..........................(....*...0............................(....*.0..(.........r...p(......,....r...p........(......*.0..).......(2.....(4.......(5..._............(...._*N......rQ..p..(....*R......rQ..p...(....*B..........(....*F...........(....*F...........(....*J........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):5.073320023485428
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VP3bjfBuBX39tYew3jhC4h9Xx8P3RV2ReWBP3lYen:RfBg39Cew3oKihGce
                                                                                    MD5:A1D2A38772AE525ED4C0A165C3197187
                                                                                    SHA1:5EAF512F42F0DCEF235F914F104FE0696C4310B7
                                                                                    SHA-256:CF3803BC5985B65888BA30261E93E366E1C8E76AF91B6E40F36FB14812F57BF2
                                                                                    SHA-512:6D3AC43928F8A6E6F93C6C64A20B2C1E512A045979F8C2C29A584C56CF29B14477FC7DF954C4EB0F1D34F9381ABEE3C238AE7868DEA6FCDD175DB364A633D098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..0..........*N... ...`....... ..............................j.....`..................................M..O....`..@............................L............................................... ............... ..H............text...0.... ...0.................. ..`.rsrc...@....`.......2..............@..@.reloc...............8..............@..B.................N......H........+...............G...... L.......................................0...........r...p.r...p..................(........Q..+..*...0..2........r...p.r...p..................(........Q...Q..+..*...0...............~....Q..~....Qs.............,3.(......~..........(.....*...(........Q...Q...8n....o....o.....r...p.....,.....*...(.......o....&............(........,$.(.......o....(........Q...Q...8......,.....+......9......o......Yo....o........o....o .........o....o ...(!.......,t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):185544
                                                                                    Entropy (8bit):6.1143984102987075
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:I8eNPCLiHSIZ8gcAx081w88sss9wNACJ1xZ7iOo7EM22PBdc:xeF5HSIwHACRVS9P8
                                                                                    MD5:589E1B764C0DC53BF645054960626AB1
                                                                                    SHA1:A5616537CA4E4AD5EB0BEB48863AE65E9EA91080
                                                                                    SHA-256:1C7FA94DE5E727852934387B6B0094ABC16F660C6C91B38FB3F5BC580CFBDC1F
                                                                                    SHA-512:DFD6924DD7BAF7EB1B8D3CC862FD7FB4A311818EE5684C7A85E3106EAD0F3DAE2A79956AAD9B5404C88A1D2607CAD627D0EFD729E9A9C1C1425B907884FBD1D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...E..T...........!..................... ........... ....................... ............`.....................................K...................................h................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H......../..............p...u2..P ......................................d.G..n.y=.v..].....Y...wE...#.".q[...f..N....k.:sj.D...q.`6o.........A..zt..P.6.+..{8....(...'_L[...X....~..yr....Z>/..t.8..0............i...X.........o.............*..0...........u......-..(...+..*..0..$........u......,..*.u......-..s......s....*.0...........u......,..*.s....*..0..$........u......,..*.u......,..o....*.s....*B...o.....Yo ...*....0..<........o!.....E............+..........*..o".....*.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55904
                                                                                    Entropy (8bit):6.299047178318044
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BYQaIZaEmaOQxn6JxKjtlMZAnuETAV+w4:aIhOQcSLAj4
                                                                                    MD5:580244BC805220253A87196913EB3E5E
                                                                                    SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
                                                                                    SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
                                                                                    SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.6185885465184437
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lwHcAI/PI/UwULoLYLLOcZDOcFDPfD6YUXvWalPqAxXxroQMhI4jAqwIA9oqTx8:J8AYPYULcEn5DlDPfvw1lPyfIYcOnwa
                                                                                    MD5:5FE71E8866CA3CA8660355EBB521A174
                                                                                    SHA1:4C82D1CBE94DCEAACE70374131E4A52BD0BC3378
                                                                                    SHA-256:9D2BB3F14323A39207C229112B41DFE5D494DB8092FC586B4D26D5C61F11BBA0
                                                                                    SHA-512:68BD1433436F682C8A8D9FF4B285D363D4DBFB1CBE7D99A2F3DF51679AB609247BC94BECBB245D07FD607AC59AB395E29D9BBB2E342926A9A227ED065FFBA754
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6909032251512306
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YneXmayKpiyyXP3LC3XrNXiwblPXFoeQr:rXdiVXP3LC3XhXi4boeQ
                                                                                    MD5:6F2670E182618ED8D6CA44F54FE8EA5E
                                                                                    SHA1:03923621C472D766C168C081F0BDA4F8D8228B99
                                                                                    SHA-256:28ECA5095903FC714D95420A1F6D1D22B0C29209B986773FE965575BE0B592C7
                                                                                    SHA-512:4266ED0B35A98F6EA79750C0B21E08D707D57948D0340D078176C648D055B8403AA815F501738DD1BD3EE2AE241C08CFC19185CE2726C98F2A3148A2C86F4F5D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................>+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ +......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8691901965523297
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:fCSNfpQwM7PxNTeK1S57U2KRlPgw0TGbdvK:fCCpwNTeJ5ANRfdv
                                                                                    MD5:4AF5AD6BE2909483795D315B8029BCB2
                                                                                    SHA1:A818970B3ACF9B2BC51CB5270C5BBB727A6A1B86
                                                                                    SHA-256:E7FA776BF8A19AA5C5AC866067AA3326EF2F6CB2B66BF986EA99A6674931ACD4
                                                                                    SHA-512:4BE9481D281E40E733E206F3998A3F33A29D1E4BC632EBA04D66412F9E085F98AD06ACD2DC7B96E1C3EC1FB1E0B3D6BAFCB8E4D02755897F9BB926077B829E21
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@.................................x0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........,..............P ..\...........................................X..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.589575428609492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9xHq93PzjhJH/rHOUllPqNKS2pxsrISQj7qXp2qwz2/UbGp0JJ2Y:+Ds/XfbZlPm2KhlBZq
                                                                                    MD5:73D681F55B0A4B484EB80B26602AD4C6
                                                                                    SHA1:D72DAD121D5440368A38BB587E724ADCD9397B5E
                                                                                    SHA-256:9BF894ADCB50B4902108CDA8EEB8533C7F8C48E6099BF6BFA11F8690AAC19403
                                                                                    SHA-512:A8F53B278DC7D2DFC4DEA1AC00B3E321E201BA1E8CF1F48C341EF761498BFAE881FAAC70AE72B668AD4A086D866577B97C125336CF6F9218F719941577D2F378
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!................~(... ...@....... ....................................@.................................$(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`(......H.......`$..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.066221331285762
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:H0B5nPn1fU2V6ofLSM8NoG/qn7NmKmmsDtFlBdeNo+N9RAPFIU5KrkG/KW5MKMyZ:H0255awvoUc7eHKKQ99f6
                                                                                    MD5:6C1501A7C57481123C8FA7A711E657A2
                                                                                    SHA1:2B2D55CF4BECAEAE686F2A5E3F2CD931F11B4684
                                                                                    SHA-256:2EAF8203B97509DAB0F0936703744F9F3431B41F010A14FDD2F1E087A48334CF
                                                                                    SHA-512:4DA0C4CB2445AED44F72EC688BAF2CCE1FE04BCADFF3D1D17376DB27F1A2E02EBE0D4B165BE891B71CBF96A5C9939A03156979FCDEDB8ECCD2E764EEAEAAD51B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................J..O....`............................................................................... ............... ..H............text....*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...&...........................................&.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.811275919755305
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:QYOtEIhbiDnnfD2Y4YzX4PG6u+7DmXj1qYlPwW2ij:QYOsSMXx5F
                                                                                    MD5:9150D1D649F5D98363AB3CDEA99FB777
                                                                                    SHA1:525AD06E4848132A4CD82DE73FD0F6C3F17F0F67
                                                                                    SHA-256:190587CC3A00A09F124B8614D1A609CE448A97462845DFF34C53CDE56B315E08
                                                                                    SHA-512:C3D439214276402A7CA2059480DAAA866B131DDE40A4A9B95B432475D1DB3838CC80CE7FA2AEEFB6F96BD8CFFBBC06F8E452D2E8CA66EED5570258AF73454268
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.268954196614551
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:PrgPr//lGyGj5BuWQAcuA0Ec00r33xJJG5B/khHJrnsTsVW/p8bLbVH9VHyVHiVq:z2nJWQALA0EL4DVdVSVCVOP95cs6I
                                                                                    MD5:8FDDC32B1BA005A4C93FA5A360D9FDBF
                                                                                    SHA1:DF14F08EA55211AD411D9F5FF1E5AECC200B0D74
                                                                                    SHA-256:0B22AC988ACE40B1ACB5522031C2909FEB32569F950223175C8A8B46C1616B59
                                                                                    SHA-512:9A24510D20934CF70543087F6DCA32BD9AF0F6BDCE96C4D4BB1105E5522515DFD3494A94CFF2CE364EEC8CEE42435CA5AAFD2BF2E2A4B0BBD50AD552B00C023C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......47..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.782520457585241
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gge9DhH23S+lvgeKlNota0blPq+LDJsrhj3vgIUxWyoFp/98P28s9JJ2L:tFDhW396WlPN6tj3Ya7T3
                                                                                    MD5:77BE1E70CE867E9E704381F8725E5C6E
                                                                                    SHA1:165F43C1B35E87B6344FCD477F983721A6898C37
                                                                                    SHA-256:010CCD405D3BC1D133CC16DAC9F850EA4B6F01CEFBEB3D63430EAE8002DE529D
                                                                                    SHA-512:E00D6B98561D5C38DCC5AF29702EC8FAE150D759FA161F7A218AEB85E15036EE2E84AE1E5A5A5D2F8DB3F4CF798D28F30666AFF53D7706ECCBD9FC22AC89C1B7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..S....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v.,...!..2....`..y..}........?........U.;k1....(l@bV.`...~B?..(.".....;.........r7..*....1J.k.P./6o7...k..Q..ZB+[..s|.t.^...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.031616183452897
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CtEoG7FWt1fzoYMV4otlclPNrYjGBlZsKJ:OERWBotScqg
                                                                                    MD5:9EDD65E6737DE7C073D65ED46837AA18
                                                                                    SHA1:9CBD45DB426D02E4C20CD4DEEF878A878473AB03
                                                                                    SHA-256:4389F26A446BF3295F57AF7C03A90EEFF539F64907C7955AAD352D4EE98D1703
                                                                                    SHA-512:544BF0825A0D4632BBEB901725D78AA793A551BB23C0047B16F8ADC3D75D33D2FD11216BED496E32CB97C325655D8C95541206C7DA147660AAFE5CF639C259F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................y.....@.................................4)..W....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B................p)......H.......(%............... ..X...P .......................................b........@./%..t..g<n.2u.h........=#..[.3.^]..X$.I+.7..#...X..y.d...W...EL...X.TB.e.@Y6%.^...:.....0`.fC.,....e.>.....T.T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.031616183452897
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CtEoG7FWt1fzoYMV4otlclPNrYjGBlZsKJ:OERWBotScqg
                                                                                    MD5:9EDD65E6737DE7C073D65ED46837AA18
                                                                                    SHA1:9CBD45DB426D02E4C20CD4DEEF878A878473AB03
                                                                                    SHA-256:4389F26A446BF3295F57AF7C03A90EEFF539F64907C7955AAD352D4EE98D1703
                                                                                    SHA-512:544BF0825A0D4632BBEB901725D78AA793A551BB23C0047B16F8ADC3D75D33D2FD11216BED496E32CB97C325655D8C95541206C7DA147660AAFE5CF639C259F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................y.....@.................................4)..W....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B................p)......H.......(%............... ..X...P .......................................b........@./%..t..g<n.2u.h........=#..[.3.^]..X$.I+.7..#...X..y.d...W...EL...X.TB.e.@Y6%.^...:.....0`.fC.,....e.>.....T.T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8691901965523297
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:fCSNfpQwM7PxNTeK1S57U2KRlPgw0TGbdvK:fCCpwNTeJ5ANRfdv
                                                                                    MD5:4AF5AD6BE2909483795D315B8029BCB2
                                                                                    SHA1:A818970B3ACF9B2BC51CB5270C5BBB727A6A1B86
                                                                                    SHA-256:E7FA776BF8A19AA5C5AC866067AA3326EF2F6CB2B66BF986EA99A6674931ACD4
                                                                                    SHA-512:4BE9481D281E40E733E206F3998A3F33A29D1E4BC632EBA04D66412F9E085F98AD06ACD2DC7B96E1C3EC1FB1E0B3D6BAFCB8E4D02755897F9BB926077B829E21
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@.................................x0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........,..............P ..\...........................................X..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6909032251512306
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YneXmayKpiyyXP3LC3XrNXiwblPXFoeQr:rXdiVXP3LC3XhXi4boeQ
                                                                                    MD5:6F2670E182618ED8D6CA44F54FE8EA5E
                                                                                    SHA1:03923621C472D766C168C081F0BDA4F8D8228B99
                                                                                    SHA-256:28ECA5095903FC714D95420A1F6D1D22B0C29209B986773FE965575BE0B592C7
                                                                                    SHA-512:4266ED0B35A98F6EA79750C0B21E08D707D57948D0340D078176C648D055B8403AA815F501738DD1BD3EE2AE241C08CFC19185CE2726C98F2A3148A2C86F4F5D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................>+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ +......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.589575428609492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9xHq93PzjhJH/rHOUllPqNKS2pxsrISQj7qXp2qwz2/UbGp0JJ2Y:+Ds/XfbZlPm2KhlBZq
                                                                                    MD5:73D681F55B0A4B484EB80B26602AD4C6
                                                                                    SHA1:D72DAD121D5440368A38BB587E724ADCD9397B5E
                                                                                    SHA-256:9BF894ADCB50B4902108CDA8EEB8533C7F8C48E6099BF6BFA11F8690AAC19403
                                                                                    SHA-512:A8F53B278DC7D2DFC4DEA1AC00B3E321E201BA1E8CF1F48C341EF761498BFAE881FAAC70AE72B668AD4A086D866577B97C125336CF6F9218F719941577D2F378
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!................~(... ...@....... ....................................@.................................$(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`(......H.......`$..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.6185885465184437
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lwHcAI/PI/UwULoLYLLOcZDOcFDPfD6YUXvWalPqAxXxroQMhI4jAqwIA9oqTx8:J8AYPYULcEn5DlDPfvw1lPyfIYcOnwa
                                                                                    MD5:5FE71E8866CA3CA8660355EBB521A174
                                                                                    SHA1:4C82D1CBE94DCEAACE70374131E4A52BD0BC3378
                                                                                    SHA-256:9D2BB3F14323A39207C229112B41DFE5D494DB8092FC586B4D26D5C61F11BBA0
                                                                                    SHA-512:68BD1433436F682C8A8D9FF4B285D363D4DBFB1CBE7D99A2F3DF51679AB609247BC94BECBB245D07FD607AC59AB395E29D9BBB2E342926A9A227ED065FFBA754
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.782520457585241
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gge9DhH23S+lvgeKlNota0blPq+LDJsrhj3vgIUxWyoFp/98P28s9JJ2L:tFDhW396WlPN6tj3Ya7T3
                                                                                    MD5:77BE1E70CE867E9E704381F8725E5C6E
                                                                                    SHA1:165F43C1B35E87B6344FCD477F983721A6898C37
                                                                                    SHA-256:010CCD405D3BC1D133CC16DAC9F850EA4B6F01CEFBEB3D63430EAE8002DE529D
                                                                                    SHA-512:E00D6B98561D5C38DCC5AF29702EC8FAE150D759FA161F7A218AEB85E15036EE2E84AE1E5A5A5D2F8DB3F4CF798D28F30666AFF53D7706ECCBD9FC22AC89C1B7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..S....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v.,...!..2....`..y..}........?........U.;k1....(l@bV.`...~B?..(.".....;.........r7..*....1J.k.P./6o7...k..Q..ZB+[..s|.t.^...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.268954196614551
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:PrgPr//lGyGj5BuWQAcuA0Ec00r33xJJG5B/khHJrnsTsVW/p8bLbVH9VHyVHiVq:z2nJWQALA0EL4DVdVSVCVOP95cs6I
                                                                                    MD5:8FDDC32B1BA005A4C93FA5A360D9FDBF
                                                                                    SHA1:DF14F08EA55211AD411D9F5FF1E5AECC200B0D74
                                                                                    SHA-256:0B22AC988ACE40B1ACB5522031C2909FEB32569F950223175C8A8B46C1616B59
                                                                                    SHA-512:9A24510D20934CF70543087F6DCA32BD9AF0F6BDCE96C4D4BB1105E5522515DFD3494A94CFF2CE364EEC8CEE42435CA5AAFD2BF2E2A4B0BBD50AD552B00C023C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......47..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.811275919755305
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:QYOtEIhbiDnnfD2Y4YzX4PG6u+7DmXj1qYlPwW2ij:QYOsSMXx5F
                                                                                    MD5:9150D1D649F5D98363AB3CDEA99FB777
                                                                                    SHA1:525AD06E4848132A4CD82DE73FD0F6C3F17F0F67
                                                                                    SHA-256:190587CC3A00A09F124B8614D1A609CE448A97462845DFF34C53CDE56B315E08
                                                                                    SHA-512:C3D439214276402A7CA2059480DAAA866B131DDE40A4A9B95B432475D1DB3838CC80CE7FA2AEEFB6F96BD8CFFBBC06F8E452D2E8CA66EED5570258AF73454268
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.066221331285762
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:H0B5nPn1fU2V6ofLSM8NoG/qn7NmKmmsDtFlBdeNo+N9RAPFIU5KrkG/KW5MKMyZ:H0255awvoUc7eHKKQ99f6
                                                                                    MD5:6C1501A7C57481123C8FA7A711E657A2
                                                                                    SHA1:2B2D55CF4BECAEAE686F2A5E3F2CD931F11B4684
                                                                                    SHA-256:2EAF8203B97509DAB0F0936703744F9F3431B41F010A14FDD2F1E087A48334CF
                                                                                    SHA-512:4DA0C4CB2445AED44F72EC688BAF2CCE1FE04BCADFF3D1D17376DB27F1A2E02EBE0D4B165BE891B71CBF96A5C9939A03156979FCDEDB8ECCD2E764EEAEAAD51B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................J..O....`............................................................................... ............... ..H............text....*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...&...........................................&.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7776738283051285
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:I8AYPYnaPwxxDCPfW8lt4qlP+PI8cOnwa:I8zhlSqtW
                                                                                    MD5:6C9DFD2C4C06705A883EEEBA02082EB3
                                                                                    SHA1:A485F416392C110D07E4400E7E9B81ADEF643C06
                                                                                    SHA-256:7BA3309A9C01F9A58233747226199CC5A3A9BB1AED3BFCDDF3B6B232C9532AF1
                                                                                    SHA-512:7B609A239532903B6E503B3B5DB138CD667B1ABEC9D89F59590664DCFBF70ABFB38926A6D429242F5355B988E0F65AB239AA4038D0AD05410C2A2BD777CB2F24
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@.................................x+..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..:...........................................6..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.699670159881912
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:7XmayKwgyyXYHuNo9XrLXqLo8lPLNoeQr:7X8gVX+uNo9XPXqvXoeQ
                                                                                    MD5:AD12271A5A1D6CC30985517116091CC0
                                                                                    SHA1:D09B96C5DE05D643FFCA973226DEC15E8924244F
                                                                                    SHA-256:35946298511CB617ED9B977F599F4A9AE30BB4E7C47DF5C7C93A039CA4A02279
                                                                                    SHA-512:8BB45D1E07E68B325474B2EF16BA3CD76A6A3C8ABC1C977E7D773A7195723B29346C8621789D5ABCD2117878946F5A127F27CDD4A845314274680B03B5B07354
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......,'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.70864786784634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6w8LHo6cs+EcWCc1SLcQdcOcJLcdrc7oc0c3ypcrlmczcqcKcPcSYcfApc5cFkYu:61q8GY8OggpIgQpHnlPgw03Itd0K
                                                                                    MD5:E94CDDA083208AF1EE2BBC71136E711E
                                                                                    SHA1:268E1031AE9F3D6F9D6DFB250651C8CA7B43A133
                                                                                    SHA-256:53BDA1D8FD445D0A603CFF91AB244B27BA1B7A37FEF1541499617D3A30998987
                                                                                    SHA-512:2709966E7D8FC95298DB0E42098E19427D4A0DAE4161A59F67B2F19BCA708CC0F218964DE00A684DE3A020F3A93FB96E8BE3E12DFBFB60098CDFED85DC68BCC7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@................................../..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........+..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.60500006591566
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b1lHq9fRzjMlIm2FmollPqNKS2pxsrIeEjPqXp2qwz2/UbGp0JJ2Y:+/s5XM2lPm2mxlBZq
                                                                                    MD5:0FD00B3821011A7323CC2B230145FE50
                                                                                    SHA1:C1AFAEFC985099E8A36BBA935D652B880B80266B
                                                                                    SHA-256:75FE8CF182A0BC65CC3DF60155837528520492CF3290F3F5BDF839DB813CA62E
                                                                                    SHA-512:61B5C7C2B9F8A22676190885C0617F10377D26926421F6C45CACD64EE0593F791C58EB31D3D0D0DCEEEB301C94365D373144FEC33EE2095088CFED67BBFA5601
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H.......|$..............P ..+...........................................'..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):4.007462076109497
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:KB5nPluBuJv/ck5wwAaoR5JzQ+f3m/mjc3vJedenoksk3TwYoX5w6rvXEw5uMXyL:KbqdBtNfFY/yODli4dffpOjVVVVm4
                                                                                    MD5:0D1501560F4C0F41860E76F3F5B74B59
                                                                                    SHA1:B8797909B0BD90B2756A05DEAB85C63594C8B5B1
                                                                                    SHA-256:920C0762603F014FD80868D0DD29AF526867BD06E037C38D5E44263F4BE13B93
                                                                                    SHA-512:366A4DC5E17BFF06E99F02B761E8E8ADEE5B21778971C2C3431757FED0BBA9EBFFA0424398CD043040CE5FE30BFAFC787E0FD28E2EF53F7443AF5A04389E946F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....*..........NI... ...`....... ....................................@..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................0I......H.......TE..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.721606779468658
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:oYOtEDDvdMRFnZWtYbYzm24kC/dDMQZTMzxlPwyKDj:oYOy2ZWxE
                                                                                    MD5:BC14789692741C5B5BFF2BDC5929CEDA
                                                                                    SHA1:CD1982FA66827AA7B4413D7A25F85467CED0D53A
                                                                                    SHA-256:CE02FACC1F26555511E8CEBFDE1867C108D25EB3FE109A8318C09D031291A427
                                                                                    SHA-512:603DEA7111CDCFA0B6C9CF15A6C3D657D88188F7B7A558910186399170581BE8F89A8C88F5FEF7EBB02A5E491E02C448B3043D0FADBB9ACBD4EF2AC03BDAA822
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!.................1... ...@....... ....................................@..................................0..W....@..h....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B.................0......H....... -..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.124706156241719
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:V2npMuAyAHendmVeVPVqVSFkb3XoJUycJ:VvZAdmAlYIFkLFyo
                                                                                    MD5:21F3F29C689AAE23376ECEABDE463EB5
                                                                                    SHA1:7E19912A38EBC4D3189C028E76611CA4BCB6DD79
                                                                                    SHA-256:939C8238C3CF20D94B3EB5A2ADF3FBAD17C2839919758BE43051BCA2975FD0CC
                                                                                    SHA-512:D493FF3EF9597ACA24691893BAA8FA705349772818A2E1CCD81278E0824A0CED0F712AE1F82F574C1E5867878B4A79AEA9A7F96A4974BE6712C0348CEF845332
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................9... ...@....... ....................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H.......\6..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.767046359489489
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6go6olXKH23S+lvzexlN7Ea/DlPq+LDJIRhj3vgIU1WyoFp/98P28s9JJ2L:tuKW3W//DlPNCfj3YG7T3
                                                                                    MD5:3A3AF6CDBD99FA1C777CBF9BD36D1E69
                                                                                    SHA1:20E09FE02F7101FCA45442DB2D3D1836FB75A29F
                                                                                    SHA-256:2C2C12760C8410DABD37BC9838ADD8B5EE974F7DA0B6137D3053FE4814BE1C14
                                                                                    SHA-512:CFF1E25A2E88920108C882348FC6EA7B2884294A155DD3181EFB247B3C668B9B752801DF43B5D9C59F380E9C5D6C5DCD86FFCC952AFB2F95BCD194D5775C1ABA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................jQ.D..qA.N..3F.%<hy.m...1B<.,.+.)Q.5.W"./.P4`.H.....e...H...g.........YK...h..\........f1.Y..7.L7......n"s...<#.a.8.d.C................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.084015860715217
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:C7gkXWt1ExlZ5SUS2zRf4fQlclPNTgjiBlZsKJ:h0WfUS2zRf4fQSsug
                                                                                    MD5:AB356388E50971B0CCC8BB02C96858BE
                                                                                    SHA1:CD9F4BC5358D5651C398807D45F439ED43E0BE57
                                                                                    SHA-256:DFA7D81FAC26A31642BE5845089E4570DB06350494161D8C3CCE07A258F192D9
                                                                                    SHA-512:215E35030175267D1F3DD9261D24634031F836028F9CF4F87C30B8C477B9008C7F8BEDF0355BBAD8005BA41CB6615FAC4A06031FE2CC74EF9CD7DA039D609B34
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ....................................@.................................h)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......\%............... ......P ......................................4".. .M....1(.gwP...F7...r.....<._.....<...X.>..V............h.*5e..yy.b.$nTI..m|H....|.y.)m.@@..;.[>..4.R}......:..0..u.G5...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.124706156241719
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:V2npMuAyAHendmVeVPVqVSFkb3XoJUycJ:VvZAdmAlYIFkLFyo
                                                                                    MD5:21F3F29C689AAE23376ECEABDE463EB5
                                                                                    SHA1:7E19912A38EBC4D3189C028E76611CA4BCB6DD79
                                                                                    SHA-256:939C8238C3CF20D94B3EB5A2ADF3FBAD17C2839919758BE43051BCA2975FD0CC
                                                                                    SHA-512:D493FF3EF9597ACA24691893BAA8FA705349772818A2E1CCD81278E0824A0CED0F712AE1F82F574C1E5867878B4A79AEA9A7F96A4974BE6712C0348CEF845332
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................9... ...@....... ....................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H.......\6..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7776738283051285
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:I8AYPYnaPwxxDCPfW8lt4qlP+PI8cOnwa:I8zhlSqtW
                                                                                    MD5:6C9DFD2C4C06705A883EEEBA02082EB3
                                                                                    SHA1:A485F416392C110D07E4400E7E9B81ADEF643C06
                                                                                    SHA-256:7BA3309A9C01F9A58233747226199CC5A3A9BB1AED3BFCDDF3B6B232C9532AF1
                                                                                    SHA-512:7B609A239532903B6E503B3B5DB138CD667B1ABEC9D89F59590664DCFBF70ABFB38926A6D429242F5355B988E0F65AB239AA4038D0AD05410C2A2BD777CB2F24
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@.................................x+..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..:...........................................6..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.70864786784634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6w8LHo6cs+EcWCc1SLcQdcOcJLcdrc7oc0c3ypcrlmczcqcKcPcSYcfApc5cFkYu:61q8GY8OggpIgQpHnlPgw03Itd0K
                                                                                    MD5:E94CDDA083208AF1EE2BBC71136E711E
                                                                                    SHA1:268E1031AE9F3D6F9D6DFB250651C8CA7B43A133
                                                                                    SHA-256:53BDA1D8FD445D0A603CFF91AB244B27BA1B7A37FEF1541499617D3A30998987
                                                                                    SHA-512:2709966E7D8FC95298DB0E42098E19427D4A0DAE4161A59F67B2F19BCA708CC0F218964DE00A684DE3A020F3A93FB96E8BE3E12DFBFB60098CDFED85DC68BCC7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@................................../..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........+..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.721606779468658
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:oYOtEDDvdMRFnZWtYbYzm24kC/dDMQZTMzxlPwyKDj:oYOy2ZWxE
                                                                                    MD5:BC14789692741C5B5BFF2BDC5929CEDA
                                                                                    SHA1:CD1982FA66827AA7B4413D7A25F85467CED0D53A
                                                                                    SHA-256:CE02FACC1F26555511E8CEBFDE1867C108D25EB3FE109A8318C09D031291A427
                                                                                    SHA-512:603DEA7111CDCFA0B6C9CF15A6C3D657D88188F7B7A558910186399170581BE8F89A8C88F5FEF7EBB02A5E491E02C448B3043D0FADBB9ACBD4EF2AC03BDAA822
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!.................1... ...@....... ....................................@..................................0..W....@..h....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B.................0......H....... -..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.084015860715217
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:C7gkXWt1ExlZ5SUS2zRf4fQlclPNTgjiBlZsKJ:h0WfUS2zRf4fQSsug
                                                                                    MD5:AB356388E50971B0CCC8BB02C96858BE
                                                                                    SHA1:CD9F4BC5358D5651C398807D45F439ED43E0BE57
                                                                                    SHA-256:DFA7D81FAC26A31642BE5845089E4570DB06350494161D8C3CCE07A258F192D9
                                                                                    SHA-512:215E35030175267D1F3DD9261D24634031F836028F9CF4F87C30B8C477B9008C7F8BEDF0355BBAD8005BA41CB6615FAC4A06031FE2CC74EF9CD7DA039D609B34
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ....................................@.................................h)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......\%............... ......P ......................................4".. .M....1(.gwP...F7...r.....<._.....<...X.>..V............h.*5e..yy.b.$nTI..m|H....|.y.)m.@@..;.[>..4.R}......:..0..u.G5...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.699670159881912
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:7XmayKwgyyXYHuNo9XrLXqLo8lPLNoeQr:7X8gVX+uNo9XPXqvXoeQ
                                                                                    MD5:AD12271A5A1D6CC30985517116091CC0
                                                                                    SHA1:D09B96C5DE05D643FFCA973226DEC15E8924244F
                                                                                    SHA-256:35946298511CB617ED9B977F599F4A9AE30BB4E7C47DF5C7C93A039CA4A02279
                                                                                    SHA-512:8BB45D1E07E68B325474B2EF16BA3CD76A6A3C8ABC1C977E7D773A7195723B29346C8621789D5ABCD2117878946F5A127F27CDD4A845314274680B03B5B07354
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......,'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):4.007462076109497
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:KB5nPluBuJv/ck5wwAaoR5JzQ+f3m/mjc3vJedenoksk3TwYoX5w6rvXEw5uMXyL:KbqdBtNfFY/yODli4dffpOjVVVVm4
                                                                                    MD5:0D1501560F4C0F41860E76F3F5B74B59
                                                                                    SHA1:B8797909B0BD90B2756A05DEAB85C63594C8B5B1
                                                                                    SHA-256:920C0762603F014FD80868D0DD29AF526867BD06E037C38D5E44263F4BE13B93
                                                                                    SHA-512:366A4DC5E17BFF06E99F02B761E8E8ADEE5B21778971C2C3431757FED0BBA9EBFFA0424398CD043040CE5FE30BFAFC787E0FD28E2EF53F7443AF5A04389E946F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....*..........NI... ...`....... ....................................@..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................0I......H.......TE..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.60500006591566
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b1lHq9fRzjMlIm2FmollPqNKS2pxsrIeEjPqXp2qwz2/UbGp0JJ2Y:+/s5XM2lPm2mxlBZq
                                                                                    MD5:0FD00B3821011A7323CC2B230145FE50
                                                                                    SHA1:C1AFAEFC985099E8A36BBA935D652B880B80266B
                                                                                    SHA-256:75FE8CF182A0BC65CC3DF60155837528520492CF3290F3F5BDF839DB813CA62E
                                                                                    SHA-512:61B5C7C2B9F8A22676190885C0617F10377D26926421F6C45CACD64EE0593F791C58EB31D3D0D0DCEEEB301C94365D373144FEC33EE2095088CFED67BBFA5601
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H.......|$..............P ..+...........................................'..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.767046359489489
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6go6olXKH23S+lvzexlN7Ea/DlPq+LDJIRhj3vgIU1WyoFp/98P28s9JJ2L:tuKW3W//DlPNCfj3YG7T3
                                                                                    MD5:3A3AF6CDBD99FA1C777CBF9BD36D1E69
                                                                                    SHA1:20E09FE02F7101FCA45442DB2D3D1836FB75A29F
                                                                                    SHA-256:2C2C12760C8410DABD37BC9838ADD8B5EE974F7DA0B6137D3053FE4814BE1C14
                                                                                    SHA-512:CFF1E25A2E88920108C882348FC6EA7B2884294A155DD3181EFB247B3C668B9B752801DF43B5D9C59F380E9C5D6C5DCD86FFCC952AFB2F95BCD194D5775C1ABA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................jQ.D..qA.N..3F.%<hy.m...1B<.,.+.)Q.5.W"./.P4`.H.....e...H...g.........YK...h..\........f1.Y..7.L7......n"s...<#.a.8.d.C................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.611718739849792
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:61QHcAI/PI/Fw/LbLKLMOcVDOcJPfDu+qKflPqAxXxrjQ/I4jsqwIA9oqTxg+G/T:h8AYPYFgH2A1DpPfy+jlPRCIccOnwa
                                                                                    MD5:432AE46FB1FF650ACD3618337FE6C087
                                                                                    SHA1:A324BAABAC5780B940E5698E59FAEA7906BEE124
                                                                                    SHA-256:D93CC7FCC531AD750259B93D83B0830AAB1AE24F52ABA11588288DD7D237E8CA
                                                                                    SHA-512:DD882632FAD281D7480532D6751085E170B6B6A446FAAFE5A4AC99352B83DB8835B6866E6941360193F6A3F6A4058AA317FDA11038D924B5729A1BD449D51AF9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..S....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7206804459236347
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gDeHwml8jiKazjaOikAKi98ZGXIxcytvdVQdXuKcdXDzvjkmlPqbxX6r0lbjSQD:8XmayKpiykXYcy/4Xr6X/vLlPIyoeQr
                                                                                    MD5:298968842797555AA432A2D3A022C1D2
                                                                                    SHA1:DDCEB8B79A5AAC29FF48E309B0997FA571657008
                                                                                    SHA-256:A8BD5FC80F169CE8EBB3F857C4AB321D3F4BF9E10882AFCDE52ED7ECA4E4EEC3
                                                                                    SHA-512:AAED7D391AA58A5C46F8AE9235E0C7FD8E248A88CD4BE976B46F79FFE99A19BD33EC373A07C95CE16BE540DC24B82BD0128A7048CD5A5713383687616DB1CB0B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................+..K....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......4'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.788413097425715
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6y61Ho6cs+EcWrccLcQQ5cjcSSLcdIc77cAc5pc7c7cxCcpcycSKcfAtcpkcFGbN:fS13lI4Syk1XzlLelPgw0c7DdfK
                                                                                    MD5:68BF2BF6E62E6A0B2D6E162FB71C2245
                                                                                    SHA1:B74FB50E88F17B9061F93E8B35845A45519E9AF0
                                                                                    SHA-256:DC99CA534224B7DF3EFA7CBEE89D03F0A50B3FD876A6CD1523631954B5D7F4A2
                                                                                    SHA-512:8B72E256FC728CF3D22AEA450D656E43C089AD5AE0908E78DC7644D5140DBB265395BFD7E9B9D2C04AC1A508053FE6A64650DF0599B3664D8E3A1B50457A8104
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................~0... ...@....... ....................................@.................................(0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`0......H.......\,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6288370455300125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9++Hq9AuzjlGE+SClPllPqNKS2pxsrIxmGjLqXp2qwz2/UbGp0JJ2Y:+Q+s3XlgRXlPm2pKlBZq
                                                                                    MD5:156E34CED576F9B4B136C6EBC7AA7831
                                                                                    SHA1:583F0A05839B89ED53073EA892948376D15DA069
                                                                                    SHA-256:81A8AE83F074304FB4905F1CD654731563008010629519A8E78BD033C34B8C62
                                                                                    SHA-512:1F3ACF3C5BBF1FC3B861EBD7F1815EE3FD6D01AF6FC2568B3930FED6B85E47EF2ADE84AD69697A9E77FFBC2A4B85E15458A9A477435F61649E6A88DF64C86A56
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................T(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):3.9950788719370136
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1B5nPl+RjC8jZh7J/XioJSi9lTmRcmCiCpHFdeto3mOACdkyn58Z6UQ21hM5HWWN:1xQwcV7IHN8Ad7l
                                                                                    MD5:2DBBDDDAC0F761B1B1E3F3058A3CD877
                                                                                    SHA1:747508C8AAFC4CE0A57A5F912EC574AC15CF1AB9
                                                                                    SHA-256:F4B60A93D1261CEC92F792E9983D44C01F8977B1C8E2CF975D2A85C32DD8AA96
                                                                                    SHA-512:B37678E42EB281D811F9DC03860AF50724C940ACB3321351F6B8D0482988A46AB02FF483FCE287AC00BDDE7278E4974D417521583F3399D9E5E5BCC15555E2C8
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................I..W....`............................................................................... ............... ..H............text...$*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.795961986609238
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:AYOtExuqOg6njYBYCYzLP+qkTz8lPw98ij:AYOHa8o
                                                                                    MD5:DCA2BED49B1A3FE2BC94DC1F9B457115
                                                                                    SHA1:9DD240710FE7341BF3A6508782E95C7C437EA5E1
                                                                                    SHA-256:165AF3A1EBD2D461F03AD17521ED4692FA992A8227BD4F243BF764A2C20ABCA8
                                                                                    SHA-512:8FD6D205E71253896DDDDB59706DE39FE2459ABB9AE61BD887D8CC14936782A39BFBC259DA67C4AECD827E76824E67BA7F6B93E7F23D56CB3904B55FE8144B58
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.251113891221509
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:b2nqcsAzAzltEvlVvVtVXVvT1SFLFwcsLjLreKm:bSE3EvlNXt1T1SFLmccjWF
                                                                                    MD5:4F42D0E6AC0D91BBF16A658CDD2EB345
                                                                                    SHA1:4BA06EEBC69B664FAC12773E59C6CFEBE81A5950
                                                                                    SHA-256:78F3203B702C28F112F3E0D4B771D55F6CC9257114CB708A99B4F6784F4D52B1
                                                                                    SHA-512:A7A8EC320761F91DD61BD25E590F1513F09313AA477330028EF1F0B79E3E51768326229BA5FDE52D75721FF6EA1CE31D99079D5BF23A3F844301763F8644C2A1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......87..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7725614852658125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gEd5lhH23S+lvgexlk7OaMoklPq+LDJnWhj3vgIU1WyoFp/98P28s9JJ2L:tslhW39oQlPNRij3YG7T3
                                                                                    MD5:7D02D631A76EB6668A1F2C53EC39ECB0
                                                                                    SHA1:AEA9A149D324AA931C0DABB5825E7B517619E11D
                                                                                    SHA-256:CEC8007F6DF984001F09942E5D46B9A02B51B759DBC09B3528395B8B0FF59A46
                                                                                    SHA-512:A063989662D3A844DC5AE62973E8CA273B59B625AC58F547B18D74262644C3061D4370B63D495784E545DCECA3760D2A7C154CC30FC7DCDE8985C05BA800FC51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...............................U....@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v..[I.F.q-...9?e...-...HK..&.....*.... ..X..'..$r..o....[`.x.i.2....Tx..........o..,..F.........>....%FJ....$E..3....m...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.110286419307638
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CxCqGWt134Gw567aYElclPNcZjLOBlZsKJ:TVWBGYESa+g
                                                                                    MD5:D64865F67DA8E3BABEF95DB7C459BE59
                                                                                    SHA1:C3069A7007DE5914F2E1D51BC10F0B8C555FB66C
                                                                                    SHA-256:9860CC9C7D3E29C060A6AAFADA2C33C6758EE71B3B0A193E4EB78AB026CA55B2
                                                                                    SHA-512:FE0ED73CF65084283ECC6BE676C332DF19A60D43D8C4E3FAD7C003F0218E9A6BFA87280E1D69D4C1B94E8DCB0420995338CA2FD2D1E05FDB2FF863FDCD979733
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................*_....@.................................x)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......l%............... ......P .........................................o.w............A...ei..^x./E6....&.6%.Vw..0......Z...a.......WEi.G.7\......M..5.5..:.......fm...(E4.6g.T.9.c...v.+...a9................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7206804459236347
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gDeHwml8jiKazjaOikAKi98ZGXIxcytvdVQdXuKcdXDzvjkmlPqbxX6r0lbjSQD:8XmayKpiykXYcy/4Xr6X/vLlPIyoeQr
                                                                                    MD5:298968842797555AA432A2D3A022C1D2
                                                                                    SHA1:DDCEB8B79A5AAC29FF48E309B0997FA571657008
                                                                                    SHA-256:A8BD5FC80F169CE8EBB3F857C4AB321D3F4BF9E10882AFCDE52ED7ECA4E4EEC3
                                                                                    SHA-512:AAED7D391AA58A5C46F8AE9235E0C7FD8E248A88CD4BE976B46F79FFE99A19BD33EC373A07C95CE16BE540DC24B82BD0128A7048CD5A5713383687616DB1CB0B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................+..K....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......4'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.251113891221509
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:b2nqcsAzAzltEvlVvVtVXVvT1SFLFwcsLjLreKm:bSE3EvlNXt1T1SFLmccjWF
                                                                                    MD5:4F42D0E6AC0D91BBF16A658CDD2EB345
                                                                                    SHA1:4BA06EEBC69B664FAC12773E59C6CFEBE81A5950
                                                                                    SHA-256:78F3203B702C28F112F3E0D4B771D55F6CC9257114CB708A99B4F6784F4D52B1
                                                                                    SHA-512:A7A8EC320761F91DD61BD25E590F1513F09313AA477330028EF1F0B79E3E51768326229BA5FDE52D75721FF6EA1CE31D99079D5BF23A3F844301763F8644C2A1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......87..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7725614852658125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gEd5lhH23S+lvgexlk7OaMoklPq+LDJnWhj3vgIU1WyoFp/98P28s9JJ2L:tslhW39oQlPNRij3YG7T3
                                                                                    MD5:7D02D631A76EB6668A1F2C53EC39ECB0
                                                                                    SHA1:AEA9A149D324AA931C0DABB5825E7B517619E11D
                                                                                    SHA-256:CEC8007F6DF984001F09942E5D46B9A02B51B759DBC09B3528395B8B0FF59A46
                                                                                    SHA-512:A063989662D3A844DC5AE62973E8CA273B59B625AC58F547B18D74262644C3061D4370B63D495784E545DCECA3760D2A7C154CC30FC7DCDE8985C05BA800FC51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...............................U....@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v..[I.F.q-...9?e...-...HK..&.....*.... ..X..'..$r..o....[`.x.i.2....Tx..........o..,..F.........>....%FJ....$E..3....m...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):3.9950788719370136
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1B5nPl+RjC8jZh7J/XioJSi9lTmRcmCiCpHFdeto3mOACdkyn58Z6UQ21hM5HWWN:1xQwcV7IHN8Ad7l
                                                                                    MD5:2DBBDDDAC0F761B1B1E3F3058A3CD877
                                                                                    SHA1:747508C8AAFC4CE0A57A5F912EC574AC15CF1AB9
                                                                                    SHA-256:F4B60A93D1261CEC92F792E9983D44C01F8977B1C8E2CF975D2A85C32DD8AA96
                                                                                    SHA-512:B37678E42EB281D811F9DC03860AF50724C940ACB3321351F6B8D0482988A46AB02FF483FCE287AC00BDDE7278E4974D417521583F3399D9E5E5BCC15555E2C8
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................I..W....`............................................................................... ............... ..H............text...$*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.788413097425715
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6y61Ho6cs+EcWrccLcQQ5cjcSSLcdIc77cAc5pc7c7cxCcpcycSKcfAtcpkcFGbN:fS13lI4Syk1XzlLelPgw0c7DdfK
                                                                                    MD5:68BF2BF6E62E6A0B2D6E162FB71C2245
                                                                                    SHA1:B74FB50E88F17B9061F93E8B35845A45519E9AF0
                                                                                    SHA-256:DC99CA534224B7DF3EFA7CBEE89D03F0A50B3FD876A6CD1523631954B5D7F4A2
                                                                                    SHA-512:8B72E256FC728CF3D22AEA450D656E43C089AD5AE0908E78DC7644D5140DBB265395BFD7E9B9D2C04AC1A508053FE6A64650DF0599B3664D8E3A1B50457A8104
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................~0... ...@....... ....................................@.................................(0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`0......H.......\,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.611718739849792
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:61QHcAI/PI/Fw/LbLKLMOcVDOcJPfDu+qKflPqAxXxrjQ/I4jsqwIA9oqTxg+G/T:h8AYPYFgH2A1DpPfy+jlPRCIccOnwa
                                                                                    MD5:432AE46FB1FF650ACD3618337FE6C087
                                                                                    SHA1:A324BAABAC5780B940E5698E59FAEA7906BEE124
                                                                                    SHA-256:D93CC7FCC531AD750259B93D83B0830AAB1AE24F52ABA11588288DD7D237E8CA
                                                                                    SHA-512:DD882632FAD281D7480532D6751085E170B6B6A446FAAFE5A4AC99352B83DB8835B6866E6941360193F6A3F6A4058AA317FDA11038D924B5729A1BD449D51AF9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..S....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.110286419307638
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CxCqGWt134Gw567aYElclPNcZjLOBlZsKJ:TVWBGYESa+g
                                                                                    MD5:D64865F67DA8E3BABEF95DB7C459BE59
                                                                                    SHA1:C3069A7007DE5914F2E1D51BC10F0B8C555FB66C
                                                                                    SHA-256:9860CC9C7D3E29C060A6AAFADA2C33C6758EE71B3B0A193E4EB78AB026CA55B2
                                                                                    SHA-512:FE0ED73CF65084283ECC6BE676C332DF19A60D43D8C4E3FAD7C003F0218E9A6BFA87280E1D69D4C1B94E8DCB0420995338CA2FD2D1E05FDB2FF863FDCD979733
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................*_....@.................................x)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......l%............... ......P .........................................o.w............A...ei..^x./E6....&.6%.Vw..0......Z...a.......WEi.G.7\......M..5.5..:.......fm...(E4.6g.T.9.c...v.+...a9................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6288370455300125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9++Hq9AuzjlGE+SClPllPqNKS2pxsrIxmGjLqXp2qwz2/UbGp0JJ2Y:+Q+s3XlgRXlPm2pKlBZq
                                                                                    MD5:156E34CED576F9B4B136C6EBC7AA7831
                                                                                    SHA1:583F0A05839B89ED53073EA892948376D15DA069
                                                                                    SHA-256:81A8AE83F074304FB4905F1CD654731563008010629519A8E78BD033C34B8C62
                                                                                    SHA-512:1F3ACF3C5BBF1FC3B861EBD7F1815EE3FD6D01AF6FC2568B3930FED6B85E47EF2ADE84AD69697A9E77FFBC2A4B85E15458A9A477435F61649E6A88DF64C86A56
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................T(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.795961986609238
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:AYOtExuqOg6njYBYCYzLP+qkTz8lPw98ij:AYOHa8o
                                                                                    MD5:DCA2BED49B1A3FE2BC94DC1F9B457115
                                                                                    SHA1:9DD240710FE7341BF3A6508782E95C7C437EA5E1
                                                                                    SHA-256:165AF3A1EBD2D461F03AD17521ED4692FA992A8227BD4F243BF764A2C20ABCA8
                                                                                    SHA-512:8FD6D205E71253896DDDDB59706DE39FE2459ABB9AE61BD887D8CC14936782A39BFBC259DA67C4AECD827E76824E67BA7F6B93E7F23D56CB3904B55FE8144B58
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):41616
                                                                                    Entropy (8bit):6.118366181712053
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:/1UUBVS1yKegy8XiOYgzECu0WIbHzVfQ+t9yIor+8ie4:tUTy8XVnzECTWILufr+8u
                                                                                    MD5:7A271CE5582DDCC325732581A533D8BE
                                                                                    SHA1:5FA2C5390EE84BF975C861AFA361D2E17AC9F625
                                                                                    SHA-256:9202C7E903172AE1855AB96EE5D80248292B86100A843DDCC6DB664CD6EDD1B6
                                                                                    SHA-512:43F575A8FDB98565358C7C5C3FECA78A9154CDDAE6BDD1AEF1A2B108B0650059257F8983B9A1E544C12586807303D2C4F440AF0171295EA284C8F7347D24BE70
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....~..........>.... ........... ...............................&....`....................................S.......h............................................................................ ............... ..H............text...D|... ...~.................. ..`.rsrc...h...........................@..@.reloc..............................@..B................ .......H........:..._...........1......P .........................................%]..?.....V.AJ3Z^f.6g.u4.5cJ...+8.j....c;...PP8......6...T...9..kA.u;+U.na6\.......I.c(.J..L.....h.K[.!....s!Sdr.Q><S.&.0..*........-.r...ps....z.(......sG.....o.....o.....*...0..........s.....(......o....o......8......o......o....o......8......o.........o....o......+S..o........o....o......+#..o........o.....o.....(....-....+...o ...-.....,...o!......o ...-.....,...o!......-...o"...-...o#.....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71808
                                                                                    Entropy (8bit):6.302233040356993
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BZb60QnEfniRuc4MG7uKMgM1lBa/0jSNgDWcLbtNnstX1Ac:BZcEfni4c4MG7vKFLLjwX1T
                                                                                    MD5:391166F9D5D40EE90F0744982177F4AB
                                                                                    SHA1:F7DFF35B30DE2E02BCB3A7EFE45334E1B5D7C8FE
                                                                                    SHA-256:FA36ED1236CDA36DFA34BE757A791EC94011D43D19E73D0BD9D0F9F802473A22
                                                                                    SHA-512:700FBE5FD992F678C83CCA1170F68593149C04E314402F7505B8A640FA89CD24633426ECB3548057E7AF14F0342301E66B5785F01F7FDD64ED2AF13614CD98EE
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`."Q...........!..................... ........... .......................@......2.....`.....................................W........................>... ....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........t...w...........]..0...P .......................................v.{....On..O.w..-t..x<P....e.@0v.bY>.7. %c.\.h.J....MW......P.w.J...(...3^.....>M.............(WIH....1..../O}.}...gOm...{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.*6..(.........*.*.*.*.0...........-.r...ps....z..2...o....o....2.r...ps....z..2...o....2.r)..ps....z.o....,..o....o....-.s....z.o.....o......o....,..o....o....-..*.o....-.s.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):760
                                                                                    Entropy (8bit):5.024737792359112
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:TMHdGPa9V9l2K4r3e5f3VOcreI9GakSNFF7ap+5v5OXrRf/2//FicYo4xT:2dz9V9rY36rZPF7NhOXrRH2/d9y
                                                                                    MD5:30F4A541A4542DFD2761089C573AA534
                                                                                    SHA1:871F7FA84886F6697A268D393C8F706894820C99
                                                                                    SHA-256:64E51DCC54AB9C10E197389CCB5FCA50FA419E7108623F6C2FE261BB623EC6E2
                                                                                    SHA-512:3FD8808268718FA1E00A7C8C5AE724374F2E3F9130E939EBB635E0304D86FB68FB5C8EF08A050DAD54648B3A8301CA9D56BBFCF6BC81D3DEDB825408EB54EB59
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <section name="environment" type="Sofrel.Uranus.Framework.Environment.Configuration.EnvironmentSettings, SUFEnvironment" />.. </configSections>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <environment configSource="Config\Environment.config" />.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):87040
                                                                                    Entropy (8bit):5.4554148178321675
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:nDsxiI7pW/tZrszqJBWDnvSYT3VeArUOXeeu:nJI7pW/tZrseyf3fjXeeu
                                                                                    MD5:EAEDE0361F15C2EB139C7E2FC6C6AB71
                                                                                    SHA1:DBC9F9DC7E158538C0FFDEE9AA536C33868EF693
                                                                                    SHA-256:8C8B835E81010D99B0F240E598D65951D4A50771A4B4D85CB74E513FDF169E36
                                                                                    SHA-512:3575D111C742C8D2B56BBC0EAEF1B3E95CE0AB31100047A8EAFE87E91D063BA4D420D7BB7BBD332EAC34BCE6B8DAFCED7AD7E81CEEA830394805A3F61293F40E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Vu..........." ..0..J...........h... ........... ....................................`.................................ih..O....................................g..8............................................ ............... ..H............text....H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........V..............X...0I.........................................."..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):711952
                                                                                    Entropy (8bit):5.967185619483575
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:GBja5bBvR8Q0TE2HB0WLmvXbsVG1Gw03RzxNHgKhwFBkjSHXP36RMGy1NqTUO:GBjk38WuBcAbwoA/BkjSHXP36RMG/
                                                                                    MD5:195FFB7167DB3219B217C4FD439EEDD6
                                                                                    SHA1:1E76E6099570EDE620B76ED47CF8D03A936D49F8
                                                                                    SHA-256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
                                                                                    SHA-512:56EB7F070929B239642DAB729537DDE2C2287BDB852AD9E80B5358C74B14BC2B2DDED910D0E3B6304EA27EB587E5F19DB0A92E1CBAE6A70FB20B4EF05057E4AC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...p$?..........." ..0.............B.... ........... ....................... ............`....................................O......................../.......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................$.......H.......x...(9............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X..+....b....aX....X.....2.....cY.....cY....cY..|....(......._..{........+,..{|....3...{{......(....,...{{...*..{}.......-..*...0...........-.r...ps....z.o......-.~....*.~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.509347235200524
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WBX0TqVWFUM3HmOFs8mXXiA+L3Ad8DUntPKeUELxK2Yj7uIt:+ayIWmp2YeU4x5suIt
                                                                                    MD5:3684F924B38D4FB23DE40554ADFB1537
                                                                                    SHA1:E4FB7143ED7DFD2CAD2E379703808CEF429882BF
                                                                                    SHA-256:702444FCDE9AC6550E636A32678493E6835B247D8D8D344E2F803184F9F0EA45
                                                                                    SHA-512:8ACAED49F0204B8BEC8DD92D759F0E7913B447A53D0962FAE290A40EE36A20435EE7508E813EDCBD5A6BA1638385D235C64C1643052EDCA890D218DE3453606C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..0...........N... ...`....... ....................................`..................................M..O....`............................................................................... ............... ..H............text...$.... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......p$...............A..@...........................................r.(......}......}......}....*....0..T........-..+.(......(.....r...pr'..p...(.....(.....{.....(....-.(....+....{.....{....o....**....(....*..0...........(....-.(....+.....YE............!.../...=...K...Y...g...u.......................................8......(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14496
                                                                                    Entropy (8bit):6.327509765949796
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:rb6Oaxhqm1st8jjMfGkqWx/zB//0GftpBjcc3:rCwUQ8jjenj8i53
                                                                                    MD5:964AB2C3520B8A735329F0BE577C5850
                                                                                    SHA1:968EAB9103EC64A0DD4657582F28BB6FE9644209
                                                                                    SHA-256:DA3ABFEE09DDE110E4E9A0321F7223F7380A1052CB506313F44947E32F09BB5F
                                                                                    SHA-512:0BF393D15E64FB1A2BC0BEF663DD760E3ACDFDA503AEA185A83B904B01D612FA3AFFE7FFEC8780C23274D9B8E182B29CDD906CF8A0825569AB02ABBF4DE0AA61
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....="S...........!................>4... ...@....... ...................................`..................................3..O....@.......................`.......2............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 4......H.......(#...............!..X...P ......................................;.)%.6.h..q..O(-.`......&7.q.G..G1..J...S1.&..f....H.....bl....W(.E).K.RI..............8&Q.b......H+!df-.f..3h.H..h7|.]...(....*.0..3.......~.....(...., r...p.....(....o....s...........~....*.~....*.......*V(....ry..p~....o....*.0...........u!.....-.r...ps....z.(....*Z.,..~....o.....$...*.*V.,..~......$...o....*.r...p.$...(.........(......$..........s ...s!...("........*...T..............lSystem.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14336
                                                                                    Entropy (8bit):4.9314244617466665
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:FzP9VECr49b0mHsP86g8n6ZhMv11wE7uDzfpK2Ft/GjX3:dP9VL208sU6qniwEqjF1qX3
                                                                                    MD5:1F2D54F48C615F086E1CB19DD44FD97C
                                                                                    SHA1:1B97539D5AC39B7C989D8CD5CF8D71D6745287B4
                                                                                    SHA-256:3ED0A4217517B17E1459D649E4C3811865A4838E71508A953D777B2F9E16A4C3
                                                                                    SHA-512:6178AB1ED7D626186E879FDFCCF3833B68B47915D715AE9177DACEFB4B7B53869CBF8D2E8852079E5A8586E8E8DA8CE40D7DB1A4AF4D1A6372741228AAFAEFAA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............L... ...`....... ....................................`.................................dL..O....`............................................................................... ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................L......H........&..|%...........................................................0..H........o......-..*.o......u!...,...*.u"...,..*.u#...,..*.u$...,..*.u%...,..*.*..{!...*:.(......}!...*b..3..*......3...*.,..*.*~.-.r...pr...p.(.....*.o.......*..-.r9..pr...p.(.....s....*.o.....(....*.0..y.........c1..........*.E............#...A..._.......}...............8.....rc..p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r8..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):139888
                                                                                    Entropy (8bit):7.142634633787823
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:TNZyjlo+Ib/RorkWhl/pNODb6lwztxdbbDFlkYUo8:TNYAb/2rk2l/jkb6uzj5Qo8
                                                                                    MD5:18DB3E02D95A16FD502C7C091C0361D9
                                                                                    SHA1:AB2D700306E0A0A3D094A0BC856FF1FFAD916C49
                                                                                    SHA-256:34843CFEA24B713B1B5FD9A93C61D7C6D3FA320DBB84DF60D9D48C5560C79452
                                                                                    SHA-512:6DE8751ABED256BCC381F69248F33AAE551A17966EFBC0ABB5C1DC98865B46E3924202C1347E0EC6949F1719E1D282817838815E99E68E7B1381A6B204C95416
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...]."Q...........!..................... ........... .......................@............`.....................................K.......................p>... ......X................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......X....K...........M..._..P ......................................Du..l..O..(|.n.....z.fj.W4.mc....f...>e..~.V....<../..}....1$q.7@r..3w..JQ....._C(S....C. .Z.Pt..d,......f-..]..".SO.7.4...x.0..:........(.....s......r...p(M...o.....(.....~....(.....~....(....*F.~....(.........*J.~..........(....*F.~....(.....+...*J.~......+...(....*.0..,.......s.......(....o......(....o......(....o.....*F.~....(.....+...*J.~......+...(....*....0..3........t.......(...............#..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.488842171019742
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6fhZMjDlMDH5lpoJDLYNMTwCRXQtPyqE4Ev/mZWjH1AglkAqVwAK5W1AxF:UoDlUbmJfzwCRXQtqqE4zWjugRuXaWu
                                                                                    MD5:23E59CC67C075C315F717770D46B00A6
                                                                                    SHA1:260D18B0BDBB8ADABB1A6D8565ACA14CCC462CB2
                                                                                    SHA-256:1E2636B145C0C69E30DB1492950EE23D02458DFE6DAC69EA51D865BA15FA0FDE
                                                                                    SHA-512:36128BAE654D5C58053FEF3EB8DCD54B7671DACB5CEA6F26C5340E0BC38579667064F169FE7FA744FDB40DEBAAA4CA040D749C1DA803A139594DF9E7D1D42284
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Y.........." ..0.............N'... ...@....... ....................................`..................................&..O....@..8....................`.......%............................................... ............... ..H............text...T.... ...................... ..`.rsrc...8....@......................@..@.reloc.......`......................@..B................0'......H.......P ..t...........................................................BSJB............v4.0.30319......l...|...#~......P...#Strings....8.......#US.<.......#GUID...L...(...#Blob......................3..................................................y.....@.....>.....h.................`.....,.....E...........T.....2...............................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........#.....,.....K...#.T...+.x...3.x...;.~...C.T...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11776
                                                                                    Entropy (8bit):4.956614026804989
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WCvPuFqE/nQ+L9XRy/z/J0pD+zcNwlClvhMHJaOHuM:TZEfQa9I/Jy+4ZWROM
                                                                                    MD5:0A0505AFC1C5AF06E4383DF3032D0674
                                                                                    SHA1:6242B357013B9E1B6423DCB5482B2D0EB510A4D5
                                                                                    SHA-256:A902F1790B60C1177301073CC1FDA983B4E3186FD6EC247335B115A41A3786E2
                                                                                    SHA-512:F7A471192BE900AC14B4C39B39CCA5EAE1ED35A04E1BC70B50AAB2867DDCBA9428EA431F00B5E05B96AEE05DBE70F2673C286752F05776BDC54192364054C1FA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..$...........B... ...`....... ...............................0....`.................................4B..O....`..\............................@............................................... ............... ..H............text...."... ...$.................. ..`.rsrc...\....`.......&..............@..@.reloc...............,..............@..B................hB......H........%......................|@........................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.0..S.......s....r...p......%..(..........%..(..........%..(..........%..(..........(....o....*..(....*V(+...o,...o$...s....*.(....*.(....*B(+...o,...o$...*.0..(.......(+...o,...o%....(......(....-...(......*B(+...o-...o'...*B(+...o-...o(...*B(+...o-...o)...*..0..F.......(....o....o.....s....%.o....o....%.o....o....%.o ...o....%.o!...o...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):211632
                                                                                    Entropy (8bit):5.3707738806905905
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:3TdnDzOb56Xp6kGijb7N5KH+KnklI7o5UuL8J:3TdnDCbgX4ecoY
                                                                                    MD5:B8ACA033D81112E38EEA7B9525F1BD56
                                                                                    SHA1:7428C64C3E68DD45E89FDFEBA08F75F1D3A49B29
                                                                                    SHA-256:D750B661263AEFCBE961942D15C2DC507DA6361748A8E65426963274B5744EE7
                                                                                    SHA-512:045E2D152DD2AB8AB64BCF0B32ACBEDC2700018A354E26C9ADB2D26C7390D648A51903DFA33FC61CDDAF2DE6B5DC38D3F0745D37AB8BDB9328566EE48806892E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ......~.... ... ....... .......................`......q.....`.................................,...O.... ............... .......@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):24576
                                                                                    Entropy (8bit):5.439852939293774
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:zbXOwhwMrAfN2/hkBwkGa2+dWLG4ZfAcION/65Hld2qFKNk8qluGLRqOunsWsrj:PhhwMrsek2+I95shhJRXiJs/
                                                                                    MD5:74E7BEBF2E462C337B1280A3E98D0B35
                                                                                    SHA1:0DF183BA4D1C4E13073581E56564F95AC5CB3254
                                                                                    SHA-256:F55761468B9B0CE16C70A2F011C486DFF07948D35EAE3E67B092D610C381F368
                                                                                    SHA-512:870D44A95CC69D694189A702DDFCEA6D98F8DD25BB0DAD78AA7259E73E328946B68160215FF209EFF93AD40DD19B34752E9E15217E78298E4C696712F0F2DF49
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..V...........t... ........... ...................................`.................................dt..O...................................,s............................................... ............... ..H............text....T... ...V.................. ..`.rsrc................X..............@..@.reloc...............^..............@..B.................t......H.......@2...=...........o.......r.......................................0..G.........(....}.......}.......}.......}.......}......|......(...+..|....( ...*..(!....s"...}....r...pr...p.(#...*......(....*...0.................{....o$...o%....+9.o&.......o'....j3&...r'..pr=..p..A....o(...()....(#......o*...-....,..o+.....9.....o,...o-.....8......o........o/...r...p(0...,t..o1...o2....3e..-...o3...-7...o4.....r...po5...r'..pr...p..A....(6...()....(#...+.r'..pr...p..A...(7....(#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7680
                                                                                    Entropy (8bit):4.609043127953718
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:4x/lg1lEFiC83HY+z63w6n9HdDBFeK9R303inq6ncYZCl6lSWn:4Dg1sovz6AiDYKTDnbchMlSW
                                                                                    MD5:56E7B6DDF9FA1BB2363D5813120674A4
                                                                                    SHA1:92745E5EE779EEC4C4E2021FFA59E3FFF6242DC7
                                                                                    SHA-256:816C7FA679B7B5E529FA8274ABBC75FD56E73C1244B79EA90B552F31AC6C219D
                                                                                    SHA-512:A315110A1CB434914B37373DEB36D669EE1CF3A9B6269927F8C2D49AD2C1991560748D64F63DC1F1E2F9ED5BC01EE621EDCDC1F851F942FFB734129695173996
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............~3... ...@....... ....................................`.................................,3..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`3......H....... !..............................................................~r...p(....r...p(....(.........*.0..T........(.......}.......}.......}.......}.......}......}......}.......}.......}......}....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*BSJB............v4.0.30319......l.......#~..L...D...#Strings............#US.........#GUID.......X...#Blob...........W..........3..................................................................A.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55904
                                                                                    Entropy (8bit):6.299047178318044
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BYQaIZaEmaOQxn6JxKjtlMZAnuETAV+w4:aIhOQcSLAj4
                                                                                    MD5:580244BC805220253A87196913EB3E5E
                                                                                    SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
                                                                                    SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
                                                                                    SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):1180
                                                                                    Entropy (8bit):5.055540465344216
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JduPF7NhOXrRH2/dVyH2/5VEH2/qoV3H2/qo9y:327O7Rgd8g5OgX1gXw
                                                                                    MD5:131D63E86E45EC3D3A831BF1F7FECFEA
                                                                                    SHA1:41BFCDDD7C6C7A011693DA8956F7415D7219371A
                                                                                    SHA-256:318E8D19BEE652FFD2B8AEE736E9C3C537979043365E079A95C0DA758B8558C8
                                                                                    SHA-512:CAE1254C31E947A9BA8560974BBE9D9DF082234D954C1AB5D649437343D3302715E19B4DED6AD8853A727E37F49805D7C8A4B69F24E5C8488577370EBD8BDBF9
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFInfrastructure" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutra
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*67 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):34304
                                                                                    Entropy (8bit):3.2335417829239637
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:YPMAPuAPVwAPuAPVdAPoEC5ELMNfK1exhUubzAk9vO6bq/jcPWY4tx0EfTVv9ptR:EzR1RsoE9Lt1erxsFmoE7v2
                                                                                    MD5:5BA7CC3B868063DBF7B76EC9E8B4D7D6
                                                                                    SHA1:3F7196D56077DDD8DEB6B8DFA0F4D84C41D43274
                                                                                    SHA-256:33879940E55C62FA5353E04552111E47950699D3AE1CB4C0A16D4FD06211A941
                                                                                    SHA-512:9170ECDD06EBAEF196CEEE68168A6F39928099692A219087353BD7B808855D330F44243C70DDF302C03EB209B43EA6FE0674E23E989A3878480AD8CB78FB7A91
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS...........C...........B...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):686
                                                                                    Entropy (8bit):5.095369395177209
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:MMHdGzNFF7ap+5KJf/2/DXFip+5NJf/2/qKFicYo4xT:JduPF7NyH2/5V3H2/qo9y
                                                                                    MD5:1C692F9907BB6FCD97ECA18D587E5B87
                                                                                    SHA1:C6021EA19B5F88925AB27FB2E65C3CB47A6601AB
                                                                                    SHA-256:EF01791FD533C9B51F2F279D21A6CA4B6F935C1AFE6D4A24E75DB91E568C6404
                                                                                    SHA-512:15195678CF637D7E19445523F9B39604FDA221D3D5F530FF5F6090C0AF22BC9D46C3936811D02F20BB133ACA210575F6C860247B63ED1574EE9EAAC4725B3F5D
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.0786290349934315
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Cf8wjVl9lOPAmVqzzNBdu3DPxXEvLCiDfp6wZ8ETV56hjRUA8qbC/We3nebPLqX:TjGImk/5Q1EewZ82Vwjc2Ceu5O
                                                                                    MD5:649DFD82FE2569BC5873F0715AA545CB
                                                                                    SHA1:9D2A506C841D233C32DCF39506D5EAC7EE60B97B
                                                                                    SHA-256:7411B7C9E368E1CEE613FE97728D504E31D5F2091D11951A4DBEB88A9551BCAE
                                                                                    SHA-512:217FCADEF712A7DE2DCDF7A1036EB50AE47EC752400A1A7EFA3BB4A49F7276E3BDDCA03FA5044513DC06378EE1AEE1527498DCC534AA9D16A4873DCDCBDC5C00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..............,... ...@....... ...............................>....`..................................+..O....@..4....................`......|*............................................... ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................+......H........ .......................)........................................o.....o....o...........(.....o...........*.0...........(...+..,..o....*.o....*.0..E.........o...........X%..o....2..*..+ ...o...........X%..o....2..*..X...2..*...BSJB............v4.0.30319......l.......#~..(...x...#Strings............#US.........#GUID.......T...#Blob...........G..........3..............................................................5...............K.................1...........k.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18120
                                                                                    Entropy (8bit):6.226050809869831
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:U0xk42ZtyyslnQyrgbPyIH/rFzsX+cAW++2Wx1q//0GftpBjIc0:DVegwRe+c3S8iC/
                                                                                    MD5:E834E45855E8D220B0C5D0C1CAC24E44
                                                                                    SHA1:D8AAF831CF5B90A206EE9348386A72498AF0C0EE
                                                                                    SHA-256:78AC70411C71B7A0C68FE8746EDD3F3A8CD3F72044B329A40AB53C57891BE37D
                                                                                    SHA-512:F91A3FA6D522AD5F977AF744618D5ADC1A6CAEA0645D870E10962E00C03534CC3A9FA1D82001627F5B6FC3186BD51E3E69D16DD689C5E7CD4D84AC66AE9A63F3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......R...........!....."...........A... ...`....... ....................................@..................................A..O....`...............,..............T@............................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........&..d............$..O...P ............................................V.{..(.;.X5..b.2X..L.{.z7t.P1).qf...w.g....ik..:.5a..J.FK.e..mSgn9.cQM..9.B..ZLSy@..j.e...Z.......6..c.'...m1.{....(....*"..(....*&...(....*v(....-.(#...s....z~....o....*.......*2~..........*&...o....*&...o....*...0.............o............o.....s....z.*...................0............o...........o.....s....z.*................^......(.....o.........*^......(.....o.........*.0..<.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):12432
                                                                                    Entropy (8bit):6.213812838430843
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:C349VlDs8a3XUVW2itvXS9nMTI/s/nGfe4pBjS735:Cq83XUVWNvXS9//0GftpBjU
                                                                                    MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                                                    SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                                                    SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                                                    SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):108168
                                                                                    Entropy (8bit):6.179559450110609
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:hf+YSZc1rj0oek7u05g3XG5rs+eUvNL3NX5S8caZkvsd65FAU9Qyx1NElSJK/Tr:R4ZYrj0oeOg325ragNDNP+AUzqSJMr
                                                                                    MD5:3034CC0D5CF3731ED90153AA616F3F59
                                                                                    SHA1:AACE8D26358D9829F0E6632BDDF183534ACFEC0D
                                                                                    SHA-256:63CD5E8A60D77D1007352538A4285C60C0C3EFB9C771035589105A284E4F63A9
                                                                                    SHA-512:88589B022D713D565342E331394ED5600D1FE346AA788E45E16CF51221CE898F10BD28C6A09FDC44D9AD94F25B4ED22C6F0EB28FA832863C01732DEF5B6C6086
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X."Q...........!.....^..........n}... ........... ..............................C.....`..................................}..O....................h...>...........{............................................... ............... ..H............text...t]... ...^.................. ..`.rsrc................`..............@..@.reloc...............f..............@..B................P}......H.......L...................1...P ......................................Am.........C.....7.7....|..........,...w?..T....A.e......I}.#N..E....~...y. x`E......C`A&P.....Y.....A..J......#.p..).uGkJ1:.(......}....*:.(......}....*...0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*"..(....*"..(....*..*..{....,..{.....o....*.{....o....*2.~....(....*6.~.....(....*F.~....(....td...*6.~.....(....*J.(.....s ...}....*F.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):4.35096535887655
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:HDbZgmWgUGOBlTGYI+eQ6/70dRbSA3oO4OHPbPa:fKQU6/70dRj4O4Oz
                                                                                    MD5:BAF74BAB27F9EF9F3857B4DBBB215FB7
                                                                                    SHA1:2D2068477DD2AD2C1747E08CC0BD2EB6B9E0516D
                                                                                    SHA-256:E851DD88BF9EB69383017E1211B9DD2826F94ACF3FFD345A539228DF52E9492E
                                                                                    SHA-512:20F04A0D5D8F8F8A21E84A5AC266143E151AE84C45172D45C4187A7E4D361295220B0F701FA4FF68EDC3A0097641A7C1E889F7F88A5E36C5208A97881605455F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............0... ...@....... ....................................`.................................d0..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........ ................................................................{....*"..}....*N..(.....(....(....*>..(......(....*..{....*"..}....*:.(......(....*...BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob...........W..........3..................................................................................................................................!.................t.....U.................<.?.....Y...........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.347287743366354
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:6oN4JUNanMSU/JU7r299nL2kSDtHAvCp3me0PfRnCe8SfVq6X8RRga5Rf7NjNfft:im6ab7exE0
                                                                                    MD5:DFF6850E8B2FA1D6FD14773AD9F6F150
                                                                                    SHA1:EB41A2AE0FD2BCA2D0E4E857D02BDD2245A698AB
                                                                                    SHA-256:B4453E1AB70758E8B08F1F9CC6947A18DB2519075B494C4CD8D6E1E020A68A0E
                                                                                    SHA-512:2743D550CFF83639E2D6ABCD4A1AE4C055C5A8B5FA459EB5ACE005A68CE08D83B31E296DA120ACA04FAD190F60AD0565912FEC64C79233B9414E7BF42EC3AB92
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e.........." ..0..P...........n... ........... ....................................`..................................m..O.................................................................................... ............... ..H............text....N... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B.................m......H........'...............V................................................(........s....}.....~....}....*2.{....o....*"..}....*^.{......{........o....*2.{....o....*2.{....o....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r`..p~....o....*V(....r...p~....o....*V(....rP..p~....o....*V(....r...p~....o....*V(....rI..p~....o....*V(....r...p~....o....*V(....r/..p~....o....*V(....r...p~....o....*V(....r4..p~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*439 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):224768
                                                                                    Entropy (8bit):4.138821035130012
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:OYZrzdzRISZ/hCzBv1hLHfTYxk8mC6MNpMrptsuFkC6TvhkAjwYVNpwAj:tI2/huBv1hLHfEm8mkMrptsuFkC0hX
                                                                                    MD5:B2EBA7F35E2DEF32749E36A6C181BA0B
                                                                                    SHA1:4EF2027C1E03BFC948457AECCD5E77A45C78CA7B
                                                                                    SHA-256:52BACFD1EE622B668CFEC91321A95552B9D7ED2FCDA10AE31A433F650E0E8184
                                                                                    SHA-512:23359C79495A26D7E39EAF652D734CC8AA1D8ED90EC38C225C329C590453343E08BE3BF7CB923F09D243856F8D97526DF48B4428E3D5634C8D4A6BECAAAFAD8A
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS...............T................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................_..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.865639255366771
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:akOKSRVDKCJRCNdLnRWpnipnuncpt2JbJH0qV28xqNK7I2yd1u7qAGxhrGTEZmlR:akONl3eRngpnipnuncpMJbx0qV28xtCa
                                                                                    MD5:8576099B78B5A2B4371F5607C1CC4B56
                                                                                    SHA1:56959AF98B01B360DBBF247F0B01DDE4CE8D5C9E
                                                                                    SHA-256:A3F1B2DF20581CB7D64B008692939AEC45F4D7F6D8037F29F34D58AA14C2BD84
                                                                                    SHA-512:1717169904BB82D28B9B48DA167C960CE417B6F6983380ECD40B32418149B94AED3B6DA97F87FDDF47F887D0BA334F6A1109F750C87D81A0624B3ECFA21A48D5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e.........." ..0.."...........A... ...`....... ....................................`..................................@..O....`............................................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........"..h...........d<..X............................................0..r.......s......s.......+V..]..E............*...+:.r...p.(....o....&+&.rk..p.(....o....&+..r...p.(....o....&..X...2..o....*...0............o....o.......o....*....0...........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....,.(.........s....*r...ps.....o....o....-.(.........s....*~....*....0..b........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....-.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):185544
                                                                                    Entropy (8bit):6.1143984102987075
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:I8eNPCLiHSIZ8gcAx081w88sss9wNACJ1xZ7iOo7EM22PBdc:xeF5HSIwHACRVS9P8
                                                                                    MD5:589E1B764C0DC53BF645054960626AB1
                                                                                    SHA1:A5616537CA4E4AD5EB0BEB48863AE65E9EA91080
                                                                                    SHA-256:1C7FA94DE5E727852934387B6B0094ABC16F660C6C91B38FB3F5BC580CFBDC1F
                                                                                    SHA-512:DFD6924DD7BAF7EB1B8D3CC862FD7FB4A311818EE5684C7A85E3106EAD0F3DAE2A79956AAD9B5404C88A1D2607CAD627D0EFD729E9A9C1C1425B907884FBD1D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...E..T...........!..................... ........... ....................... ............`.....................................K...................................h................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H......../..............p...u2..P ......................................d.G..n.y=.v..].....Y...wE...#.".q[...f..N....k.:sj.D...q.`6o.........A..zt..P.6.+..{8....(...'_L[...X....~..yr....Z>/..t.8..0............i...X.........o.............*..0...........u......-..(...+..*..0..$........u......,..*.u......-..s......s....*.0...........u......,..*.s....*..0..$........u......,..*.u......,..o....*.s....*B...o.....Yo ...*....0..<........o!.....E............+..........*..o".....*.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.8275707319309165
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:Fifvs56GFPy0GPVcRQoN5E6ZmOGZX36uE5daEy:Ks56GxHG9gu6e
                                                                                    MD5:DD9DD242A4F7AA3083435FCE216BCB25
                                                                                    SHA1:F86E801E1A13A8087B9CB1330C9B0B2D91AD9B05
                                                                                    SHA-256:6A272F121B0F098DEE2519C19C8EB150141D8533D4CD49459B84BD58EA9B42A3
                                                                                    SHA-512:F7FD0C104D6B27BCB1006469C3011623A7F0999CCFFFFBD7FCC830C48C7C70AEE97BFD4CA48124D76C2D8E8A907212B11433049862A6047AB829F980BE4F9E7D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....7..........."...0..*..........^H... ...`....@.. ....................................`..................................H..O....`..\...........................$G..8............................................ ............... ..H............text...d(... ...*.................. ..`.rsrc...\....`.......,..............@..@.reloc...............4..............@..B................>H......H........%..L!............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.r...p.....*...0...........((....(....%-.&.+.o......-.r/..prU..p.(.....*.(.......+G......&...%...%.r...p.%.r...p.%.(.....%.(.....(.....s....o....(......X....i2..*.0...........(....-.r/..pr...p.(.....(....*.(....,.r/..pr...p.(.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):140432
                                                                                    Entropy (8bit):6.059133240260085
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:z5cEGcPGEuEz6C62cxocEt+7f0YuuriDjNcYEhPoBj2bRViOsPKJKPfqIn37nNfv:z4ciEl6pJ7f0YuuAKA2XcnCyKY+8rz
                                                                                    MD5:4CBC7B9D057E89C6A5BA313F6C2F036C
                                                                                    SHA1:BE57AE313DE841F987D0AE4CF9632E5F155955BE
                                                                                    SHA-256:EB8F7CECA9DFCA2080A8A9C30EBF49298778743F288A289970846D02074C5322
                                                                                    SHA-512:63077C81B1C0379FD86BC88571F8AEF227B449693C0B015BEEEABD99C3033C644F17AB089BBC55594C0FF98BD302C503C435B992DD7E83876CCB2111483CF902
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!..................... ... ....... .......................`...........`.....................................S.... ..`....................@....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B........................H............I..............%..P .......................................f.>dT.j.P..s..K..K...|"Y...r...^. ....}1k..mu...Q'Y......4..;b0.....\Y;....W...1..I...{...8...9M..-....,.......x...vG.IQ2..{....*"..}....*..{....*"..}....*..{....*"..}....*.sI...*"..o....*.s....*.*B.e...((...(u...*....0..........()...o...+..o....*...0..^.......()...o...+..,N......((...()...o...+o..........((...()...o...+o..........((...()...o...+o.....*...0..........()...o...+..9.....r...p.<...((..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):686
                                                                                    Entropy (8bit):5.095369395177209
                                                                                    Encrypted:false
                                                                                    SSDEEP:12:MMHdGzNFF7ap+5KJf/2/DXFip+5NJf/2/qKFicYo4xT:JduPF7NyH2/5V3H2/qo9y
                                                                                    MD5:1C692F9907BB6FCD97ECA18D587E5B87
                                                                                    SHA1:C6021EA19B5F88925AB27FB2E65C3CB47A6601AB
                                                                                    SHA-256:EF01791FD533C9B51F2F279D21A6CA4B6F935C1AFE6D4A24E75DB91E568C6404
                                                                                    SHA-512:15195678CF637D7E19445523F9B39604FDA221D3D5F530FF5F6090C0AF22BC9D46C3936811D02F20BB133ACA210575F6C860247B63ED1574EE9EAAC4725B3F5D
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="SUFEnvironment" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18281" newVersion="1.10.10.18281" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="SUFLogger" publicKeyToken="1740bc29bac5d844" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-1.10.10.18293" newVersion="1.10.10.18293" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.627470324915964
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:ZnRxqFcduFzlbKYTQA7sGzaM+vgh3DQqQy6B3rqWsuYXATXjLdGC/au/z:NqFHpboA7sGeM4cv23rqiYXATXV/au/
                                                                                    MD5:852BF0289D774738CFB036A8BB5C6B11
                                                                                    SHA1:98F4D60BE0EE949346AD95BC6234D677E1C7D389
                                                                                    SHA-256:BB3AB16E765F17C784DE9CDB0C35D1B6A299ABAB476FE2F9CA1B39528A629B8F
                                                                                    SHA-512:CFDF0079C9C42D2870FA18BDC92AAD49F16481744B0AB3B296DEA4F258FDF3A6A64B419943E61173D17D3FE8A9A6BAE728AC9F245E6196770BDC77DF5B55AD30
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.............V7... ...@....... ....................................`..................................7..O....@..T....................`.......5............................................... ............... ..H............text...\.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`....... ..............@..B................87......H.......($..$...................L5......................................:.(......}....**....(....**....(....*....0...........-.s....%.o....%(....o.......{....(....&.....(....s......{.....(..............o....r...pr...p.{....(.....(.......r[..p.(.........,..o......*.*........E.+p........E.;........0..............(....&.....r...pr...p.o ...(!....(.......b.r...pr...p.o ...(!....(.......B.r...pr...p.o ...(!....(......."..r...pr...p..o ...(!....(.........*..4......... ........./.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144496
                                                                                    Entropy (8bit):6.219127874938619
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:0RZlEOzBzB3yZwUDXSNhB+IIx3zUOEF7xQQwQQQQQQTreulTnXGZFfHjKUhcweTo:0RUONhhUDyhB1IRUOEoUjHBhT/nLN
                                                                                    MD5:5BD39A82AACF1AA423E6EEEEDA696EEA
                                                                                    SHA1:B7971F9807520DAC9523BFD1185A7DCC9E5CC77C
                                                                                    SHA-256:1D69EAF538008E0FE1A7EB2CE0124A49B95C491797749640C8351ED4643F5C97
                                                                                    SHA-512:CBD255E7323A7E82D8B9443E8CE67BEF88F88BF46E525333E4017024A31952656F61F93334B3957D85FB0E422E561197C0ADB1366653DA007C9667651B1F37B1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[."Q...........!..................... ... ....... .......................`......a.....`.....................................W.... ..................p>...@....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......$...h...............c...P ...............................................\.E..-.....A.}.8.p. 0AF@4.....T.P\...S.aEf.....$..m..G.h......Q.,.2....N..jE...QD.V..<i<(*".\q.7_..;.ge. Q[..P..{....*"..}....*F.o....r...p(....*..0..C........(......~....-....7...s.........~....(...+(...+(.....(1.....o....&*F.~....(....t....*6.~.....(....*F.~....(....t....*6.~.....(....*F.~....(.....j...*J.~......j...(....*F.~....(.........*J.~..........(....*F.~....(.........*J.~......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27792
                                                                                    Entropy (8bit):6.1321477705881335
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:FBg0ucz9tgkgZWJkkgZWvvwKuk4WBul+S2vKURa5kMac1WkrzvXS9//0GftpBjBh:FBgbch/vxnRakBcbr+8iN
                                                                                    MD5:8AD746D4BB9B64AC5F0CE29896162259
                                                                                    SHA1:79041040D9CC0070B9DCE4026466B195BFF78EB4
                                                                                    SHA-256:F4043D2182666F67ACF71449EA60477DBDC577B1A09574ED6562A5C3FA6C42A9
                                                                                    SHA-512:D38CA6AE2133F231E89E15A7470E24D477F9D1DF7838E793FA427E048EBBADE1618EB08CDA30FFEC72080ED4EBF2EE2A897AB9D575C205EFBC4FCA92C88E0456
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....H...........f... ........... ...............................<....`.................................`f..K.......h............R..............(e............................................... ............... ..H............text....F... ...H.................. ..`.rsrc...h............J..............@..@.reloc...............P..............@..B.................f......H........7..............P-......P .......................................(>..P.^+..Vf.......y..Cd.^....kL*.C..d.....J.4.3..P3.}..1z...9...a>..uF..XR.o.(k.:.C3.R....:...../K%n..........e.S..(...........s....}............s....}....*..{....*..0..@........{....,..{.....{....o......}.....{....,..{.....{....o.....o....*..{....*^.{.........}.....o....*Z.{....o....u.........*..0..J........(.........-...( .....(!...*.("...,%.(........("....(#...o$.........o%...*..o....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):61440
                                                                                    Entropy (8bit):5.4953592987125335
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:v1P9PM1EO9m30XOgj6sogR/nho16ATIdYOrvQ7NR6KfgB1XxLP8uQ9O3rJt/EjBc:9PVM1i0XlhLATIdY1z5gBMuQ9On/Ky
                                                                                    MD5:E520C02EE6A83ACFE58CD9EDB296E392
                                                                                    SHA1:665A83902C560C610F1F34108742551F1E4F7BCA
                                                                                    SHA-256:A729B344885A5F7F7F09A6D6EF2B9AE86E643BBC118EA60B27CB08AE0991705C
                                                                                    SHA-512:E6EA3148DBB182909790BADF66EE0C9F4BFD5B3B624BAAE13AE4EE85CA89A44A4C1C39D4A25A72A53C1BD55DE647E9D0081DCB6AF82F05D566C300D53D831E0E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.................. ... ....... .......................`...... h....`.................................t...O.... ..,....................@......<................................................ ............... ..H............text........ ...................... ..`.rsrc...,.... ......................@..@.reloc.......@......................@..B........................H........c..8............................................................0......................(....*...0..+.......r...p(......,....r...p.......(.....(....&.*.(2.....(4......(5..._...........(...._*..0..........................(....*...0............................(....*.0..(.........r...p(......,....r...p........(......*.0..).......(2.....(4.......(5..._............(...._*N......rQ..p..(....*R......rQ..p...(....*B..........(....*F...........(....*F...........(....*J........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*47 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):24064
                                                                                    Entropy (8bit):2.8139684302156573
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:GDwjVAfAm3ACA4C+9p80/v/z+fyvx/ZsbwZ9SWCNHn3bmEPl33dD446DAE/f5ek/:GDwjsI+rHzhVxl7
                                                                                    MD5:1B0B75EA764B048A27B3205970D2FA0B
                                                                                    SHA1:2865C064AFD9CF51B7B5916E321870EB3FDAF952
                                                                                    SHA-256:2130C737EB69EB79A9ABC74DCD9BE2A733AAFD43174FB9C177601935A08A43F8
                                                                                    SHA-512:0012D14AFE49AE0A59ABE5451AC2A705E090311A4DA5AEB3A87DD6DB4982A26747AD18DB6421E9D500F4687D4AD5399C068037C4712606334608384FF2FC060D
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS.........../...........,...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):56832
                                                                                    Entropy (8bit):5.690835792827563
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:DkXuiukTFT3hvhZUq5UkA33mSIZ0lt+DDNXspw9IwL+P:DQu1kTFlhmq6kAnSKlt+nVuwGvP
                                                                                    MD5:BBA60FC073D9CBF5CB5658BC4DCD8A3F
                                                                                    SHA1:9CFBD36334B9404B3E7E8042C4F15B7F01391441
                                                                                    SHA-256:133B772B48EADF9F2FA51296A508EE0BC7B71CAB84C699F23B10B8B55F310550
                                                                                    SHA-512:CCF5DE9F317B734AF85D34FB3BD264DAEF1C326CDCEEBE6569590473F68914EF333631D15628021474494BA07F8A40EE20DB46F1C6C0F8C9D63E0295BAF36027
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............n.... ........... .......................@............`.....................................O.......p.................... ....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...p...........................@..@.reloc....... ......................@..B................P.......H........A...x..........t....8............................................{....*"..}....*..{....*"..}....*..(!...*..{....*"..}....*..0........................("...o#...(....*...0......................(....*...0...........(!...r...pr7..p.($......}.......}.......}.....{......o%.....}......s#...}.....{......s&...%r...p.(U...s'...o(...o'....s ...}.....{.....{....o).....s3...}............s....}......o).....{....o).........sg...}....*f.{.....{....o(...._o9...*.*..(....*..{.....{...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):5.073320023485428
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VP3bjfBuBX39tYew3jhC4h9Xx8P3RV2ReWBP3lYen:RfBg39Cew3oKihGce
                                                                                    MD5:A1D2A38772AE525ED4C0A165C3197187
                                                                                    SHA1:5EAF512F42F0DCEF235F914F104FE0696C4310B7
                                                                                    SHA-256:CF3803BC5985B65888BA30261E93E366E1C8E76AF91B6E40F36FB14812F57BF2
                                                                                    SHA-512:6D3AC43928F8A6E6F93C6C64A20B2C1E512A045979F8C2C29A584C56CF29B14477FC7DF954C4EB0F1D34F9381ABEE3C238AE7868DEA6FCDD175DB364A633D098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..0..........*N... ...`....... ..............................j.....`..................................M..O....`..@............................L............................................... ............... ..H............text...0.... ...0.................. ..`.rsrc...@....`.......2..............@..@.reloc...............8..............@..B.................N......H........+...............G...... L.......................................0...........r...p.r...p..................(........Q..+..*...0..2........r...p.r...p..................(........Q...Q..+..*...0...............~....Q..~....Qs.............,3.(......~..........(.....*...(........Q...Q...8n....o....o.....r...p.....,.....*...(.......o....&............(........,$.(.......o....(........Q...Q...8......,.....+......9......o......Yo....o........o....o .........o....o ...(!.......,t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):19968
                                                                                    Entropy (8bit):5.327502630579932
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:WR1TB+EYvodkn5OeUq5gCS1x9UQflcltvlVyUWY5FVRsp5GiPjcVuGk/6uQKztku:WZYvoy5OeUqp2UhLs9P4VBXuQK+u
                                                                                    MD5:CCF6F3D56977D1AFBF4A3EC884D1A32E
                                                                                    SHA1:D29EFBCC5AB0F6C7403BE0DDE5EC202D61FF410F
                                                                                    SHA-256:2129BCD055F493FE34B7E44AEE5F8175CF9D43D7AC037D742E6070A58AFE1266
                                                                                    SHA-512:329607A495E0DAEC735F81A15B8B92C4DF84F71015D9AB762967CCC664714BC2C883BD321255FDCDFAFA04BF5C24DED92B98FC940DFF30A36D72E2831A2AE012
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...XR.e.........." ..0..D...........c... ........... ....................................`.................................dc..O.................................................................................... ............... ..H............text....C... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B.................c......H........0...2............................................................(....*"..(....*&...(....*&...(....*....0..e........(.....s....}......}......}......}......%-.&s......%o...........s....(....t....o...............(....*....0...........{.........o....&.,....o.....{.......o.......(...+(!...}.....{.....o"....{..........xXs#...o$....,..{....o%...o&...r...ps'...o(.....(....*...0..|.......~)....~)....s*.......~)...~)... .........o+...-6.(,...,..(,...,.r...prm..p.(-....(,...-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):62160
                                                                                    Entropy (8bit):6.394651976589669
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Lu5fLsPcyp/79lGhbTfpp6tpJbox15i4R5we/MvSKi0cOEwC7:y5fQLMhbTfpp6tpJsx1R2eMqK2WC7
                                                                                    MD5:B5BBEE69523810F8AA9D92E3D3ECB896
                                                                                    SHA1:9A45F181AC22B5C633EED421B59F5FE9D12D6A7C
                                                                                    SHA-256:BF99695470075C4E2C906BE4567F1D0AB3A6D85D31EC1D8F6B4139015C48A2B3
                                                                                    SHA-512:9EEFF3BA247793163FD091FB26D8E620C99A8CB1B510F26EA7C31EB9EC27F2DE9E92F14CA470852C84FF1DCCF5FBCBAED8C93EA2F05C6515E2C078776C62BA7E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...a."Q...........!..................... ........... ....................... ............`.................................@...K.......`................>........................................................... ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B................p.......H.......PE...............D......P .......................................xk.r..E. z.aD.-$..}...=..+<%...Z....x.N.,..D...nA*....1T. 6./n.`j..."q..rE........44.(..a...\..>...~.......9.M.).#..c.0..W.......(....s.........(.........~.....(....,+(....~....~.....o....t>........~....(....&*(....*j~....%-.&~....~.....o....*.......*2~.....(....*Z~....(.....o.....?...*Z~....(.....o.....?...*.(....,.(....,.~....(.....o....&*(....*.(....,.(....,.~....(.....o....&*(....*Z(....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31376
                                                                                    Entropy (8bit):6.161352322277959
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:r27oPj3ZdGnwIDMIMoMMMIMIM408PUugN+8ik:rEorPGpUnN+8r
                                                                                    MD5:5C9985D31E098BF7DF031171E046D67E
                                                                                    SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                                                    SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                                                    SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):269824
                                                                                    Entropy (8bit):6.248597977496272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:w9hcO7H2po0qDQh/mLJ2e4NY647eS56K2K+p637RArP1CKlF:w9hn0Cus+c32
                                                                                    MD5:761C33DCFD02AF3A9B60C3A307362989
                                                                                    SHA1:636D766B076E05DBEAB1FC9117F1B0931DC33A8D
                                                                                    SHA-256:B17012332BC4B2745349101AEEB02501E68F1E8D470CFCF316CA3AD13A2356E6
                                                                                    SHA-512:414F48F3FC381078A5B8E0D49F8D822BF1BD9B36EF944B3A7B2FCFFBCBF2F547108FC7002179EF2DF4021F499FE23E4D87BBAE5CB83B236AAFCEFBA23C7044F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e.........." ..0.............j2... ...@....... ....................................`..................................2..O....@.......................`....................................................... ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................L2......H....... ...................hV............................................(%...*..(&...*z...(.....-.r...ps'...z..}....*..((....-.r...ps'...z..}......}....*^.{....,..{.....o)...*.*6.{.....o*...*....0...........u......-.*...(+...o,....o-......o......o....*6.~.....o/...*.s0...%.o1...%.o2...%.o....%.o,...*.r!..p.....(3........(3..........s4...s5...(6........*....0..#.......s.......}.............s7....o8...&*..0..?.......s.......}.....(.......o9...,..{....o:...*.........s7....o8..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):415408
                                                                                    Entropy (8bit):5.573182313694346
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:fXvGO+uec6A3HQ0nHajgLx+lkMPSDt2nb+6PVM0H+ULFpUKiw9OBTj1ESZ31W:fOO+66OCoMna6PV/H+UE1xZ31W
                                                                                    MD5:4DDB62841065A6587A5CF72944AA996B
                                                                                    SHA1:A437A112A19F4220E18A6C8E764D73E315F47ADA
                                                                                    SHA-256:AD18F28213EBC685A4E6F38CEA549F85DEA2E51025F4D08F672EFCE128FF105F
                                                                                    SHA-512:161A169FA60CFED2D67F135E0DBB6932FCFCA0676B6E7BEACF4BA9FCE35E887DE0AA3BBBA76EABE173CBBCD060ED8325E0C732BCFBA9E486445D5E516F5CFE8A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....2...........P... ...`....... .............................."G....`..................................P..K....`...............<..............hO............................................... ............... ..H............text....0... ...2.................. ..`.rsrc........`.......4..............@..@.reloc...............:..............@..B.................P......H....... ;..H...........x....2..P .......................................q.+.$.~..n.P..8\.^._.v)..&Y$..".....-.]%..^...Xjf'...D......m..,e74.n..O.-X~h....%:$U=.....A+........v..g....P..u.....Rs..O.]..(-...*&...(....*.(....s/...z^.(......9...(2...o3...*J...9...(2...(....*.s....*..(-...*&...(....*.(....s/...z^.(......Y...(2...o3...*:.r...p..(....*....Y...(2...(......(......(....*F.r...p(4........*J.r...p......(5...*F.r9..p(4...t....*6.r9..p.(5...*..o7...*..o7....(....~....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18944
                                                                                    Entropy (8bit):5.123452606388303
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:y0sI9oCUN+uMVZFZfZ9gNe5nlpW85s2wmQs56TtmOjXis0j7XcyFXcXPXrfX2H0r:xsf+5FCNepkmuTtmOrX/y
                                                                                    MD5:B2690A6C3C2E97FA8A89F1DEF550D53B
                                                                                    SHA1:E2811A4F491D9833C1D7880AE28F7755EF179BD0
                                                                                    SHA-256:8B64B6FF4274103A919C08DADDB8E295772F38582A098E0DA097CAA632A7083E
                                                                                    SHA-512:AECC9ED7F6E57D231A4362346BF38BC094495AA5A1131508466C9DBA34A67A2F83A15CBF420C646A28A52AC444EE4E6B16B8426531CFEE0F773F65934BFF5E0F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..@...........^... ...`....... ....................................`.................................d^..O....`............................................................................... ............... ..H............text....>... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B.................^......H........'.../...........W..............................................F.-.*.(.....(....*...0...........o@...-........oA....o@....i.1.*.........+ ..s....%..Xo....%r...po.......X...7..o@......+........o..........Y%.......X....i2...oA...*....0...........o>...-........o?....o>....i..1.*..........+ ..sV...%..XoS...%r...poU......X....7..o>......+........oR.........Y%.......X....i2...o?...*.0.......... ....s........,/..,+..i.....(........+..o....&....(......X...2..,>..,:..i...,..o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):368816
                                                                                    Entropy (8bit):5.365214438266103
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:KrNvoFXHxeLeKdwU1SzZiZ5pbC7K4vQg7wwhFQSamkV8EvA3PXiD3fm553inDg8I:KxPeRiZ5nqwSuzvAsu5Jiq
                                                                                    MD5:37742E95B192B5B3F8707C2487A70BB0
                                                                                    SHA1:74F0A74F1E8F1513FFF13CD4D7A60658F59DC856
                                                                                    SHA-256:B410452B0A9BDBB8C860169F669A8E051AFB51FA53030D31E8667E5FC1B9C445
                                                                                    SHA-512:174F5DFD8DDD1C31D707F8EC0EAB29B9E563DE7DEC85A1F32BCB658E43309CE48F0BACF75964C1CDB24AFB5014D17E0DA252B7C2C7B585A9BB8430792A87EEE5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....|..........>.... ........... ...............................5....`....................................O.................................................................................... ............... ..H............text...D{... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B................ .......H........+...m..........(...._..P .......................................G.x7tf...r|-.}...)e{.@.[......y.P...Rt...@...a..o..%9 ..n...!.M<...u...QM........l..MVNU:G.D...5#u....b$.3N_...'.....EZ.r. v.s!...}.....s"...}.....(!...*...0..6........x...(#...............o$.................(%...tP.....*...0...........s&.....*2.~'...o...+*...0..m............{....%....((....{.......o)...,.....A...(a.....(c....o.........(a...o*.....{......o+......,...(,.....*..*...........Y]........-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48344
                                                                                    Entropy (8bit):6.53421522959476
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:4L/YzwmxRqw+4aECjhmUYVmePi+6bYKN4:aMxRqF4BCjhmHPZiYKN4
                                                                                    MD5:06296D204C279118CB8863F07E3DE4E1
                                                                                    SHA1:175553C011BA3B50322833477F095142F1C3D699
                                                                                    SHA-256:CEB0E446953833CAA54BC01E84B787281CF6712BA7DB65D4C9A664413E95CEFB
                                                                                    SHA-512:BFA4479554B841A17969D124FD69701DC1313E8F24EAD667C45002AE8D60C3F615D8D484D1334C87E5C93F1FB30B8217A0CBD528125EDFFEF050B898BDC1598A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."Q...........!.....t............... ........... ..............................~H....`.................................l...O.......`............~...>..........4................................................ ............... ..H............text....s... ...t.................. ..`.rsrc...`............v..............@..@.reloc...............|..............@..B........................H........p..L!...........0..&@..P ........................................9q.}..;q._^.X.A...&Y..n._=....*...%...'.Dc...S)..C....W.....k.Q......l.U.v.%...l...."ITo.Z".w..|-:.L%5g..cy':....=.6..Z.bF.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*..{....*"..}....*..{....*"..}....*"..}....*..{....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.762661257689725
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zRWAtSQqSbmIl3kn75fCN7RHQSFl+ouzQLxdETbSqNNDZ+GclRq3zQ6SfJtkinNu:tWwSf6mw3k7yFqhzNNiRTkin6gNb69d
                                                                                    MD5:C7F090DF56B4B7F00FBC30BE93E19CB5
                                                                                    SHA1:762A1352B78DA7970367094C4EA1DE2119BA03A0
                                                                                    SHA-256:A0B5A4E0D399D0E848A8B2CE2C9DEB3B8F2ADF0411C4BAFB066CF4646595512C
                                                                                    SHA-512:EBB747416375D393BC981D7A7C3182A4FA6A29D675C8C7366A0A1E2EED2A5D60BFBA6194C8C6AEA6291456EB6048C69CC1557DD3FFA1E330B55E36431A0DF61F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text.... ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................?......H........$................................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*...0..+.......r...p..(....,.r...p.r#..p..(....(....s....*..{....*"..}....*..{....*"..}....*J.(.....s....(....*.0..O.......s.........+...o.......o......X...o....2.......r1..p.r1..p(.........,..o.......*.........<B.......0..M.......s.........+...o.......o......X...o....2.........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):22768
                                                                                    Entropy (8bit):6.201382004474863
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:PF5AZ+le8+2KCYTzs2um7GH9SJSWcGvXS9//0GftpBjE4u:PF52+le8gR7GH9yok+8iyf
                                                                                    MD5:7C08EA125D8054BFA6057104590A7F83
                                                                                    SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                                                    SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                                                    SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):20480
                                                                                    Entropy (8bit):5.12438911804574
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:9/raLgzj2a2VtNY6gA2NGiQEt1u2UUAxT:J6Ba2Vs+intc2U
                                                                                    MD5:4E14602466E04BA26B85799C7B583135
                                                                                    SHA1:35BA198DFBEDD4E9E2A14315EDC985518011E5AE
                                                                                    SHA-256:E4382B9036CC9A50558992245D5AEDEA247567FD87E24D2CC318AA47A0898B34
                                                                                    SHA-512:054A8FD1F6218D1F2E85C46244EE2C9EA7C5D93353EA615A7F2D32317FFF7EDB6A2612270CB8621D9DA76634F8645A459FC075CFB970D028EBBD9C00DC131238
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..F...........d... ........... ..............................@.....`..................................d..O...................................tc............................................... ............... ..H............text....E... ...F.................. ..`.rsrc................H..............@..@.reloc...............N..............@..B.................d......H.......X-...5...................b.......................................0..............(......-i..o(....o......(....,.r...pr...p....6...(.....(....+R..r...pr...p......%...%...%...%...6....(.....(....+...r...pr...p...6...(.....(.....*...0..8.........(.....o(....o....(.....r...pr...p....6...(.....(.....*.0..............(......-i..o(....o......(....,.r...pr...p....:...(.....(....+R..r...pr...p......%...%...%...%...:....(.....(....+...r...pr1..p...:...(.....(.....*...0..8.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.819954761317961
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:m58AYPY+n+Zy+D9PfYPFdlP0OIgcOnwa:m58wYjkS
                                                                                    MD5:F989BC031F487F9367D86B10853DA339
                                                                                    SHA1:0F582C96068414147C269E4C39C3B548C6783D26
                                                                                    SHA-256:CE9963B629113FDE6B675FFC0EC55194823FED65EFFD08DE376F163CBC5A64F8
                                                                                    SHA-512:E797AF33CAB09B77412FE5C44461F95B18F487BF42A11F87C3F03CBC5962BA478E77937684E4C0878BD2BFDC1C07DD0982E0FCE8823B8D4BFF1D5AB85EAB79A7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@..................................+..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..]...........................................Y..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6958695447362193
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zXmayK6ryXX0A3GrXrQXyTAxJlPdOoeQr:zXGrYX0A3GrXMXHfqoeQ
                                                                                    MD5:E2785675831C1F909579ECFAB1D7E959
                                                                                    SHA1:F99B843C033804A4E4D3F702C0EC033B66A6333F
                                                                                    SHA-256:808A662089A1589365B99F11BBCA2400F01CED84D053CC81B18C28DD5CDEE326
                                                                                    SHA-512:14CDAB4D6A3D5539CB7FA4E250FEC960930423586EEEE764BE730803B9A2AEFDC6BE8C63F161B790D6E53874A2CF649C35B7A3DF0F3B0DEBCEA8732C9201E4B4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......('..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.7829722115887696
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vMHo6cs+TcW5cyLcQQ5cGcSSLcdcc7Ac6cWpc4cTcyc3Gc+cSGcfAdc/cFUuCWR:3SYpA9ZS6R8jlPgw0xUdnK
                                                                                    MD5:DA3AEDB793E7A652125FEEA58C8CA668
                                                                                    SHA1:39505321C2B90575C8F5125E1739FF720EC9E5FE
                                                                                    SHA-256:5AC1F7DF23CAAB0D8DA0FC9286BB8E84C09AE22B1FD5BA4C50F3D01DA4E61B6B
                                                                                    SHA-512:AC92291FB3C8C110E5C0C6587099215E5E600A22F00FC2D11634FFBDF9410D761AF3A002C67850F7F21AF540A19B7963B1755272FFC52263247AA3B964514636
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................n0... ...@....... ....................................@................................. 0..K....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P0......H.......T,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6030306404916543
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b11Hq9LUzj6XIMwullPqNKS2pxsrIUgj3qXp2qwz2/UbGp0JJ2Y:+/sgX6YMw0lPm2cNlBZq
                                                                                    MD5:335A00AED1F5DF1C1484AD887B808699
                                                                                    SHA1:EB2B942F1AB27D9E02C63F72F47F3ABEB23553C7
                                                                                    SHA-256:A8EB1D010C3A528B48EB20FD2A641A2E61CAA956E451D1B4CD067E616C512D52
                                                                                    SHA-512:AF8801D0A64D852C519DA2F1381D6C650266DF30B3BA74A12767FED7CA37F4D735D832BF0A707FA0F884013188F52C3F6BADCFC6673EC6DD1DFD24006EBA44A5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................H(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..1...........................................-..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.001844386696812
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:JB5nPlTrz0X3MOAbs2goRzRqkVmUm4pGo1SdekoMOMPleRW/b5d8vyQK15m3FybR:JaL6mNRd1+kBsMYzMYzMPeM7tnM6Puh
                                                                                    MD5:346111BF7AA931CBB8BDB0FA6D5BB9F4
                                                                                    SHA1:0BDAF5CD286648CEE5D99AEE48DC976590AFD3E7
                                                                                    SHA-256:8FF7B1A4BFA01E1999D6BF597E81049B6DED084986C45D51702951B445C8A974
                                                                                    SHA-512:A88335E3C1B09ADE8912F90E37A5051EC0884C877D11537F605D12ABE02C097DF36C66F5B128A3C148E7DEC21A32016675188EBBF51D1DD63CD4087ED1CDE14F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,..........NJ... ...`....... ....................................@..................................I..S....`............................................................................... ............... ..H............text...T*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B................0J......H.......PF..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8032152674339303
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:9lgYOtEyMURUynqONYEYzfBAbFoE3mMqOWjoFlPwgC2j:HgYOm4qD8b
                                                                                    MD5:7621D349CB5611229DA6FF3DFDB15699
                                                                                    SHA1:0F6147E4EE7FD8B2E63A583DF6E97577B33C6013
                                                                                    SHA-256:8348315B8BF99BA57C93A3D30904C8CEEFBC072BBA17020F54EC1F532438C1E3
                                                                                    SHA-512:573086EB8AD6760AFC04B18F7008BC3224340BB780E445501B052CC0BFBCED228FAF164A2C6DE2E230B6E7D7FB41EF70D804CD76EA882D6D44AAD3A6EDC38EAC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................n1... ...@....... ....................................@..................................1..O....@..h....................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................P1......H........-..............P ..6...........................................2..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.236877578473013
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:z2nvlHAHAn4lk25VeVOVWVCxZgMBQwH8Mc1yQgBBAj/:zDg6k25UM04xZgMBQ28Mc1yQgBBAL
                                                                                    MD5:19FF931A1A6174554591EC4498A36E36
                                                                                    SHA1:49385F8D2D5C7C68514F68000ABDDB279BFC53EA
                                                                                    SHA-256:67658FBA88F500247513B7299B6BF56954B4AC128EBFF5657AAFFF4E8A3A52EE
                                                                                    SHA-512:F2E0887C889B60380A01D7A2F37971746F9CBA91B9944B8D83CACB4049F1905479D6AAE3D945F7A5FB10268DBA5976BC9D71E5826163D7A0C5F7D1C5D8D74C12
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......D7..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.775199124098076
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gN6PKH23S+lvgeKlkoEa/flPq+LDJqLhj3vgIU1WyoFp/98P28s9JJ2L:tiKW39G/flPNgNj3YG7T3
                                                                                    MD5:D394F3FF3C36D9DAAE4352683225C955
                                                                                    SHA1:1A4BE2C8B43ABAE0B5CA27CEBC8E5EB13D433158
                                                                                    SHA-256:A30E0A68E0ED335C5F07529F11C0FDA5DEE9367C14C32278AFEAE7D7869ADEB2
                                                                                    SHA-512:CC8E612AAD1FA974CD0C89F01B90406E7A5C39F20EEC31C86488FE4A82F067EFA133156902B31C3248022F9634296D5DC3A4D8291B2FFFD65D00DEC850F0969A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................!..X.3m..Da.........n.:.c}......N..U.G.E.D......R<..{D..l.g.....n......`O..c.h.Y....$.w.^....a...L..)8y.xq...|....Q.j_.L1.".w................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.090141264865196
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Crp1+cWt1eyDw4hSRJQ6sFJ788WlclPNt8jaBlZsKJ:a8cWpDU/S2Gg
                                                                                    MD5:6E2786D15CE907DA2983E5859777F599
                                                                                    SHA1:93B82E7200A6E792777A3376D41C76A4D18B77C2
                                                                                    SHA-256:B29C7FA55190D89BF0A24FFFBAB8752C36CA709BAB085B8F04EF969FD528C6B6
                                                                                    SHA-512:A68862D12620A828B20077CE768D6108785FC6EB3A489B00E34BA658CE954D9F1264C3FAC398B3FEA5FDEBC80B115DEF921C9F1A53ED30A24AE4153C69CEC6F6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ...............................W....@.................................p)..K....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......d%............... ......P ......................................nA!.7..D.....a..Mp.........A.0.8.Uk8.T..r...<......I..y[..Ka.X..ls..Sl....&-..&Q.E.4&(1^zd.9.^....bH.3@&...T.{.....3...9...E...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8032152674339303
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:9lgYOtEyMURUynqONYEYzfBAbFoE3mMqOWjoFlPwgC2j:HgYOm4qD8b
                                                                                    MD5:7621D349CB5611229DA6FF3DFDB15699
                                                                                    SHA1:0F6147E4EE7FD8B2E63A583DF6E97577B33C6013
                                                                                    SHA-256:8348315B8BF99BA57C93A3D30904C8CEEFBC072BBA17020F54EC1F532438C1E3
                                                                                    SHA-512:573086EB8AD6760AFC04B18F7008BC3224340BB780E445501B052CC0BFBCED228FAF164A2C6DE2E230B6E7D7FB41EF70D804CD76EA882D6D44AAD3A6EDC38EAC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................n1... ...@....... ....................................@..................................1..O....@..h....................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................P1......H........-..............P ..6...........................................2..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.090141264865196
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Crp1+cWt1eyDw4hSRJQ6sFJ788WlclPNt8jaBlZsKJ:a8cWpDU/S2Gg
                                                                                    MD5:6E2786D15CE907DA2983E5859777F599
                                                                                    SHA1:93B82E7200A6E792777A3376D41C76A4D18B77C2
                                                                                    SHA-256:B29C7FA55190D89BF0A24FFFBAB8752C36CA709BAB085B8F04EF969FD528C6B6
                                                                                    SHA-512:A68862D12620A828B20077CE768D6108785FC6EB3A489B00E34BA658CE954D9F1264C3FAC398B3FEA5FDEBC80B115DEF921C9F1A53ED30A24AE4153C69CEC6F6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ...............................W....@.................................p)..K....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......d%............... ......P ......................................nA!.7..D.....a..Mp.........A.0.8.Uk8.T..r...<......I..y[..Ka.X..ls..Sl....&-..&Q.E.4&(1^zd.9.^....bH.3@&...T.{.....3...9...E...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.7829722115887696
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vMHo6cs+TcW5cyLcQQ5cGcSSLcdcc7Ac6cWpc4cTcyc3Gc+cSGcfAdc/cFUuCWR:3SYpA9ZS6R8jlPgw0xUdnK
                                                                                    MD5:DA3AEDB793E7A652125FEEA58C8CA668
                                                                                    SHA1:39505321C2B90575C8F5125E1739FF720EC9E5FE
                                                                                    SHA-256:5AC1F7DF23CAAB0D8DA0FC9286BB8E84C09AE22B1FD5BA4C50F3D01DA4E61B6B
                                                                                    SHA-512:AC92291FB3C8C110E5C0C6587099215E5E600A22F00FC2D11634FFBDF9410D761AF3A002C67850F7F21AF540A19B7963B1755272FFC52263247AA3B964514636
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................n0... ...@....... ....................................@................................. 0..K....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P0......H.......T,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.001844386696812
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:JB5nPlTrz0X3MOAbs2goRzRqkVmUm4pGo1SdekoMOMPleRW/b5d8vyQK15m3FybR:JaL6mNRd1+kBsMYzMYzMPeM7tnM6Puh
                                                                                    MD5:346111BF7AA931CBB8BDB0FA6D5BB9F4
                                                                                    SHA1:0BDAF5CD286648CEE5D99AEE48DC976590AFD3E7
                                                                                    SHA-256:8FF7B1A4BFA01E1999D6BF597E81049B6DED084986C45D51702951B445C8A974
                                                                                    SHA-512:A88335E3C1B09ADE8912F90E37A5051EC0884C877D11537F605D12ABE02C097DF36C66F5B128A3C148E7DEC21A32016675188EBBF51D1DD63CD4087ED1CDE14F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,..........NJ... ...`....... ....................................@..................................I..S....`............................................................................... ............... ..H............text...T*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B................0J......H.......PF..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.775199124098076
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gN6PKH23S+lvgeKlkoEa/flPq+LDJqLhj3vgIU1WyoFp/98P28s9JJ2L:tiKW39G/flPNgNj3YG7T3
                                                                                    MD5:D394F3FF3C36D9DAAE4352683225C955
                                                                                    SHA1:1A4BE2C8B43ABAE0B5CA27CEBC8E5EB13D433158
                                                                                    SHA-256:A30E0A68E0ED335C5F07529F11C0FDA5DEE9367C14C32278AFEAE7D7869ADEB2
                                                                                    SHA-512:CC8E612AAD1FA974CD0C89F01B90406E7A5C39F20EEC31C86488FE4A82F067EFA133156902B31C3248022F9634296D5DC3A4D8291B2FFFD65D00DEC850F0969A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................!..X.3m..Da.........n.:.c}......N..U.G.E.D......R<..{D..l.g.....n......`O..c.h.Y....$.w.^....a...L..)8y.xq...|....Q.j_.L1.".w................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.819954761317961
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:m58AYPY+n+Zy+D9PfYPFdlP0OIgcOnwa:m58wYjkS
                                                                                    MD5:F989BC031F487F9367D86B10853DA339
                                                                                    SHA1:0F582C96068414147C269E4C39C3B548C6783D26
                                                                                    SHA-256:CE9963B629113FDE6B675FFC0EC55194823FED65EFFD08DE376F163CBC5A64F8
                                                                                    SHA-512:E797AF33CAB09B77412FE5C44461F95B18F487BF42A11F87C3F03CBC5962BA478E77937684E4C0878BD2BFDC1C07DD0982E0FCE8823B8D4BFF1D5AB85EAB79A7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@..................................+..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..]...........................................Y..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.236877578473013
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:z2nvlHAHAn4lk25VeVOVWVCxZgMBQwH8Mc1yQgBBAj/:zDg6k25UM04xZgMBQ28Mc1yQgBBAL
                                                                                    MD5:19FF931A1A6174554591EC4498A36E36
                                                                                    SHA1:49385F8D2D5C7C68514F68000ABDDB279BFC53EA
                                                                                    SHA-256:67658FBA88F500247513B7299B6BF56954B4AC128EBFF5657AAFFF4E8A3A52EE
                                                                                    SHA-512:F2E0887C889B60380A01D7A2F37971746F9CBA91B9944B8D83CACB4049F1905479D6AAE3D945F7A5FB10268DBA5976BC9D71E5826163D7A0C5F7D1C5D8D74C12
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......D7..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6030306404916543
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b11Hq9LUzj6XIMwullPqNKS2pxsrIUgj3qXp2qwz2/UbGp0JJ2Y:+/sgX6YMw0lPm2cNlBZq
                                                                                    MD5:335A00AED1F5DF1C1484AD887B808699
                                                                                    SHA1:EB2B942F1AB27D9E02C63F72F47F3ABEB23553C7
                                                                                    SHA-256:A8EB1D010C3A528B48EB20FD2A641A2E61CAA956E451D1B4CD067E616C512D52
                                                                                    SHA-512:AF8801D0A64D852C519DA2F1381D6C650266DF30B3BA74A12767FED7CA37F4D735D832BF0A707FA0F884013188F52C3F6BADCFC6673EC6DD1DFD24006EBA44A5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................H(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..1...........................................-..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6958695447362193
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zXmayK6ryXX0A3GrXrQXyTAxJlPdOoeQr:zXGrYX0A3GrXMXHfqoeQ
                                                                                    MD5:E2785675831C1F909579ECFAB1D7E959
                                                                                    SHA1:F99B843C033804A4E4D3F702C0EC033B66A6333F
                                                                                    SHA-256:808A662089A1589365B99F11BBCA2400F01CED84D053CC81B18C28DD5CDEE326
                                                                                    SHA-512:14CDAB4D6A3D5539CB7FA4E250FEC960930423586EEEE764BE730803B9A2AEFDC6BE8C63F161B790D6E53874A2CF649C35B7A3DF0F3B0DEBCEA8732C9201E4B4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......('..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):467288
                                                                                    Entropy (8bit):6.047761304423497
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:ABk34hZ9hNZbkDu0WtH7epyiNrt3329rzSkmN0OE0QxlmGJcdBI8rO7le2LvFVNs:OhuUiNrt33sSkmN0OE0QyGJeBwL/G5
                                                                                    MD5:195ED09E0B4F3B09EA4A3B67A0D3F396
                                                                                    SHA1:01A250631397C93C4AAB9A777A86E39FD8D84F09
                                                                                    SHA-256:AEF9FCBB874FC82E151E32279330061F8F22A77C05F583A0CB5E5696654AC456
                                                                                    SHA-512:B801C03EFA3E8079366A7782D2634A3686D88F64C3C31A03AA5CE71B7BF472766724D209290C231D55DA89DD4F03BD1C0153FFEB514E1D5D408CC2C713CD4098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!................> ... ...@....@.. ...............................>....@.....................................S....@..................X....`......h................................................ ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ ......H..........|q..........8.......P .......................................LO.K. 6}.5N..LA..D..|..=T.+.%.O..!@....D.tLl.....8..o...x"...&..C.@"}.dd..CZ..+..4l|<.V....Z....=..)...':..n.....*.....K..{....*"..}....*F.~....(H...t<...*6.~.....(I...*.r...p.<...(J........(J...(K........*..(L...*F.~....oH...t....*6.~.....oI...*...0.."........u'.....,...(M...t......,...o....*...0..F........(....,.r...psN...z..(......o............sO...oP...........sO...oQ...*...0..F........(....-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146874
                                                                                    Entropy (8bit):5.030528522591216
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrErnmt/3mUUQargP7/vhpdVB6CIxumugPDtAwN7:YZmUDIgP7/vhpdVB6CIxumHPN7
                                                                                    MD5:39CABAE4F278D1F95DC3D86C45FEDD38
                                                                                    SHA1:D4A7236D59DD94DBFCAC61765E77E38460C11FE2
                                                                                    SHA-256:30382A9B8678F3C6506F7F08F447C39986584F5264EE2962C984077140050462
                                                                                    SHA-512:1E65129381B8D6164DA4D8E4AB556BE39684D346AAA396C029EE49E1AD187EC2B3693554D14E0D7205D41096B2F2D0ACEA3826DEA7CF05029681F32F50DFF99C
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.6185885465184437
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lwHcAI/PI/UwULoLYLLOcZDOcFDPfD6YUXvWalPqAxXxroQMhI4jAqwIA9oqTx8:J8AYPYULcEn5DlDPfvw1lPyfIYcOnwa
                                                                                    MD5:5FE71E8866CA3CA8660355EBB521A174
                                                                                    SHA1:4C82D1CBE94DCEAACE70374131E4A52BD0BC3378
                                                                                    SHA-256:9D2BB3F14323A39207C229112B41DFE5D494DB8092FC586B4D26D5C61F11BBA0
                                                                                    SHA-512:68BD1433436F682C8A8D9FF4B285D363D4DBFB1CBE7D99A2F3DF51679AB609247BC94BECBB245D07FD607AC59AB395E29D9BBB2E342926A9A227ED065FFBA754
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6909032251512306
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YneXmayKpiyyXP3LC3XrNXiwblPXFoeQr:rXdiVXP3LC3XhXi4boeQ
                                                                                    MD5:6F2670E182618ED8D6CA44F54FE8EA5E
                                                                                    SHA1:03923621C472D766C168C081F0BDA4F8D8228B99
                                                                                    SHA-256:28ECA5095903FC714D95420A1F6D1D22B0C29209B986773FE965575BE0B592C7
                                                                                    SHA-512:4266ED0B35A98F6EA79750C0B21E08D707D57948D0340D078176C648D055B8403AA815F501738DD1BD3EE2AE241C08CFC19185CE2726C98F2A3148A2C86F4F5D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................>+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ +......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8691901965523297
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:fCSNfpQwM7PxNTeK1S57U2KRlPgw0TGbdvK:fCCpwNTeJ5ANRfdv
                                                                                    MD5:4AF5AD6BE2909483795D315B8029BCB2
                                                                                    SHA1:A818970B3ACF9B2BC51CB5270C5BBB727A6A1B86
                                                                                    SHA-256:E7FA776BF8A19AA5C5AC866067AA3326EF2F6CB2B66BF986EA99A6674931ACD4
                                                                                    SHA-512:4BE9481D281E40E733E206F3998A3F33A29D1E4BC632EBA04D66412F9E085F98AD06ACD2DC7B96E1C3EC1FB1E0B3D6BAFCB8E4D02755897F9BB926077B829E21
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@.................................x0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........,..............P ..\...........................................X..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.589575428609492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9xHq93PzjhJH/rHOUllPqNKS2pxsrISQj7qXp2qwz2/UbGp0JJ2Y:+Ds/XfbZlPm2KhlBZq
                                                                                    MD5:73D681F55B0A4B484EB80B26602AD4C6
                                                                                    SHA1:D72DAD121D5440368A38BB587E724ADCD9397B5E
                                                                                    SHA-256:9BF894ADCB50B4902108CDA8EEB8533C7F8C48E6099BF6BFA11F8690AAC19403
                                                                                    SHA-512:A8F53B278DC7D2DFC4DEA1AC00B3E321E201BA1E8CF1F48C341EF761498BFAE881FAAC70AE72B668AD4A086D866577B97C125336CF6F9218F719941577D2F378
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!................~(... ...@....... ....................................@.................................$(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`(......H.......`$..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835294577934021
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHAJn:CuQiS0Mw+f+Sb+jkyNr1rmqn
                                                                                    MD5:EF0CCCA5BA90200B76F1D38B2C551854
                                                                                    SHA1:B4B9A61745D68E6D95FC02ED9613AA7AA65DF960
                                                                                    SHA-256:6D5C1DE62E79F2AD84118C4195F6FBA7E017A0EA98C36EFED01067D47670E621
                                                                                    SHA-512:D80E9472044CBC827499CD3D7B91D44B00D346BEF5ECBDDD2FD4216DA080DCD0B1511CE4FBE8BF617AE8C0F8FE818F79B6D651F3BE9EA180504F6BB628B5DEBA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.4926374753106115
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6O13lHdyrp71jt6koZlqdBlPq02pxQdNWjfqlF8yge2wDGpQBJ2Y:L/9yrF1jt6rMrlPR2Ktm5o
                                                                                    MD5:A72C7635F324D2BABBA25B1875F34EB7
                                                                                    SHA1:7D6EA37C1D080F44B7A8946F6D7E4B52FF18A46F
                                                                                    SHA-256:2E93FA1DC13BB8D8E8603C8832F3D45F66C77804D5426501B7BDECE9C6FAC94F
                                                                                    SHA-512:44817CAEADF07D2BA950142F53E6D9C41CA8C07F2B16C6A0E51D18403672308362D407FFD22B6AFE7DFB323017D8E7C20C6BCA104F64D80E4D228B57AEA49984
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................P(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..O...........................................K..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.......L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7690940088540894
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6YVOXH2HpSp6p63y8nIuTb4TClvlPqox14r7Wjwq4o4wmHDvSGEpJ2Y:hwXWHpSp6p63y8IuT0TCllPi/xgX
                                                                                    MD5:E7E9EBF4800F9C14CCBCD0E9DFF94AFA
                                                                                    SHA1:2F98001343EEC80B4A5BBA3AE3CD1A3756CE792B
                                                                                    SHA-256:F7B38062E476F4A010A354869722DF860F2C9E013B7B0A6957D15BE957AF46A8
                                                                                    SHA-512:436C5185DD162DD71B6B3B957A5EC48B26D6F7C0DAB84DBD40345EF5A856223388C91E82D82F7DB29856421AC19BED65A94C685CA072ECFAF40A0D1240B45154
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................\)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........%..............P ..F...........................................B..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.066221331285762
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:H0B5nPn1fU2V6ofLSM8NoG/qn7NmKmmsDtFlBdeNo+N9RAPFIU5KrkG/KW5MKMyZ:H0255awvoUc7eHKKQ99f6
                                                                                    MD5:6C1501A7C57481123C8FA7A711E657A2
                                                                                    SHA1:2B2D55CF4BECAEAE686F2A5E3F2CD931F11B4684
                                                                                    SHA-256:2EAF8203B97509DAB0F0936703744F9F3431B41F010A14FDD2F1E087A48334CF
                                                                                    SHA-512:4DA0C4CB2445AED44F72EC688BAF2CCE1FE04BCADFF3D1D17376DB27F1A2E02EBE0D4B165BE891B71CBF96A5C9939A03156979FCDEDB8ECCD2E764EEAEAAD51B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................J..O....`............................................................................... ............... ..H............text....*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...&...........................................&.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7872115466343765
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:65GHpQUFezLUr/Mdl/OlO8OlhP0R9FdHSwYn2kU+lPqLx/zzKKjewqcF7JPWSG3L:vJRFezLUrGOlO8OLP0RJt9kplPHf5
                                                                                    MD5:D65A3887158DB3F7BA95DEC627432519
                                                                                    SHA1:2933E71B38562AA5CA3EC85FC15B4A193D497FDB
                                                                                    SHA-256:025839A3B263ED0493813D3283068B5407E7ECC27F6D36B9420096912569AB28
                                                                                    SHA-512:F5D27D4A48E929CD45FADC147A069EED7CD834BAFD59066855ADB8407763A683442D1EDA75DEA33BE1B70BAF3A84BED3296B1869471470C6623BE7F33EC22457
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................T+..W....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..X...........................................T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3355208441131676
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6VNHNoVy3lPqVx/uz/bpjrqtE8+6GzaJ2Y:UtoVilPFbL4
                                                                                    MD5:9F964F0110F89EAF46065A7F39103282
                                                                                    SHA1:4BEF4C3C5A6E7D3B56DDA27E36EB0C5F4CD17C08
                                                                                    SHA-256:C125429B2DAFE421290E207A42F91231DA55E294AB9D14B103CE9B5AF2E4EDD6
                                                                                    SHA-512:ADC547B3867C0CA36C114AB19B85B95C9472C543A6070F5CB7E935E24C0F252E311066F4408F2F2E4BEE8F68C40F53B183EC9ED2F42908BFF9D2BB7BC45522A2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................8&..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......x"..............P ..%...........................................!..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6545702649554492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxWHt1G5ilQ/eQ/e9J0ZSlPqfzx/rzSNfujsqN0gyF/GtpJ2Y:QcNjlQeQe71lPwQVxmX
                                                                                    MD5:5F71E42D0FBEE58DD1674E3DBB54DE25
                                                                                    SHA1:AEEA76E27DF535DD508283D7734E6BC394FA0281
                                                                                    SHA-256:7DFD8ABDAB51043C3F44868BFC27C7BD4B4500BD6E50F304AAE8A6A013C7CE06
                                                                                    SHA-512:16DEB68520DD07E411DE7130B3F6B2E671FBC3CAFB666ED01F738B083B55FA0090AA88E158F207A15F71736A674F6736A671FF341AFE3BE1B3B8E4F2FFB04928
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@..................................'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.811275919755305
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:QYOtEIhbiDnnfD2Y4YzX4PG6u+7DmXj1qYlPwW2ij:QYOsSMXx5F
                                                                                    MD5:9150D1D649F5D98363AB3CDEA99FB777
                                                                                    SHA1:525AD06E4848132A4CD82DE73FD0F6C3F17F0F67
                                                                                    SHA-256:190587CC3A00A09F124B8614D1A609CE448A97462845DFF34C53CDE56B315E08
                                                                                    SHA-512:C3D439214276402A7CA2059480DAAA866B131DDE40A4A9B95B432475D1DB3838CC80CE7FA2AEEFB6F96BD8CFFBBC06F8E452D2E8CA66EED5570258AF73454268
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.232012742966397
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:iuG1zHCNHzc8A3coFwQj50eoSpKVFKhdrSZ3EV3KVi4F:iuG1zHCNHzc8A3coOSpKShWEo
                                                                                    MD5:999E5F01BF727BD122F400ACF03FDA37
                                                                                    SHA1:FB8269134BE364F042AE0CD27C2A6B5385C16A7A
                                                                                    SHA-256:68CC7FE9FE3D9C7F9E31EB10F6320D8D7F90F18427DCE4A89898F548BCAA24E8
                                                                                    SHA-512:105050082682CEADA4F5B6CBB16CB24E882559D049F8F26BEB88F09C9EC9574D9A17F26A6D30570D59FE988800803D06C57FCDA046E61FCD74A88F9C87E72093
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p..........~.... ........... ....................................@.................................0...K.................................................................................... ............... ..H............text....n... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B................`.......H.......`...............P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.208005182662268
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:NHfCwjjB4NfVgV+Q8X9S9j9Y9fOqabQ7wPQWSM5Ijuy4F:Zd8K+5upiM5Quy4F
                                                                                    MD5:59C430488A04DE01C938643911998D26
                                                                                    SHA1:7C7D5657144EF34511482ADD0DAE850B4A92D010
                                                                                    SHA-256:18626257403124203E279A7C7D776597F6FB4D1DF8E440400448410C56B47993
                                                                                    SHA-512:57E707A657FF74D8F4EBEA953A82CAC57CC7300830D7B692C6AADA9743B792EF0AEA8F5A4704AD2A1BA22315A892776AE4D646B072F36FF5E5760DB452F1A572
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0..........~O... ...`....... ....................................@.................................$O..W....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B................`O......H.......\K..............P ...+...........................................+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6054633100180387
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E8ZfH2d56R2QlA1qFHFbFKDF/MDlPqWZlx/4zps8tscjMqNvFJm9fWGzFwJ2Y:GZfWd5KlKvclPCbtsDFzFS
                                                                                    MD5:111049AB27D0E576136B6822B1A8FA83
                                                                                    SHA1:5FEF8676B81F509CF5392BBE61BB3042A4C2B8A1
                                                                                    SHA-256:77066F1B182C4FC32B87152B00F3847C04A40726A071A3263D5882C3625D475D
                                                                                    SHA-512:9F4E9CB3CEF9E3A16FA6641FC56291F09C17B8CA523E3FABF87E80010304B962907AB645F553CA605E787612A2FFCE07549D9327E75EBC5D0DD1DB4C83161707
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..I...........................................E..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5490255233244485
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6PwpHer9UloNaCYUfcRgYlPqWZlx/Xzew1sMSjAqNvYJmwfnGzF1J2Y:rp+reluPYUfcRgYlPKw1sxg6Fr
                                                                                    MD5:964BDE3712BA4392C0B7C17920A750CB
                                                                                    SHA1:99012442E13542CBD809F4A2E879907264186789
                                                                                    SHA-256:E6BB86ED3135CBFAFBC5471813B501C7FBC2BFBA4A835C9D58BEEA234D290CC7
                                                                                    SHA-512:AEC25A01A66A5DD2D97B139D9A4552E4C8DAF7DB6526C758459C9F58EADCEFC22D42A841A46E246FB7C7ABB82D48E5931FFC00062DAA8ECA21A4AAC4B86009E3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................N'... ...@....... ....................................@..................................&..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0'......H.......0#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4558743407865586
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzzesajEfqNvjJmbfsGzFCJ2YO:WlviGlPiesxz1FwY
                                                                                    MD5:95D716431A44C555759F2FFBA62F9340
                                                                                    SHA1:C454148644C05538ECB3891FB02063BF317993CD
                                                                                    SHA-256:9EFD7DFB87A3408E6BB42F050F925C4A35677B3146AF8FAE703F96037917A222
                                                                                    SHA-512:D836B1C593EF234082D4D9CC22E08C22E64CEC533E8485F173D71BDC21D7EC811ADDD12A477DE3E2E432B20CD79803B0462069F0EF3747FADD20297DA17121C4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.73780389740473
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6dshHECSlV7geg9fhg70grWZFwbUU9pu7/lPqWZlx/5zAjisljIAqNvOJmmf9Gzx:xhk3zsN9fi776ZFHx/lPy2sYmkFh
                                                                                    MD5:EF29FB263B0B6630D6E8E9793A7645EC
                                                                                    SHA1:39EE2B76310FFAE035AFD494864D007A489503DA
                                                                                    SHA-256:E8B2220227841A6EB879DBD0B7B0F7AA66A9172B38ABF06EA93B27B9053ECC7B
                                                                                    SHA-512:314A62DC148C9B4DD4662F98ED0612CE97517013878EA83FA66958B730772B132D6F27BABC0E62D6806E1BC907B7FE440298173D0B5574C106A903DE707F6E79
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..O....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3392926869070463
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/SCnsrjL/qNvcJm0fDGzFBJ2Ye:gNClPaCnsykWFfI
                                                                                    MD5:3B190F2829E0939B31AE7FB269832D7F
                                                                                    SHA1:23B0104BD90BC87536BDFAC3B09E740BC6C6F0E6
                                                                                    SHA-256:6F11B2FFEFE4C3F207C1EA0BFD4E4103556EE2EEA1D23EECF95A9DA97438FEAB
                                                                                    SHA-512:59731CFBDBD1985D300408BE94089BC168D988F316AA6EC40CA675C35840F240411BD47EB28B9D894D5BBAE4390B2CE5CA485D07EA4AB778772F7B29A9036468
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.268954196614551
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:PrgPr//lGyGj5BuWQAcuA0Ec00r33xJJG5B/khHJrnsTsVW/p8bLbVH9VHyVHiVq:z2nJWQALA0EL4DVdVSVCVOP95cs6I
                                                                                    MD5:8FDDC32B1BA005A4C93FA5A360D9FDBF
                                                                                    SHA1:DF14F08EA55211AD411D9F5FF1E5AECC200B0D74
                                                                                    SHA-256:0B22AC988ACE40B1ACB5522031C2909FEB32569F950223175C8A8B46C1616B59
                                                                                    SHA-512:9A24510D20934CF70543087F6DCA32BD9AF0F6BDCE96C4D4BB1105E5522515DFD3494A94CFF2CE364EEC8CEE42435CA5AAFD2BF2E2A4B0BBD50AD552B00C023C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......47..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.782520457585241
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gge9DhH23S+lvgeKlNota0blPq+LDJsrhj3vgIUxWyoFp/98P28s9JJ2L:tFDhW396WlPN6tj3Ya7T3
                                                                                    MD5:77BE1E70CE867E9E704381F8725E5C6E
                                                                                    SHA1:165F43C1B35E87B6344FCD477F983721A6898C37
                                                                                    SHA-256:010CCD405D3BC1D133CC16DAC9F850EA4B6F01CEFBEB3D63430EAE8002DE529D
                                                                                    SHA-512:E00D6B98561D5C38DCC5AF29702EC8FAE150D759FA161F7A218AEB85E15036EE2E84AE1E5A5A5D2F8DB3F4CF798D28F30666AFF53D7706ECCBD9FC22AC89C1B7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..S....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v.,...!..2....`..y..}........?........U.;k1....(l@bV.`...~B?..(.".....;.........r7..*....1J.k.P./6o7...k..Q..ZB+[..s|.t.^...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.031616183452897
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CtEoG7FWt1fzoYMV4otlclPNrYjGBlZsKJ:OERWBotScqg
                                                                                    MD5:9EDD65E6737DE7C073D65ED46837AA18
                                                                                    SHA1:9CBD45DB426D02E4C20CD4DEEF878A878473AB03
                                                                                    SHA-256:4389F26A446BF3295F57AF7C03A90EEFF539F64907C7955AAD352D4EE98D1703
                                                                                    SHA-512:544BF0825A0D4632BBEB901725D78AA793A551BB23C0047B16F8ADC3D75D33D2FD11216BED496E32CB97C325655D8C95541206C7DA147660AAFE5CF639C259F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................y.....@.................................4)..W....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B................p)......H.......(%............... ..X...P .......................................b........@./%..t..g<n.2u.h........=#..[.3.^]..X$.I+.7..#...X..y.d...W...EL...X.TB.e.@Y6%.^...:.....0`.fC.,....e.>.....T.T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.589575428609492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9xHq93PzjhJH/rHOUllPqNKS2pxsrISQj7qXp2qwz2/UbGp0JJ2Y:+Ds/XfbZlPm2KhlBZq
                                                                                    MD5:73D681F55B0A4B484EB80B26602AD4C6
                                                                                    SHA1:D72DAD121D5440368A38BB587E724ADCD9397B5E
                                                                                    SHA-256:9BF894ADCB50B4902108CDA8EEB8533C7F8C48E6099BF6BFA11F8690AAC19403
                                                                                    SHA-512:A8F53B278DC7D2DFC4DEA1AC00B3E321E201BA1E8CF1F48C341EF761498BFAE881FAAC70AE72B668AD4A086D866577B97C125336CF6F9218F719941577D2F378
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!................~(... ...@....... ....................................@.................................$(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`(......H.......`$..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835294577934021
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHAJn:CuQiS0Mw+f+Sb+jkyNr1rmqn
                                                                                    MD5:EF0CCCA5BA90200B76F1D38B2C551854
                                                                                    SHA1:B4B9A61745D68E6D95FC02ED9613AA7AA65DF960
                                                                                    SHA-256:6D5C1DE62E79F2AD84118C4195F6FBA7E017A0EA98C36EFED01067D47670E621
                                                                                    SHA-512:D80E9472044CBC827499CD3D7B91D44B00D346BEF5ECBDDD2FD4216DA080DCD0B1511CE4FBE8BF617AE8C0F8FE818F79B6D651F3BE9EA180504F6BB628B5DEBA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5490255233244485
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6PwpHer9UloNaCYUfcRgYlPqWZlx/Xzew1sMSjAqNvYJmwfnGzF1J2Y:rp+reluPYUfcRgYlPKw1sxg6Fr
                                                                                    MD5:964BDE3712BA4392C0B7C17920A750CB
                                                                                    SHA1:99012442E13542CBD809F4A2E879907264186789
                                                                                    SHA-256:E6BB86ED3135CBFAFBC5471813B501C7FBC2BFBA4A835C9D58BEEA234D290CC7
                                                                                    SHA-512:AEC25A01A66A5DD2D97B139D9A4552E4C8DAF7DB6526C758459C9F58EADCEFC22D42A841A46E246FB7C7ABB82D48E5931FFC00062DAA8ECA21A4AAC4B86009E3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................N'... ...@....... ....................................@..................................&..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0'......H.......0#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8691901965523297
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:fCSNfpQwM7PxNTeK1S57U2KRlPgw0TGbdvK:fCCpwNTeJ5ANRfdv
                                                                                    MD5:4AF5AD6BE2909483795D315B8029BCB2
                                                                                    SHA1:A818970B3ACF9B2BC51CB5270C5BBB727A6A1B86
                                                                                    SHA-256:E7FA776BF8A19AA5C5AC866067AA3326EF2F6CB2B66BF986EA99A6674931ACD4
                                                                                    SHA-512:4BE9481D281E40E733E206F3998A3F33A29D1E4BC632EBA04D66412F9E085F98AD06ACD2DC7B96E1C3EC1FB1E0B3D6BAFCB8E4D02755897F9BB926077B829E21
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@.................................x0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........,..............P ..\...........................................X..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7690940088540894
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6YVOXH2HpSp6p63y8nIuTb4TClvlPqox14r7Wjwq4o4wmHDvSGEpJ2Y:hwXWHpSp6p63y8IuT0TCllPi/xgX
                                                                                    MD5:E7E9EBF4800F9C14CCBCD0E9DFF94AFA
                                                                                    SHA1:2F98001343EEC80B4A5BBA3AE3CD1A3756CE792B
                                                                                    SHA-256:F7B38062E476F4A010A354869722DF860F2C9E013B7B0A6957D15BE957AF46A8
                                                                                    SHA-512:436C5185DD162DD71B6B3B957A5EC48B26D6F7C0DAB84DBD40345EF5A856223388C91E82D82F7DB29856421AC19BED65A94C685CA072ECFAF40A0D1240B45154
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................\)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........%..............P ..F...........................................B..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4558743407865586
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzzesajEfqNvjJmbfsGzFCJ2YO:WlviGlPiesxz1FwY
                                                                                    MD5:95D716431A44C555759F2FFBA62F9340
                                                                                    SHA1:C454148644C05538ECB3891FB02063BF317993CD
                                                                                    SHA-256:9EFD7DFB87A3408E6BB42F050F925C4A35677B3146AF8FAE703F96037917A222
                                                                                    SHA-512:D836B1C593EF234082D4D9CC22E08C22E64CEC533E8485F173D71BDC21D7EC811ADDD12A477DE3E2E432B20CD79803B0462069F0EF3747FADD20297DA17121C4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6054633100180387
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E8ZfH2d56R2QlA1qFHFbFKDF/MDlPqWZlx/4zps8tscjMqNvFJm9fWGzFwJ2Y:GZfWd5KlKvclPCbtsDFzFS
                                                                                    MD5:111049AB27D0E576136B6822B1A8FA83
                                                                                    SHA1:5FEF8676B81F509CF5392BBE61BB3042A4C2B8A1
                                                                                    SHA-256:77066F1B182C4FC32B87152B00F3847C04A40726A071A3263D5882C3625D475D
                                                                                    SHA-512:9F4E9CB3CEF9E3A16FA6641FC56291F09C17B8CA523E3FABF87E80010304B962907AB645F553CA605E787612A2FFCE07549D9327E75EBC5D0DD1DB4C83161707
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..I...........................................E..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.4926374753106115
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6O13lHdyrp71jt6koZlqdBlPq02pxQdNWjfqlF8yge2wDGpQBJ2Y:L/9yrF1jt6rMrlPR2Ktm5o
                                                                                    MD5:A72C7635F324D2BABBA25B1875F34EB7
                                                                                    SHA1:7D6EA37C1D080F44B7A8946F6D7E4B52FF18A46F
                                                                                    SHA-256:2E93FA1DC13BB8D8E8603C8832F3D45F66C77804D5426501B7BDECE9C6FAC94F
                                                                                    SHA-512:44817CAEADF07D2BA950142F53E6D9C41CA8C07F2B16C6A0E51D18403672308362D407FFD22B6AFE7DFB323017D8E7C20C6BCA104F64D80E4D228B57AEA49984
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................P(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..O...........................................K..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.......L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3392926869070463
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/SCnsrjL/qNvcJm0fDGzFBJ2Ye:gNClPaCnsykWFfI
                                                                                    MD5:3B190F2829E0939B31AE7FB269832D7F
                                                                                    SHA1:23B0104BD90BC87536BDFAC3B09E740BC6C6F0E6
                                                                                    SHA-256:6F11B2FFEFE4C3F207C1EA0BFD4E4103556EE2EEA1D23EECF95A9DA97438FEAB
                                                                                    SHA-512:59731CFBDBD1985D300408BE94089BC168D988F316AA6EC40CA675C35840F240411BD47EB28B9D894D5BBAE4390B2CE5CA485D07EA4AB778772F7B29A9036468
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.782520457585241
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gge9DhH23S+lvgeKlNota0blPq+LDJsrhj3vgIUxWyoFp/98P28s9JJ2L:tFDhW396WlPN6tj3Ya7T3
                                                                                    MD5:77BE1E70CE867E9E704381F8725E5C6E
                                                                                    SHA1:165F43C1B35E87B6344FCD477F983721A6898C37
                                                                                    SHA-256:010CCD405D3BC1D133CC16DAC9F850EA4B6F01CEFBEB3D63430EAE8002DE529D
                                                                                    SHA-512:E00D6B98561D5C38DCC5AF29702EC8FAE150D759FA161F7A218AEB85E15036EE2E84AE1E5A5A5D2F8DB3F4CF798D28F30666AFF53D7706ECCBD9FC22AC89C1B7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..S....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v.,...!..2....`..y..}........?........U.;k1....(l@bV.`...~B?..(.".....;.........r7..*....1J.k.P./6o7...k..Q..ZB+[..s|.t.^...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.232012742966397
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:iuG1zHCNHzc8A3coFwQj50eoSpKVFKhdrSZ3EV3KVi4F:iuG1zHCNHzc8A3coOSpKShWEo
                                                                                    MD5:999E5F01BF727BD122F400ACF03FDA37
                                                                                    SHA1:FB8269134BE364F042AE0CD27C2A6B5385C16A7A
                                                                                    SHA-256:68CC7FE9FE3D9C7F9E31EB10F6320D8D7F90F18427DCE4A89898F548BCAA24E8
                                                                                    SHA-512:105050082682CEADA4F5B6CBB16CB24E882559D049F8F26BEB88F09C9EC9574D9A17F26A6D30570D59FE988800803D06C57FCDA046E61FCD74A88F9C87E72093
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p..........~.... ........... ....................................@.................................0...K.................................................................................... ............... ..H............text....n... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B................`.......H.......`...............P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.811275919755305
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:QYOtEIhbiDnnfD2Y4YzX4PG6u+7DmXj1qYlPwW2ij:QYOsSMXx5F
                                                                                    MD5:9150D1D649F5D98363AB3CDEA99FB777
                                                                                    SHA1:525AD06E4848132A4CD82DE73FD0F6C3F17F0F67
                                                                                    SHA-256:190587CC3A00A09F124B8614D1A609CE448A97462845DFF34C53CDE56B315E08
                                                                                    SHA-512:C3D439214276402A7CA2059480DAAA866B131DDE40A4A9B95B432475D1DB3838CC80CE7FA2AEEFB6F96BD8CFFBBC06F8E452D2E8CA66EED5570258AF73454268
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7872115466343765
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:65GHpQUFezLUr/Mdl/OlO8OlhP0R9FdHSwYn2kU+lPqLx/zzKKjewqcF7JPWSG3L:vJRFezLUrGOlO8OLP0RJt9kplPHf5
                                                                                    MD5:D65A3887158DB3F7BA95DEC627432519
                                                                                    SHA1:2933E71B38562AA5CA3EC85FC15B4A193D497FDB
                                                                                    SHA-256:025839A3B263ED0493813D3283068B5407E7ECC27F6D36B9420096912569AB28
                                                                                    SHA-512:F5D27D4A48E929CD45FADC147A069EED7CD834BAFD59066855ADB8407763A683442D1EDA75DEA33BE1B70BAF3A84BED3296B1869471470C6623BE7F33EC22457
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................T+..W....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..X...........................................T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.031616183452897
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CtEoG7FWt1fzoYMV4otlclPNrYjGBlZsKJ:OERWBotScqg
                                                                                    MD5:9EDD65E6737DE7C073D65ED46837AA18
                                                                                    SHA1:9CBD45DB426D02E4C20CD4DEEF878A878473AB03
                                                                                    SHA-256:4389F26A446BF3295F57AF7C03A90EEFF539F64907C7955AAD352D4EE98D1703
                                                                                    SHA-512:544BF0825A0D4632BBEB901725D78AA793A551BB23C0047B16F8ADC3D75D33D2FD11216BED496E32CB97C325655D8C95541206C7DA147660AAFE5CF639C259F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................y.....@.................................4)..W....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B................p)......H.......(%............... ..X...P .......................................b........@./%..t..g<n.2u.h........=#..[.3.^]..X$.I+.7..#...X..y.d...W...EL...X.TB.e.@Y6%.^...:.....0`.fC.,....e.>.....T.T..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6909032251512306
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YneXmayKpiyyXP3LC3XrNXiwblPXFoeQr:rXdiVXP3LC3XhXi4boeQ
                                                                                    MD5:6F2670E182618ED8D6CA44F54FE8EA5E
                                                                                    SHA1:03923621C472D766C168C081F0BDA4F8D8228B99
                                                                                    SHA-256:28ECA5095903FC714D95420A1F6D1D22B0C29209B986773FE965575BE0B592C7
                                                                                    SHA-512:4266ED0B35A98F6EA79750C0B21E08D707D57948D0340D078176C648D055B8403AA815F501738DD1BD3EE2AE241C08CFC19185CE2726C98F2A3148A2C86F4F5D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................>+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ +......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3355208441131676
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6VNHNoVy3lPqVx/uz/bpjrqtE8+6GzaJ2Y:UtoVilPFbL4
                                                                                    MD5:9F964F0110F89EAF46065A7F39103282
                                                                                    SHA1:4BEF4C3C5A6E7D3B56DDA27E36EB0C5F4CD17C08
                                                                                    SHA-256:C125429B2DAFE421290E207A42F91231DA55E294AB9D14B103CE9B5AF2E4EDD6
                                                                                    SHA-512:ADC547B3867C0CA36C114AB19B85B95C9472C543A6070F5CB7E935E24C0F252E311066F4408F2F2E4BEE8F68C40F53B183EC9ED2F42908BFF9D2BB7BC45522A2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................8&..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......x"..............P ..%...........................................!..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6545702649554492
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxWHt1G5ilQ/eQ/e9J0ZSlPqfzx/rzSNfujsqN0gyF/GtpJ2Y:QcNjlQeQe71lPwQVxmX
                                                                                    MD5:5F71E42D0FBEE58DD1674E3DBB54DE25
                                                                                    SHA1:AEEA76E27DF535DD508283D7734E6BC394FA0281
                                                                                    SHA-256:7DFD8ABDAB51043C3F44868BFC27C7BD4B4500BD6E50F304AAE8A6A013C7CE06
                                                                                    SHA-512:16DEB68520DD07E411DE7130B3F6B2E671FBC3CAFB666ED01F738B083B55FA0090AA88E158F207A15F71736A674F6736A671FF341AFE3BE1B3B8E4F2FFB04928
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@..................................'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.208005182662268
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:NHfCwjjB4NfVgV+Q8X9S9j9Y9fOqabQ7wPQWSM5Ijuy4F:Zd8K+5upiM5Quy4F
                                                                                    MD5:59C430488A04DE01C938643911998D26
                                                                                    SHA1:7C7D5657144EF34511482ADD0DAE850B4A92D010
                                                                                    SHA-256:18626257403124203E279A7C7D776597F6FB4D1DF8E440400448410C56B47993
                                                                                    SHA-512:57E707A657FF74D8F4EBEA953A82CAC57CC7300830D7B692C6AADA9743B792EF0AEA8F5A4704AD2A1BA22315A892776AE4D646B072F36FF5E5760DB452F1A572
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0..........~O... ...`....... ....................................@.................................$O..W....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B................`O......H.......\K..............P ...+...........................................+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.6185885465184437
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lwHcAI/PI/UwULoLYLLOcZDOcFDPfD6YUXvWalPqAxXxroQMhI4jAqwIA9oqTx8:J8AYPYULcEn5DlDPfvw1lPyfIYcOnwa
                                                                                    MD5:5FE71E8866CA3CA8660355EBB521A174
                                                                                    SHA1:4C82D1CBE94DCEAACE70374131E4A52BD0BC3378
                                                                                    SHA-256:9D2BB3F14323A39207C229112B41DFE5D494DB8092FC586B4D26D5C61F11BBA0
                                                                                    SHA-512:68BD1433436F682C8A8D9FF4B285D363D4DBFB1CBE7D99A2F3DF51679AB609247BC94BECBB245D07FD607AC59AB395E29D9BBB2E342926A9A227ED065FFBA754
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.73780389740473
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6dshHECSlV7geg9fhg70grWZFwbUU9pu7/lPqWZlx/5zAjisljIAqNvOJmmf9Gzx:xhk3zsN9fi776ZFHx/lPy2sYmkFh
                                                                                    MD5:EF29FB263B0B6630D6E8E9793A7645EC
                                                                                    SHA1:39EE2B76310FFAE035AFD494864D007A489503DA
                                                                                    SHA-256:E8B2220227841A6EB879DBD0B7B0F7AA66A9172B38ABF06EA93B27B9053ECC7B
                                                                                    SHA-512:314A62DC148C9B4DD4662F98ED0612CE97517013878EA83FA66958B730772B132D6F27BABC0E62D6806E1BC907B7FE440298173D0B5574C106A903DE707F6E79
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..O....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.268954196614551
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:PrgPr//lGyGj5BuWQAcuA0Ec00r33xJJG5B/khHJrnsTsVW/p8bLbVH9VHyVHiVq:z2nJWQALA0EL4DVdVSVCVOP95cs6I
                                                                                    MD5:8FDDC32B1BA005A4C93FA5A360D9FDBF
                                                                                    SHA1:DF14F08EA55211AD411D9F5FF1E5AECC200B0D74
                                                                                    SHA-256:0B22AC988ACE40B1ACB5522031C2909FEB32569F950223175C8A8B46C1616B59
                                                                                    SHA-512:9A24510D20934CF70543087F6DCA32BD9AF0F6BDCE96C4D4BB1105E5522515DFD3494A94CFF2CE364EEC8CEE42435CA5AAFD2BF2E2A4B0BBD50AD552B00C023C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......47..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.066221331285762
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:H0B5nPn1fU2V6ofLSM8NoG/qn7NmKmmsDtFlBdeNo+N9RAPFIU5KrkG/KW5MKMyZ:H0255awvoUc7eHKKQ99f6
                                                                                    MD5:6C1501A7C57481123C8FA7A711E657A2
                                                                                    SHA1:2B2D55CF4BECAEAE686F2A5E3F2CD931F11B4684
                                                                                    SHA-256:2EAF8203B97509DAB0F0936703744F9F3431B41F010A14FDD2F1E087A48334CF
                                                                                    SHA-512:4DA0C4CB2445AED44F72EC688BAF2CCE1FE04BCADFF3D1D17376DB27F1A2E02EBE0D4B165BE891B71CBF96A5C9939A03156979FCDEDB8ECCD2E764EEAEAAD51B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................J..O....`............................................................................... ............... ..H............text....*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...&...........................................&.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):142975
                                                                                    Entropy (8bit):4.966849523029269
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YMMP8lxm4xLZxpKiqaUCSONPu09geb3AOMo6H8sj:uz4xLtMPoIj
                                                                                    MD5:C27C08E57059357B781CEB4E83B6DAB5
                                                                                    SHA1:8366633C00515C4578BAC0FED604E65ACB413485
                                                                                    SHA-256:F898A93FDAD3FF4FEAE3727FEE4ED4E8F79471601DA2AE72F3DBB170B27384F6
                                                                                    SHA-512:472C0E758A0BFC272EE4CB8206D8360A61740594C0F41122E49A727D6E1A29A4F2270823BF9464C417A60FAFE6B5459F8826C03560774BC54028C3775D967CF1
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7776738283051285
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:I8AYPYnaPwxxDCPfW8lt4qlP+PI8cOnwa:I8zhlSqtW
                                                                                    MD5:6C9DFD2C4C06705A883EEEBA02082EB3
                                                                                    SHA1:A485F416392C110D07E4400E7E9B81ADEF643C06
                                                                                    SHA-256:7BA3309A9C01F9A58233747226199CC5A3A9BB1AED3BFCDDF3B6B232C9532AF1
                                                                                    SHA-512:7B609A239532903B6E503B3B5DB138CD667B1ABEC9D89F59590664DCFBF70ABFB38926A6D429242F5355B988E0F65AB239AA4038D0AD05410C2A2BD777CB2F24
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@.................................x+..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..:...........................................6..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.699670159881912
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:7XmayKwgyyXYHuNo9XrLXqLo8lPLNoeQr:7X8gVX+uNo9XPXqvXoeQ
                                                                                    MD5:AD12271A5A1D6CC30985517116091CC0
                                                                                    SHA1:D09B96C5DE05D643FFCA973226DEC15E8924244F
                                                                                    SHA-256:35946298511CB617ED9B977F599F4A9AE30BB4E7C47DF5C7C93A039CA4A02279
                                                                                    SHA-512:8BB45D1E07E68B325474B2EF16BA3CD76A6A3C8ABC1C977E7D773A7195723B29346C8621789D5ABCD2117878946F5A127F27CDD4A845314274680B03B5B07354
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......,'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.70864786784634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6w8LHo6cs+EcWCc1SLcQdcOcJLcdrc7oc0c3ypcrlmczcqcKcPcSYcfApc5cFkYu:61q8GY8OggpIgQpHnlPgw03Itd0K
                                                                                    MD5:E94CDDA083208AF1EE2BBC71136E711E
                                                                                    SHA1:268E1031AE9F3D6F9D6DFB250651C8CA7B43A133
                                                                                    SHA-256:53BDA1D8FD445D0A603CFF91AB244B27BA1B7A37FEF1541499617D3A30998987
                                                                                    SHA-512:2709966E7D8FC95298DB0E42098E19427D4A0DAE4161A59F67B2F19BCA708CC0F218964DE00A684DE3A020F3A93FB96E8BE3E12DFBFB60098CDFED85DC68BCC7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@................................../..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........+..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.60500006591566
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b1lHq9fRzjMlIm2FmollPqNKS2pxsrIeEjPqXp2qwz2/UbGp0JJ2Y:+/s5XM2lPm2mxlBZq
                                                                                    MD5:0FD00B3821011A7323CC2B230145FE50
                                                                                    SHA1:C1AFAEFC985099E8A36BBA935D652B880B80266B
                                                                                    SHA-256:75FE8CF182A0BC65CC3DF60155837528520492CF3290F3F5BDF839DB813CA62E
                                                                                    SHA-512:61B5C7C2B9F8A22676190885C0617F10377D26926421F6C45CACD64EE0593F791C58EB31D3D0D0DCEEEB301C94365D373144FEC33EE2095088CFED67BBFA5601
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H.......|$..............P ..+...........................................'..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835094194750168
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHUJn:CuQiS0Mw+f+Sb+jkyNr1rmWn
                                                                                    MD5:B4CC4CBFAB9F3613FCB254C6309D7804
                                                                                    SHA1:1C2BC7716B222EA704B23C005F3797DF8FC07151
                                                                                    SHA-256:FDE9F88C107BC8BDDF7030D314DD1D2068D5511A573EB240417202C8E650CC81
                                                                                    SHA-512:049ABEFD59DA8F38C7BFA9C9939141945AC1F9881765E6025B49CBD50D64016024EBF48D7BD0442190597155A1D85E8DC63E0CCD05E4ADFA3F83789312BF97DD
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.468979119248313
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6OVHy+HdyApEwW80n5mRz9kwBlPq02pxQVVTjPqlF8yge2wDGpQBJ2Y:Lk+9yA6wW80W7lPR2mVYm5o
                                                                                    MD5:C4A98A773ED1610B6F8BC7C3E4A4CC9E
                                                                                    SHA1:88FDC429F7AE44A4B5E98DED1FFE176B8EDDE244
                                                                                    SHA-256:BE2BFF39EB37BB9B7890EA0640A575C96A70CC719E1F82FDF35C85B7D3AF09CD
                                                                                    SHA-512:A97E7E2A86E3E71D3310081E031708C2C07F27AC768E196CA6D1862339EBB6E1E61402C8F9F6CE67C742BBC033B4A88FBB039966D603F81ABD7F6FC415287C1F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.......L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.710177983891544
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:hY/WHpSp7p62tAcUHlo1a/5apllPuKgX:G/WFHlo1a/5aLs
                                                                                    MD5:D0BE7FFB71C072311C273311A4B1B215
                                                                                    SHA1:9D30E4EE172583EEB0CD5586D93B59668C983D9E
                                                                                    SHA-256:7A19B06AD8DB8F3702856F888340B768FDD0CEAB650A1B15A10C6FB9ED4F95F7
                                                                                    SHA-512:29AF33B7CEC6BC87BDD46D8769943CE5BDF66FF52F961A2DB7FD241A2647656AB9C33228AA81D58A85D305E3A88423BAA6AA105BD8C74456686F70959A2B806A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................8)..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p)......H.......t%..............P ..!..........................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):4.007462076109497
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:KB5nPluBuJv/ck5wwAaoR5JzQ+f3m/mjc3vJedenoksk3TwYoX5w6rvXEw5uMXyL:KbqdBtNfFY/yODli4dffpOjVVVVm4
                                                                                    MD5:0D1501560F4C0F41860E76F3F5B74B59
                                                                                    SHA1:B8797909B0BD90B2756A05DEAB85C63594C8B5B1
                                                                                    SHA-256:920C0762603F014FD80868D0DD29AF526867BD06E037C38D5E44263F4BE13B93
                                                                                    SHA-512:366A4DC5E17BFF06E99F02B761E8E8ADEE5B21778971C2C3431757FED0BBA9EBFFA0424398CD043040CE5FE30BFAFC787E0FD28E2EF53F7443AF5A04389E946F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....*..........NI... ...`....... ....................................@..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................0I......H.......TE..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.786140605383779
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6pyHpQUFezFKIlTM6lIOEOzOlyGAKu5tdHSFy4lPqLx/zzm5jaQqcF7JPWSG3RWo:zJRFezFKIgOEOzOcGluNH4lP7A5
                                                                                    MD5:D7D6A04DFF0CD58FC0A40EB9AC632FAE
                                                                                    SHA1:B7B683FCA0A8745C06AC1760822DF471967A9FAA
                                                                                    SHA-256:40A31456DA57EBD0BF1DE7FFA03ECFBEFA624853A2B4F3442061A64E6F36D765
                                                                                    SHA-512:FB30C65BCC9A1A9A09010BF701DB17A99223F6B04828999C1262058E9AE1B9E9ED9C46E6297305AF8DBDCBD2303026D1093246F7640ED24A8C86CA8AE8ECA356
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................X+..S....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..Y...........................................U..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3295946971418413
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6dxHNoD/q0lPqVx/uzD5pjnqtE8+6GzaJ2Y:4toD/rlPt534
                                                                                    MD5:A8E964993A3D509AAAD234B709D52E23
                                                                                    SHA1:9D368FF3FFDC0F632A6246D728C9798D9E5B0EA0
                                                                                    SHA-256:65E5AA290E5E6C8401B251B43F3B5F7B4EF18EE83EAFE8D5E2E300F578CC692B
                                                                                    SHA-512:9191254E9DAD3CF1CDE4202627BF444CC488FC932EAAC1B5E9401C8634C91D42B1E9F0F216DCEE6DA3F6905E7438B0E05CEEDB3433D1F2C7269DD727505E04F9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................4&..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......t"..............P ..!..........................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5662559985732036
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxeHt1G5JlQ/HQ//aPYYo/lPqfzx/rzeloIfujsqN0gyF/GtpJ2Y:QkNUlQHQ/qy/lPwoqUxmX
                                                                                    MD5:EF451779C2BDA793A6390BC38E9EB34F
                                                                                    SHA1:AB2887F98FDCD68B1D2DA245C41BD7D3DA1101EE
                                                                                    SHA-256:FD2F0691B4EAB9695F3F83AD47619CC861EDC72D1EF28A3D8E479B32B7096994
                                                                                    SHA-512:D6273CE8524084B7737B1FDFDEE3E0B7BCA053026C1A885B87C91ABB2670FA18A42B48EE1D8CE118A0033493E89E6AB79D195DC97266559597A84C5AD0B4EAEC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................D'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..U...........................................Q..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.721606779468658
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:oYOtEDDvdMRFnZWtYbYzm24kC/dDMQZTMzxlPwyKDj:oYOy2ZWxE
                                                                                    MD5:BC14789692741C5B5BFF2BDC5929CEDA
                                                                                    SHA1:CD1982FA66827AA7B4413D7A25F85467CED0D53A
                                                                                    SHA-256:CE02FACC1F26555511E8CEBFDE1867C108D25EB3FE109A8318C09D031291A427
                                                                                    SHA-512:603DEA7111CDCFA0B6C9CF15A6C3D657D88188F7B7A558910186399170581BE8F89A8C88F5FEF7EBB02A5E491E02C448B3043D0FADBB9ACBD4EF2AC03BDAA822
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!.................1... ...@....... ....................................@..................................0..W....@..h....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B.................0......H....... -..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):30720
                                                                                    Entropy (8bit):4.188502209597651
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:cHpLDVuCN4IKCmemLt+DzNmxScA8ZRaIHYXOByV7Lbi4F:cHpLDVuCN4IKbemLtbA8ZRamYXJV7L1
                                                                                    MD5:F319D728E37C82821DCEE673180B8BC7
                                                                                    SHA1:03F7CB4EEC20A04420B610AA54D721669D7C9091
                                                                                    SHA-256:93F5FE155661395B4CE9E2781EFF6478A910BB258026A6BE841708B9B70B97C3
                                                                                    SHA-512:10F370AFC4793D8189CCA6BE49AF4FCF1F336B793336245C7ADE73E15910EB56E32C52385AE03FFEA670969B7062FBA6FF488F9FBF1321526DF94C16CAC135A0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....n............... ........... ....................................@.................................p...K.................................................................................... ............... ..H............text....l... ...n.................. ..`.rsrc................p..............@..@.reloc...............v..............@..B........................H.......................P ..Mh..........................................Ih.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.143460124442194
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:yfCwJauW0EV5VM0n9i9Yh79l995+GA+xMZ5Ujy4F:yCt7M09PfrMijy4F
                                                                                    MD5:D32E8B47309DB3A9CF5F6E657A2FBCBD
                                                                                    SHA1:1AB440F02D1130542AB87FF4523DA2C650892E06
                                                                                    SHA-256:11EDA09B2ED6671B52268AFAEB9C40BA771A5F4FCB7029270CF85776BA966203
                                                                                    SHA-512:32122F989291DA0E1B5907931E870AAF4F8CCE1EFFAB3EB9BF3AAB6EE29CC28BB44269A9FF009218CB524C60B532CF0F123BD3A436C5812E792657A97A25E8F2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........N... ...`....... ....................................@..................................N..W....`............................................................................... ............... ..H............text........ ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H........J..............P ..z*..........................................v*.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6065454885539276
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E8ZfH2d56R2QlA1gFzFaFK1FMMjVruulPqWZlx/4zRPnscjMqNvFJm9fWGzFwJV:GZfWd5KlKyzVruulPOPnsDFzFS
                                                                                    MD5:709255BA86311DACF9FE3AA96CDB764B
                                                                                    SHA1:4BBE7381E046DD90A8F2506A0801EB480E76635A
                                                                                    SHA-256:2F2423C37BAF396563C4CC47C1491D0AB30AA8AF2B71EB10C5A0E941C9070B3A
                                                                                    SHA-512:3DCD7D24D3C3B14819B27C130B7437EE83C3225CA4A1B32E77B1840DD783E607A625A8423CD60AFAF999BC0E4C45B798C5279DF482BD36E9824B0B47BBF11623
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..I...........................................E..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5535212934107925
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6mcu8rHer9UloNaC+xU39nlPqWZlx/XzqR1sMSjsqNvYJmwfnGzF1J2Y:MJ+reluPQU39nlPmR1sNg6Fr
                                                                                    MD5:B55C4D3ECA32B431E1104DF347D0E683
                                                                                    SHA1:40D0D26E0514392590E06EF544B1B8CD3350A7B2
                                                                                    SHA-256:DFD078EEB8C2D45DD6A916EC172004EF168923095C8BB48D173D5B1FF6D0767C
                                                                                    SHA-512:8152D5247FEB3C8BD22E74457CB1B1525D3BEC06620D3BE9300ECF9C73E81CF08A0DA3E8735B8B74230FB05D76009C0D52DEDA432EF1B8D48BD16CB247F04080
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................^'... ...@....... ....................................@..................................'..W....@.......................`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@'......H.......<#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4521669022409402
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzX4sajEfqNvjJmbfsGzFCJ2YO:WlviGlPu4sxz1FwY
                                                                                    MD5:DC0C6E7BB0B0B3AADE82340128415535
                                                                                    SHA1:A073D7CAABC0FBDE5E5A0508DBD8343DCDE12E17
                                                                                    SHA-256:C7656AA7D2A6A74B2EE5C5727B7F15C597B4C4D736331C9AB80EFE220F00FC86
                                                                                    SHA-512:A81E228105E84898F7CD1BA2E1C06AE9E0B8951B12A662000593B0FB29748C46C254E826EB6A3EF528B5278C665F5F08ACBD29AA65DA0AAA6E784C42CE3CB512
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6601952679288634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6kT9HECSlV7geg96g7jgr8vE3clHa1TOnFRaIelPqWZlx/5zY+sljJqNvOJmmf9Y:t9k3zsN9R70wvEMa+uTlP++ssmkFh
                                                                                    MD5:ED8948368E4EBEF017932592C8FE57F8
                                                                                    SHA1:4042437FC83640E3225944F94A182FC4DA2CF46E
                                                                                    SHA-256:7976684E575C3DA819992A0F9A919F247D7A6A3C3632A924E7D143AFC319FF0E
                                                                                    SHA-512:FFABF67266F0885438F842BFCA26B024803832BA69DF34812997291E7E1A8F7ACC82A15E7E987DA23233E9EF0632F93F15D2EFA956AE53BC28A3D8A11559339A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................*... ...@....... ....................................@..................................*..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........&..............P ..h...........................................d..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3398873123981887
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/eCVGsrjL/qNvcJm0fDGzFBJ2Ye:gNClP2CVGsykWFfI
                                                                                    MD5:A4C7BF91A6C7754EC192FC8C3A20D069
                                                                                    SHA1:BDD9EAB17745E0ACA034C678F20DD9EA6865C3B5
                                                                                    SHA-256:6D4F48A9128EE7E5F717169A6958E76C1DDE25B378E368B8FCB0A9E12C0A4D4C
                                                                                    SHA-512:90CA5779E04CB079146688D5A18C35FFC773B3407A1B2F8A7A25F9A468A5F49596FD3646887DB707B42ECCEE0336389D181AC628590084BFA36BD1BAC17CD701
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.124706156241719
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:V2npMuAyAHendmVeVPVqVSFkb3XoJUycJ:VvZAdmAlYIFkLFyo
                                                                                    MD5:21F3F29C689AAE23376ECEABDE463EB5
                                                                                    SHA1:7E19912A38EBC4D3189C028E76611CA4BCB6DD79
                                                                                    SHA-256:939C8238C3CF20D94B3EB5A2ADF3FBAD17C2839919758BE43051BCA2975FD0CC
                                                                                    SHA-512:D493FF3EF9597ACA24691893BAA8FA705349772818A2E1CCD81278E0824A0CED0F712AE1F82F574C1E5867878B4A79AEA9A7F96A4974BE6712C0348CEF845332
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................9... ...@....... ....................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H.......\6..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.767046359489489
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6go6olXKH23S+lvzexlN7Ea/DlPq+LDJIRhj3vgIU1WyoFp/98P28s9JJ2L:tuKW3W//DlPNCfj3YG7T3
                                                                                    MD5:3A3AF6CDBD99FA1C777CBF9BD36D1E69
                                                                                    SHA1:20E09FE02F7101FCA45442DB2D3D1836FB75A29F
                                                                                    SHA-256:2C2C12760C8410DABD37BC9838ADD8B5EE974F7DA0B6137D3053FE4814BE1C14
                                                                                    SHA-512:CFF1E25A2E88920108C882348FC6EA7B2884294A155DD3181EFB247B3C668B9B752801DF43B5D9C59F380E9C5D6C5DCD86FFCC952AFB2F95BCD194D5775C1ABA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................jQ.D..qA.N..3F.%<hy.m...1B<.,.+.)Q.5.W"./.P4`.H.....e...H...g.........YK...h..\........f1.Y..7.L7......n"s...<#.a.8.d.C................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.084015860715217
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:C7gkXWt1ExlZ5SUS2zRf4fQlclPNTgjiBlZsKJ:h0WfUS2zRf4fQSsug
                                                                                    MD5:AB356388E50971B0CCC8BB02C96858BE
                                                                                    SHA1:CD9F4BC5358D5651C398807D45F439ED43E0BE57
                                                                                    SHA-256:DFA7D81FAC26A31642BE5845089E4570DB06350494161D8C3CCE07A258F192D9
                                                                                    SHA-512:215E35030175267D1F3DD9261D24634031F836028F9CF4F87C30B8C477B9008C7F8BEDF0355BBAD8005BA41CB6615FAC4A06031FE2CC74EF9CD7DA039D609B34
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ....................................@.................................h)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......\%............... ......P ......................................4".. .M....1(.gwP...F7...r.....<._.....<...X.>..V............h.*5e..yy.b.$nTI..m|H....|.y.)m.@@..;.[>..4.R}......:..0..u.G5...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.710177983891544
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:hY/WHpSp7p62tAcUHlo1a/5apllPuKgX:G/WFHlo1a/5aLs
                                                                                    MD5:D0BE7FFB71C072311C273311A4B1B215
                                                                                    SHA1:9D30E4EE172583EEB0CD5586D93B59668C983D9E
                                                                                    SHA-256:7A19B06AD8DB8F3702856F888340B768FDD0CEAB650A1B15A10C6FB9ED4F95F7
                                                                                    SHA-512:29AF33B7CEC6BC87BDD46D8769943CE5BDF66FF52F961A2DB7FD241A2647656AB9C33228AA81D58A85D305E3A88423BAA6AA105BD8C74456686F70959A2B806A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................8)..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p)......H.......t%..............P ..!..........................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3398873123981887
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/eCVGsrjL/qNvcJm0fDGzFBJ2Ye:gNClP2CVGsykWFfI
                                                                                    MD5:A4C7BF91A6C7754EC192FC8C3A20D069
                                                                                    SHA1:BDD9EAB17745E0ACA034C678F20DD9EA6865C3B5
                                                                                    SHA-256:6D4F48A9128EE7E5F717169A6958E76C1DDE25B378E368B8FCB0A9E12C0A4D4C
                                                                                    SHA-512:90CA5779E04CB079146688D5A18C35FFC773B3407A1B2F8A7A25F9A468A5F49596FD3646887DB707B42ECCEE0336389D181AC628590084BFA36BD1BAC17CD701
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.084015860715217
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:C7gkXWt1ExlZ5SUS2zRf4fQlclPNTgjiBlZsKJ:h0WfUS2zRf4fQSsug
                                                                                    MD5:AB356388E50971B0CCC8BB02C96858BE
                                                                                    SHA1:CD9F4BC5358D5651C398807D45F439ED43E0BE57
                                                                                    SHA-256:DFA7D81FAC26A31642BE5845089E4570DB06350494161D8C3CCE07A258F192D9
                                                                                    SHA-512:215E35030175267D1F3DD9261D24634031F836028F9CF4F87C30B8C477B9008C7F8BEDF0355BBAD8005BA41CB6615FAC4A06031FE2CC74EF9CD7DA039D609B34
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ....................................@.................................h)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......\%............... ......P ......................................4".. .M....1(.gwP...F7...r.....<._.....<...X.>..V............h.*5e..yy.b.$nTI..m|H....|.y.)m.@@..;.[>..4.R}......:..0..u.G5...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4521669022409402
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzX4sajEfqNvjJmbfsGzFCJ2YO:WlviGlPu4sxz1FwY
                                                                                    MD5:DC0C6E7BB0B0B3AADE82340128415535
                                                                                    SHA1:A073D7CAABC0FBDE5E5A0508DBD8343DCDE12E17
                                                                                    SHA-256:C7656AA7D2A6A74B2EE5C5727B7F15C597B4C4D736331C9AB80EFE220F00FC86
                                                                                    SHA-512:A81E228105E84898F7CD1BA2E1C06AE9E0B8951B12A662000593B0FB29748C46C254E826EB6A3EF528B5278C665F5F08ACBD29AA65DA0AAA6E784C42CE3CB512
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.60500006591566
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b1lHq9fRzjMlIm2FmollPqNKS2pxsrIeEjPqXp2qwz2/UbGp0JJ2Y:+/s5XM2lPm2mxlBZq
                                                                                    MD5:0FD00B3821011A7323CC2B230145FE50
                                                                                    SHA1:C1AFAEFC985099E8A36BBA935D652B880B80266B
                                                                                    SHA-256:75FE8CF182A0BC65CC3DF60155837528520492CF3290F3F5BDF839DB813CA62E
                                                                                    SHA-512:61B5C7C2B9F8A22676190885C0617F10377D26926421F6C45CACD64EE0593F791C58EB31D3D0D0DCEEEB301C94365D373144FEC33EE2095088CFED67BBFA5601
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H.......|$..............P ..+...........................................'..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7776738283051285
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:I8AYPYnaPwxxDCPfW8lt4qlP+PI8cOnwa:I8zhlSqtW
                                                                                    MD5:6C9DFD2C4C06705A883EEEBA02082EB3
                                                                                    SHA1:A485F416392C110D07E4400E7E9B81ADEF643C06
                                                                                    SHA-256:7BA3309A9C01F9A58233747226199CC5A3A9BB1AED3BFCDDF3B6B232C9532AF1
                                                                                    SHA-512:7B609A239532903B6E503B3B5DB138CD667B1ABEC9D89F59590664DCFBF70ABFB38926A6D429242F5355B988E0F65AB239AA4038D0AD05410C2A2BD777CB2F24
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@.................................x+..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..:...........................................6..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.468979119248313
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6OVHy+HdyApEwW80n5mRz9kwBlPq02pxQVVTjPqlF8yge2wDGpQBJ2Y:Lk+9yA6wW80W7lPR2mVYm5o
                                                                                    MD5:C4A98A773ED1610B6F8BC7C3E4A4CC9E
                                                                                    SHA1:88FDC429F7AE44A4B5E98DED1FFE176B8EDDE244
                                                                                    SHA-256:BE2BFF39EB37BB9B7890EA0640A575C96A70CC719E1F82FDF35C85B7D3AF09CD
                                                                                    SHA-512:A97E7E2A86E3E71D3310081E031708C2C07F27AC768E196CA6D1862339EBB6E1E61402C8F9F6CE67C742BBC033B4A88FBB039966D603F81ABD7F6FC415287C1F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................@(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.......L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.143460124442194
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:yfCwJauW0EV5VM0n9i9Yh79l995+GA+xMZ5Ujy4F:yCt7M09PfrMijy4F
                                                                                    MD5:D32E8B47309DB3A9CF5F6E657A2FBCBD
                                                                                    SHA1:1AB440F02D1130542AB87FF4523DA2C650892E06
                                                                                    SHA-256:11EDA09B2ED6671B52268AFAEB9C40BA771A5F4FCB7029270CF85776BA966203
                                                                                    SHA-512:32122F989291DA0E1B5907931E870AAF4F8CCE1EFFAB3EB9BF3AAB6EE29CC28BB44269A9FF009218CB524C60B532CF0F123BD3A436C5812E792657A97A25E8F2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........N... ...`....... ....................................@..................................N..W....`............................................................................... ............... ..H............text........ ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H........J..............P ..z*..........................................v*.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):30720
                                                                                    Entropy (8bit):4.188502209597651
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:cHpLDVuCN4IKCmemLt+DzNmxScA8ZRaIHYXOByV7Lbi4F:cHpLDVuCN4IKbemLtbA8ZRamYXJV7L1
                                                                                    MD5:F319D728E37C82821DCEE673180B8BC7
                                                                                    SHA1:03F7CB4EEC20A04420B610AA54D721669D7C9091
                                                                                    SHA-256:93F5FE155661395B4CE9E2781EFF6478A910BB258026A6BE841708B9B70B97C3
                                                                                    SHA-512:10F370AFC4793D8189CCA6BE49AF4FCF1F336B793336245C7ADE73E15910EB56E32C52385AE03FFEA670969B7062FBA6FF488F9FBF1321526DF94C16CAC135A0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....n............... ........... ....................................@.................................p...K.................................................................................... ............... ..H............text....l... ...n.................. ..`.rsrc................p..............@..@.reloc...............v..............@..B........................H.......................P ..Mh..........................................Ih.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.699670159881912
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:7XmayKwgyyXYHuNo9XrLXqLo8lPLNoeQr:7X8gVX+uNo9XPXqvXoeQ
                                                                                    MD5:AD12271A5A1D6CC30985517116091CC0
                                                                                    SHA1:D09B96C5DE05D643FFCA973226DEC15E8924244F
                                                                                    SHA-256:35946298511CB617ED9B977F599F4A9AE30BB4E7C47DF5C7C93A039CA4A02279
                                                                                    SHA-512:8BB45D1E07E68B325474B2EF16BA3CD76A6A3C8ABC1C977E7D773A7195723B29346C8621789D5ABCD2117878946F5A127F27CDD4A845314274680B03B5B07354
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..S....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......,'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835094194750168
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHUJn:CuQiS0Mw+f+Sb+jkyNr1rmWn
                                                                                    MD5:B4CC4CBFAB9F3613FCB254C6309D7804
                                                                                    SHA1:1C2BC7716B222EA704B23C005F3797DF8FC07151
                                                                                    SHA-256:FDE9F88C107BC8BDDF7030D314DD1D2068D5511A573EB240417202C8E650CC81
                                                                                    SHA-512:049ABEFD59DA8F38C7BFA9C9939141945AC1F9881765E6025B49CBD50D64016024EBF48D7BD0442190597155A1D85E8DC63E0CCD05E4ADFA3F83789312BF97DD
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5535212934107925
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6mcu8rHer9UloNaC+xU39nlPqWZlx/XzqR1sMSjsqNvYJmwfnGzF1J2Y:MJ+reluPQU39nlPmR1sNg6Fr
                                                                                    MD5:B55C4D3ECA32B431E1104DF347D0E683
                                                                                    SHA1:40D0D26E0514392590E06EF544B1B8CD3350A7B2
                                                                                    SHA-256:DFD078EEB8C2D45DD6A916EC172004EF168923095C8BB48D173D5B1FF6D0767C
                                                                                    SHA-512:8152D5247FEB3C8BD22E74457CB1B1525D3BEC06620D3BE9300ECF9C73E81CF08A0DA3E8735B8B74230FB05D76009C0D52DEDA432EF1B8D48BD16CB247F04080
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................^'... ...@....... ....................................@..................................'..W....@.......................`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@'......H.......<#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6601952679288634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6kT9HECSlV7geg96g7jgr8vE3clHa1TOnFRaIelPqWZlx/5zY+sljJqNvOJmmf9Y:t9k3zsN9R70wvEMa+uTlP++ssmkFh
                                                                                    MD5:ED8948368E4EBEF017932592C8FE57F8
                                                                                    SHA1:4042437FC83640E3225944F94A182FC4DA2CF46E
                                                                                    SHA-256:7976684E575C3DA819992A0F9A919F247D7A6A3C3632A924E7D143AFC319FF0E
                                                                                    SHA-512:FFABF67266F0885438F842BFCA26B024803832BA69DF34812997291E7E1A8F7ACC82A15E7E987DA23233E9EF0632F93F15D2EFA956AE53BC28A3D8A11559339A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................*... ...@....... ....................................@..................................*..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H........&..............P ..h...........................................d..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6065454885539276
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E8ZfH2d56R2QlA1gFzFaFK1FMMjVruulPqWZlx/4zRPnscjMqNvFJm9fWGzFwJV:GZfWd5KlKyzVruulPOPnsDFzFS
                                                                                    MD5:709255BA86311DACF9FE3AA96CDB764B
                                                                                    SHA1:4BBE7381E046DD90A8F2506A0801EB480E76635A
                                                                                    SHA-256:2F2423C37BAF396563C4CC47C1491D0AB30AA8AF2B71EB10C5A0E941C9070B3A
                                                                                    SHA-512:3DCD7D24D3C3B14819B27C130B7437EE83C3225CA4A1B32E77B1840DD783E607A625A8423CD60AFAF999BC0E4C45B798C5279DF482BD36E9824B0B47BBF11623
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..I...........................................E..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5662559985732036
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxeHt1G5JlQ/HQ//aPYYo/lPqfzx/rzeloIfujsqN0gyF/GtpJ2Y:QkNUlQHQ/qy/lPwoqUxmX
                                                                                    MD5:EF451779C2BDA793A6390BC38E9EB34F
                                                                                    SHA1:AB2887F98FDCD68B1D2DA245C41BD7D3DA1101EE
                                                                                    SHA-256:FD2F0691B4EAB9695F3F83AD47619CC861EDC72D1EF28A3D8E479B32B7096994
                                                                                    SHA-512:D6273CE8524084B7737B1FDFDEE3E0B7BCA053026C1A885B87C91ABB2670FA18A42B48EE1D8CE118A0033493E89E6AB79D195DC97266559597A84C5AD0B4EAEC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................D'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..U...........................................Q..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.786140605383779
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6pyHpQUFezFKIlTM6lIOEOzOlyGAKu5tdHSFy4lPqLx/zzm5jaQqcF7JPWSG3RWo:zJRFezFKIgOEOzOcGluNH4lP7A5
                                                                                    MD5:D7D6A04DFF0CD58FC0A40EB9AC632FAE
                                                                                    SHA1:B7B683FCA0A8745C06AC1760822DF471967A9FAA
                                                                                    SHA-256:40A31456DA57EBD0BF1DE7FFA03ECFBEFA624853A2B4F3442061A64E6F36D765
                                                                                    SHA-512:FB30C65BCC9A1A9A09010BF701DB17A99223F6B04828999C1262058E9AE1B9E9ED9C46E6297305AF8DBDCBD2303026D1093246F7640ED24A8C86CA8AE8ECA356
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................X+..S....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..Y...........................................U..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.124706156241719
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:V2npMuAyAHendmVeVPVqVSFkb3XoJUycJ:VvZAdmAlYIFkLFyo
                                                                                    MD5:21F3F29C689AAE23376ECEABDE463EB5
                                                                                    SHA1:7E19912A38EBC4D3189C028E76611CA4BCB6DD79
                                                                                    SHA-256:939C8238C3CF20D94B3EB5A2ADF3FBAD17C2839919758BE43051BCA2975FD0CC
                                                                                    SHA-512:D493FF3EF9597ACA24691893BAA8FA705349772818A2E1CCD81278E0824A0CED0F712AE1F82F574C1E5867878B4A79AEA9A7F96A4974BE6712C0348CEF845332
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................9... ...@....... ....................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H.......\6..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):4.007462076109497
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:KB5nPluBuJv/ck5wwAaoR5JzQ+f3m/mjc3vJedenoksk3TwYoX5w6rvXEw5uMXyL:KbqdBtNfFY/yODli4dffpOjVVVVm4
                                                                                    MD5:0D1501560F4C0F41860E76F3F5B74B59
                                                                                    SHA1:B8797909B0BD90B2756A05DEAB85C63594C8B5B1
                                                                                    SHA-256:920C0762603F014FD80868D0DD29AF526867BD06E037C38D5E44263F4BE13B93
                                                                                    SHA-512:366A4DC5E17BFF06E99F02B761E8E8ADEE5B21778971C2C3431757FED0BBA9EBFFA0424398CD043040CE5FE30BFAFC787E0FD28E2EF53F7443AF5A04389E946F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....*..........NI... ...`....... ....................................@..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................0I......H.......TE..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.721606779468658
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:oYOtEDDvdMRFnZWtYbYzm24kC/dDMQZTMzxlPwyKDj:oYOy2ZWxE
                                                                                    MD5:BC14789692741C5B5BFF2BDC5929CEDA
                                                                                    SHA1:CD1982FA66827AA7B4413D7A25F85467CED0D53A
                                                                                    SHA-256:CE02FACC1F26555511E8CEBFDE1867C108D25EB3FE109A8318C09D031291A427
                                                                                    SHA-512:603DEA7111CDCFA0B6C9CF15A6C3D657D88188F7B7A558910186399170581BE8F89A8C88F5FEF7EBB02A5E491E02C448B3043D0FADBB9ACBD4EF2AC03BDAA822
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!.................1... ...@....... ....................................@..................................0..W....@..h....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B.................0......H....... -..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3295946971418413
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6dxHNoD/q0lPqVx/uzD5pjnqtE8+6GzaJ2Y:4toD/rlPt534
                                                                                    MD5:A8E964993A3D509AAAD234B709D52E23
                                                                                    SHA1:9D368FF3FFDC0F632A6246D728C9798D9E5B0EA0
                                                                                    SHA-256:65E5AA290E5E6C8401B251B43F3B5F7B4EF18EE83EAFE8D5E2E300F578CC692B
                                                                                    SHA-512:9191254E9DAD3CF1CDE4202627BF444CC488FC932EAAC1B5E9401C8634C91D42B1E9F0F216DCEE6DA3F6905E7438B0E05CEEDB3433D1F2C7269DD727505E04F9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................4&..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......t"..............P ..!..........................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.767046359489489
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6go6olXKH23S+lvzexlN7Ea/DlPq+LDJIRhj3vgIU1WyoFp/98P28s9JJ2L:tuKW3W//DlPNCfj3YG7T3
                                                                                    MD5:3A3AF6CDBD99FA1C777CBF9BD36D1E69
                                                                                    SHA1:20E09FE02F7101FCA45442DB2D3D1836FB75A29F
                                                                                    SHA-256:2C2C12760C8410DABD37BC9838ADD8B5EE974F7DA0B6137D3053FE4814BE1C14
                                                                                    SHA-512:CFF1E25A2E88920108C882348FC6EA7B2884294A155DD3181EFB247B3C668B9B752801DF43B5D9C59F380E9C5D6C5DCD86FFCC952AFB2F95BCD194D5775C1ABA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ....................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................jQ.D..qA.N..3F.%<hy.m...1B<.,.+.)Q.5.W"./.P4`.H.....e...H...g.........YK...h..\........f1.Y..7.L7......n"s...<#.a.8.d.C................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.70864786784634
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6w8LHo6cs+EcWCc1SLcQdcOcJLcdrc7oc0c3ypcrlmczcqcKcPcSYcfApc5cFkYu:61q8GY8OggpIgQpHnlPgw03Itd0K
                                                                                    MD5:E94CDDA083208AF1EE2BBC71136E711E
                                                                                    SHA1:268E1031AE9F3D6F9D6DFB250651C8CA7B43A133
                                                                                    SHA-256:53BDA1D8FD445D0A603CFF91AB244B27BA1B7A37FEF1541499617D3A30998987
                                                                                    SHA-512:2709966E7D8FC95298DB0E42098E19427D4A0DAE4161A59F67B2F19BCA708CC0F218964DE00A684DE3A020F3A93FB96E8BE3E12DFBFB60098CDFED85DC68BCC7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!.................0... ...@....... ....................................@................................../..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........+..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146478
                                                                                    Entropy (8bit):5.022669204701854
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YHhUfGiw9Xw/8hqRk3cPO0rb8ZZHPkbBO9E7//CB:wkGiwl+8YqM//CB
                                                                                    MD5:E78740BBABACCBEDDB3B10985D7E4C50
                                                                                    SHA1:EFC947D5BAE52C80D3B7D48368A637B2F1F66398
                                                                                    SHA-256:8EC64246EFB29D7D7F48FB7DAA700AF486E952BAC0AE13F8916B00977D3996C5
                                                                                    SHA-512:521229F993BDF612D58BEBF2B545C2E2CDA488A07BCFD953A09DD6B5340304A2B09D1E3AA5BF11EBB276613262718F8425AEF9066E04FC180DE3323CF1E83228
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.611718739849792
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:61QHcAI/PI/Fw/LbLKLMOcVDOcJPfDu+qKflPqAxXxrjQ/I4jsqwIA9oqTxg+G/T:h8AYPYFgH2A1DpPfy+jlPRCIccOnwa
                                                                                    MD5:432AE46FB1FF650ACD3618337FE6C087
                                                                                    SHA1:A324BAABAC5780B940E5698E59FAEA7906BEE124
                                                                                    SHA-256:D93CC7FCC531AD750259B93D83B0830AAB1AE24F52ABA11588288DD7D237E8CA
                                                                                    SHA-512:DD882632FAD281D7480532D6751085E170B6B6A446FAAFE5A4AC99352B83DB8835B6866E6941360193F6A3F6A4058AA317FDA11038D924B5729A1BD449D51AF9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..S....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7206804459236347
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gDeHwml8jiKazjaOikAKi98ZGXIxcytvdVQdXuKcdXDzvjkmlPqbxX6r0lbjSQD:8XmayKpiykXYcy/4Xr6X/vLlPIyoeQr
                                                                                    MD5:298968842797555AA432A2D3A022C1D2
                                                                                    SHA1:DDCEB8B79A5AAC29FF48E309B0997FA571657008
                                                                                    SHA-256:A8BD5FC80F169CE8EBB3F857C4AB321D3F4BF9E10882AFCDE52ED7ECA4E4EEC3
                                                                                    SHA-512:AAED7D391AA58A5C46F8AE9235E0C7FD8E248A88CD4BE976B46F79FFE99A19BD33EC373A07C95CE16BE540DC24B82BD0128A7048CD5A5713383687616DB1CB0B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................+..K....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......4'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.788413097425715
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6y61Ho6cs+EcWrccLcQQ5cjcSSLcdIc77cAc5pc7c7cxCcpcycSKcfAtcpkcFGbN:fS13lI4Syk1XzlLelPgw0c7DdfK
                                                                                    MD5:68BF2BF6E62E6A0B2D6E162FB71C2245
                                                                                    SHA1:B74FB50E88F17B9061F93E8B35845A45519E9AF0
                                                                                    SHA-256:DC99CA534224B7DF3EFA7CBEE89D03F0A50B3FD876A6CD1523631954B5D7F4A2
                                                                                    SHA-512:8B72E256FC728CF3D22AEA450D656E43C089AD5AE0908E78DC7644D5140DBB265395BFD7E9B9D2C04AC1A508053FE6A64650DF0599B3664D8E3A1B50457A8104
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................~0... ...@....... ....................................@.................................(0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`0......H.......\,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6288370455300125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9++Hq9AuzjlGE+SClPllPqNKS2pxsrIxmGjLqXp2qwz2/UbGp0JJ2Y:+Q+s3XlgRXlPm2pKlBZq
                                                                                    MD5:156E34CED576F9B4B136C6EBC7AA7831
                                                                                    SHA1:583F0A05839B89ED53073EA892948376D15DA069
                                                                                    SHA-256:81A8AE83F074304FB4905F1CD654731563008010629519A8E78BD033C34B8C62
                                                                                    SHA-512:1F3ACF3C5BBF1FC3B861EBD7F1815EE3FD6D01AF6FC2568B3930FED6B85E47EF2ADE84AD69697A9E77FFBC2A4B85E15458A9A477435F61649E6A88DF64C86A56
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................T(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.8364774248255165
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHZJn:CuQiS0Mw+f+Sb+jkyNr1rmrn
                                                                                    MD5:C0434225FC69573BA3E3F54511928EB1
                                                                                    SHA1:737C15B8477F08B918BD1C06084486F9D0FDFF85
                                                                                    SHA-256:9D97823F29E25D87BB288B5C043BB63D2016D44AE8BE163248A8B1DF3FCBF97A
                                                                                    SHA-512:C52A443AF2BE85E0E47C2B368AFFAB506B0E9053C593429E9ACE31A650901926EBD2449E98CA1423178297D61F608C4137559B93CFC4EF8AA560BB29EE8F473D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.5147445310100505
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6OVZNlHdyvp1PgWhtOodOBlPq02pxQarWj3qlF8yge2wDGpQBJ2Y:LH/9yvrPgWhtHOlPR2pXm5o
                                                                                    MD5:9D47FFCDFA16EF041A0EA61186A38F00
                                                                                    SHA1:2BA1B64C36F09B0E8CDA76D0E2FDF7E6FDE62CCC
                                                                                    SHA-256:73F506195B2781A68E61977CC2CD6F4F41507785CADD45B5C2B8DBD87F51AF3A
                                                                                    SHA-512:001989A97090A384473B81E37DE90C61B369330548AF7A86E8A992E6F43CDF85449BA0C7A4E54D3E42E1E93E5F2E1A60AD71FDE28BC663B92639090B26472D60
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................h(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..f...........................................b..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.#.....L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.715860235049701
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6YV2rH2HpSp6p6EB+iXPm9h/CXEBlvlPqox1TsjQq4o4wmHDvSGEpJ2Y:hArWHpSp6p6EB5XUk+llPhXgX
                                                                                    MD5:F42130CF13E9B7ABB4B50D6EEC72BCB8
                                                                                    SHA1:A752B81C89E32DBB8E3A139DD108BB544BDF3802
                                                                                    SHA-256:A0B1C4AF9E00F88CFA45A0BCB1F371AC9564F59D1131F2794EF7659976A13B87
                                                                                    SHA-512:0FE93F33D12CF467CE21A4A43D118A5CA679BCA3960D0272F568997B5FE34CDBB55AB1289EF76517695E91C5DCE90ECCF9F56789BF02E853005EF21AA16399B6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................<)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p)......H.......x%..............P ..%...........................................!..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):3.9950788719370136
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1B5nPl+RjC8jZh7J/XioJSi9lTmRcmCiCpHFdeto3mOACdkyn58Z6UQ21hM5HWWN:1xQwcV7IHN8Ad7l
                                                                                    MD5:2DBBDDDAC0F761B1B1E3F3058A3CD877
                                                                                    SHA1:747508C8AAFC4CE0A57A5F912EC574AC15CF1AB9
                                                                                    SHA-256:F4B60A93D1261CEC92F792E9983D44C01F8977B1C8E2CF975D2A85C32DD8AA96
                                                                                    SHA-512:B37678E42EB281D811F9DC03860AF50724C940ACB3321351F6B8D0482988A46AB02FF483FCE287AC00BDDE7278E4974D417521583F3399D9E5E5BCC15555E2C8
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................I..W....`............................................................................... ............... ..H............text...$*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.798856573078593
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6pCHpQUFezLWsXMzlNOfOP+OlD9BkFdHS0kolPqLx/zzptjWwqcF7JPWSG3RWMJV:rJRFezLWsKOfOmOZ9BOBkolPYo5
                                                                                    MD5:1BEBB406C4BBB002D333CC67DC0BEA99
                                                                                    SHA1:0523E3D8BC5179167CDB23C106775CF9659C60C4
                                                                                    SHA-256:761B113E97CA0E73CF11A07FEEF6BCA815BB8698B509F5EE46AE5F22172BA157
                                                                                    SHA-512:E20AE347B5B13A73D07B3E9D76B076F6D4900788A30967640CA776DAFBB08C4C6E853B7FF3B32E8194883452892A1818E0724C79F79B9A59B66167DD45D956D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................\+..O....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..^...........................................Z..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.338123317829017
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6d1HNoyKlPqVx/uzQDpjnqtE8+6GzaJ2Y:ctoyKlPCD34
                                                                                    MD5:011259AF019FC1519CCA0890D104E896
                                                                                    SHA1:D1248797C002076BA28EB062169CC4361931840F
                                                                                    SHA-256:23FC6A41A20BD76E7DE9A3FF6E275F80DC5761C58C137C541CF3F133F507F7A1
                                                                                    SHA-512:5F0B5BF3CFB9F73686F4211FEE335984404BFF253F9C3A791FD5DD36CE3BA86B2CBE776644ED3A93AADD5997F336B9EBED8830AB4A709B8BDFA13933F050DC70
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................4&..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......t"..............P ..$........................................... ..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6119235571667456
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxiHt1G56lQ/LQ/9TI1QVqklPqfzx/rzxdfujMqN0gyF/GtpJ2Y:QwN7lQLQxxRlPwrlRmX
                                                                                    MD5:7C3828051EF232CE7A7008761E2E43ED
                                                                                    SHA1:7F5184F2EED971864E3E70FD65E866BF496A521D
                                                                                    SHA-256:D41578EFD4933AEA3761B52438BD61DEB1FC73A5B774F5EE0EADD1CA579A366F
                                                                                    SHA-512:A197CFE4D9D437EFCAF5BBDE5F62584CB76EC6DC4CD7FA7371FA65ED34DFB0E225311A7768CC25BA14CCBB1DD043EBE7293918F05FA63841D4C07B9EBCB7DC8A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..w...........................................s..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.795961986609238
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:AYOtExuqOg6njYBYCYzLP+qkTz8lPw98ij:AYOHa8o
                                                                                    MD5:DCA2BED49B1A3FE2BC94DC1F9B457115
                                                                                    SHA1:9DD240710FE7341BF3A6508782E95C7C437EA5E1
                                                                                    SHA-256:165AF3A1EBD2D461F03AD17521ED4692FA992A8227BD4F243BF764A2C20ABCA8
                                                                                    SHA-512:8FD6D205E71253896DDDDB59706DE39FE2459ABB9AE61BD887D8CC14936782A39BFBC259DA67C4AECD827E76824E67BA7F6B93E7F23D56CB3904B55FE8144B58
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.248676169905017
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:KXevAvrpeKhCC7iZtd583aXdQDAzgcUVfoDR26lGoi4F:KXevAvrpeKhCC7iZJQDAzZUqDR2KGy
                                                                                    MD5:78F530549A9B08FAC034E3C17C605CDC
                                                                                    SHA1:009A6C19DA97C876972FCD606C130977104E23F6
                                                                                    SHA-256:27A9E20945B809BA232D224E2780121ADCFBF1F79C8A33769548431C6C764245
                                                                                    SHA-512:D14BD1A9DE877ED2680EEE35DEADEF526D71FB19E51DF1BE7A4E5AEA3623CC9FFA3DC56C3594D2AF9299A2C41F3ABE7D982177EF3DC392229D3152E9DA993C7F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p............... ........... ....................................@....................................K.................................................................................... ............... ..H............text...$o... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B........................H.......................P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.255508847021893
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:XhfCwdJxwBbVJVv/y9c9fM9p9u/glhm0pGxowCLE/Ky4F:RFUrv/z0hmvFC2Ky4F
                                                                                    MD5:C938F461B4371F4D0FAAC0D6609A4896
                                                                                    SHA1:A8BD1E1CA4D9DE1D69A8D53D4B499459D0C7ED15
                                                                                    SHA-256:49E99FB91C99A872581DF20E212B53D08B205FF58CBBD233C573CCB909B51CE0
                                                                                    SHA-512:79666A3D7A31BA6C1C6A1B18898C960839F46EE97015FD070F1DF255C700D726F2F4945284AFA12232CE12F224245D54067495BF52727AB6FE253421E0A2EC0A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........O... ...`....... ....................................@..................................O..K....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................O......H........K..............P ..w+..........................................s+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.620871473179559
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6kkVH2d56R2QlA1pFJFEFK/F0gMx6DlPqWZlx/4z+iscjUqNvFJm9fWGzFwJ2Y:uVWd5KlKt9DlPBisLFzFS
                                                                                    MD5:D62469F33BEECDE93B4754BA6ABA41F3
                                                                                    SHA1:EDCCD90D97DCD538F503BBF425085E3E13C90AA0
                                                                                    SHA-256:62142BD9128779BDF1AC2EF8E95A562BF16C044741CB5235C7570E1B71F7E9BB
                                                                                    SHA-512:19388534442C81CE275B07899CA85EE6BFA5C5BB499B3F1585424F1E2BD13BFBAC4153A8EBA2BB689DE5A002936707BD78CDFBF32C6DE6F92FA9FCE5AEBF507F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................l'..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..T...........................................P..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5671350269277853
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:62EpHer9UloNaC+xU3t4elPqWZlx/XzFY1sMSj0qNvYJmwfnGzF1J2Y:Up+reluPQU3GelPpY1s1g6Fr
                                                                                    MD5:1ACB4D26B23CDF16672E831E0D2BBA9A
                                                                                    SHA1:F359B7599A71059643FC3630E2551B1070702D90
                                                                                    SHA-256:6FB7D1A92C5F7EA6EC76A2E321E31A307C4B09A231BA0DF6FCD6EB14B37549A7
                                                                                    SHA-512:56AA33CD21E33A78E1C24CD4ED1663F838B1AAEC45B91BF49AD41D65B5CA2866E42DD2A2A2682EBCB12F05C065CC1666A101005F9DA72CC0E71B0748E3AF26C0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................^'... ...@....... ....................................@..................................'..O....@.......................`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@'......H.......D#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.452456536559997
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/Sz8ZsajEfqNvjJmbfsGzFCJ2YO:WlviGlPhZsxz1FwY
                                                                                    MD5:D875701E12C3C1370397760702EF1AD9
                                                                                    SHA1:96904311F06A3E275E09CB8A76448C1A6BE570D3
                                                                                    SHA-256:F5D7A8EBBA5D706659EF6779D1769F4BC4D411E8C01F990FA9467457A0D3AF74
                                                                                    SHA-512:8B0378B5D8FB864D9387A511350C4E2590912F6959F55DFF3144B2B2506649C37543DC14CB9B41AE49950697782EA707E9A2D5992F34ADECE55376EB8EB884BC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.737823800304287
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:x9k3zsN9fi7iAMKAtw1VKxlPRi8sYmkFh:7WzKz1xP/mkF
                                                                                    MD5:4E46395CE469EED7E35E6FC5FAE71C66
                                                                                    SHA1:2A613592FB2D89BF6A152A1181C04170F41486CC
                                                                                    SHA-256:3FD6F5D90D0CEDEB0D6EF0D7695D071C2D27E1596A229318EB93FEC193B578CC
                                                                                    SHA-512:AF255BFB716D23B3AE67148B2F523B524846CDDD52747DFD84DC916C951A122D14E7BB35BF5CDD54B856D8EA8A8BA57BBEDCAD424D6C5DA1FF7F2CA2889FC5FB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..O....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3391623480925063
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/xvsrjL/qNvcJm0fDGzFBJ2Ye:gNClPZvsykWFfI
                                                                                    MD5:FB5415E738152536EE53A0D36CC8BDB2
                                                                                    SHA1:139CBB433D29DFF9929AF5657D13C55856C31CB9
                                                                                    SHA-256:8472EDDC1CC9E63DBD1B06ACDEF43F9A5DD4AB550CD51F10C09983FAFF069245
                                                                                    SHA-512:B89E0295CED95950040CD1D44796ABFC057F83CC3592F70781E820B60CEF18E42C4F98E7B230599B0F097C191770823C24B085756C3033E1DBA962C253587AC3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.251113891221509
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:b2nqcsAzAzltEvlVvVtVXVvT1SFLFwcsLjLreKm:bSE3EvlNXt1T1SFLmccjWF
                                                                                    MD5:4F42D0E6AC0D91BBF16A658CDD2EB345
                                                                                    SHA1:4BA06EEBC69B664FAC12773E59C6CFEBE81A5950
                                                                                    SHA-256:78F3203B702C28F112F3E0D4B771D55F6CC9257114CB708A99B4F6784F4D52B1
                                                                                    SHA-512:A7A8EC320761F91DD61BD25E590F1513F09313AA477330028EF1F0B79E3E51768326229BA5FDE52D75721FF6EA1CE31D99079D5BF23A3F844301763F8644C2A1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......87..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7725614852658125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gEd5lhH23S+lvgexlk7OaMoklPq+LDJnWhj3vgIU1WyoFp/98P28s9JJ2L:tslhW39oQlPNRij3YG7T3
                                                                                    MD5:7D02D631A76EB6668A1F2C53EC39ECB0
                                                                                    SHA1:AEA9A149D324AA931C0DABB5825E7B517619E11D
                                                                                    SHA-256:CEC8007F6DF984001F09942E5D46B9A02B51B759DBC09B3528395B8B0FF59A46
                                                                                    SHA-512:A063989662D3A844DC5AE62973E8CA273B59B625AC58F547B18D74262644C3061D4370B63D495784E545DCECA3760D2A7C154CC30FC7DCDE8985C05BA800FC51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...............................U....@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v..[I.F.q-...9?e...-...HK..&.....*.... ..X..'..$r..o....[`.x.i.2....Tx..........o..,..F.........>....%FJ....$E..3....m...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.110286419307638
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CxCqGWt134Gw567aYElclPNcZjLOBlZsKJ:TVWBGYESa+g
                                                                                    MD5:D64865F67DA8E3BABEF95DB7C459BE59
                                                                                    SHA1:C3069A7007DE5914F2E1D51BC10F0B8C555FB66C
                                                                                    SHA-256:9860CC9C7D3E29C060A6AAFADA2C33C6758EE71B3B0A193E4EB78AB026CA55B2
                                                                                    SHA-512:FE0ED73CF65084283ECC6BE676C332DF19A60D43D8C4E3FAD7C003F0218E9A6BFA87280E1D69D4C1B94E8DCB0420995338CA2FD2D1E05FDB2FF863FDCD979733
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................*_....@.................................x)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......l%............... ......P .........................................o.w............A...ei..^x./E6....&.6%.Vw..0......Z...a.......WEi.G.7\......M..5.5..:.......fm...(E4.6g.T.9.c...v.+...a9................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):3.611718739849792
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:61QHcAI/PI/Fw/LbLKLMOcVDOcJPfDu+qKflPqAxXxrjQ/I4jsqwIA9oqTxg+G/T:h8AYPYFgH2A1DpPfy+jlPRCIccOnwa
                                                                                    MD5:432AE46FB1FF650ACD3618337FE6C087
                                                                                    SHA1:A324BAABAC5780B940E5698E59FAEA7906BEE124
                                                                                    SHA-256:D93CC7FCC531AD750259B93D83B0830AAB1AE24F52ABA11588288DD7D237E8CA
                                                                                    SHA-512:DD882632FAD281D7480532D6751085E170B6B6A446FAAFE5A4AC99352B83DB8835B6866E6941360193F6A3F6A4058AA317FDA11038D924B5729A1BD449D51AF9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................,... ...@....... ....................................@..................................+..S....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.3391623480925063
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/xvsrjL/qNvcJm0fDGzFBJ2Ye:gNClPZvsykWFfI
                                                                                    MD5:FB5415E738152536EE53A0D36CC8BDB2
                                                                                    SHA1:139CBB433D29DFF9929AF5657D13C55856C31CB9
                                                                                    SHA-256:8472EDDC1CC9E63DBD1B06ACDEF43F9A5DD4AB550CD51F10C09983FAFF069245
                                                                                    SHA-512:B89E0295CED95950040CD1D44796ABFC057F83CC3592F70781E820B60CEF18E42C4F98E7B230599B0F097C191770823C24B085756C3033E1DBA962C253587AC3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.248676169905017
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:KXevAvrpeKhCC7iZtd583aXdQDAzgcUVfoDR26lGoi4F:KXevAvrpeKhCC7iZJQDAzZUqDR2KGy
                                                                                    MD5:78F530549A9B08FAC034E3C17C605CDC
                                                                                    SHA1:009A6C19DA97C876972FCD606C130977104E23F6
                                                                                    SHA-256:27A9E20945B809BA232D224E2780121ADCFBF1F79C8A33769548431C6C764245
                                                                                    SHA-512:D14BD1A9DE877ED2680EEE35DEADEF526D71FB19E51DF1BE7A4E5AEA3623CC9FFA3DC56C3594D2AF9299A2C41F3ABE7D982177EF3DC392229D3152E9DA993C7F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p............... ........... ....................................@....................................K.................................................................................... ............... ..H............text...$o... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B........................H.......................P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.8364774248255165
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mHZJn:CuQiS0Mw+f+Sb+jkyNr1rmrn
                                                                                    MD5:C0434225FC69573BA3E3F54511928EB1
                                                                                    SHA1:737C15B8477F08B918BD1C06084486F9D0FDFF85
                                                                                    SHA-256:9D97823F29E25D87BB288B5C043BB63D2016D44AE8BE163248A8B1DF3FCBF97A
                                                                                    SHA-512:C52A443AF2BE85E0E47C2B368AFFAB506B0E9053C593429E9ACE31A650901926EBD2449E98CA1423178297D61F608C4137559B93CFC4EF8AA560BB29EE8F473D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5671350269277853
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:62EpHer9UloNaC+xU3t4elPqWZlx/XzFY1sMSj0qNvYJmwfnGzF1J2Y:Up+reluPQU3GelPpY1s1g6Fr
                                                                                    MD5:1ACB4D26B23CDF16672E831E0D2BBA9A
                                                                                    SHA1:F359B7599A71059643FC3630E2551B1070702D90
                                                                                    SHA-256:6FB7D1A92C5F7EA6EC76A2E321E31A307C4B09A231BA0DF6FCD6EB14B37549A7
                                                                                    SHA-512:56AA33CD21E33A78E1C24CD4ED1663F838B1AAEC45B91BF49AD41D65B5CA2866E42DD2A2A2682EBCB12F05C065CC1666A101005F9DA72CC0E71B0748E3AF26C0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................^'... ...@....... ....................................@..................................'..O....@.......................`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................@'......H.......D#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7206804459236347
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gDeHwml8jiKazjaOikAKi98ZGXIxcytvdVQdXuKcdXDzvjkmlPqbxX6r0lbjSQD:8XmayKpiykXYcy/4Xr6X/vLlPIyoeQr
                                                                                    MD5:298968842797555AA432A2D3A022C1D2
                                                                                    SHA1:DDCEB8B79A5AAC29FF48E309B0997FA571657008
                                                                                    SHA-256:A8BD5FC80F169CE8EBB3F857C4AB321D3F4BF9E10882AFCDE52ED7ECA4E4EEC3
                                                                                    SHA-512:AAED7D391AA58A5C46F8AE9235E0C7FD8E248A88CD4BE976B46F79FFE99A19BD33EC373A07C95CE16BE540DC24B82BD0128A7048CD5A5713383687616DB1CB0B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................+..K....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......4'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.795961986609238
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:AYOtExuqOg6njYBYCYzLP+qkTz8lPw98ij:AYOHa8o
                                                                                    MD5:DCA2BED49B1A3FE2BC94DC1F9B457115
                                                                                    SHA1:9DD240710FE7341BF3A6508782E95C7C437EA5E1
                                                                                    SHA-256:165AF3A1EBD2D461F03AD17521ED4692FA992A8227BD4F243BF764A2C20ABCA8
                                                                                    SHA-512:8FD6D205E71253896DDDDB59706DE39FE2459ABB9AE61BD887D8CC14936782A39BFBC259DA67C4AECD827E76824E67BA7F6B93E7F23D56CB3904B55FE8144B58
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................N1... ...@....... ....................................@..................................1..K....@..h....................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................01......H.......l-..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.737823800304287
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:x9k3zsN9fi7iAMKAtw1VKxlPRi8sYmkFh:7WzKz1xP/mkF
                                                                                    MD5:4E46395CE469EED7E35E6FC5FAE71C66
                                                                                    SHA1:2A613592FB2D89BF6A152A1181C04170F41486CC
                                                                                    SHA-256:3FD6F5D90D0CEDEB0D6EF0D7695D071C2D27E1596A229318EB93FEC193B578CC
                                                                                    SHA-512:AF255BFB716D23B3AE67148B2F523B524846CDDD52747DFD84DC916C951A122D14E7BB35BF5CDD54B856D8EA8A8BA57BBEDCAD424D6C5DA1FF7F2CA2889FC5FB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..O....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.6119235571667456
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxiHt1G56lQ/LQ/9TI1QVqklPqfzx/rzxdfujMqN0gyF/GtpJ2Y:QwN7lQLQxxRlPwrlRmX
                                                                                    MD5:7C3828051EF232CE7A7008761E2E43ED
                                                                                    SHA1:7F5184F2EED971864E3E70FD65E866BF496A521D
                                                                                    SHA-256:D41578EFD4933AEA3761B52438BD61DEB1FC73A5B774F5EE0EADD1CA579A366F
                                                                                    SHA-512:A197CFE4D9D437EFCAF5BBDE5F62584CB76EC6DC4CD7FA7371FA65ED34DFB0E225311A7768CC25BA14CCBB1DD043EBE7293918F05FA63841D4C07B9EBCB7DC8A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..w...........................................s..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.620871473179559
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6kkVH2d56R2QlA1pFJFEFK/F0gMx6DlPqWZlx/4z+iscjUqNvFJm9fWGzFwJ2Y:uVWd5KlKt9DlPBisLFzFS
                                                                                    MD5:D62469F33BEECDE93B4754BA6ABA41F3
                                                                                    SHA1:EDCCD90D97DCD538F503BBF425085E3E13C90AA0
                                                                                    SHA-256:62142BD9128779BDF1AC2EF8E95A562BF16C044741CB5235C7570E1B71F7E9BB
                                                                                    SHA-512:19388534442C81CE275B07899CA85EE6BFA5C5BB499B3F1585424F1E2BD13BFBAC4153A8EBA2BB689DE5A002936707BD78CDFBF32C6DE6F92FA9FCE5AEBF507F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................l'..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..T...........................................P..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.338123317829017
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6d1HNoyKlPqVx/uzQDpjnqtE8+6GzaJ2Y:ctoyKlPCD34
                                                                                    MD5:011259AF019FC1519CCA0890D104E896
                                                                                    SHA1:D1248797C002076BA28EB062169CC4361931840F
                                                                                    SHA-256:23FC6A41A20BD76E7DE9A3FF6E275F80DC5761C58C137C541CF3F133F507F7A1
                                                                                    SHA-512:5F0B5BF3CFB9F73686F4211FEE335984404BFF253F9C3A791FD5DD36CE3BA86B2CBE776644ED3A93AADD5997F336B9EBED8830AB4A709B8BDFA13933F050DC70
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!.................&... ...@....... ....................................@.................................4&..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H.......t"..............P ..$........................................... ..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.110286419307638
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:CxCqGWt134Gw567aYElclPNcZjLOBlZsKJ:TVWBGYESa+g
                                                                                    MD5:D64865F67DA8E3BABEF95DB7C459BE59
                                                                                    SHA1:C3069A7007DE5914F2E1D51BC10F0B8C555FB66C
                                                                                    SHA-256:9860CC9C7D3E29C060A6AAFADA2C33C6758EE71B3B0A193E4EB78AB026CA55B2
                                                                                    SHA-512:FE0ED73CF65084283ECC6BE676C332DF19A60D43D8C4E3FAD7C003F0218E9A6BFA87280E1D69D4C1B94E8DCB0420995338CA2FD2D1E05FDB2FF863FDCD979733
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ..............................*_....@.................................x)..S....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......l%............... ......P .........................................o.w............A...ei..^x./E6....&.6%.Vw..0......Z...a.......WEi.G.7\......M..5.5..:.......fm...(E4.6g.T.9.c...v.+...a9................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.251113891221509
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:b2nqcsAzAzltEvlVvVtVXVvT1SFLFwcsLjLreKm:bSE3EvlNXt1T1SFLmccjWF
                                                                                    MD5:4F42D0E6AC0D91BBF16A658CDD2EB345
                                                                                    SHA1:4BA06EEBC69B664FAC12773E59C6CFEBE81A5950
                                                                                    SHA-256:78F3203B702C28F112F3E0D4B771D55F6CC9257114CB708A99B4F6784F4D52B1
                                                                                    SHA-512:A7A8EC320761F91DD61BD25E590F1513F09313AA477330028EF1F0B79E3E51768326229BA5FDE52D75721FF6EA1CE31D99079D5BF23A3F844301763F8644C2A1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......87..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):3.9950788719370136
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:1B5nPl+RjC8jZh7J/XioJSi9lTmRcmCiCpHFdeto3mOACdkyn58Z6UQ21hM5HWWN:1xQwcV7IHN8Ad7l
                                                                                    MD5:2DBBDDDAC0F761B1B1E3F3058A3CD877
                                                                                    SHA1:747508C8AAFC4CE0A57A5F912EC574AC15CF1AB9
                                                                                    SHA-256:F4B60A93D1261CEC92F792E9983D44C01F8977B1C8E2CF975D2A85C32DD8AA96
                                                                                    SHA-512:B37678E42EB281D811F9DC03860AF50724C940ACB3321351F6B8D0482988A46AB02FF483FCE287AC00BDDE7278E4974D417521583F3399D9E5E5BCC15555E2C8
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,...........J... ...`....... ....................................@..................................I..W....`............................................................................... ............... ..H............text...$*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B.................J......H........F..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.715860235049701
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6YV2rH2HpSp6p6EB+iXPm9h/CXEBlvlPqox1TsjQq4o4wmHDvSGEpJ2Y:hArWHpSp6p6EB5XUk+llPhXgX
                                                                                    MD5:F42130CF13E9B7ABB4B50D6EEC72BCB8
                                                                                    SHA1:A752B81C89E32DBB8E3A139DD108BB544BDF3802
                                                                                    SHA-256:A0B1C4AF9E00F88CFA45A0BCB1F371AC9564F59D1131F2794EF7659976A13B87
                                                                                    SHA-512:0FE93F33D12CF467CE21A4A43D118A5CA679BCA3960D0272F568997B5FE34CDBB55AB1289EF76517695E91C5DCE90ECCF9F56789BF02E853005EF21AA16399B6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................<)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p)......H.......x%..............P ..%...........................................!..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.798856573078593
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6pCHpQUFezLWsXMzlNOfOP+OlD9BkFdHS0kolPqLx/zzptjWwqcF7JPWSG3RWMJV:rJRFezLWsKOfOmOZ9BOBkolPYo5
                                                                                    MD5:1BEBB406C4BBB002D333CC67DC0BEA99
                                                                                    SHA1:0523E3D8BC5179167CDB23C106775CF9659C60C4
                                                                                    SHA-256:761B113E97CA0E73CF11A07FEEF6BCA815BB8698B509F5EE46AE5F22172BA157
                                                                                    SHA-512:E20AE347B5B13A73D07B3E9D76B076F6D4900788A30967640CA776DAFBB08C4C6E853B7FF3B32E8194883452892A1818E0724C79F79B9A59B66167DD45D956D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................\+..O....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..^...........................................Z..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.5147445310100505
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6OVZNlHdyvp1PgWhtOodOBlPq02pxQarWj3qlF8yge2wDGpQBJ2Y:LH/9yvrPgWhtHOlPR2pXm5o
                                                                                    MD5:9D47FFCDFA16EF041A0EA61186A38F00
                                                                                    SHA1:2BA1B64C36F09B0E8CDA76D0E2FDF7E6FDE62CCC
                                                                                    SHA-256:73F506195B2781A68E61977CC2CD6F4F41507785CADD45B5C2B8DBD87F51AF3A
                                                                                    SHA-512:001989A97090A384473B81E37DE90C61B369330548AF7A86E8A992E6F43CDF85449BA0C7A4E54D3E42E1E93E5F2E1A60AD71FDE28BC663B92639090B26472D60
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...yR.e...........!.................(... ...@....... ....................................@.................................h(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..f...........................................b..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.#.....L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6288370455300125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b9++Hq9AuzjlGE+SClPllPqNKS2pxsrIxmGjLqXp2qwz2/UbGp0JJ2Y:+Q+s3XlgRXlPm2pKlBZq
                                                                                    MD5:156E34CED576F9B4B136C6EBC7AA7831
                                                                                    SHA1:583F0A05839B89ED53073EA892948376D15DA069
                                                                                    SHA-256:81A8AE83F074304FB4905F1CD654731563008010629519A8E78BD033C34B8C62
                                                                                    SHA-512:1F3ACF3C5BBF1FC3B861EBD7F1815EE3FD6D01AF6FC2568B3930FED6B85E47EF2ADE84AD69697A9E77FFBC2A4B85E15458A9A477435F61649E6A88DF64C86A56
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................T(..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..=...........................................9..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.788413097425715
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6y61Ho6cs+EcWrccLcQQ5cjcSSLcdIc77cAc5pc7c7cxCcpcycSKcfAtcpkcFGbN:fS13lI4Syk1XzlLelPgw0c7DdfK
                                                                                    MD5:68BF2BF6E62E6A0B2D6E162FB71C2245
                                                                                    SHA1:B74FB50E88F17B9061F93E8B35845A45519E9AF0
                                                                                    SHA-256:DC99CA534224B7DF3EFA7CBEE89D03F0A50B3FD876A6CD1523631954B5D7F4A2
                                                                                    SHA-512:8B72E256FC728CF3D22AEA450D656E43C089AD5AE0908E78DC7644D5140DBB265395BFD7E9B9D2C04AC1A508053FE6A64650DF0599B3664D8E3A1B50457A8104
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................~0... ...@....... ....................................@.................................(0..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`0......H.......\,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.7725614852658125
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gEd5lhH23S+lvgexlk7OaMoklPq+LDJnWhj3vgIU1WyoFp/98P28s9JJ2L:tslhW39oQlPNRij3YG7T3
                                                                                    MD5:7D02D631A76EB6668A1F2C53EC39ECB0
                                                                                    SHA1:AEA9A149D324AA931C0DABB5825E7B517619E11D
                                                                                    SHA-256:CEC8007F6DF984001F09942E5D46B9A02B51B759DBC09B3528395B8B0FF59A46
                                                                                    SHA-512:A063989662D3A844DC5AE62973E8CA273B59B625AC58F547B18D74262644C3061D4370B63D495784E545DCECA3760D2A7C154CC30FC7DCDE8985C05BA800FC51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...............................U....@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P .......................................v..[I.F.q-...9?e...-...HK..&.....*.... ..X..'..$r..o....[`.x.i.2....Tx..........o..,..F.........>....%FJ....$E..3....m...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.452456536559997
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/Sz8ZsajEfqNvjJmbfsGzFCJ2YO:WlviGlPhZsxz1FwY
                                                                                    MD5:D875701E12C3C1370397760702EF1AD9
                                                                                    SHA1:96904311F06A3E275E09CB8A76448C1A6BE570D3
                                                                                    SHA-256:F5D7A8EBBA5D706659EF6779D1769F4BC4D411E8C01F990FA9467457A0D3AF74
                                                                                    SHA-512:8B0378B5D8FB864D9387A511350C4E2590912F6959F55DFF3144B2B2506649C37543DC14CB9B41AE49950697782EA707E9A2D5992F34ADECE55376EB8EB884BC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.255508847021893
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:XhfCwdJxwBbVJVv/y9c9fM9p9u/glhm0pGxowCLE/Ky4F:RFUrv/z0hmvFC2Ky4F
                                                                                    MD5:C938F461B4371F4D0FAAC0D6609A4896
                                                                                    SHA1:A8BD1E1CA4D9DE1D69A8D53D4B499459D0C7ED15
                                                                                    SHA-256:49E99FB91C99A872581DF20E212B53D08B205FF58CBBD233C573CCB909B51CE0
                                                                                    SHA-512:79666A3D7A31BA6C1C6A1B18898C960839F46EE97015FD070F1DF255C700D726F2F4945284AFA12232CE12F224245D54067495BF52727AB6FE253421E0A2EC0A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........O... ...`....... ....................................@..................................O..K....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................O......H........K..............P ..w+..........................................s+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):140177
                                                                                    Entropy (8bit):5.0105247259887
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:ISq8lJH/U99Xl6F92R8dzXFrIj2I3ldwzG3LPf0T8gVQPQBUCbURNhyxJ9FRr:IF9Xl6F9mo4wzG3LPf0T8gVQPQeCl3
                                                                                    MD5:1776E84B2665C7B16E3D16D70494DFF5
                                                                                    SHA1:B27308CDDC32C22D426E74490458BCA4F9792235
                                                                                    SHA-256:B35890427D2336E889A03E6DFF6B51268E49A1281B326EE6BD64B54E9DB8D576
                                                                                    SHA-512:76D4BC644AF0B37784DCB9A28E5A615625F61F951D18541695C455C0614AE5651C8904C079DE8EC682A1AC9B73A02F73130D5ADC95F6DB1229D3C7DE0F8A3D9C
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument" />.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Trace ordre 2 {0} {1} {2}">..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):283136
                                                                                    Entropy (8bit):6.00665871292273
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:zTlyoOCGOd8DxSEjnhkHTI4A2j4xBJz+gM5w9HDAVvbLvm5KhgeeCjDrgvmjG0Wz:N3n2lB+xQyUeklXAknj1ur
                                                                                    MD5:07137E5CC4D5ECC95CA267C9DCE042D4
                                                                                    SHA1:D82F5E3D718BC9172FCFE0E8C50CB20251762058
                                                                                    SHA-256:56F525E33494F4CD2A560A71CDF237303A3FB54A8FA44E1693EBA35C9245C60A
                                                                                    SHA-512:9D1D6EB2887653260B62A24D3AB2C358BF15B89F68A1A3A1104F1EB5362725EB535218B9A53211F9CDB67D7793CE346C520A289D66C3EDF786B0DA5DB7C39F0C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Y.............!.....H...........f... ........@.. ...................................`..................................e..S...................................Pe..8............................................ ............... ..H............text....F... ...H.................. ..`.rsrc................J..............@..@.reloc...............P..............@..B.................e......H.......\....J...........................................................(....*..(....*V.~....(........o....*"..(....*Z.~....(....-..s....*.*....0.............(.....*...0..8.......................{........{....M........ZXM).......(....*V.~....(........o....*"..(....*Z.~....(....-..s....*.*...0.............(.....*...0..8.......................{........{....M........ZXM).......(....*.0.....................(....}.......(....}........(.......+r...<....(....}.......<....}.......<.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.514935440551161
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:YjuR5/lqHudrQZ+6ouOAG2R4cd6wTmK0GEIy/o6W1A2Tk:PnoeUlRbd6mH1Aq
                                                                                    MD5:BD6803706AA2B094D3E4763867900201
                                                                                    SHA1:DF2FFFA4E269AD792EBF57C231AF07E46F62B3E7
                                                                                    SHA-256:74258BFB810371CFAADC3395151B76352723ABD26FA08561134D3AE411854741
                                                                                    SHA-512:71C416301A18F87440058E8C2856CC71A4FC9EF455AB33100E00488368A418F66423088FD1B8DFBD6E7538A9BED4C46FA6160C57F2AEB3087177228889F843B2
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0..............6... ...@....... ....................................`.................................06..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B................d6......H........!..$.............................................................(....*.s....%......r...po....%......r...po....%......r...po....."...*B(....r...po....*J. ....Z. ....ZX.X*.~+...*...+...*...0..2.......(....r?..po...+..(....,.(....o......(.......(....*..BSJB............v4.0.30319......l...t...#~......t...#Strings....T...T...#US.........#GUID.......l...#Blob...........W..........3................0...............-...................................................*.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):51888
                                                                                    Entropy (8bit):4.733153779202759
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:nwO5mYXPEmIeNc0jh+9fzLkguHw+n6xLVC65qMARM0Juu9sKDPMimhk8l+YGAIxG:nydeNBjhEfzLkguHw+DaNgzK151v8ix
                                                                                    MD5:2FCEF68860A27342DB0BEC3CF32188DD
                                                                                    SHA1:9135DF90FA78D08A6ADAD7926724D92D024CA74C
                                                                                    SHA-256:65CA3103E4DBDF334CC663313BA61025ED7125F59C21BB1463B27E8DB1BB8478
                                                                                    SHA-512:25C346CCFB22FB506195CE8EE362AE70A98BFE77C30BED6C96235610D80C29FD000AB2E9FF908CA845D8C697DC70B79F81E7DBD70E3478B5F8BC7A8A389CB16A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ........... ........... ...............................k....`.................................`...K.......(...........................(................................................ ............... ..H............text....p... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):79872
                                                                                    Entropy (8bit):5.414166396089919
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:7OuYsC7iQ8gtO98NotMSyxNSYxl0uZhctTJIc+mBVD7D3mBnJIc8r:7HQE98NKmX6TmfuD7D3OmH
                                                                                    MD5:8B397B9E6D81D29B38CCF252B22526E5
                                                                                    SHA1:B1CA02779A70C89D0737637B6ECB167CE345DA6E
                                                                                    SHA-256:30007B209C850405F29FC1B67163E5136B54D77923189C0A560C2C133155952B
                                                                                    SHA-512:2256724A91F877F98C7B8A48592F37BB7788B3E791BE6E48045776B655DB32B83C10DEC029E981C90EC707756E7992B2398E7EB4DE1108CAF83E569B59E1F1AB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....O............" ..0..............M... ...`....... ....................................`.................................xM..O....`...............................L..8............................................ ............... ..H............text....-... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................M......H........\..4...........PG..8.............................................s....}.....(.....#.....@.@s....}.....{...........s....o....*...0..........s.......}.....{....,.*..}...........(......{....~....%-.&~..........s....%.....(...+s....}.......,..(......{...........s....o......}....*.........!.?`......2.{....o ...*J.{....o!....(....*.0..5..............(.....{.....o"...,....{.....o#......,..(.....*...........&*.......0...........o#...~....%-.&~..........s$...%.....(...+,..o/.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.967993823220595
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:vnskGvPbslkoobHmpTUiiwZk1Llywb2HezdtJazF7NtDS:vqvMa7m+YZqLlyiCS
                                                                                    MD5:F927988E1BC92A9FD9A9A9FC280359A9
                                                                                    SHA1:91061B23ADFB6BD850527C3CD9CB404AEFBE947C
                                                                                    SHA-256:95CFC1492297ADDB93C4A5321C8203B21739B6765DF5C515196B3BCB6D487AB8
                                                                                    SHA-512:87B8123FE9F71C9148C687F030D5C7D336BB493142507C7D4251CF721B258B54BCC3028D869DD9A96AD7587108B67D39C0FD98EC0C59468BDEE80C172B6FAE06
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..0...........N... ...`....... ....................................`..................................N..O....`............................................................................... ............... ..H............text........ ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......L"...$..........,G..`.............................................(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rJ..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r>..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rB..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....rR..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27136
                                                                                    Entropy (8bit):5.62370208146286
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:QWacd6CBYTN80lL1Wgh1v9OkEO05YzBElfhpfpx02Vb0Q7RB7lenx+CghxXZ1:QAd6C2nt1Ey2hpxx9xFX7
                                                                                    MD5:A93A19288FB79D9B782E03901ADE875F
                                                                                    SHA1:9CE82E8B91922CE5E9FC03138DA7F77A1219AAFB
                                                                                    SHA-256:496863F170A41A8DD6712EF2A4D88B9253B96D253B6A5F47B745E3BE41D16D5D
                                                                                    SHA-512:5A833B569EEF73531038A9ADB4825966FA16ADECD325AA85A44DF86F526F96ED5C7EAEF334279CF0E3A8CBEA3309786013AB9561D874706C95BFA17282EF599C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...TH............" ..0..`............... ........... ....................................`.....................................O....................................~..8............................................ ............... ..H............text...._... ...`.................. ..`.rsrc................b..............@..@.reloc...............h..............@..B........................H........,...A...........n..(..........................................."..}....*..{....*Fr...pr?..p.(....*..(....*..0..e........(......}......}.......}.......rm..pr...pr...pr...pr...pr%..ps.....~....s....}.......s#...s....}....*....0..........s.......}....rC..prw..p.(.....s....}.....{.....s....%r...p(...+o ...%.o!...%r...p(...+o"...%r...p(...+o#...%r...p(...+o$...o.....{....o.....(......{....o%...}.....{.....{........o&....{.....{....o.....{....o'.....{....o(....../...s)...o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.8771212955964223
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6T+UQDKnHslyxqLF0Fy9X7qG2VGABb81iEOaETjbU0jfjqtqQ/NVbnQXmtG87KG8:GoKnHOyQFmy2t9E1yU0PWPbdzLFY
                                                                                    MD5:3EF03FB5F6D6A63E8FD67FBF144135BA
                                                                                    SHA1:4AE9461926FAB8AA9F8D2FC4FADA25A28BF8727D
                                                                                    SHA-256:EE6590FB47A18B2EFBD8EE70B1BFDEA1318DA6AB7DBF802B6C434F449FA9BD32
                                                                                    SHA-512:8353AE4BB8C815C2A2E14534EC74CC910BFD070312CDE1E13054A6F35227E3252BF68C00F1572DE75D78E0DBC8BDF2AA42A035D6488F5854E8A869B099B6A45B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............2*... ...@....... ....................................`..................................)..O....@.......................`....................................................... ............... ..H............text...8.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......| ..d...........................................................>..(......}....*J......(.....(....*..{....*.BSJB............v4.0.30319......l.......#~.. ...T...#Strings....t.......#US.x.......#GUID...........#Blob...........W..........3..............................................................................Z...........2.....A.................4.......!.................................O.x.........A.................r.....-.......S...F.....................h...M.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1101824
                                                                                    Entropy (8bit):5.023302066642073
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:zKzbh1ndx6nAsUfoFoo9VCrh58feUpM+:zQlyosVih50pM+
                                                                                    MD5:0532E0660453C89AF5955445972E5D5B
                                                                                    SHA1:C0907DDFE071EF98A26D9EDEEFD2D83139C17CE9
                                                                                    SHA-256:C341D62E5343E77BF0420433D9B1FA493115422C8FC8E5512CDDAC382C1FA51C
                                                                                    SHA-512:FEA07DBA3695006B90449769264649EAC018CE203457A25C06F2A04C8CA299B9F64687F54EEE301585715401523572B3EB91880A194FE8A91BA36D22000881E1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ........@.. .......................@.......D....`.................................p...W.... ..<...........................hW............................................... ............... ..H............text........ ...................... ..`.reloc..............................@..B.rsrc...<.... ......................@..@........................H........W..............@>.......V......................................6.(....(.....*...0..$........(-.....}......}/.....}0......}1...*.0...........{....*..0...........{/...*..0...........{0...*..0...........{1...*..0...........u......9.....E.........-......&(2...%&.{.....{....o3...%&,U(4...%&.{/....{/...o5...,;(6...%&.{0....{0...o7...,!.E........(8....{1....{1...o9...*.*..0..j....... ...n )UU.Z(2...%&.{....o:...%&X )UU.Z(4...%&.{/...o;...X )UU.Z(6....{0...o<...X )UU.Z(8....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):32256
                                                                                    Entropy (8bit):5.5805424459907345
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VRDROHaea45sA5AJibBCN/46XRWswufCFvF88MAhBK0ePnaSuTpz8/kk0dbXn7iN:VDOHaea5iB3TVvzamB5yqPOxXB
                                                                                    MD5:3630B889474F16781C307E814AA85292
                                                                                    SHA1:E7870ACED20FC325D6FB6E97E586F63909A02092
                                                                                    SHA-256:C8B37479A066F7332F584BE5CB100D4461A4C5399D9BED901EB815830416149A
                                                                                    SHA-512:1D391CDEC2E5DED0FB747A5BCE1D1D8B930B76F2471DA6EED2C694CBCB33AFC8ECD0A1D408B88E3C60289968705E21E2142C54DDDF48C9CAA3DFBCBB55A0D270
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....X..........." ..0..t............... ........... ....................................`.................................1...O...................................P...8............................................ ............... ..H............text....s... ...t.................. ..`.rsrc................v..............@..@.reloc...............|..............@..B................e.......H........2...M............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.s%...%.o ...%~ ...o"...%r...po$...*.s....*..{....*V.(......}......}....*..sW...*..{....*...0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):22768
                                                                                    Entropy (8bit):6.201382004474863
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:PF5AZ+le8+2KCYTzs2um7GH9SJSWcGvXS9//0GftpBjE4u:PF52+le8gR7GH9yok+8iyf
                                                                                    MD5:7C08EA125D8054BFA6057104590A7F83
                                                                                    SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                                                    SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                                                    SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):725157
                                                                                    Entropy (8bit):6.524818615519142
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:2sMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyRj:xMcMoi3rPR37dzHRA6G7WbuSEmK50syO
                                                                                    MD5:F403E2C6DBBF42ABEC4E5B652214B871
                                                                                    SHA1:0ADBEEF61C281FBDCF573FC82B36991DCFE36205
                                                                                    SHA-256:442A9BEE6C3C457C3DBA7C918B26A64B6A40CAC10FE074EA9143D528C14E2CAF
                                                                                    SHA-512:585881B7D5AD71277420E899C6C0F812BD392B00955DBC81C26FAD7D0149728E9D610EB283469356F83E0D942FA229AE44C8768CB715BBB0C88ECA86EDAD82EB
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Unicode text, UTF-8 text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3
                                                                                    Entropy (8bit):1.584962500721156
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:g:g
                                                                                    MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
                                                                                    SHA1:57218C316B6921E2CD61027A2387EDC31A2D9471
                                                                                    SHA-256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
                                                                                    SHA-512:37C783B80B1D458B89E712C2DFE2777050EFF0AEFC9F6D8BEEDEE77807D9AEB2E27D14815CF4F0229B1D36C186BB5F2B5EF55E632B108CC41E9FB964C39B42A5
                                                                                    Malicious:false
                                                                                    Preview:.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):26112
                                                                                    Entropy (8bit):5.504870778700713
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:tMsUagR+NCVz3IU/oulvE+5LE1jqXR+EL54L2aYUNTWmeF:tJgTIUwG1XR1a8UQmeF
                                                                                    MD5:08E71FF89AEF2C04D1DD93A9314AF78A
                                                                                    SHA1:B19A9EEFA06112F83F7BAB1B5BFA4F7A072721EB
                                                                                    SHA-256:5885FF0727652243CB1544B3AAE4E31352E749E78436EAC3A6BA318A5CF1585C
                                                                                    SHA-512:B9A38F05719E4FD0DB696D0923F5B0FCA0EE36E8339EB6E042FE9EF0CA4A66A626471D12B0118C25606263F9591549E8F4432C550A5009FEDC9E20D90F8DBDC3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....G..........." ..0..\..........Fz... ........... ....................................`..................................y..O....................................y..8............................................ ............... ..H............text...LZ... ...\.................. ..`.rsrc................^..............@..@.reloc...............d..............@..B................&z......H.......`%..l>...........c..8...........................................V......tI.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V....tI.........( ...*2.(!...t....*b.(.....("....(#...s/...*z.(#....(.....("....($...s....*F...tI......(%...*2.(&...t....*..('....((...o).....(*....(.....(+....(,...s%...*2.(-...t....*V......tI.......(....*..(/....(0....(1....(.....(2...s....*2.(3...t....*N......tI...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48344
                                                                                    Entropy (8bit):6.53421522959476
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:4L/YzwmxRqw+4aECjhmUYVmePi+6bYKN4:aMxRqF4BCjhmHPZiYKN4
                                                                                    MD5:06296D204C279118CB8863F07E3DE4E1
                                                                                    SHA1:175553C011BA3B50322833477F095142F1C3D699
                                                                                    SHA-256:CEB0E446953833CAA54BC01E84B787281CF6712BA7DB65D4C9A664413E95CEFB
                                                                                    SHA-512:BFA4479554B841A17969D124FD69701DC1313E8F24EAD667C45002AE8D60C3F615D8D484D1334C87E5C93F1FB30B8217A0CBD528125EDFFEF050B898BDC1598A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."Q...........!.....t............... ........... ..............................~H....`.................................l...O.......`............~...>..........4................................................ ............... ..H............text....s... ...t.................. ..`.rsrc...`............v..............@..@.reloc...............|..............@..B........................H........p..L!...........0..&@..P ........................................9q.}..;q._^.X.A...&Y..n._=....*...%...'.Dc...S)..C....W.....k.Q......l.U.v.%...l...."ITo.Z".w..|-:.L%5g..cy':....=.6..Z.bF.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*F.~....(.....#...*J.~......#...(....*..{....*"..}....*..{....*"..}....*"..}....*..{....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):211632
                                                                                    Entropy (8bit):5.3707738806905905
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:3TdnDzOb56Xp6kGijb7N5KH+KnklI7o5UuL8J:3TdnDCbgX4ecoY
                                                                                    MD5:B8ACA033D81112E38EEA7B9525F1BD56
                                                                                    SHA1:7428C64C3E68DD45E89FDFEBA08F75F1D3A49B29
                                                                                    SHA-256:D750B661263AEFCBE961942D15C2DC507DA6361748A8E65426963274B5744EE7
                                                                                    SHA-512:045E2D152DD2AB8AB64BCF0B32ACBEDC2700018A354E26C9ADB2D26C7390D648A51903DFA33FC61CDDAF2DE6B5DC38D3F0745D37AB8BDB9328566EE48806892E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!......... ......~.... ... ....... .......................`......q.....`.................................,...O.... ............... .......@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7680
                                                                                    Entropy (8bit):4.609043127953718
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:4x/lg1lEFiC83HY+z63w6n9HdDBFeK9R303inq6ncYZCl6lSWn:4Dg1sovz6AiDYKTDnbchMlSW
                                                                                    MD5:56E7B6DDF9FA1BB2363D5813120674A4
                                                                                    SHA1:92745E5EE779EEC4C4E2021FFA59E3FFF6242DC7
                                                                                    SHA-256:816C7FA679B7B5E529FA8274ABBC75FD56E73C1244B79EA90B552F31AC6C219D
                                                                                    SHA-512:A315110A1CB434914B37373DEB36D669EE1CF3A9B6269927F8C2D49AD2C1991560748D64F63DC1F1E2F9ED5BC01EE621EDCDC1F851F942FFB734129695173996
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............~3... ...@....... ....................................`.................................,3..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`3......H....... !..............................................................~r...p(....r...p(....(.........*.0..T........(.......}.......}.......}.......}.......}......}......}.......}.......}......}....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*BSJB............v4.0.30319......l.......#~..L...D...#Strings............#US.........#GUID.......X...#Blob...........W..........3..................................................................A.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.893431167436209
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:j3L1ossT+tBSTXrIJOGqjTcfeEXs8zfH2yxJi:j3L1MBTXrIJrqLEXTWyTi
                                                                                    MD5:1A15932E3DDA65E9FBCC696A51C891E7
                                                                                    SHA1:DBA73103CB5FB8EE38718E1E000C9E18D82D1204
                                                                                    SHA-256:D8DDB54F93A12DAEE51ED36FC735B56C67C01294E3493FA71B81C4C731E237FF
                                                                                    SHA-512:E4FB92ABB58EFE9534ECAA5A6E3435ED2DEA7CB0C63CBCA4422C1F81921D20857AF050F6F3E51DCD68249E879DF3EA14C9A289BB7A24D92208BE14DE0DA5C821
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text...4 ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........&..T.............................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*J.(.....s....(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.~....*.......*.~....*.......*.~....*.......*....0..7........(....(....(....(....r...p(....(......(....(.....(....*N.(.....(.....(....*..0..L.......s....(....(....(....:....(....(....9.........(....s.....(......s .....s!...%....o"...t....o....o#.....+e..o$.....(......o.....,.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):26556
                                                                                    Entropy (8bit):4.728335524596591
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:dltvbTSU47YPo0nLcZ6zE06PoPfqVnuv1tD/Xb0gnlf+BWRHmIFcM:9zg0nLcZ6zE0bPSVnu6BWRHmgcM
                                                                                    MD5:B0372EDDCE04EBA949E87B05788FE144
                                                                                    SHA1:8511A2A3E02B0AEDE1FF5B77043094A6E7ABDE0E
                                                                                    SHA-256:E294D347CB9FB7CE6E7A83B96943D5EC51DD59991D0496BBB99F6573767EF5CD
                                                                                    SHA-512:8C1B14D048D5600C8B8E163D20E4E3EF3920ED9CF8EBACDE33214D11B8F3731A0F8225EB2EBA1B84C23822325418633CAAFF1B49B7FA2428C1A0476F95C3EF28
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....4..#~...5......#Strings.....7.. ...#GUID....7...,..#Blob....d..|...#Pdb................../....3........................H...P...........\...i...................................................2...?............... ...........U...^.......'...........|.......................7...@.................e...............~...........................................3..._...................'...I...u................... ...-...5...\...y.......................6...S...f...............................)...P...............2...t...........................................................0...=...E...e...........................1...L...g.......................................%...2...?...L...Y...g.......................)...I...k...................T...a...........5...A...N...V...}.......................%...6...D...L...i...............)...s...z.......................<...O...[...g...n...........................................$...1...C...P...X...k...~...........................#.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11776
                                                                                    Entropy (8bit):4.956614026804989
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WCvPuFqE/nQ+L9XRy/z/J0pD+zcNwlClvhMHJaOHuM:TZEfQa9I/Jy+4ZWROM
                                                                                    MD5:0A0505AFC1C5AF06E4383DF3032D0674
                                                                                    SHA1:6242B357013B9E1B6423DCB5482B2D0EB510A4D5
                                                                                    SHA-256:A902F1790B60C1177301073CC1FDA983B4E3186FD6EC247335B115A41A3786E2
                                                                                    SHA-512:F7A471192BE900AC14B4C39B39CCA5EAE1ED35A04E1BC70B50AAB2867DDCBA9428EA431F00B5E05B96AEE05DBE70F2673C286752F05776BDC54192364054C1FA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..$...........B... ...`....... ...............................0....`.................................4B..O....`..\............................@............................................... ............... ..H............text...."... ...$.................. ..`.rsrc...\....`.......&..............@..@.reloc...............,..............@..B................hB......H........%......................|@........................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.0..S.......s....r...p......%..(..........%..(..........%..(..........%..(..........(....o....*..(....*V(+...o,...o$...s....*.(....*.(....*B(+...o,...o$...*.0..(.......(+...o,...o%....(......(....-...(......*B(+...o-...o'...*B(+...o-...o(...*B(+...o-...o)...*..0..F.......(....o....o.....s....%.o....o....%.o....o....%.o ...o....%.o!...o...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):467288
                                                                                    Entropy (8bit):6.047761304423497
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:ABk34hZ9hNZbkDu0WtH7epyiNrt3329rzSkmN0OE0QxlmGJcdBI8rO7le2LvFVNs:OhuUiNrt33sSkmN0OE0QyGJeBwL/G5
                                                                                    MD5:195ED09E0B4F3B09EA4A3B67A0D3F396
                                                                                    SHA1:01A250631397C93C4AAB9A777A86E39FD8D84F09
                                                                                    SHA-256:AEF9FCBB874FC82E151E32279330061F8F22A77C05F583A0CB5E5696654AC456
                                                                                    SHA-512:B801C03EFA3E8079366A7782D2634A3686D88F64C3C31A03AA5CE71B7BF472766724D209290C231D55DA89DD4F03BD1C0153FFEB514E1D5D408CC2C713CD4098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!................> ... ...@....@.. ...............................>....@.....................................S....@..................X....`......h................................................ ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ ......H..........|q..........8.......P .......................................LO.K. 6}.5N..LA..D..|..=T.+.%.O..!@....D.tLl.....8..o...x"...&..C.@"}.dd..CZ..+..4l|<.V....Z....=..)...':..n.....*.....K..{....*"..}....*F.~....(H...t<...*6.~.....(I...*.r...p.<...(J........(J...(K........*..(L...*F.~....oH...t....*6.~.....oI...*...0.."........u'.....,...(M...t......,...o....*...0..F........(....,.r...psN...z..(......o............sO...oP...........sO...oQ...*...0..F........(....-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):95064
                                                                                    Entropy (8bit):6.069925755579635
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:ejt4SdWiPPH+PhqaEMN+3esQG0AZGblWfp8/x1il5OvNYXBTfciwN9rHUj:ejt1Yi8KUblWfpqwdXBfciwN9o
                                                                                    MD5:22D9D032858972B8EE628FA818AB04DB
                                                                                    SHA1:6EEAE133E394292C6C349F838114C2A39DFE8357
                                                                                    SHA-256:E3D7F794442D9DBE99F5D578C0BC8D9E3198FE4055CF5581FC1DE78085967C50
                                                                                    SHA-512:6899B2650AAFD1E88049303C7EE26FF7E0DFE201D8A7188386EF2354DEEB32F611BB4B73A02BE9127FC96D5B4D37CAB9BDBEC3CFCB3BF4CADA43170AC4349E0F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!.....R...........p... ........@.. ..............................0j....@.................................Pp..K.......8............\..X............o............................................... ............... ..H............text....P... ...R.................. ..`.rsrc...8............T..............@..@.reloc...............Z..............@..B.................p......H.......L...`...........xr...I..P ......................................g......o..g.Y...O.*....o.d....y.R2@...C.l0.HI..UV..U.(..K32[.`[@J&%~*&.;...+.n8...I[b.w.....KT.'y..j7=!p9R9<.u..........h."..(....*..{....*"..}....*..{....*"..}....*F.~....(.....Y...*...}.....~......Y...( .....}....*...0..-........t......{....-....(!....Y...o....(....s"...z*..{....*....0..F........{....,..{...........s#...o$.....}.....{....,..{...........s#...o%...*F.~....(....u]...*6.~.....( ...*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31376
                                                                                    Entropy (8bit):6.161352322277959
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:r27oPj3ZdGnwIDMIMoMMMIMIM408PUugN+8ik:rEorPGpUnN+8r
                                                                                    MD5:5C9985D31E098BF7DF031171E046D67E
                                                                                    SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                                                    SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                                                    SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.799493422443734
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:zyNyhhFi/zagE8FZMhywyrB4Mg5BK1QCF:Hti/zagE8jMhywyN455BK1QCF
                                                                                    MD5:D75047A487A327C213220C5F7285599E
                                                                                    SHA1:D81438AFABD3A7C7E9AC82FB3A451D2D8889B233
                                                                                    SHA-256:AE006EF5A57225B73F3BA810548193AD1EFB7AAC1C066C93224F120E5F828C69
                                                                                    SHA-512:BBCA0B6B015E7A94BDF3B8BF814BC5FD1988933FB6D689CD1C6C16C2DB8CD2D1D9624362715FE8E9B2A02AAE887461DFAA7DB9A8D48C93720B85F4EA1FECCA15
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0............."9... ...@....... ....................................`..................................8..O....@.......................`....................................................... ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H........"................................................................(....r...prK..p.(.....s....}.....{.....o....*Fr...pr...p.(....*....0..B.......s.......}.....{...........s....(...+..-..*..o....o....}.....{....*V.{....,..{.....o....*..(....*"..(....*&...(....*..{....*"..}....*rr...pr...p.(.....(....o ...*..(....*....0..a..............%...(!....(....,..(....(...+-.r...ps....z..(....~....%-.&~..........s#...%.....(...+(....*..{....*"..}....*2.(....o%...*..(....*^.o&...o'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):78220
                                                                                    Entropy (8bit):5.051201187467832
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:CpHzmX5+N9aIcSyP6JFzIocUNX290MKc7P9tOaZQTZH:CpyTmyiJFzvNX29frPaTZH
                                                                                    MD5:1600D8ADB3E99F85C1E9719E59828559
                                                                                    SHA1:A2259A45EA284247B3AA65EC9C1DBEBD47FE208F
                                                                                    SHA-256:BBA95514FB062788C9AEC9CD7BC553CF47843C42CA5EB572814FF4B7C82CE7FD
                                                                                    SHA-512:DD967AB0F86D77FEF2E09830C00F318020B519205DD6F8BE70FB5D07FD5F6B988ACE83487B56EE49973216B385DCAF802408223AA0FD6D9F6203DAC6066BCC00
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p......#~..4.......#Strings........ ...#GUID...,...4...#Blob...`#......#Pdb..................?....3....K...........R.......,...=...E...........................0...;...........................}...............f...o...........E...N...........I...R...................................................7...@...........................@'..I'..m)..v).../.../...1...1...3...3..b9..k9...;...;...;...;...<...<..S=..\=...=...>..w>...>...>...>...B...B...C...C..8E..CE...E...E...E...E.."F..-F...F...F...F...F..OG..ZG...G...G..TH.._H...H...H..SI..^I...I...I...I...I..MJ..XJ...J...J.._K..jK..NL..YL...L...L...M..&M...M...M...M...M...N...N..%O..0O...O...O..BP..MP..YQ..dQ..%R..0R...S...S...S...S..:T..ET...T...T..kU..vU...U...U..RV..]V..9_..F_............Z...................#...4...A...I...V...........P...X...`...h...........?...m...u...}.......................*...@...V...m...........................+...P...........................+...8...Y...s.....................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):109400
                                                                                    Entropy (8bit):6.071956198915581
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:G+s08khkhGbYzCripb/8JExywW9lGW7MPSXfciFTd95:G308khN8IExyrSWGKv
                                                                                    MD5:9722713E648F42B57299E9D2CF3D5C1A
                                                                                    SHA1:A4D0DC4F09CE84A33F1AA3E0C5CB4AE131F9FB0C
                                                                                    SHA-256:BC3A78EB4DF2FD5B39244FA0586CC0A82FE3D0E185D151E6C340C53072A61872
                                                                                    SHA-512:F6BB5724DFC46476E94448ECB4650AD23197CA21965EDF923E5D8BF51A31A707C058BCA6CBAC8E40E324BB54944DA4129659DC2D2FC965E260BD40123A8AEEBB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!..................... ........@.. ..............................~`....@.....................................W.......0...............X............................................................ ............... ..H............text........ ...................... ..`.rsrc...0...........................@..@.reloc..............................@..B.......................H.......l...............0~..9<..P ..............................................~.mM.z..L..#....K...L.eY$.....R.1.........wSn./.\fl.........h..../..U9..$$.......... .....e.TY.y><".#/M......"..s!...*..{#...*"..}#...*..{$...*"..}$...*V.(%.....(&.....('...*F.~....(*....d...*J.~......d...(+...*...0...........t......o....*..(6...*..{....*"..}....*..{....*"..}....*F.~....(*....e...*J.~......e...(+...*....0...........u.......(,....e......o....*.0..m........./.(....s-...z.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4824576
                                                                                    Entropy (8bit):7.776304506864257
                                                                                    Encrypted:false
                                                                                    SSDEEP:98304:WOrDbgLR3nV/30BnLce2emqSwF3/HJ7f/kRLHCVUhY:BsV3nV/0BH2emqDFPHJ7nkRuCY
                                                                                    MD5:FD7A9437356762EE30088DDAF1B56ED5
                                                                                    SHA1:0426B255F4307498E6F531BFEB1135937E008863
                                                                                    SHA-256:C056E932DC3AFF16E8FDB56500E952C696A60A4CA22566C1B5BFC00C49756ED8
                                                                                    SHA-512:5705EC681E1BD00FB3FEEF1775737CD3053B0BD5F1724E78F5305BE31C8AFE02148FBDA9B02453D8621CAD40EB6250ED69EC20B6BAD8736E6B15BA43E81A6541
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0...I...I.....N.I.. ....I...@.. ........................J.....pTJ...`...................................I.W.....I.......................I.....8.D.............................................. ............... ..H............text...T.I.. ....I................. ..`.reloc........I.......I.............@..B.rsrc.........I.......I.............@..@................0.I.....H.........D.<...............(S7...D.....................................6.(....(l....*...0............*..0...........(&...*..0...........('...*..0..>........{.........((...%&t(.....|......(...+...3..E.........-......&*...0..)........{.........(*...t(.....|......(...+...3.*....0............s+...(....*....0..............s*...(....*..0..0.........(.....|....(,...%&.d1...}.....r[..ps+...(....*.0............(....*.0..&........{......,..E.........-......&...o-...*...0..K.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18944
                                                                                    Entropy (8bit):5.123452606388303
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:y0sI9oCUN+uMVZFZfZ9gNe5nlpW85s2wmQs56TtmOjXis0j7XcyFXcXPXrfX2H0r:xsf+5FCNepkmuTtmOrX/y
                                                                                    MD5:B2690A6C3C2E97FA8A89F1DEF550D53B
                                                                                    SHA1:E2811A4F491D9833C1D7880AE28F7755EF179BD0
                                                                                    SHA-256:8B64B6FF4274103A919C08DADDB8E295772F38582A098E0DA097CAA632A7083E
                                                                                    SHA-512:AECC9ED7F6E57D231A4362346BF38BC094495AA5A1131508466C9DBA34A67A2F83A15CBF420C646A28A52AC444EE4E6B16B8426531CFEE0F773F65934BFF5E0F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..@...........^... ...`....... ....................................`.................................d^..O....`............................................................................... ............... ..H............text....>... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B.................^......H........'.../...........W..............................................F.-.*.(.....(....*...0...........o@...-........oA....o@....i.1.*.........+ ..s....%..Xo....%r...po.......X...7..o@......+........o..........Y%.......X....i2...oA...*....0...........o>...-........o?....o>....i..1.*..........+ ..sV...%..XoS...%r...poU......X....7..o>......+........oR.........Y%.......X....i2...o?...*.0.......... ....s........,/..,+..i.....(........+..o....&....(......X...2..,>..,:..i...,..o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):21652
                                                                                    Entropy (8bit):4.849878167461133
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:OXwP73y8HB6AreJkS9RBbwX/QreSLG1UI43I6Y3Ix:OXmyiB6hkSVsoFI60Ix
                                                                                    MD5:3C7CE2802DAEE6DBA9E39970995C4069
                                                                                    SHA1:4FB7A312CC269CB44487B0FEE6B94695024A6B0B
                                                                                    SHA-256:226F82B448C2F8700CA5C9F3658A0808A251F98D8543753E6231BC41B2A2053C
                                                                                    SHA-512:203B5F374AE63AD4F9A3F926D8D0AFD351F2886D6B3A1FF6D0356C080980E850B9934B875B34ACCAB8EB0382A69B168C3497484BD2CE9F2F4B23B5230D751AC6
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....#..#~..t#......#Strings....P).. ...#GUID...p)..8%..#Blob....N..x...#Pdb..................?....3........1...T...S...........E...M...........e...r...................Q...Z... ...)...................................................g...p...U...b.................b...n...u...............................*.......................?...............I...p...................:...F...i...v...~.......................I...u...............5...=...D...K...\...m...........................................o...........................>...O...o...|...............0...]...j...r...........................+...9...Q..._...w.......................h...............................1...]...f...............................a...{.......................%...:...P...^...s...........................5...`...........................................-...T...a...............&.......;...C...K...S...[...c...k...s...........................=...`...................................+...8...X.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):4.35096535887655
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:HDbZgmWgUGOBlTGYI+eQ6/70dRbSA3oO4OHPbPa:fKQU6/70dRj4O4Oz
                                                                                    MD5:BAF74BAB27F9EF9F3857B4DBBB215FB7
                                                                                    SHA1:2D2068477DD2AD2C1747E08CC0BD2EB6B9E0516D
                                                                                    SHA-256:E851DD88BF9EB69383017E1211B9DD2826F94ACF3FFD345A539228DF52E9492E
                                                                                    SHA-512:20F04A0D5D8F8F8A21E84A5AC266143E151AE84C45172D45C4187A7E4D361295220B0F701FA4FF68EDC3A0097641A7C1E889F7F88A5E36C5208A97881605455F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............0... ...@....... ....................................`.................................d0..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H........ ................................................................{....*"..}....*N..(.....(....(....*>..(......(....*..{....*"..}....*:.(......(....*...BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob...........W..........3..................................................................................................................................!.................t.....U.................<.?.....Y...........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):269824
                                                                                    Entropy (8bit):6.248597977496272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:w9hcO7H2po0qDQh/mLJ2e4NY647eS56K2K+p637RArP1CKlF:w9hn0Cus+c32
                                                                                    MD5:761C33DCFD02AF3A9B60C3A307362989
                                                                                    SHA1:636D766B076E05DBEAB1FC9117F1B0931DC33A8D
                                                                                    SHA-256:B17012332BC4B2745349101AEEB02501E68F1E8D470CFCF316CA3AD13A2356E6
                                                                                    SHA-512:414F48F3FC381078A5B8E0D49F8D822BF1BD9B36EF944B3A7B2FCFFBCBF2F547108FC7002179EF2DF4021F499FE23E4D87BBAE5CB83B236AAFCEFBA23C7044F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e.........." ..0.............j2... ...@....... ....................................`..................................2..O....@.......................`....................................................... ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................L2......H....... ...................hV............................................(%...*..(&...*z...(.....-.r...ps'...z..}....*..((....-.r...ps'...z..}......}....*^.{....,..{.....o)...*.*6.{.....o*...*....0...........u......-.*...(+...o,....o-......o......o....*6.~.....o/...*.s0...%.o1...%.o2...%.o....%.o,...*.r!..p.....(3........(3..........s4...s5...(6........*....0..#.......s.......}.............s7....o8...&*..0..?.......s.......}.....(.......o9...,..{....o:...*.........s7....o8..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6656
                                                                                    Entropy (8bit):4.505709054960742
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Fap+7OssnvRymQuQedb0sWFNFbiphORQ9FTegrDv:r7sMsyZFmpsRQ9F6grD
                                                                                    MD5:34A60A6A68B81056A0E6C61DB469166B
                                                                                    SHA1:0CEFC433427FE075FF69CBD5152FD04DEF521E31
                                                                                    SHA-256:91FD46A63FFAF1E09F25E919E620EE4F282CC15939FA3AE8859F2705D42F250B
                                                                                    SHA-512:845935EF25A5B8AB7A5002EFAF2C7E47EA2F396152933F24239988CF8EAF85B46FC5274CE254A42368C5AF156B6272F7DC87B9FE820060018662F16BC80E6B01
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0............../... ...@....... ....................................`................................../..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................./......H.......$!..`.............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*BSJB............v4.0.30319......l.......#~..H.......#Strings....d.......#US.h.......#GUID...x.......#Blob...........W..........3................................2...................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):3749
                                                                                    Entropy (8bit):5.078741552603271
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JdJo8oHeJk+Okv3AvtiI6jS0rw4I0tHBA2/NGudf/81/K31JMJ2NeXvT/4eJ0ESA:3u8E+jrc2t2D6GVq1A
                                                                                    MD5:08789E08E94AC3B663CD8369C964C849
                                                                                    SHA1:02EBAE23B018DE670BBD59270A8A068BAD4B99AE
                                                                                    SHA-256:F0A321DB7486ED5A5163EE126D6B7C718975634D01B9BB6084B690D83A99C34A
                                                                                    SHA-512:50C2171AE97B164B59651911E85B581FEA1CDCC26F964A92E277A38C5565CC5ABC8E1CF897D96109DD25E0F0B8F203560A270F7F17449FE7DF1C0EF7ECD53890
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="UTF-8"?>..<ArrayOfSerialNumberDescription xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.... <SerialNumberDescription Product="3100" Model="S4W 8-0-0 GSM-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.... <SerialNumberDescription Product="3101" Model="S4W 8-2-2 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescription Product="3102" Model="S4W 12-2-4 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="4" DiCount="12"/>.... <SerialNumberDescription Product="3103" Model="S4W 16-4-4 GSM-XIO" Market="1" AoCount="0" AiCount="4" DoCount="4" DiCount="16"/>... <SerialNumberDescription Product="3104" Model="S4W 8-0-0 4G-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.. <SerialNumberDescription Product="3105" Model="S4W 8-2-2 4G-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescriptio
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):49152
                                                                                    Entropy (8bit):5.480020840457158
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:7q8U/PCFUeQ8QRoGuUHMUfUCFCMUTUv4Y40kZUfUURUOodJ4uZtRc/NjSVNG6Tvv:I8K5CUodDZPokVNppllGRTS
                                                                                    MD5:79EBB46AB8A5C3B161ED49FC14608257
                                                                                    SHA1:A1C5908F0872C2A2746D9FFA8E70564A1A04AC73
                                                                                    SHA-256:C0C98B750914CC930AE576861DCC35BEFFCCBA42D899685C1E2DFE94D5854B67
                                                                                    SHA-512:D639A58C2658F4CA51DE2E01CB73312CC414C2B77986E89D0593CA5E2ADD34343BE69D1D197A469F66FFEA366B13E87CB55B78DAD12C4D829733D887F36C4B7A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0.............N.... ........... ....................... ............`.....................................O.................................................................................... ............... ..H............text...T.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B................0.......H........K..,.............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..(......(......(............s...........s....s....}....*..-.r...pra..p.(....*.{.....o......(.....(....*~r...pr...p.(......(......(....*br...pr...p.(......(....*..(....*.0..;.........Y...%.r...p.%.r...p.%.r...p..s....%.o......(.....(....o......H..r2..p..(......(.........s....(...........r2..p..(......s....(.........(...+,..r2..p(...+.....s....(..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13312
                                                                                    Entropy (8bit):5.0948277461097105
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:TVoCUNaG+BIfUngxRU2nhgLrGPAyuqMzDZOikYmPj5nwrf5:CbfkWLZYVz9OHt2f5
                                                                                    MD5:894D75122FC4DFE34BF56484C361612C
                                                                                    SHA1:6FD416A2EDA7881D67E93F88E5081FBB0260E7C7
                                                                                    SHA-256:94AB68CFEE90C1D0D36DA3BD9A4679B490F2347826333F5BFAC57F9903A16992
                                                                                    SHA-512:1E75609E04F40EE523A297E1921AB733E8E9E8CE940373476FB07173339BE1A97ABBCEB19ACCE156DDA292FD5D49B45B86DC93DC1DED66135922A5C097B7498D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..*...........I... ...`....... ....................................`..................................H..O....`............................................................................... ............... ..H............text....)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B.................H......H........#.. %............................................................{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{ ...*"..} ...*..{!...*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55808
                                                                                    Entropy (8bit):5.775367059131953
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:VHCwr/Irm+5HZfetnHSvnAimB4Y7FtIQh9baSoC61VtCK28bnEsF:VCwjAm+5ZfynHSvn6g4oC61VtCl8r
                                                                                    MD5:73295A2768DC84259D3C2B9EA4AECF8E
                                                                                    SHA1:B85D251AC6A173DAE37430A9C6A61FE902A3D657
                                                                                    SHA-256:3845D947E5DB1A7C3F4EFD509EE35BC29ACB2393FD865D9244986C9424187D24
                                                                                    SHA-512:D7BD59F4E97C06363EAB2C1BEF1D52455939A820D2849E7651507CA04B7D4EC22C4B05DB0340A079EACE206C4AFEE619D444E0D039BECD961BB38D1C1443FA26
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....J..........." ..0.................. ........... .......................@............`.................................v...O............................ ..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........8...u.......... ...h?..........................................V......td.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*z.(.....(.....(.....(....s-...*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o ...*V(....r...p~....o ...*V(....r2..p~....o ...*V(....r...p~....o ...*V(....r@..p~....o ...*V(....rr..p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....r...p~....o ...*V(....rL..p~....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71808
                                                                                    Entropy (8bit):6.302233040356993
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BZb60QnEfniRuc4MG7uKMgM1lBa/0jSNgDWcLbtNnstX1Ac:BZcEfni4c4MG7vKFLLjwX1T
                                                                                    MD5:391166F9D5D40EE90F0744982177F4AB
                                                                                    SHA1:F7DFF35B30DE2E02BCB3A7EFE45334E1B5D7C8FE
                                                                                    SHA-256:FA36ED1236CDA36DFA34BE757A791EC94011D43D19E73D0BD9D0F9F802473A22
                                                                                    SHA-512:700FBE5FD992F678C83CCA1170F68593149C04E314402F7505B8A640FA89CD24633426ECB3548057E7AF14F0342301E66B5785F01F7FDD64ED2AF13614CD98EE
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`."Q...........!..................... ........... .......................@......2.....`.....................................W........................>... ....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H........t...w...........]..0...P .......................................v.{....On..O.w..-t..x<P....e.@0v.bY>.7. %c.\.h.J....MW......P.w.J...(...3^.....>M.............(WIH....1..../O}.}...gOm...{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.*6..(.........*.*.*.*.0...........-.r...ps....z..2...o....o....2.r...ps....z..2...o....2.r)..ps....z.o....,..o....o....-.s....z.o.....o......o....,..o....o....-..*.o....-.s.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):5.818260075879258
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:p3Bz9k7imvWiznlHnixQJhXbfMM/yTDl5GwiVmQD8HEIPCMBxQRxSfsxmAIi37vr:Nh9wimh5GObfn/yTJIhGkma37NwU
                                                                                    MD5:40A0212AF1723D130234B7BBCAA0D582
                                                                                    SHA1:851CF72667EE5A7906DC832762E4B73A0BD34487
                                                                                    SHA-256:0D3DBDCE73FF02E14B507944525DE062895E5F9D1961CE9D6BDCE5E02318371A
                                                                                    SHA-512:01329798A4146BC4C6B9F4897D04F9517CB5FE067FFDEBA36C06ABDE55C3F0717C4B708F4239C3301584F383311606A0460DC72A3DE76101F424EBDA6025E5F1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!................n.... ........@.. .......................@.......*....`.....................................O............................ ..........8............................................ ............... ..H............text...t.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................P.......H.......0z..|....................y........................................(....*.0..\.......~.......(.....(.....3...(......o.......(.....+...(......o.......(........o.....(......(....*.0..9........(.....%.,...i-....+...........(......i(.........(......*"..(....*Z.~....(....-..s....*.*..(....*....0.............(.....*...0.............(.....*..(....*..(....*z.{.....{....M........ZXM)....*....0..N.......~......{........{....M........ZXM)....(......~....(....,...s....Q+...Q..(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):549376
                                                                                    Entropy (8bit):5.964237858388747
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:oh57NfiIVOaoTWg3kEnZ+NpOHiVcDj/ICvIMwmIjiV49JjAfNHo7dlKoQ/:oh5wtT1kEZ+2Hi6WhvJQ/
                                                                                    MD5:98FF049A39021CED91144D20E8A46E75
                                                                                    SHA1:E9FAA61EF57109DF25E0E04F20A0158B42A9A04F
                                                                                    SHA-256:27672D1050DC906DEFE6668F9E8966706231DB707D4D7E2D7103C1F276753DD0
                                                                                    SHA-512:8B0CEF90E10B9E375C66B61BFB9F553BE26315EB675723ACDA12474ACFF2005B73DEC3B5FD0C4D4CFBE05C760D4FC03F9848705E84E77C86FD659AE20AA1E2F9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..X...........v... ........... ....................................`..................................u..O.................................................................................... ............... ..H............text....V... ...X.................. ..`.rsrc................Z..............@..@.reloc...............`..............@..B.................u......H.......pQ..|O..........................................................0...........(#.....}......}.......}.......}......}.......}......r...pr...ps$...}.......rA..pr...ps%...}......{.....{.....s=...}.....s&...}.....s'...}.....s(...}....*..{ ...*..{....*..{....*..{....*..{....*...0...........{....o).....,...s3...}....+...}......s<...}.....s5...}.....{.....(....o4....{....o3...o*....(....(...+&.{....o3..........s,...o-....{.....{....o.....(....*.0../.......r_..p(...+r...p(...+
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):711952
                                                                                    Entropy (8bit):5.967185619483575
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:GBja5bBvR8Q0TE2HB0WLmvXbsVG1Gw03RzxNHgKhwFBkjSHXP36RMGy1NqTUO:GBjk38WuBcAbwoA/BkjSHXP36RMG/
                                                                                    MD5:195FFB7167DB3219B217C4FD439EEDD6
                                                                                    SHA1:1E76E6099570EDE620B76ED47CF8D03A936D49F8
                                                                                    SHA-256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
                                                                                    SHA-512:56EB7F070929B239642DAB729537DDE2C2287BDB852AD9E80B5358C74B14BC2B2DDED910D0E3B6304EA27EB587E5F19DB0A92E1CBAE6A70FB20B4EF05057E4AC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...p$?..........." ..0.............B.... ........... ....................... ............`....................................O......................../.......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................$.......H.......x...(9............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X..+....b....aX....X.....2.....cY.....cY....cY..|....(......._..{........+,..{|....3...{{......(....,...{{...*..{}.......-..*...0...........-.r...ps....z.o......-.~....*.~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):78848
                                                                                    Entropy (8bit):5.940078992456604
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:RyP1jNOd3IEdih9JyPptMaHWKOZmR2obefWXT3eDFkpFL0w13MDzOfa0BUKTifB+:RyvGZUAaQQmR2k2KpFL0w13Iz5xkWQ
                                                                                    MD5:38F6FC962A2EC0F82CC82B92A7E1505F
                                                                                    SHA1:4A9954206350CC37F1C4C4C87EC2A1DB960C6B7D
                                                                                    SHA-256:665F15A83B027DA51C5071B81FF787BB6CDC89A7DC35E744F61326E55B12882C
                                                                                    SHA-512:373D5466C3CC9BD7DE2AD1AC269ACACD24709865688A8A44C0640E2A34341ED7F54C3A30F4403CBE497442C102D4EC5F97590A2D3AB9F6A3912A79CF2044F9D9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..*..........>H... ...`....... ....................................`..................................G..O....`............................................................................... ............... ..H............text...D(... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B................ H......H.......\5................................................................{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):43008
                                                                                    Entropy (8bit):5.5092202549262455
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:6aw3APZKsp8Us47hcl2WY65cpTS41404TrgwvIcW414Q4I:6a22ZKk7oLbIcB
                                                                                    MD5:80C441CC31210C4C6843EA5FD05316C0
                                                                                    SHA1:CA4799AA1E55DD995F6C0070944A6E74E026DB5B
                                                                                    SHA-256:BBBBC9FD5A8B674A0985A3FBD73C3F86EA43020EE227D2F730F901407D837018
                                                                                    SHA-512:7C7CAC148A9189CA43780351CB3205BD7ACFCB5AA7C6E6C77AC79BB91AF80C407DFC39AF797C7291C9268DEC4989C1C4FC979B0D9FC056300839A8FA08C04500
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0.............&.... ........... ....................................`....................................O.................................................................................... ............... ..H............text...T.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........B..@y............................................................{....*"..}....*..{....*"..}....*...0...........(......(......(......(......(,.....(......(......(!.....(............s...........s....s....}............s...........s....s....}........&...s.......'...s....s....}........1...s.......2...s....s....}....*..0..3.......sd......}3.....}4.....}5......e...s.....{5...(...+*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..-.r...pru..p.(!...*.{.....o"....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):16896
                                                                                    Entropy (8bit):5.272173882144138
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:HGL26y5LNCzgMxHtY7LfP/vzL1D7dvWkI9F9iJBvs:HdbNNCsMJKHzLXvWkciPvs
                                                                                    MD5:41E6678FDFD8CC38B8946AF5EA334C00
                                                                                    SHA1:9E1846138BAA23BE3FE68BBA52583D4C07DE18E8
                                                                                    SHA-256:8BD7A4AA6EDCD88A13D2582E22A4C5595DBA764CA61C739D2D0269F03D80989A
                                                                                    SHA-512:68433F4AAB72547F7FBDE21EB55B908CC258EE11611EB4210866B86FF1F7F87687FC77CF9CBEEE159F35B38996BD94A40B5D2B153D5C15C8E574387C45B4E9C9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..8..........vW... ...`....... ....................................`.................................$W..O....`............................................................................... ............... ..H............text...|7... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B................XW......H.......L(..............................................................6.(.....o....*..(....*..{....*"..}....*..(....(....,.(....o....(....(.....s....(....*..(.....(.....(.....(......(...........s....s....o....*.0..........r...prS..p.(....+[( .....(!...o"...,..(!...o#....($...o%...,..($...o&....('...o(...,..('...o)......(*...(+....(,...,.(....,.(....o....r...pr...p.(....*..0..r.......r...pr...p.(.....(-...o....8%...( .....(/...o0...,..(/...o1....(-...o2...,..(-...o3....(4...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):21504
                                                                                    Entropy (8bit):5.3805904454188225
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:TlGvUdvdFxVXl825RaL7+nNcnvY7OazcIZJZaGlMOrXYnpvg:0vY/xV18YMf+c4PzhaGlMkXYpI
                                                                                    MD5:35062F3A377A0DF03E3C2D5643341518
                                                                                    SHA1:545C2835538A0FA84B9F905224F2AFC5033B16C0
                                                                                    SHA-256:7F2C26BE3F655B23C0A74ED2E2C1859B1CB77F3B9AE8FAA08E1FB1934DFDA5D5
                                                                                    SHA-512:60EEA1F6ED2B05E1189DF010F3C7FF61154E816281B57EAFD0E39B429188B213272CB68E3D535D9CD8AF738B6B7BA2CB2514CADF15BFD9980B5EECBD7703DDEB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..J...........h... ........... ....................................`..................................h..O.................................................................................... ............... ..H............text....I... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H.......p(..8@............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*....0...............(.....(.........(........ ...%.r...p.%...%.r...p.%..(.....%.r-..p.%..(.....%.rA..p.%..(.....%.rU..p.%...(.......(.....%..rq..p.%....(.....(.......(.....%..r...p.%....(.....(.......(.....%..r...p.%....(.....(.......(.....(....*..._...*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*".
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):140432
                                                                                    Entropy (8bit):6.059133240260085
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:z5cEGcPGEuEz6C62cxocEt+7f0YuuriDjNcYEhPoBj2bRViOsPKJKPfqIn37nNfv:z4ciEl6pJ7f0YuuAKA2XcnCyKY+8rz
                                                                                    MD5:4CBC7B9D057E89C6A5BA313F6C2F036C
                                                                                    SHA1:BE57AE313DE841F987D0AE4CF9632E5F155955BE
                                                                                    SHA-256:EB8F7CECA9DFCA2080A8A9C30EBF49298778743F288A289970846D02074C5322
                                                                                    SHA-512:63077C81B1C0379FD86BC88571F8AEF227B449693C0B015BEEEABD99C3033C644F17AB089BBC55594C0FF98BD302C503C435B992DD7E83876CCB2111483CF902
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!..................... ... ....... .......................`...........`.....................................S.... ..`....................@....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B........................H............I..............%..P .......................................f.>dT.j.P..s..K..K...|"Y...r...^. ....}1k..mu...Q'Y......4..;b0.....\Y;....W...1..I...{...8...9M..-....,.......x...vG.IQ2..{....*"..}....*..{....*"..}....*..{....*"..}....*.sI...*"..o....*.s....*.*B.e...((...(u...*....0..........()...o...+..o....*...0..^.......()...o...+..,N......((...()...o...+o..........((...()...o...+o..........((...()...o...+o.....*...0..........()...o...+..9.....r...p.<...((..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27792
                                                                                    Entropy (8bit):6.1321477705881335
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:FBg0ucz9tgkgZWJkkgZWvvwKuk4WBul+S2vKURa5kMac1WkrzvXS9//0GftpBjBh:FBgbch/vxnRakBcbr+8iN
                                                                                    MD5:8AD746D4BB9B64AC5F0CE29896162259
                                                                                    SHA1:79041040D9CC0070B9DCE4026466B195BFF78EB4
                                                                                    SHA-256:F4043D2182666F67ACF71449EA60477DBDC577B1A09574ED6562A5C3FA6C42A9
                                                                                    SHA-512:D38CA6AE2133F231E89E15A7470E24D477F9D1DF7838E793FA427E048EBBADE1618EB08CDA30FFEC72080ED4EBF2EE2A897AB9D575C205EFBC4FCA92C88E0456
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....H...........f... ........... ...............................<....`.................................`f..K.......h............R..............(e............................................... ............... ..H............text....F... ...H.................. ..`.rsrc...h............J..............@..@.reloc...............P..............@..B.................f......H........7..............P-......P .......................................(>..P.^+..Vf.......y..Cd.^....kL*.C..d.....J.4.3..P3.}..1z...9...a>..uF..XR.o.(k.:.C3.R....:...../K%n..........e.S..(...........s....}............s....}....*..{....*..0..@........{....,..{.....{....o......}.....{....,..{.....{....o.....o....*..{....*^.{.........}.....o....*Z.{....o....u.........*..0..J........(.........-...( .....(!...*.("...,%.(........("....(#...o$.........o%...*..o....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.865639255366771
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:akOKSRVDKCJRCNdLnRWpnipnuncpt2JbJH0qV28xqNK7I2yd1u7qAGxhrGTEZmlR:akONl3eRngpnipnuncpMJbx0qV28xtCa
                                                                                    MD5:8576099B78B5A2B4371F5607C1CC4B56
                                                                                    SHA1:56959AF98B01B360DBBF247F0B01DDE4CE8D5C9E
                                                                                    SHA-256:A3F1B2DF20581CB7D64B008692939AEC45F4D7F6D8037F29F34D58AA14C2BD84
                                                                                    SHA-512:1717169904BB82D28B9B48DA167C960CE417B6F6983380ECD40B32418149B94AED3B6DA97F87FDDF47F887D0BA334F6A1109F750C87D81A0624B3ECFA21A48D5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e.........." ..0.."...........A... ...`....... ....................................`..................................@..O....`............................................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........"..h...........d<..X............................................0..r.......s......s.......+V..]..E............*...+:.r...p.(....o....&+&.rk..p.(....o....&+..r...p.(....o....&..X...2..o....*...0............o....o.......o....*....0...........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....,.(.........s....*r...ps.....o....o....-.(.........s....*~....*....0..b........o.....2..o......1"(...... ...... ...(.........s....*r...ps.....o....o....-.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23552
                                                                                    Entropy (8bit):5.296076848221744
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:J7ZrPZfvaob5PqTMGdAkNh5RgnlrSwH+JzO:fPZfAgPkP52nlrZ+Y
                                                                                    MD5:39EFF900514B54508575FAB39599FB25
                                                                                    SHA1:A5D527AC87B3A8D7D7C7CC2E1BF12E2448067962
                                                                                    SHA-256:392EC5F7DCEF0EFB95C4382637E46537ABDCE389C2499758F564DA16867D99F0
                                                                                    SHA-512:AD370CAF8B2FAAAF9F11176A19357BC6283FB1A6DDD5BC4597472077243053EE1B9273C62D91BB9495CF68898EA2B475B39E468D2B9B713A347ED3679F928628
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..R..........>q... ........... ....................................`..................................p..O.................................................................................... ............... ..H............text...DQ... ...R.................. ..`.rsrc................T..............@..@.reloc...............Z..............@..B................ q......H............A............................................................(....*.0..7........(....r...p...o...../3....o........s........s....}....*..0..;........(....r...p...o...../3....o........s............s....}....*N.{....r1..p..o...+*..0..7........(....ru..p...o...../3....o........s........s....}....*..0..;........(....ru..p...o...../3....o........s............s....}....*N.{....r...p..o...+*..0..7........(....r...p...o...../3....o........s........s....}....*..0..;.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):30720
                                                                                    Entropy (8bit):5.487658724802801
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:RrQiGJJgNIuhP8h1Oz0pQL8HCrR4ZOSrRTyEuu6eAEdBddFM:lBGJEc1OztL2C4NBpk
                                                                                    MD5:EAAB4BF6F12E7C8CE83079125D46D1CF
                                                                                    SHA1:A66EA182E9315289A6D73D2B7882642486B04261
                                                                                    SHA-256:B5A14083B406290E5E1FB1C7C209B24C13933B96F797CFF3BCD7118B0EBA2126
                                                                                    SHA-512:830C0A1A7930A8AC1C13461726988C5AB59AF3DB5A0E2401BF0DAF92CFC2ED85D941C0979304DA17F3D3A0D2BF5465BAE565C63B6049C0033F4A987F47A96328
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vR.e.........." ..0..n............... ........... ....................................`.................................P...O.................................................................................... ............... ..H............text....m... ...n.................. ..`.rsrc................p..............@..@.reloc...............v..............@..B........................H.......,=..$P............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*.(....r...po....,...(....(....*r!..pr...p.(....*...0..J.......s....%.o....o......(.....(....o......H..r...p..(......(.........s....(...........r...p..(......s....(..........(...+,..r...p(...+.....s....(....*.o......-.r...pr[..p.(....*(....r...po....-.r...pr...pr...p( ....(....*(....r...po...+..-.r...prG..p.(....*s"..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31744
                                                                                    Entropy (8bit):5.659269598716413
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:85o05vARIetCM94LfgbMPmyfgN6v1qGO4rLF:d0NetCM94LfOMVVv1qGOo
                                                                                    MD5:73D5A44E1A9627AC01BC22B6BE269887
                                                                                    SHA1:7CB9B3D105AD9AECC9F3252B38D5870C4AB39708
                                                                                    SHA-256:749734C73806CBD24898CD4FE9DBEF882CCE96A5FD3CA94C5CA246C9F9DA99F8
                                                                                    SHA-512:E5D43A9056CB07F6FA66C8EDCFD43A0F174D3432F00D2653173490F3F0FD062CFEC86F1F8FF3BD373812B2495206D0FC9AE2AD1BCA43F826A92FA3E06323A67C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..r............... ........... ....................................`.................................D...O.................................................................................... ............... ..H............text....q... ...r.................. ..`.rsrc................t..............@..@.reloc...............z..............@..B................x.......H........-...J..........<x.....................................................tE.......(....r...prG..p.(....*2.(....t....*b.(.....(.....(....s....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r:..p~....o....*V(....rp..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r:..p~....o....*V(....r...p~....o....*V(....r...p~....o....*>..tI.....( ...*2.(!...t....*b.(.....("....(#...s....*>..tI.....($...*2.(%...t....*f..(.....(&....('...s....*..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14336
                                                                                    Entropy (8bit):4.9314244617466665
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:FzP9VECr49b0mHsP86g8n6ZhMv11wE7uDzfpK2Ft/GjX3:dP9VL208sU6qniwEqjF1qX3
                                                                                    MD5:1F2D54F48C615F086E1CB19DD44FD97C
                                                                                    SHA1:1B97539D5AC39B7C989D8CD5CF8D71D6745287B4
                                                                                    SHA-256:3ED0A4217517B17E1459D649E4C3811865A4838E71508A953D777B2F9E16A4C3
                                                                                    SHA-512:6178AB1ED7D626186E879FDFCCF3833B68B47915D715AE9177DACEFB4B7B53869CBF8D2E8852079E5A8586E8E8DA8CE40D7DB1A4AF4D1A6372741228AAFAEFAA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0..............L... ...`....... ....................................`.................................dL..O....`............................................................................... ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................L......H........&..|%...........................................................0..H........o......-..*.o......u!...,...*.u"...,..*.u#...,..*.u$...,..*.u%...,..*.*..{!...*:.(......}!...*b..3..*......3...*.,..*.*~.-.r...pr...p.(.....*.o.......*..-.r9..pr...p.(.....s....*.o.....(....*.0..y.........c1..........*.E............#...A..._.......}...............8.....rc..p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r...p......(.....(.....s....*.r8..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):32256
                                                                                    Entropy (8bit):5.509801431083607
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:Q4+hvEDyN2j1LwCgWX4KxupnIZUCYXUQ4kfiVZBEaacR9mw7LbO6hY:G5EDyN2jxZ4KxPqCYZ0ZcomiLC
                                                                                    MD5:8E6A0501C3193D8CAC1C971DE3FDA562
                                                                                    SHA1:4FE5BB62C445EB6FD49AFBF437DAEA8B4A3C12AE
                                                                                    SHA-256:C7AF158CD6D3E617231224AD713A98228972E23E4C7D524808FB2789D2EF8D64
                                                                                    SHA-512:2973735866D7686A4AF01A2372A5ADE5B39874B9E017C74A21F10FE6ACB37C4961E50FA0CEBC7976DE30060C200B4AD15F4C3BFB858E3F5878E5D61CA2E376D9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..t............... ........... ....................................`.....................................O.................................................................................... ............... ..H............text...0r... ...t.................. ..`.rsrc................v..............@..@.reloc...............|..............@..B.......................H........>...S............................................................{....*"..}....*....0..1.......s.........+...o.......o......X...o....2....(....*....0..3.......sf......}-.....}......}/......g...s.....{/...(...+*..0............(...+...(....,...(.....+r.o.......d....e."+A.r...p.o.....P...(.....(......+?.r[..p.o.....P...(.....(.......+..r...p.o.....P...(.....(.......*..(....*..{....*"..}....*6.{.....o....*6.{.....o....*6.{.....o2...*..{....*..{....*..{....*..{....*..s...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):215552
                                                                                    Entropy (8bit):5.480542089734276
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:BW+i1u3AZ2YRCPJ4e3qHKSOZ53ZSOUE5Cgil7MEcR5hpGO5wZ+iEZUn1Bt+ZknSB:BdAZDCziyEs5Pib+ZknSTpc
                                                                                    MD5:50E6524B7EE9C2C93F5210B63CB1CA54
                                                                                    SHA1:3E296EC3BB24750833EA80515E6FB4C73874C91A
                                                                                    SHA-256:4C9615496970EA84320E2A6E99F8FB828E3C7790384DF5585D93FC368885D94E
                                                                                    SHA-512:F9D3B296E14D72F4BFF727ACFDCFB520AE1436BA5DED03BE04A559F493D4A8F9F915C0A2F498214309D0B84D6B3AE29750186615AE3250AD218AEB09DD7175AB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&w............!.....@..........~_... ........@.. ..............................ff....`.................................$_..W....`...............................^..8............................................ ............... ..H............text....?... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............H..............@..B................`_......H............>..................x........................................0..Z.........}.....E................$...+/..(....}....*..(....}....*..}....*..(....}....*."....}....*F..}.......[}....*.0..A........{....l#...`.!.@(....k.."..I.5.."...@X.+.."..I@6.."...@Y...}....*....0..*........{...."...@]..l#........4.."...@X...}....*2.{....(....*6..(....}....*2.{....(....*6..(....}....*.0..:........{....(......"....4..l(....k...Y"..pBZ*.l(....k...Y"..pBZ*...0..*........{....(....l(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):113328
                                                                                    Entropy (8bit):5.212181591929611
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:z9o2x9/b+S5QunlLrFV8FLjpnAwYxFBGPiV1uDxp454qd5kymiDuYszyW9EJP3fo:5UunVryVSFBGpBqfkzcWcxfr8vN
                                                                                    MD5:62D60CFC697E83E6646D5BD6E4CB1E51
                                                                                    SHA1:9F5F78A3738729D1D721E02CF31BED62DA27BFEB
                                                                                    SHA-256:01BA1D6A7EAF5CF39E33724B4EBA05BDFB4507B581E4789DEB59F1C473997690
                                                                                    SHA-512:F0069EEFB65762040E0C16AAC2768A7B459910E02554B4BB9E26C9EFC3892C5946F72B23D381CADCAD9A164907E3FDCF85903AA27C741FEDC854C4A2C40266DB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....p... ........... ........... ...................................`.................................<...O.................................................................................... ............... ..H............text....e... ...p.................. ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.509347235200524
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:WBX0TqVWFUM3HmOFs8mXXiA+L3Ad8DUntPKeUELxK2Yj7uIt:+ayIWmp2YeU4x5suIt
                                                                                    MD5:3684F924B38D4FB23DE40554ADFB1537
                                                                                    SHA1:E4FB7143ED7DFD2CAD2E379703808CEF429882BF
                                                                                    SHA-256:702444FCDE9AC6550E636A32678493E6835B247D8D8D344E2F803184F9F0EA45
                                                                                    SHA-512:8ACAED49F0204B8BEC8DD92D759F0E7913B447A53D0962FAE290A40EE36A20435EE7508E813EDCBD5A6BA1638385D235C64C1643052EDCA890D218DE3453606C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..0...........N... ...`....... ....................................`..................................M..O....`............................................................................... ............... ..H............text...$.... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................N......H.......p$...............A..@...........................................r.(......}......}......}....*....0..T........-..+.(......(.....r...pr'..p...(.....(.....{.....(....-.(....+....{.....{....o....**....(....*..0...........(....-.(....+.....YE............!.../...=...K...Y...g...u.......................................8......(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*..(.....(....*
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8192
                                                                                    Entropy (8bit):4.686310790005849
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:lKrvY5r86vkbfsPnZBlkeakXNvDQGYar8lgPoqIe9xF9xpHneTQDU:Yrw9KsPZBlQkXNFYK8CPo49BbHeTQD
                                                                                    MD5:E333CB2180A294D8B0B820FD307ED582
                                                                                    SHA1:D38D57248847E23C474A86B2448E15EB1FF0C71B
                                                                                    SHA-256:566919740B196E00049AA6826805F9E40F8A7E7AEF27A17CDD8BE9F5C9EF2B87
                                                                                    SHA-512:ACEE7E93C97B7A1C54A998BCDF13086FBC4616CA0A7EE522B1336E04D0EF1A3858F1E6B60DBAE93E6C41347031817557844E10D5FE5DC9C8AB535D431FF499E6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0.............R5... ...@....... ....................................`..................................5..O....@.......................`....................................................... ............... ..H............text...X.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................45......H........!..T.............................................................{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*BSJB............v4.0.30319......l.......#~..........#Strings
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):108168
                                                                                    Entropy (8bit):6.179559450110609
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:hf+YSZc1rj0oek7u05g3XG5rs+eUvNL3NX5S8caZkvsd65FAU9Qyx1NElSJK/Tr:R4ZYrj0oeOg325ragNDNP+AUzqSJMr
                                                                                    MD5:3034CC0D5CF3731ED90153AA616F3F59
                                                                                    SHA1:AACE8D26358D9829F0E6632BDDF183534ACFEC0D
                                                                                    SHA-256:63CD5E8A60D77D1007352538A4285C60C0C3EFB9C771035589105A284E4F63A9
                                                                                    SHA-512:88589B022D713D565342E331394ED5600D1FE346AA788E45E16CF51221CE898F10BD28C6A09FDC44D9AD94F25B4ED22C6F0EB28FA832863C01732DEF5B6C6086
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X."Q...........!.....^..........n}... ........... ..............................C.....`..................................}..O....................h...>...........{............................................... ............... ..H............text...t]... ...^.................. ..`.rsrc................`..............@..@.reloc...............f..............@..B................P}......H.......L...................1...P ......................................Am.........C.....7.7....|..........,...w?..T....A.e......I}.#N..E....~...y. x`E......C`A&P.....Y.....A..J......#.p..).uGkJ1:.(......}....*:.(......}....*...0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*"..(....*"..(....*..*..{....,..{.....o....*.{....o....*2.~....(....*6.~.....(....*F.~....(....td...*6.~.....(....*J.(.....s ...}....*F.(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18120
                                                                                    Entropy (8bit):6.226050809869831
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:U0xk42ZtyyslnQyrgbPyIH/rFzsX+cAW++2Wx1q//0GftpBjIc0:DVegwRe+c3S8iC/
                                                                                    MD5:E834E45855E8D220B0C5D0C1CAC24E44
                                                                                    SHA1:D8AAF831CF5B90A206EE9348386A72498AF0C0EE
                                                                                    SHA-256:78AC70411C71B7A0C68FE8746EDD3F3A8CD3F72044B329A40AB53C57891BE37D
                                                                                    SHA-512:F91A3FA6D522AD5F977AF744618D5ADC1A6CAEA0645D870E10962E00C03534CC3A9FA1D82001627F5B6FC3186BD51E3E69D16DD689C5E7CD4D84AC66AE9A63F3
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......R...........!....."...........A... ...`....... ....................................@..................................A..O....`...............,..............T@............................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........&..d............$..O...P ............................................V.{..(.;.X5..b.2X..L.{.z7t.P1).qf...w.g....ik..:.5a..J.FK.e..mSgn9.cQM..9.B..ZLSy@..j.e...Z.......6..c.'...m1.{....(....*"..(....*&...(....*v(....-.(#...s....z~....o....*.......*2~..........*&...o....*&...o....*...0.............o............o.....s....z.*...................0............o...........o.....s....z.*................^......(.....o.........*^......(.....o.........*.0..<.......(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):338944
                                                                                    Entropy (8bit):5.8207026443713925
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:KDjDsu4bFgg64r+85o5LQciAiQ7qKC26EX3:mjYu4bFlkQc1
                                                                                    MD5:52F43683B23D23EE15E3A6423D1B5793
                                                                                    SHA1:8B4176792BC3A3C3BE21077B5D2C8052FF4D99A9
                                                                                    SHA-256:6A5CCD1A4EF6B026A8ADBC9F36394287AF49097152D57C036DD7697C06BE549B
                                                                                    SHA-512:11B3AE3217F2CAB7C8D044A24F29C30A862AE981BA0F0DF0C536EFDA386C9BED81A4B9F9910E5CB4625E4CFAFE9949692B4E634C3601AB923AD4AC9B9F5C659C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$.............!....."...........@... ........@.. ...............................d....`..................................?..O....`..............................d?..8............................................ ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H.......................................................................(w...*b(.....3...(....*..(....*j(.....3....(....*...(....*:..-..+..(....*..(....*...0../........s....(......+..(......s#...o......X...o....2.**.{&......*...0..C........{ ....0ci ...._.{ .... ci ...._.{ .....ci ...._.{ ...i ...._s....*..0..L........{&...,>.{&...../ .....{&.....cX.{&... ...._.c.{&... ...._s....*~....*~....*..(!...*.0...........|'.........(.... ....(....}........|'.........(.... ....(....}.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.357923587403832
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:RjVpfnzRJQH1NEiNJ0yIac6kWXrBD414UNZ414+WM:DtnzRK/EiE2V5N4140414S
                                                                                    MD5:76FABC663514D1A59D7179A5302A4B7B
                                                                                    SHA1:B040C021F3F4F33F38CD55EC2CEBA83E2BF9D416
                                                                                    SHA-256:97ED2B5838BD07AB63DB59081E5686AF7355994B3A48F5418358CD6B5A71F9C7
                                                                                    SHA-512:DAB153D0F6449437D32026CAE16DEC80C5E691DF488B25DC0B0D68600EC2A1A913F9D07564CF2F03D8D7813A9E27DB339B3649E634F347BF1AD621D4485AA611
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..P..........fn... ........... ....................................`..................................n..O.................................................................................... ............... ..H............text...lN... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B................Hn......H........,..DA............................................................{....*"..}....*..(......(......(............s...........s....s....}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*..-.r...pru..p.(....*.{.....o......(.....(....*.0..........r...prJ..p.(.....-.r...prN..p.(....*.o....-.r...pr...p.(....*.s....(.....o.....+...(......(.....o......(....-...........o.......(......(....*.........O.!p......br...prJ..p.(......(....*....0..........(....rM..po ...-
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):358912
                                                                                    Entropy (8bit):5.887222802567272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:CCq8eBDTLHitSpUWF7oqtnTawrJqSceW47Xx1367A:LdeB7idWqqteMLD7q
                                                                                    MD5:9277D6A62D6A0E8E47C3E6A604E89A8C
                                                                                    SHA1:0554F579C4E609023AEDDFAFF200D8FC12AE0EAA
                                                                                    SHA-256:348CBF741BF59C360B2598574C10C71B4D9B40FECF48E96CB023FEF26A2F9574
                                                                                    SHA-512:A385393BC1EA618CCA05C3E8568E53A8970B40427223B3C3258C60B326BD93B2CFAB9A72AB5767FD5961752B808EDF063235040000A11BBE1F132008F7A68C07
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......M.-...C...C...C.O...|.C.O.....C.O...&.C..:....C..:....C...B.^.C.t.....C.t.....C.......C.t.....C.Rich..C.........PE..d...s..T.........." ......................................................................`.............................................t...t...<............p...$...............%......8...........................@...p...............(............................text...z........................... ..`.rdata.............................@..@.data...X...........................@....pdata...$...p...&...,..............@..@.rsrc................R..............@..@.reloc...%.......&...T..............@..B................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):120616
                                                                                    Entropy (8bit):4.8681605086520445
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:93cL13tS8RDNugFR/6yi52SX08caJPwrV:yFtXRAgn3iwS1cYg
                                                                                    MD5:C5429024EF37DB3D20E09B8033CCAE2A
                                                                                    SHA1:FCF4C53ABF79CC196CC356D624A86FFDFF387AE8
                                                                                    SHA-256:E077F4ED5B7791708D4854B5CA290910168427767E3C02F118BDA767B5099561
                                                                                    SHA-512:6B376B5C5D0D157B87645C4FC7AD1B697C55DD16C2BB84CA3980A2E0192E552D8C03454EFB9903615036EB69058B7F730AD7B9A4A26EE101217179A3786AD521
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p.......#~..d.......#Strings....d... ...#GUID...........#Blob...........#Pdb................../....3....:...............9...;...C...%.../........... ...,...<...F...............(.......................!...$.......................N...X...................k...u...e,..o,..j/..t/...1...1...2...2...3.. 3..p3..z3..24..<4...4...4...9...9...;..);...;...;..1=..;=...=...>..U>.._>...>...>...@...A...j...j...o...o...s...s..]v..iv..Gy..Sy..Sz.._z.....................:...F.......%...................^...j...........4...@..........................u....................P...\...........9...E.............................X.......................................................................D...............A...V...............[.......................................=.......X..._...f...m...t...{...........................................%...2...D...Q...^...k...x.......................)...Z...................'...D...R...j...........................:...\...~.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4170752
                                                                                    Entropy (8bit):6.81456353807605
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:psmQ1qsmn1285Ar5l53yTOrYC0r5h3CkicAiDQs2cAfDhx:s1e1/5O5QscA3bcAFx
                                                                                    MD5:88CD35BFFA2B7F0A2DEA256245873BCD
                                                                                    SHA1:FD218530A53ADF8470FB3365987210BF3FC59460
                                                                                    SHA-256:D35FB22B4E841029511ADB45367B0A739EE7C131A58937EC64F8A9C7B5A14596
                                                                                    SHA-512:63D74DA9292FC9C8F64920747E689C3F6F4CB15EDE06C560BB2A516F9DB7EC610205BD036E287950929D68133E0824BA1D1B4190FD8ECC4A2C5840B2E0E6619B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...{R.e.........." ..0...?..........?.. ....?...... ........................@...........`.................................p.?.O.....?.`.....................?...................................................... ............... ..H............text....?.. ....?................. ..`.rsrc...`.....?.......?.............@..@.reloc........?.......?.............@..B..................?.....H........ ...............@...x?..........................................0..'..............,.r...ps....z.~..........o.....*..0..)..............,.r...ps....z.~....o..........+..*.r...p.....(.........(..........s....(.........*...BSJB............v4.0.30319......l.......#~......<...#Strings........$...#US.........#GUID...........#Blob...........W..........3................J...............I.....................................h.....h...Q.h...".6.........8.................a.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):12432
                                                                                    Entropy (8bit):6.213812838430843
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:C349VlDs8a3XUVW2itvXS9nMTI/s/nGfe4pBjS735:Cq83XUVWNvXS9//0GftpBjU
                                                                                    MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                                                    SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                                                    SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                                                    SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):274944
                                                                                    Entropy (8bit):6.122733859346656
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:IyfsmUCs3Zchh2UBSFKu033XbEUsHBEAT0C:Iy7UCs3Z22UXuwbkHBX
                                                                                    MD5:C52A44933D17D576D4C97B4CB0545841
                                                                                    SHA1:092696FDCC034910AA02C94A5C93F4E1E86E0C50
                                                                                    SHA-256:A0AF255EA4B09A8CDB995B8C6FD1075E46F098E23C2351C974E6DED9B8B620CF
                                                                                    SHA-512:8273DDB86A54C4834D469BBC856D1793C86F2577E21411F30083D4E597427170FD9CA38DA2E86F081D284043D5EA4A6D3330037EEDEDD17E37AA885927D0A76D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!.....(...........G... ........@.. ....................................`.................................8G..S....`...............................F..8............................................ ............... ..H............text....'... ...(.................. ..`.rsrc........`.......*..............@..@.reloc...............0..............@..B................pG......H..............................L........................................(....(....*..(....*..,..(....&*.0..1........{......-.r...ps....z.|......X.(.......3...X*..+.....0..9........{......|......Y.(.......3...3..%o....o.....o......Y*..+.....0..9........o....t........q....og.....M~....(....,.~B...(P...*~;...*..{....*"..}....*:..}.....(....*....0..[........(......}.....~....}.....{....,:..i........}......(...+Z..(....}......+......(......X...2.*..(...........}......(...+Z..(...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144384
                                                                                    Entropy (8bit):5.844902667019692
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:RBl45K8NHxwWqEPr2Pvuy5RIh+7s5j2H6JzV7rNx/E8/+8zMma/v8GK8V2/j/h8J:eauy5Rs+7LH6JzV7hPMmmJ6mT
                                                                                    MD5:0537BD9641501778C62A1392DD5C78A6
                                                                                    SHA1:02B058E6E30EC22BA6A0AFF616EE6A51E3C4F43C
                                                                                    SHA-256:08D55AF73DF042926B0BF49B99678B00E118EA4FD140BEEB209B1AE15BD4E52A
                                                                                    SHA-512:935D73825F73C6E009A67E55C88A09DF1841432643572C334EBAEE5B9B141A6A213C2F291EAF804D9E20AB14120B84B3F1CB47612D48D45AD4CDABB008D9BB45
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........." ..0..*...........I... ...`....... ....................................`..................................H..O....`............................................................................... ............... ..H............text...T)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B.................H......H........b..$............Z..............................................V......tq.......(....*2.(....t....*...(.....(.....(.....(.....(....sk...*..(....*"..(....*&...(....*..(....*.~....-.r...p.....( ...o!...s"........~....*.~....*.......*V(....r...p~....o#...*V(....r...p~....o#...*V(....r>..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*V(....rZ..p~....o#...*V(....r...p~....o#...*V(....r,..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):139888
                                                                                    Entropy (8bit):7.142634633787823
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:TNZyjlo+Ib/RorkWhl/pNODb6lwztxdbbDFlkYUo8:TNYAb/2rk2l/jkb6uzj5Qo8
                                                                                    MD5:18DB3E02D95A16FD502C7C091C0361D9
                                                                                    SHA1:AB2D700306E0A0A3D094A0BC856FF1FFAD916C49
                                                                                    SHA-256:34843CFEA24B713B1B5FD9A93C61D7C6D3FA320DBB84DF60D9D48C5560C79452
                                                                                    SHA-512:6DE8751ABED256BCC381F69248F33AAE551A17966EFBC0ABB5C1DC98865B46E3924202C1347E0EC6949F1719E1D282817838815E99E68E7B1381A6B204C95416
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...]."Q...........!..................... ........... .......................@............`.....................................K.......................p>... ......X................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......X....K...........M..._..P ......................................Du..l..O..(|.n.....z.fj.W4.mc....f...>e..~.V....<../..}....1$q.7@r..3w..JQ....._C(S....C. .Z.Pt..d,......f-..]..".SO.7.4...x.0..:........(.....s......r...p(M...o.....(.....~....(.....~....(....*F.~....(.........*J.~..........(....*F.~....(.....+...*J.~......+...(....*.0..,.......s.......(....o......(....o......(....o.....*F.~....(.....+...*J.~......+...(....*....0..3........t.......(...............#..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):173568
                                                                                    Entropy (8bit):6.12032044473592
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:QdkbCx9M2UJtDEbsJgNhnTK2Gu6asmzjewiZc7YgaxYU9:QqC24bs3YEAU
                                                                                    MD5:E47489D595CCD60356287B98BA2588BF
                                                                                    SHA1:7FA67EC95AF6D9AC4AAFBD296D7BA11DB9F1524C
                                                                                    SHA-256:5DAA9E04010A89BF749FDA2BAB4395F0A9449F8EF780D78D602E48B2DC61FEFA
                                                                                    SHA-512:34A12BF7DEC1A752E106B862F144FB32CCEB26D4DFC2CB13A239763CA1784B0EAE8673C2E47492CD1FA5A3F8D7E75DA686F19325F4F527805AC699B2A6C8385D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ........@.. ...................................`.................................D...W.......4............................................................................ ............... ..H............text........ ...................... ..`.reloc..............................@..B.rsrc...4...........................@..@........................H.......D................$..(...8.......................................".(E....*....0...........(....*..0..@.......~....-3.E.........-......&r[..p.....(....%&o....s.........~....*.0..........~....*...0................*..0...........(....*..0...........( ...*..0..........s....(!...%&t.........*..0..........~....*...0..G........(......}"....s#...%|$.........}%....{%....{%...}&....{%....{%...}'...*..0............{%....((...*...0..}........{&........{$........,1.E.........-.....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.762661257689725
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zRWAtSQqSbmIl3kn75fCN7RHQSFl+ouzQLxdETbSqNNDZ+GclRq3zQ6SfJtkinNu:tWwSf6mw3k7yFqhzNNiRTkin6gNb69d
                                                                                    MD5:C7F090DF56B4B7F00FBC30BE93E19CB5
                                                                                    SHA1:762A1352B78DA7970367094C4EA1DE2119BA03A0
                                                                                    SHA-256:A0B5A4E0D399D0E848A8B2CE2C9DEB3B8F2ADF0411C4BAFB066CF4646595512C
                                                                                    SHA-512:EBB747416375D393BC981D7A7C3182A4FA6A29D675C8C7366A0A1E2EED2A5D60BFBA6194C8C6AEA6291456EB6048C69CC1557DD3FFA1E330B55E36431A0DF61F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.."...........@... ...`....... ....................................`..................................?..O....`............................................................................... ............... ..H............text.... ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................?......H........$................................................................(....*"..(....*&...(....*&...(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*...0..+.......r...p..(....,.r...p.r#..p..(....(....s....*..{....*"..}....*..{....*"..}....*J.(.....s....(....*.0..O.......s.........+...o.......o......X...o....2.......r1..p.r1..p(.........,..o.......*.........<B.......0..M.......s.........+...o.......o......X...o....2.........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):144496
                                                                                    Entropy (8bit):6.219127874938619
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:0RZlEOzBzB3yZwUDXSNhB+IIx3zUOEF7xQQwQQQQQQTreulTnXGZFfHjKUhcweTo:0RUONhhUDyhB1IRUOEoUjHBhT/nLN
                                                                                    MD5:5BD39A82AACF1AA423E6EEEEDA696EEA
                                                                                    SHA1:B7971F9807520DAC9523BFD1185A7DCC9E5CC77C
                                                                                    SHA-256:1D69EAF538008E0FE1A7EB2CE0124A49B95C491797749640C8351ED4643F5C97
                                                                                    SHA-512:CBD255E7323A7E82D8B9443E8CE67BEF88F88BF46E525333E4017024A31952656F61F93334B3957D85FB0E422E561197C0ADB1366653DA007C9667651B1F37B1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[."Q...........!..................... ... ....... .......................`......a.....`.....................................W.... ..................p>...@....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......$...h...............c...P ...............................................\.E..-.....A.}.8.p. 0AF@4.....T.P\...S.aEf.....$..m..G.h......Q.,.2....N..jE...QD.V..<i<(*".\q.7_..;.ge. Q[..P..{....*"..}....*F.o....r...p(....*..0..C........(......~....-....7...s.........~....(...+(...+(.....(1.....o....&*F.~....(....t....*6.~.....(....*F.~....(....t....*6.~.....(....*F.~....(.....j...*J.~......j...(....*F.~....(.........*J.~..........(....*F.~....(.........*J.~......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.0786290349934315
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Cf8wjVl9lOPAmVqzzNBdu3DPxXEvLCiDfp6wZ8ETV56hjRUA8qbC/We3nebPLqX:TjGImk/5Q1EewZ82Vwjc2Ceu5O
                                                                                    MD5:649DFD82FE2569BC5873F0715AA545CB
                                                                                    SHA1:9D2A506C841D233C32DCF39506D5EAC7EE60B97B
                                                                                    SHA-256:7411B7C9E368E1CEE613FE97728D504E31D5F2091D11951A4DBEB88A9551BCAE
                                                                                    SHA-512:217FCADEF712A7DE2DCDF7A1036EB50AE47EC752400A1A7EFA3BB4A49F7276E3BDDCA03FA5044513DC06378EE1AEE1527498DCC534AA9D16A4873DCDCBDC5C00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..............,... ...@....... ...............................>....`..................................+..O....@..4....................`......|*............................................... ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................+......H........ .......................)........................................o.....o....o...........(.....o...........*.0...........(...+..,..o....*.o....*.0..E.........o...........X%..o....2..*..+ ...o...........X%..o....2..*..X...2..*...BSJB............v4.0.30319......l.......#~..(...x...#Strings............#US.........#GUID.......T...#Blob...........G..........3..............................................................5...............K.................1...........k.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):20480
                                                                                    Entropy (8bit):5.12438911804574
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:9/raLgzj2a2VtNY6gA2NGiQEt1u2UUAxT:J6Ba2Vs+intc2U
                                                                                    MD5:4E14602466E04BA26B85799C7B583135
                                                                                    SHA1:35BA198DFBEDD4E9E2A14315EDC985518011E5AE
                                                                                    SHA-256:E4382B9036CC9A50558992245D5AEDEA247567FD87E24D2CC318AA47A0898B34
                                                                                    SHA-512:054A8FD1F6218D1F2E85C46244EE2C9EA7C5D93353EA615A7F2D32317FFF7EDB6A2612270CB8621D9DA76634F8645A459FC075CFB970D028EBBD9C00DC131238
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..F...........d... ........... ..............................@.....`..................................d..O...................................tc............................................... ............... ..H............text....E... ...F.................. ..`.rsrc................H..............@..@.reloc...............N..............@..B.................d......H.......X-...5...................b.......................................0..............(......-i..o(....o......(....,.r...pr...p....6...(.....(....+R..r...pr...p......%...%...%...%...6....(.....(....+...r...pr...p...6...(.....(.....*...0..8.........(.....o(....o....(.....r...pr...p....6...(.....(.....*.0..............(......-i..o(....o......(....,.r...pr...p....:...(.....(....+R..r...pr...p......%...%...%...%...:....(.....(....+...r...pr1..p...:...(.....(.....*...0..8.......
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):42824
                                                                                    Entropy (8bit):5.092626203240039
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:wIla9Y6ZBiygU1v+cALYbshPln6wWxwAU/fHKcnLQ8:CO0zWcQEIlnxF66
                                                                                    MD5:2883C3A35927E62EBE1871C130E93F31
                                                                                    SHA1:1A7C10AA582CCEEBFFD9BC77A11353AAAE6417E9
                                                                                    SHA-256:4109CFFF6E17D9BD2EFDC7FD52A4F544B5C66C9743C9E8CCF7D8A2F6CFC23EB7
                                                                                    SHA-512:9BC6CDAE59163756F9110867353E513CF53003A2C171E9458D920D83A8D025AB9DCFFC3278309223E9BA257B88CDB3F7F5C23BA78BB8CA4168B74F91DACE8658
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....M..#~..0N......#Strings.....T..0...#GUID....U...M..#Blob...........#Pdb.......................3....P...l...H...;.......T...........4...<......."................................... ...)...6...?...........*...3...................$...-...a...j...............&...........G...P...k...t...................{.......V..._...................................p...y...................................c...l............'...(..=(..H(...(...(..6*..A*...,...,..r-..}-...-...-..........B/..M/.../.../...2...2...3...3...4...4...5...5...6...7...8...8...:...;..R;..];..@>..K>...?...?...@...@..UA..hA...A...A...A...B..JB..]B..}B...B...B...B...B...B..EC..XC...C...C...C...C...D...D..gD..zD...D...D...D...E..$E..7E..]E..lE.._F..nF...H...H..5H..DH...H...H...I...I...I...I...I...J...J...J...M...M............Q...........................7.......................................,...9...A...N...V...c...k...s.......................%...6...Q...]...j.......................................,...l.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):16896
                                                                                    Entropy (8bit):5.247338576691855
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:vdJ3IjBFsPlq0IBDDH2ACrgB6v2nJx9Q37/CkJGrW/6kTjWAz9hiumRKD1lXx24w:lxIjBFsPlq0IojWAPFDw4x+SWdNF
                                                                                    MD5:02CE84F4413B727980DE576904D03FD1
                                                                                    SHA1:81240B2E213AE2A4517B425B72D01A8DDC72A398
                                                                                    SHA-256:B1200417D0AA644E06CE037D3816881912623B4A7BADF6D45960C11A05515925
                                                                                    SHA-512:E634134E1FF45C9FB5F2110166D6E1D29685D6A96AAF52F8126BFC3DFF582319EEA930A3E4AD0B3DAA5976CE9C2158F8A71B5954B9A07CBE427E043B01980EB5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....v..........." ..0..8...........V... ...`....... ....................................`..................................U..O....`...............................T..8............................................ ............... ..H............text...46... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................V......H.......($.../...........S..@...........................................V......t7.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*"..(....*&...(....*..(....*.~....-.r...p.....(....o ...s!........~....*.~....*.......*V(....r...p~....o"...*V....t7.........(#...*2.($...t....*z.(%....(.....(&....('...s....*..0..s.............(....((....)...(*...tB...(+....,...(*...tB...(+...(...+(...+(...+..o0....o1...,..(2....()...o,....(3...(...+*F...t7......(5...*2.(6...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):278872
                                                                                    Entropy (8bit):6.160790996358575
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:W8VV2gG5QRPQiIK+58lx3F4ZSnDdNbOFZxAK8Jy5TALKSLm/sHOjrBFC95:W62TqBaKC8lBgSnDdNomKvSLCsujrW
                                                                                    MD5:6813EBECD58E557E1D65C08E2B1030AF
                                                                                    SHA1:4DC95C499CBE862D4C6A4FCCDE71B2869F07E279
                                                                                    SHA-256:895819BDE598F710ED62CEE50E8BAC05EEFD42DDA64DE60E7D8DE8898082CAE4
                                                                                    SHA-512:0BC8B0AF27D565F604F49733BF5BF643F360F1C78FC29335F3415329C93DFAF4CDBC2923DCD1D3025249A64291C112893468B3DDD7BBF2050F8E671AA7ECC96E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!..... ...........?... ...@....@.. ...............................D....@..................................?..K....@...............*..X....`.......>............................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................?......H.......,....U..............9d..P ........................................./T.#<..G.M...&tuW..|.......5...n.NB...6S.&}I.......$I..7.....g....g.....8.t'..@K9...0g[.6~.l.2...m...e2...iN.qO7...<...>...Y.0......................#........(.....*Z.........(......(....*..{....*"..}....*..{....*"..}....*....0..7................(.....(......r...ps....z.(.........(....(....*..0..`........u....-..*.........(.....w....(.....w...(....-...(.....w....(.....w...(....,...(.....(....3..*.*R...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14496
                                                                                    Entropy (8bit):6.327509765949796
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:rb6Oaxhqm1st8jjMfGkqWx/zB//0GftpBjcc3:rCwUQ8jjenj8i53
                                                                                    MD5:964AB2C3520B8A735329F0BE577C5850
                                                                                    SHA1:968EAB9103EC64A0DD4657582F28BB6FE9644209
                                                                                    SHA-256:DA3ABFEE09DDE110E4E9A0321F7223F7380A1052CB506313F44947E32F09BB5F
                                                                                    SHA-512:0BF393D15E64FB1A2BC0BEF663DD760E3ACDFDA503AEA185A83B904B01D612FA3AFFE7FFEC8780C23274D9B8E182B29CDD906CF8A0825569AB02ABBF4DE0AA61
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....="S...........!................>4... ...@....... ...................................`..................................3..O....@.......................`.......2............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 4......H.......(#...............!..X...P ......................................;.)%.6.h..q..O(-.`......&7.q.G..G1..J...S1.&..f....H.....bl....W(.E).K.RI..............8&Q.b......H+!df-.f..3h.H..h7|.]...(....*.0..3.......~.....(...., r...p.....(....o....s...........~....*.~....*.......*V(....ry..p~....o....*.0...........u!.....-.r...ps....z.(....*Z.,..~....o.....$...*.*V.,..~......$...o....*.r...p.$...(.........(......$..........s ...s!...("........*...T..............lSystem.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):52736
                                                                                    Entropy (8bit):5.808970555867579
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:R+M1eCjCIrV3Qb2io4UOi15pO/V/R1WpiBqCF:x0CjTV2UOi1PO/V/R1WiZ
                                                                                    MD5:C26777BE282E371083A6FDAF09C9973C
                                                                                    SHA1:4593FC1E827B9B9E1FBA578CBE1C47CAFA87ADDD
                                                                                    SHA-256:A2D6DBDDF64917C29601957C542780B4BAE82D576AC8AF47870489AC61C45F48
                                                                                    SHA-512:F784444C9787FA7E097CFD4EDC86435C61455653D48B7677769BDDE67C7F526F16D16D0D6B6AD5127457F10E639A157F906BCCABC27BE33A5864DEC0BFC0ED8B
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....k..........." ..0.............F.... ........... .......................@............`.....................................O............................ ..........8............................................ ............... ..H............text...|.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................&.......H........4...s.............(9..........................................V......th.......(....*2.(....t....*...(.....(.....(.....(.....(....s....*..(....*"..(....*&...(....*..(....*.~....-.r...p.....( ...o!...s"........~....*.~....*.......*V(....r...p~....o#...*V(....r...p~....o#...*V(....r:..p~....o#...*V(....r...p~....o#...*V(....r...p~....o#...*.~....*..($...*Vs....(%...t.........*V....to.........(&...*2.('...t....*z.((....(.....()....(*...s....*b.(.....()....((...sn...*F..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):185544
                                                                                    Entropy (8bit):6.1143984102987075
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:I8eNPCLiHSIZ8gcAx081w88sss9wNACJ1xZ7iOo7EM22PBdc:xeF5HSIwHACRVS9P8
                                                                                    MD5:589E1B764C0DC53BF645054960626AB1
                                                                                    SHA1:A5616537CA4E4AD5EB0BEB48863AE65E9EA91080
                                                                                    SHA-256:1C7FA94DE5E727852934387B6B0094ABC16F660C6C91B38FB3F5BC580CFBDC1F
                                                                                    SHA-512:DFD6924DD7BAF7EB1B8D3CC862FD7FB4A311818EE5684C7A85E3106EAD0F3DAE2A79956AAD9B5404C88A1D2607CAD627D0EFD729E9A9C1C1425B907884FBD1D7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...E..T...........!..................... ........... ....................... ............`.....................................K...................................h................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H......../..............p...u2..P ......................................d.G..n.y=.v..].....Y...wE...#.".q[...f..N....k.:sj.D...q.`6o.........A..zt..P.6.+..{8....(...'_L[...X....~..yr....Z>/..t.8..0............i...X.........o.............*..0...........u......-..(...+..*..0..$........u......,..*.u......-..s......s....*.0...........u......,..*.s....*..0..$........u......,..*.u......,..o....*.s....*B...o.....Yo ...*....0..<........o!.....E............+..........*..o".....*.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):61440
                                                                                    Entropy (8bit):5.4953592987125335
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:v1P9PM1EO9m30XOgj6sogR/nho16ATIdYOrvQ7NR6KfgB1XxLP8uQ9O3rJt/EjBc:9PVM1i0XlhLATIdY1z5gBMuQ9On/Ky
                                                                                    MD5:E520C02EE6A83ACFE58CD9EDB296E392
                                                                                    SHA1:665A83902C560C610F1F34108742551F1E4F7BCA
                                                                                    SHA-256:A729B344885A5F7F7F09A6D6EF2B9AE86E643BBC118EA60B27CB08AE0991705C
                                                                                    SHA-512:E6EA3148DBB182909790BADF66EE0C9F4BFD5B3B624BAAE13AE4EE85CA89A44A4C1C39D4A25A72A53C1BD55DE647E9D0081DCB6AF82F05D566C300D53D831E0E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.................. ... ....... .......................`...... h....`.................................t...O.... ..,....................@......<................................................ ............... ..H............text........ ...................... ..`.rsrc...,.... ......................@..@.reloc.......@......................@..B........................H........c..8............................................................0......................(....*...0..+.......r...p(......,....r...p.......(.....(....&.*.(2.....(4......(5..._...........(...._*..0..........................(....*...0............................(....*.0..(.........r...p(......,....r...p........(......*.0..).......(2.....(4.......(5..._............(...._*N......rQ..p..(....*R......rQ..p...(....*B..........(....*F...........(....*F...........(....*J........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):34752
                                                                                    Entropy (8bit):4.846700052298754
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:JNne+E628lTYV+5Puni3MKW6kqQ9aRrwytEc8nl0FXGwxXl3kKjF2kCkB72KRleh:je+E628lv5Gi3MKWNqR928ksF2t4lg
                                                                                    MD5:44E3CF00D4EDA7F4AA38044D578AA537
                                                                                    SHA1:D73E59804E3EE494A4612185771F7F67B2FD64AE
                                                                                    SHA-256:ADC6991011DA455E001F537DB1970B2208D960BA7E66D4D4A534D293235B4463
                                                                                    SHA-512:B83080B7968E5B32DD7B1BE70EB7F9BDE797DE248A5B4C5C94EEA6EC0342AD8FA78B4FF46E63835EDCA340C3F3B254044F0348BC84F728EDD37DB1EC223030DD
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p....B..#~...C......#Strings.....J.. ...#GUID....J..45..#Blob...........#Pdb................../....3....#.../...............4...<..................................................."...+...........O...X...........e...n...I...R...........'...0...x...............{.......................&.../...'...0...................b...k...........7...@...................................6...?............ ..& ...,...,........Q...........................-...9...@...L...m...................t...............................................9...u...............E...e...............................@...G...T...\...d...q...~...........................$...m...y........................... ...O...........................!...)...K...............................J...j...........................g...}...........................$...+...2...9...@...V...^...f...x...............E...R...Z...m...z...............................2...Z...g...y...............................,...>...P...b.............
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):298496
                                                                                    Entropy (8bit):6.531291714253338
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:udNe8OCNTjBES0Ib6D4b3HlsmrS+Gv6k59:udNe8OCNTjj0Ib6DAHlsczSl
                                                                                    MD5:830DB1F25A4D2B13668FFC7A7B7B7821
                                                                                    SHA1:2C968750C2B2BD1A7644852E68194E795ED8210B
                                                                                    SHA-256:1478C20A4B9F57B4AC7FEB1150EC2976B4735B1F25A455B3C722D6CB221D5A9D
                                                                                    SHA-512:FEC2CAC4C86E972067AD572CBEF25228AD9319ADD643B4CFBA595990C53589385656E2A99975DDE781ECC11B2FD4C22F872C4D3324AD4A621C6485EAD9251013
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........f5...[...[...[..U....[..U....[..U....[.......[.......[...Z...[..~....[..~....[..U....[..~....[.Rich..[.........................PE..L......T.........."!......................................................................@.............................t.......<...............................HO..P...8............................[..@............................................text...^........................... ..`.rdata..............................@..@.data...............................@....rsrc................<..............@..@.reloc..HO.......P...>..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):326144
                                                                                    Entropy (8bit):6.034873314751499
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:giUW6EA3+SZowHFnNyE2TNz4GkF4a6y8iWFucu0yMUveDOrmVpfuyw:0WVA3+SZowDp2WD8ip2D
                                                                                    MD5:FB791F993AC67F4A462DBCB66FF14BF4
                                                                                    SHA1:35EE2C6A213E324F0A7A9C9451A10CFABF427545
                                                                                    SHA-256:39A80B657B1191A017B17E5908DCE5C68D9A1A2E737CBAD67B7337CB2FC44A10
                                                                                    SHA-512:80E1FE9C5F5C6C1BF29AC1CC4F49114EA1067E71E22F63FF8F654A60FAAE9118CFDA9D4F367667E7D3F474C0C2A528189587FDF1E5DFF8B91821AB3E0A5C57B0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0.................. ... ....@.. .......................`......v`....`.................................h...W....@....................... ......|................................................ ............... ..H............text........ ...................... ..`.reloc....... ......................@..B.rsrc........@......................@..@........................H...........lz...........V..x=..........................................6.(\...(.....*...0...........4............u...%.a...(0.........u...%.b...(0.........u...%.c...(0.........u...%.d...(0.........u...%.e...(0.........u...%.f...(0.........u...%.g...(0.........u...%.h...(0.........u...%.i...(0..........u...%.j...(0..........u...%.k...(0..........u...%.l...(0..........u...%.m...(0..........u...%.n...(0..........u...%.o...(0..........u...%.p...(0..........u...%.q...(0..........
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):21504
                                                                                    Entropy (8bit):5.2523419066901695
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:wVUPc2OSIHAh+iiEMWSgn+pkZ4xRV+ralP8Xbws:YUCHAh+PRmoP0
                                                                                    MD5:8E7AC891272DC243C274EA9E451B34EE
                                                                                    SHA1:F38DAC6C573F8C1825A6CEC7C49E18D33991378E
                                                                                    SHA-256:C763B7E3B8CFE8475E23D3DF25FF6714EC604B577593CAB2530C985A11E53A28
                                                                                    SHA-512:1BE234DB923F1CEC88D4A267C3968220493C989CD7927AC8ABF2E753F348E7F91F8FB1AF4245B120C9551ACAE59383CE1C76BEDC560BD879A643280739F5FF00
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e.........." ..0..J..........2h... ........... ....................................`..................................g..O.................................................................................... ............... ..H............text...8H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........+...<............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..~........-.r...prm..p.(....*.o....->.o....-.r...pr...p.(....*r...pr...p.o....o.........(.....(.....{....,..{......o......(......(....*~r?..pr...p.(......(......(....*br...pr...p.(......(....*..0..J.......(....r...po.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):19968
                                                                                    Entropy (8bit):5.327502630579932
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:WR1TB+EYvodkn5OeUq5gCS1x9UQflcltvlVyUWY5FVRsp5GiPjcVuGk/6uQKztku:WZYvoy5OeUqp2UhLs9P4VBXuQK+u
                                                                                    MD5:CCF6F3D56977D1AFBF4A3EC884D1A32E
                                                                                    SHA1:D29EFBCC5AB0F6C7403BE0DDE5EC202D61FF410F
                                                                                    SHA-256:2129BCD055F493FE34B7E44AEE5F8175CF9D43D7AC037D742E6070A58AFE1266
                                                                                    SHA-512:329607A495E0DAEC735F81A15B8B92C4DF84F71015D9AB762967CCC664714BC2C883BD321255FDCDFAFA04BF5C24DED92B98FC940DFF30A36D72E2831A2AE012
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...XR.e.........." ..0..D...........c... ........... ....................................`.................................dc..O.................................................................................... ............... ..H............text....C... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B.................c......H........0...2............................................................(....*"..(....*&...(....*&...(....*....0..e........(.....s....}......}......}......}......%-.&s......%o...........s....(....t....o...............(....*....0...........{.........o....&.,....o.....{.......o.......(...+(!...}.....{.....o"....{..........xXs#...o$....,..{....o%...o&...r...ps'...o(.....(....*...0..|.......~)....~)....s*.......~)...~)... .........o+...-6.(,...,..(,...,.r...prm..p.(-....(,...-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):27648
                                                                                    Entropy (8bit):5.660667298583979
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:mxUvyu7KjpBJ+lwRn+MRMg+GZZm6Y98WHh7xfRZDivn2PQhomXu4VPwL:mxUvF2j0lQn+zg++7W1xfRZ22BG0
                                                                                    MD5:7D9CEA1B51F03CC56C1C3540222CA32F
                                                                                    SHA1:F2FC1A279B52B24702AE478C56C37307DC5E2F7C
                                                                                    SHA-256:B7E37C69C521CC0001A76346125B4076599D54167BC7D5CCBE129B23968DCF03
                                                                                    SHA-512:87A9E1395F8296DED9F8869D0DEFB84979465D17362B513FF8B94744FCFCC8DD000D66C75806A85A6318CB9EBA097994993FEFD2D94AACD6EA97FDCD35F2F860
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0..b............... ........... ....................................`.................................D...O.................................................................................... ............... ..H............text....a... ...b.................. ..`.rsrc................d..............@..@.reloc...............j..............@..B................x.......H.......X(...X............................................................{....*"..}....*>..(......(....*>..(......(....*..{....*"..}....*>..(......(....*>..(......(....*..{....*"..}....*..{....*"..}....*Z..(......(&.....((...*Z..(......(&.....((...*..{....*"..}....*>..(......(,...*>..(......(,...*..{....*"..}....*>..(......(0...*>..(......(0...*..{....*"..}....*>..(......(=...*>..(......(=...*..{....*"..}....*>..(......(A...*>..(......(A...*..{....*"..}....*>..(......(E...*>
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):41616
                                                                                    Entropy (8bit):6.118366181712053
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:/1UUBVS1yKegy8XiOYgzECu0WIbHzVfQ+t9yIor+8ie4:tUTy8XVnzECTWILufr+8u
                                                                                    MD5:7A271CE5582DDCC325732581A533D8BE
                                                                                    SHA1:5FA2C5390EE84BF975C861AFA361D2E17AC9F625
                                                                                    SHA-256:9202C7E903172AE1855AB96EE5D80248292B86100A843DDCC6DB664CD6EDD1B6
                                                                                    SHA-512:43F575A8FDB98565358C7C5C3FECA78A9154CDDAE6BDD1AEF1A2B108B0650059257F8983B9A1E544C12586807303D2C4F440AF0171295EA284C8F7347D24BE70
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....~..........>.... ........... ...............................&....`....................................S.......h............................................................................ ............... ..H............text...D|... ...~.................. ..`.rsrc...h...........................@..@.reloc..............................@..B................ .......H........:..._...........1......P .........................................%]..?.....V.AJ3Z^f.6g.u4.5cJ...+8.j....c;...PP8......6...T...9..kA.u;+U.na6\.......I.c(.J..L.....h.K[.!....s!Sdr.Q><S.&.0..*........-.r...ps....z.(......sG.....o.....o.....*...0..........s.....(......o....o......8......o......o....o......8......o.........o....o......+S..o........o....o......+#..o........o.....o.....(....-....+...o ...-.....,...o!......o ...-.....,...o!......-...o"...-...o#.....o
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):10752
                                                                                    Entropy (8bit):4.8225604790518455
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:/ySWVk7AJnE0J5nMuoT4Ylzpz6dPGadIce8R+az+SvdlkGYwGsnoSjM6BKMqVXLY:/Mk7eyTXz6dPXVZnblKzVbFp
                                                                                    MD5:0E5CB0025D94586D87103A9BC42D8300
                                                                                    SHA1:64700DAD9F08F73385DBE0C98FE07776F4689AC5
                                                                                    SHA-256:3B4EE52569911F5CC967B8EE9EE405353244D01A3F43A4816498F2BF1D276FCC
                                                                                    SHA-512:F5C7DF798A6431A6A62F8805F3625EA6DC6CFDFA04FB5193BECE0E8DC791E65D0C76F5895FDB7C805DF385D14E8C4775D6FF3819E67C340788A59E6F49CF4CAA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.. ...........>... ...@....... ....................................`..................................=..O....@.......................`.......<............................................... ............... ..H............text... .... ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................=......H.......X#.......................<........................................o....-.r...p.o....(....*r%..p.o....o.....o....(....(....*..0..A........o....-.rQ..p.o.....o....(....*r...p.o.....o.....o....(....(....*2.r...p(....*6.r...p.(....*.0..............(....*...0..........s$......}.....-.r...pr...ps....z.{....(....,.rC..pr...ps....z.(....o........(....r...p.o....(.....s....z.o.......%...s....(...+,...r...p.o!...*...{.....o!...*........>..K.......0..............(....*...0..M...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.068586044047949
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6q+lyNQslz1XmemhRzS9a3OSuHMRLElgvdMDfhLtJrjRq5qFu3nR7PPWguGkRWgW:Eyj/SAaebsmlg6Jpxef8Do
                                                                                    MD5:70C073A948BC973B1171218D085E9CC7
                                                                                    SHA1:1711231084690BCDEC24AFF68850845EE400ED94
                                                                                    SHA-256:7C45748F60320FA22A01A70336C80CCDB4EDBA9940B4647C68A6F96B51DAB676
                                                                                    SHA-512:F9B2650E49BD04BEA4A494B310A09FAA5BC09426E6C8A572A53B986682EFB735496549847F6802930ACE6C2541FD918A3A292EF8C3E89F2752A68F9B40968F51
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e.........." ..0..............)... ...@....... ....................................`.................................`)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ................................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.BSJB............v4.0.30319......l.......#~.. .......#Strings............#US.........#GUID...(.......#Blob...........W..........3......................................................................y...~.y...b.G.........e.....1.....J...........@.......................v.Z...2.Z.................y.........................M...A.........#.....&.....).
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):725157
                                                                                    Entropy (8bit):6.524824306128734
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:2sMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyR5:xMcMoi3rPR37dzHRA6G7WbuSEmK50syM
                                                                                    MD5:5A98B1129C909A92BCC21B2568AED759
                                                                                    SHA1:0F6FBD380411EBCC4C719E1C737FF24542AB844D
                                                                                    SHA-256:BE2DB372054BBEDFEA631EE883FA4BD4DFC29311521BA1E156843A05A3C181CD
                                                                                    SHA-512:34B20B940A8E0B9A621B83808FB01C165F2F1174F6E175C98E31D1CB9D861DD9DD076D06812A7BE6D197BFECBAEE4E1F653D00DDBF072193FFC74E4D7B91A5F7
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.488842171019742
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6fhZMjDlMDH5lpoJDLYNMTwCRXQtPyqE4Ev/mZWjH1AglkAqVwAK5W1AxF:UoDlUbmJfzwCRXQtqqE4zWjugRuXaWu
                                                                                    MD5:23E59CC67C075C315F717770D46B00A6
                                                                                    SHA1:260D18B0BDBB8ADABB1A6D8565ACA14CCC462CB2
                                                                                    SHA-256:1E2636B145C0C69E30DB1492950EE23D02458DFE6DAC69EA51D865BA15FA0FDE
                                                                                    SHA-512:36128BAE654D5C58053FEF3EB8DCD54B7671DACB5CEA6F26C5340E0BC38579667064F169FE7FA744FDB40DEBAAA4CA040D749C1DA803A139594DF9E7D1D42284
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Y.........." ..0.............N'... ...@....... ....................................`..................................&..O....@..8....................`.......%............................................... ............... ..H............text...T.... ...................... ..`.rsrc...8....@......................@..@.reloc.......`......................@..B................0'......H.......P ..t...........................................................BSJB............v4.0.30319......l...|...#~......P...#Strings....8.......#US.<.......#GUID...L...(...#Blob......................3..................................................y.....@.....>.....h.................`.....,.....E...........T.....2...............................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.....y.........#.....,.....K...#.T...+.x...3.x...;.~...C.T...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):2918
                                                                                    Entropy (8bit):5.175878718806986
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:3C2zyqG+qOs+qW+qJlZVxY3UXYzHXTYzH5wC7h+qm4gZ727RgdOgX8g51gXFro:4n+//+wHxY3HzszZwe46ro
                                                                                    MD5:61CD0483AC419DC130EF626C11A2BECB
                                                                                    SHA1:C314A5E97CA58E0378D3314FB68AC4EA614B1738
                                                                                    SHA-256:B7BE7495FD719A4F25D61EA6326126687845B91A0966C36D3218171F4D2D83DE
                                                                                    SHA-512:A073688A35B50C96F2F1D3043BA4CDC426EF3C06EAADF752D3BB29FAD8FC4E35CE2A4F2B60CB19C868A0BF680B9C907A9B7F457F8758D35EBB83478860A99167
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>....<configuration>.. <configSections>.. <section name="loggingConfiguration" type="Microsoft.Practices.EnterpriseLibrary.Logging.Configuration.LoggingSettings, Microsoft.Practices.EnterpriseLibrary.Logging, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" requirePermission="true" />.. <section name="exceptionHandling" type="Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Configuration.ExceptionHandlingSettings, Microsoft.Practices.EnterpriseLibrary.ExceptionHandling, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" />.. <section name="environment" type="Sofrel.Uranus.Framework.Environment.Configuration.EnvironmentSettings, SUFEnvironment" />.. <section name="Visualization" type="System.Configuration.DictionarySectionHandler, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" />.. <section name="Communication" type="System.Configuration.DictionarySectionHandler,
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):6.240327973349802
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrpCNNFMAxMOzchOCKePlLTK1LDq8NGl35uDZzysgL9qYIl4v0v:b/iAWYsOCKePlvK1CL3OYPLQYIllv
                                                                                    MD5:5C20E161C0B81DA188BAA9F109CD08C2
                                                                                    SHA1:1720030BC13999DAA12153073A2740C6742DA6E1
                                                                                    SHA-256:F0F9FB8BDD503F64ECE5E2286A1528044F2F2B85D288504E1ED28F07E610CF96
                                                                                    SHA-512:089F263F9DED8B635E8AD72D96286D5630309912C55597A850A4EE8CEEC876DFB61FA1C0996BA37107ED8619D8B0FA76A1CF8104C6EF01768F80CCFECE6844E0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e.........."...0..Z..........ny... ........@.. .......................@............`..................................y..O............................ ....................................................... ............... ..H............text...tY... ...Z.................. ..`.rsrc................\..............@..@.reloc....... ......................@..B................Py......H........(...8...........a..P...........................................F.(....r...p(....*...0..........sH....(...........s....o............s....( ....(!...}.....{....o"...(#......i.1;....I...s$...(...+o&.....(....,....(....&.(....&('...o(...*()...(*...o+...()...(,...o-...s....o......(/...*..0...........o0.....(1...&..o2.....(....*....0...........o3...u......(1...&..(....*..0..H.......s+...%(C...(...+(5...o-...%(B...(...+(5...o/...%.o3...s"...(6...&.(7...*.0..$........{....,.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):5.073320023485428
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:VP3bjfBuBX39tYew3jhC4h9Xx8P3RV2ReWBP3lYen:RfBg39Cew3oKihGce
                                                                                    MD5:A1D2A38772AE525ED4C0A165C3197187
                                                                                    SHA1:5EAF512F42F0DCEF235F914F104FE0696C4310B7
                                                                                    SHA-256:CF3803BC5985B65888BA30261E93E366E1C8E76AF91B6E40F36FB14812F57BF2
                                                                                    SHA-512:6D3AC43928F8A6E6F93C6C64A20B2C1E512A045979F8C2C29A584C56CF29B14477FC7DF954C4EB0F1D34F9381ABEE3C238AE7868DEA6FCDD175DB364A633D098
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..0..........*N... ...`....... ..............................j.....`..................................M..O....`..@............................L............................................... ............... ..H............text...0.... ...0.................. ..`.rsrc...@....`.......2..............@..@.reloc...............8..............@..B.................N......H........+...............G...... L.......................................0...........r...p.r...p..................(........Q..+..*...0..2........r...p.r...p..................(........Q...Q..+..*...0...............~....Q..~....Qs.............,3.(......~..........(.....*...(........Q...Q...8n....o....o.....r...p.....,.....*...(.......o....&............(........,$.(.......o....(........Q...Q...8......,.....+......9......o......Yo....o........o....o .........o....o ...(!.......,t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MSVC program database ver 7.00, 512*47 bytes
                                                                                    Category:dropped
                                                                                    Size (bytes):24064
                                                                                    Entropy (8bit):2.8139684302156573
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:GDwjVAfAm3ACA4C+9p80/v/z+fyvx/ZsbwZ9SWCNHn3bmEPl33dD446DAE/f5ek/:GDwjsI+rHzhVxl7
                                                                                    MD5:1B0B75EA764B048A27B3205970D2FA0B
                                                                                    SHA1:2865C064AFD9CF51B7B5916E321870EB3FDAF952
                                                                                    SHA-256:2130C737EB69EB79A9ABC74DCD9BE2A733AAFD43174FB9C177601935A08A43F8
                                                                                    SHA-512:0012D14AFE49AE0A59ABE5451AC2A705E090311A4DA5AEB3A87DD6DB4982A26747AD18DB6421E9D500F4687D4AD5399C068037C4712606334608384FF2FC060D
                                                                                    Malicious:false
                                                                                    Preview:Microsoft C/C++ MSF 7.00...DS.........../...........,...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):55904
                                                                                    Entropy (8bit):6.299047178318044
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:BYQaIZaEmaOQxn6JxKjtlMZAnuETAV+w4:aIhOQcSLAj4
                                                                                    MD5:580244BC805220253A87196913EB3E5E
                                                                                    SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
                                                                                    SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
                                                                                    SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):8704
                                                                                    Entropy (8bit):4.627470324915964
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:ZnRxqFcduFzlbKYTQA7sGzaM+vgh3DQqQy6B3rqWsuYXATXjLdGC/au/z:NqFHpboA7sGeM4cv23rqiYXATXV/au/
                                                                                    MD5:852BF0289D774738CFB036A8BB5C6B11
                                                                                    SHA1:98F4D60BE0EE949346AD95BC6234D677E1C7D389
                                                                                    SHA-256:BB3AB16E765F17C784DE9CDB0C35D1B6A299ABAB476FE2F9CA1B39528A629B8F
                                                                                    SHA-512:CFDF0079C9C42D2870FA18BDC92AAD49F16481744B0AB3B296DEA4F258FDF3A6A64B419943E61173D17D3FE8A9A6BAE728AC9F245E6196770BDC77DF5B55AD30
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0.............V7... ...@....... ....................................`..................................7..O....@..T....................`.......5............................................... ............... ..H............text...\.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`....... ..............@..B................87......H.......($..$...................L5......................................:.(......}....**....(....**....(....*....0...........-.s....%.o....%(....o.......{....(....&.....(....s......{.....(..............o....r...pr...p.{....(.....(.......r[..p.(.........,..o......*.*........E.+p........E.;........0..............(....&.....r...pr...p.o ...(!....(.......b.r...pr...p.o ...(!....(.......B.r...pr...p.o ...(!....(......."..r...pr...p..o ...(!....(.........*..4......... ........./.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:Microsoft Roslyn C# debugging symbols version 1.0
                                                                                    Category:dropped
                                                                                    Size (bytes):95788
                                                                                    Entropy (8bit):4.75506671884912
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:1ernxRpKZkJklUHHIWNVXVxYGGGGGGGjQYXHEmM7F7MlXZE747fBL/zdx:cbKK1NVXJTXkt7F78e747fBLJx
                                                                                    MD5:2056464074215066D3D06ABBBA1A0519
                                                                                    SHA1:C2D459A790CB21AA1C8FA92F55B96804AEFB78AA
                                                                                    SHA-256:CA3492F46E271C70182D04783B4731C6A6EAD3659FFA22EC02A758B3905E8508
                                                                                    SHA-512:EEDEF1F1DCEAD2F15928D24028C62B518F7F6B89A4E739B64C3C1FAE0B1123DC9C1A6CE024187CF2656CF5620CA670858435AB6D9C34EF9A99E283B1C14BCDF9
                                                                                    Malicious:false
                                                                                    Preview:BSJB............PDB v1.0........p.......#~..$.......#Strings........ ...#GUID...4.......#Blob...<t..|...#Pdb..................?....3....$...C...................?...G...........=...F...................[...d...3...<....!...!...$...$...(...(...-...-..Z4..c4..p5..y5..36..<6...7..!7..,8..58...9...9...<...<...@...@...A...A...[...[..|b...b..0r..;r...z...z..............................^...i..................M...X................................\...............3...;...H...P...]...~...........................$...,...9...A...I...Q...Y...a...i...q...y.......................................................................'.../...7...?...G...O...W..._...................................$...w.......................................(...I...~.......................................................[...y...............................................................%...-...5...=...E...M...................................$...6...>...P...X...`...h...................................................%.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):148480
                                                                                    Entropy (8bit):6.125792384388118
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:x/xP0dmNHRIfvXyTjUxk0+8shTbRqpzMA1JhkrIAcFpZMD9hVRg5bT+02nBJdbea:x/OSSfP60kpVxbUuZKq/4qaTXc
                                                                                    MD5:D2EDDE626C241549EAB636AA87FB5D38
                                                                                    SHA1:8D836FEBD477B3EC44CC37F4F0AECDAA1D7DB788
                                                                                    SHA-256:BC0243134C93C55EA105D0E9C2A43B6030E973290D0A061CF3A61986A2268A88
                                                                                    SHA-512:490878E20ED764E81E42B8F43FAF2ADC0810DCD2F65D36F6D6980411617FAE9543F0D7B6F110E5363BE494097BA3B30DCF3695AEA41314FBE19C6A59A55538D1
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....-.............!.....:..........NX... ........@.. ....................................`..................................W..S....`...............................W..8............................................ ............... ..H............text...T8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B................0X......H..............................X........................................(....*..0..8.......s.......o......(....~....(....(....-..,...o....+..o....*.0..............(....*...0................(......(....*J......(.....(....*...0............(.....(.......(....*...0..............(.......(.....*..0..-.............(....~....(....(....-..,..o......X.+..*"..(4...*Z.~....(....-..s....*.*....0.............(.....*...0..F.......~......{.........{....M........ZXM)....(.....~....(....,...s
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):71680
                                                                                    Entropy (8bit):5.601875671857578
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:PEEZIJuG4d/Slr8w4a90F61j1lcl7XhQeQxWrlBOz8sXrygGkh9b9+nxX+CIERBV:PZ3lFQeQ0a3Xryg8xlNuEOkZVz/7odc
                                                                                    MD5:FD8DD506BA3A8ED35E5E2C6FFD39766C
                                                                                    SHA1:65695DF981FB2D78015ED4279AF7D19258F76E5C
                                                                                    SHA-256:A39C597D0F5896A490A7F2A7104EDB85486CDDA2C505940F938CA1E14B3E6DF5
                                                                                    SHA-512:3857ABB429069658227A0881D8FEE1DC192727C8459886E3FDCB8E91633B54E8BF05A45B51334834110031714243562CDDF0E389D46F3E2353B9512E8A75E1ED
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............J-... ...@....... ....................................`..................................,..O....@.......................`.......+..8............................................ ............... ..H............text...P.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................+-......H........O..0.............................................................(....*..(......(......(......(.......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..(......(.....,...(...+(...+(......(....*..(......(.....,...(...+(...+(......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*V.(......(......(....*..{....*"..}....*..{....*"..}....*..(....*V.(......(......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):415408
                                                                                    Entropy (8bit):5.573182313694346
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:fXvGO+uec6A3HQ0nHajgLx+lkMPSDt2nb+6PVM0H+ULFpUKiw9OBTj1ESZ31W:fOO+66OCoMna6PV/H+UE1xZ31W
                                                                                    MD5:4DDB62841065A6587A5CF72944AA996B
                                                                                    SHA1:A437A112A19F4220E18A6C8E764D73E315F47ADA
                                                                                    SHA-256:AD18F28213EBC685A4E6F38CEA549F85DEA2E51025F4D08F672EFCE128FF105F
                                                                                    SHA-512:161A169FA60CFED2D67F135E0DBB6932FCFCA0676B6E7BEACF4BA9FCE35E887DE0AA3BBBA76EABE173CBBCD060ED8325E0C732BCFBA9E486445D5E516F5CFE8A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....2...........P... ...`....... .............................."G....`..................................P..K....`...............<..............hO............................................... ............... ..H............text....0... ...2.................. ..`.rsrc........`.......4..............@..@.reloc...............:..............@..B.................P......H....... ;..H...........x....2..P .......................................q.+.$.~..n.P..8\.^._.v)..&Y$..".....-.]%..^...Xjf'...D......m..,e74.n..O.-X~h....%:$U=.....A+........v..g....P..u.....Rs..O.]..(-...*&...(....*.(....s/...z^.(......9...(2...o3...*J...9...(2...(....*.s....*..(-...*&...(....*.(....s/...z^.(......Y...(2...o3...*:.r...p..(....*....Y...(2...(......(......(....*F.r...p(4........*J.r...p......(5...*F.r9..p(4...t....*6.r9..p.(5...*..o7...*..o7....(....~....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):24576
                                                                                    Entropy (8bit):5.439852939293774
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:zbXOwhwMrAfN2/hkBwkGa2+dWLG4ZfAcION/65Hld2qFKNk8qluGLRqOunsWsrj:PhhwMrsek2+I95shhJRXiJs/
                                                                                    MD5:74E7BEBF2E462C337B1280A3E98D0B35
                                                                                    SHA1:0DF183BA4D1C4E13073581E56564F95AC5CB3254
                                                                                    SHA-256:F55761468B9B0CE16C70A2F011C486DFF07948D35EAE3E67B092D610C381F368
                                                                                    SHA-512:870D44A95CC69D694189A702DDFCEA6D98F8DD25BB0DAD78AA7259E73E328946B68160215FF209EFF93AD40DD19B34752E9E15217E78298E4C696712F0F2DF49
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e.........." ..0..V...........t... ........... ...................................`.................................dt..O...................................,s............................................... ............... ..H............text....T... ...V.................. ..`.rsrc................X..............@..@.reloc...............^..............@..B.................t......H.......@2...=...........o.......r.......................................0..G.........(....}.......}.......}.......}.......}......|......(...+..|....( ...*..(!....s"...}....r...pr...p.(#...*......(....*...0.................{....o$...o%....+9.o&.......o'....j3&...r'..pr=..p..A....o(...()....(#......o*...-....,..o+.....9.....o,...o-.....8......o........o/...r...p(0...,t..o1...o2....3e..-...o3...-7...o4.....r...po5...r'..pr...p..A....(6...()....(#...+.r'..pr...p..A...(7....(#...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2213888
                                                                                    Entropy (8bit):5.810653063534655
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:69sJESAufFG0oe9ZrRSSuUKPgDMmrsZhT7UYCwOYhNVs7VonU337g023hQrK:69sJpoe9GSuJPsRYCwOCNCpAUH77ST
                                                                                    MD5:47ACD42F6F2B1476758C927A9ECAA95D
                                                                                    SHA1:4299A5BCDCAC17AEF569D26A03DD0F7A4D497656
                                                                                    SHA-256:7EF96C71C8DAD6DBCB9AB0104E840ACA915554740A8CFE12AA0556FD5BD5A782
                                                                                    SHA-512:3FE6A3E66AD90EDFC754A1F3FB3873EB0584050CADEE8E3A1A6845F0AFCF414E267F9AC675BF91227D41717EE7C2DBFAE976EB7E695EE278BB773C48C44C5BEA
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....n\........... ..0...!...!.....Z.!.. ....!...@.. ....................... "......_"...`...................................!.W.....".......................!......y............................................... ............... ..H............text...`.!.. ....!................. ..`.reloc........!.......!.............@..B.rsrc.........".......!.............@..@................<.!.....H.......dz...K..................`y......................................".(:....*....0...........(a...*..0........... 4......(b...*..0................oc...*.0..................od...*...0..0........oe...%&r[..p $.......$...%...%....of...%&t....*.0.............og...*....0...........(h...*..0...........(i.....}....*...0...........{.....t{.....#........oj...%&*..0...........(k.....}......}....*....0...........{....*..0...........{....*..0..........r{..p.....r...p.d...(l........(l
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):187904
                                                                                    Entropy (8bit):5.64211166818044
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:mtqaFU/ky6445SGWPW0s1sIsssx9JmaN5a0KRYq:m4a+/kyvja0
                                                                                    MD5:4D386FCD91A7AD05221D8E6C744F9857
                                                                                    SHA1:91C4571FB654E9ED5AE4E2C714D41B6CAEC5322B
                                                                                    SHA-256:D4554C86F065556C69295D382702CFE5A6FE8B7DD90E9E295DF50484A926E38B
                                                                                    SHA-512:4365EEA6A227C52A01C626B63D7C2F0CB4ED9B462B184ABDF855E8D929179902785B282F60C3A519584BCA0FB6CAAC7FE03AEFD37DC6BF6D5553A11EE3CD3244
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...uR.e.........." ..0.............z.... ........... .......................@............`.................................(...O............................ ....................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................\.......H.........................................................................{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......(......(....*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0.._........-.r...pra..p.(....*.o....- r...pr...p.o.........(.....(.....{....,..{......o......(.....(....*~r...pr1..p.(......(......(....*br5..pr1..p.(......(....*.0..........(....r...po....,"(....r...po....,.(....r...p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):42496
                                                                                    Entropy (8bit):5.5460008425063325
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:CETA40NKvv4nPD4l86OZIc+pojjAluxoKoadYDw185InG8RS:+/ZIcgFlJKmw1AI3RS
                                                                                    MD5:1ABEEEB32F3AEF62ADA309A297E3AA33
                                                                                    SHA1:51C5D5953A457AE988D108C3DCC2B592C3F6BA12
                                                                                    SHA-256:F5B5C57DF2ACE9999308E4B95E58ACD9386F80C163599F87711D7DF826DB8215
                                                                                    SHA-512:94395CF514C4B65B613182549045B4B24FABE4D8987E49FB0A11BB6EBB058C50774CF2D566EA83474C0EE56F0B3CF8F03701D1AA6A8436ECA62070AE5A43D8D9
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e.........." ..0.................. ........... ....................................`.................................H...O.................................................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................|.......H........T...f............................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. j... )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%q.........-.&.+.......o.....%..{.......%q.........-.&.+.......o.....(....*..(....*...0..C........(....r]..pr...p........(.....(....s....%.o ............s!...}....*..0..........("...o#......~$....rz..p
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):87040
                                                                                    Entropy (8bit):5.4554148178321675
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:nDsxiI7pW/tZrszqJBWDnvSYT3VeArUOXeeu:nJI7pW/tZrseyf3fjXeeu
                                                                                    MD5:EAEDE0361F15C2EB139C7E2FC6C6AB71
                                                                                    SHA1:DBC9F9DC7E158538C0FFDEE9AA536C33868EF693
                                                                                    SHA-256:8C8B835E81010D99B0F240E598D65951D4A50771A4B4D85CB74E513FDF169E36
                                                                                    SHA-512:3575D111C742C8D2B56BBC0EAEF1B3E95CE0AB31100047A8EAFE87E91D063BA4D420D7BB7BBD332EAC34BCE6B8DAFCED7AD7E81CEEA830394805A3F61293F40E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Vu..........." ..0..J...........h... ........... ....................................`.................................ih..O....................................g..8............................................ ............... ..H............text....H... ...J.................. ..`.rsrc................L..............@..@.reloc...............R..............@..B.................h......H........V..............X...0I.........................................."..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):62160
                                                                                    Entropy (8bit):6.394651976589669
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Lu5fLsPcyp/79lGhbTfpp6tpJbox15i4R5we/MvSKi0cOEwC7:y5fQLMhbTfpp6tpJsx1R2eMqK2WC7
                                                                                    MD5:B5BBEE69523810F8AA9D92E3D3ECB896
                                                                                    SHA1:9A45F181AC22B5C633EED421B59F5FE9D12D6A7C
                                                                                    SHA-256:BF99695470075C4E2C906BE4567F1D0AB3A6D85D31EC1D8F6B4139015C48A2B3
                                                                                    SHA-512:9EEFF3BA247793163FD091FB26D8E620C99A8CB1B510F26EA7C31EB9EC27F2DE9E92F14CA470852C84FF1DCCF5FBCBAED8C93EA2F05C6515E2C078776C62BA7E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...a."Q...........!..................... ........... ....................... ............`.................................@...K.......`................>........................................................... ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B................p.......H.......PE...............D......P .......................................xk.r..E. z.aD.-$..}...=..+<%...Z....x.N.,..D...nA*....1T. 6./n.`j..."q..rE........44.(..a...\..>...~.......9.M.).#..c.0..W.......(....s.........(.........~.....(....,+(....~....~.....o....t>........~....(....&*(....*j~....%-.&~....~.....o....*.......*2~.....(....*Z~....(.....o.....?...*Z~....(.....o.....?...*.(....,.(....,.~....(.....o....&*(....*.(....,.(....,.~....(.....o....&*(....*Z(....-..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):5.347287743366354
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:6oN4JUNanMSU/JU7r299nL2kSDtHAvCp3me0PfRnCe8SfVq6X8RRga5Rf7NjNfft:im6ab7exE0
                                                                                    MD5:DFF6850E8B2FA1D6FD14773AD9F6F150
                                                                                    SHA1:EB41A2AE0FD2BCA2D0E4E857D02BDD2245A698AB
                                                                                    SHA-256:B4453E1AB70758E8B08F1F9CC6947A18DB2519075B494C4CD8D6E1E020A68A0E
                                                                                    SHA-512:2743D550CFF83639E2D6ABCD4A1AE4C055C5A8B5FA459EB5ACE005A68CE08D83B31E296DA120ACA04FAD190F60AD0565912FEC64C79233B9414E7BF42EC3AB92
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e.........." ..0..P...........n... ........... ....................................`..................................m..O.................................................................................... ............... ..H............text....N... ...P.................. ..`.rsrc................R..............@..@.reloc...............X..............@..B.................m......H........'...............V................................................(........s....}.....~....}....*2.{....o....*"..}....*^.{......{........o....*2.{....o....*2.{....o....*..(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*V(....r...p~....o....*V(....r`..p~....o....*V(....r...p~....o....*V(....rP..p~....o....*V(....r...p~....o....*V(....rI..p~....o....*V(....r...p~....o....*V(....r/..p~....o....*V(....r...p~....o....*V(....r4..p~....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):17408
                                                                                    Entropy (8bit):5.340203016866838
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:ZuR5umKg7LDcJf/l64+p91nuQiS0Mw+f+Sb+jkyNr1rSeUu:K3X91uQiUje6E
                                                                                    MD5:711BDB4B08A5CA012F0E0042B800C113
                                                                                    SHA1:9FD08016EC0B720A8ADE512FF0A8147299C51719
                                                                                    SHA-256:2B32B674479391074476F65B73523ECB90C38F1E2FBE5CD2F05138CB07430FB3
                                                                                    SHA-512:C31607E1112CD9CE964CF070A0BFC3E892993191BACB53FC1C1DE68609378BE407F3DD5D31706DE7A4C18E58CEDBA32A7A857C9CD028886943571361812D21E6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e.........." ..0..:...........X... ...`....... ....................................`.................................XX..O....`............................................................................... ............... ..H............text....8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B.................X......H.......h"..P............<................................................(....*.~....-.r...p.....(....o....s.........~....*.~....*.......*V(....r...p~....o....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*^.(.......}......;}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*V.(......}......}....*..{....*"..}....*..{....*"..}....*..{....*".
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):56832
                                                                                    Entropy (8bit):5.690835792827563
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:DkXuiukTFT3hvhZUq5UkA33mSIZ0lt+DDNXspw9IwL+P:DQu1kTFlhmq6kAnSKlt+nVuwGvP
                                                                                    MD5:BBA60FC073D9CBF5CB5658BC4DCD8A3F
                                                                                    SHA1:9CFBD36334B9404B3E7E8042C4F15B7F01391441
                                                                                    SHA-256:133B772B48EADF9F2FA51296A508EE0BC7B71CAB84C699F23B10B8B55F310550
                                                                                    SHA-512:CCF5DE9F317B734AF85D34FB3BD264DAEF1C326CDCEEBE6569590473F68914EF333631D15628021474494BA07F8A40EE20DB46F1C6C0F8C9D63E0295BAF36027
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e.........." ..0.............n.... ........... .......................@............`.....................................O.......p.................... ....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...p...........................@..@.reloc....... ......................@..B................P.......H........A...x..........t....8............................................{....*"..}....*..{....*"..}....*..(!...*..{....*"..}....*..0........................("...o#...(....*...0......................(....*...0...........(!...r...pr7..p.($......}.......}.......}.....{......o%.....}......s#...}.....{......s&...%r...p.(U...s'...o(...o'....s ...}.....{.....{....o).....s3...}............s....}......o).....{....o).........sg...}....*f.{.....{....o(...._o9...*.*..(....*..{.....{...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):368816
                                                                                    Entropy (8bit):5.365214438266103
                                                                                    Encrypted:false
                                                                                    SSDEEP:3072:KrNvoFXHxeLeKdwU1SzZiZ5pbC7K4vQg7wwhFQSamkV8EvA3PXiD3fm553inDg8I:KxPeRiZ5nqwSuzvAsu5Jiq
                                                                                    MD5:37742E95B192B5B3F8707C2487A70BB0
                                                                                    SHA1:74F0A74F1E8F1513FFF13CD4D7A60658F59DC856
                                                                                    SHA-256:B410452B0A9BDBB8C860169F669A8E051AFB51FA53030D31E8667E5FC1B9C445
                                                                                    SHA-512:174F5DFD8DDD1C31D707F8EC0EAB29B9E563DE7DEC85A1F32BCB658E43309CE48F0BACF75964C1CDB24AFB5014D17E0DA252B7C2C7B585A9BB8430792A87EEE5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....^yQ...........!.....|..........>.... ........... ...............................5....`....................................O.................................................................................... ............... ..H............text...D{... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B................ .......H........+...m..........(...._..P .......................................G.x7tf...r|-.}...)e{.@.[......y.P...Rt...@...a..o..%9 ..n...!.M<...u...QM........l..MVNU:G.D...5#u....b$.3N_...'.....EZ.r. v.s!...}.....s"...}.....(!...*...0..6........x...(#...............o$.................(%...tP.....*...0...........s&.....*2.~'...o...+*...0..m............{....%....((....{.......o)...,.....A...(a.....(c....o.........(a...o*.....{......o+......,...(,.....*..*...........Y]........-.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):58880
                                                                                    Entropy (8bit):5.916274515752421
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:VbFZAPoGIjmU9ZMPVNOhTJCj+775suxTvJREFhtK4shNeYJub4h8ZGdwv1PmQYEQ:Vm9SXGunREFhtKhNeA+4h8Md81VYExO
                                                                                    MD5:66AEAABA0629DAF8544AFC8008079386
                                                                                    SHA1:1E09E5D24E1AA3D1700B265C6FF94B7524813F4D
                                                                                    SHA-256:268B44A78354F7A225E5B1567223179C7B73453C0A27EB4BF18BB57D7A8E08D9
                                                                                    SHA-512:DD2CD1DF484600E6CC3E686E64559C3447F255F723B5F57CD51F76A838A79416BF68B7A7B380467BCE172FC3EC868EB54A0D754108926782D31BB0CBD66F5A54
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...y(.............!..................... ........@.. .......................@............`.....................................S............................ ......p...8............................................ ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......\h.......................g........................................(....**....(....*2.-..*.o....*J.-..+..o....(....*:.(......(....*...0..............i..(.....*...0..............i..(.....*...0..-............(.......(....,..,...(....s....z.s....z.*2.(....(....*:.~......(....*......(....*....0..............(.....(.....o....*"..(....*Z.~....(....-..s....*.*...0.............(.....*...0..h.......~.....~......{...........{....M........ZXM)....(.....~....(....,...sO...Q+...Q.~
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):145632
                                                                                    Entropy (8bit):4.9623843976202675
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrjsUG1ERvDa6NVLnT9arjGoX3g6dyTE8sXjyYF9zRaTFvvZn:YXqERvGYnT9arjGoX3g6dyTE8uF9z+
                                                                                    MD5:620F8575F763F734E54D259CB7D279AD
                                                                                    SHA1:FD31BD53A90B15B41C4BE279B1719B20ADFD6D3E
                                                                                    SHA-256:F8A3D3136D1C39922BE95A745AAA0F28621252575CE6CFBB4E65FD8BA78840C3
                                                                                    SHA-512:3CFBF74907245030D8FCCD2D3B023F49A1565D0A3843DFD6B3A15A2CD666BFDFD582194209AB87908CBA2822EF571942D4578BBF0CD3CCAE23ED075DBA91A87B
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.819954761317961
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:m58AYPY+n+Zy+D9PfYPFdlP0OIgcOnwa:m58wYjkS
                                                                                    MD5:F989BC031F487F9367D86B10853DA339
                                                                                    SHA1:0F582C96068414147C269E4C39C3B548C6783D26
                                                                                    SHA-256:CE9963B629113FDE6B675FFC0EC55194823FED65EFFD08DE376F163CBC5A64F8
                                                                                    SHA-512:E797AF33CAB09B77412FE5C44461F95B18F487BF42A11F87C3F03CBC5962BA478E77937684E4C0878BD2BFDC1C07DD0982E0FCE8823B8D4BFF1D5AB85EAB79A7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@..................................+..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..]...........................................Y..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6958695447362193
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zXmayK6ryXX0A3GrXrQXyTAxJlPdOoeQr:zXGrYX0A3GrXMXHfqoeQ
                                                                                    MD5:E2785675831C1F909579ECFAB1D7E959
                                                                                    SHA1:F99B843C033804A4E4D3F702C0EC033B66A6333F
                                                                                    SHA-256:808A662089A1589365B99F11BBCA2400F01CED84D053CC81B18C28DD5CDEE326
                                                                                    SHA-512:14CDAB4D6A3D5539CB7FA4E250FEC960930423586EEEE764BE730803B9A2AEFDC6BE8C63F161B790D6E53874A2CF649C35B7A3DF0F3B0DEBCEA8732C9201E4B4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......('..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.7829722115887696
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vMHo6cs+TcW5cyLcQQ5cGcSSLcdcc7Ac6cWpc4cTcyc3Gc+cSGcfAdc/cFUuCWR:3SYpA9ZS6R8jlPgw0xUdnK
                                                                                    MD5:DA3AEDB793E7A652125FEEA58C8CA668
                                                                                    SHA1:39505321C2B90575C8F5125E1739FF720EC9E5FE
                                                                                    SHA-256:5AC1F7DF23CAAB0D8DA0FC9286BB8E84C09AE22B1FD5BA4C50F3D01DA4E61B6B
                                                                                    SHA-512:AC92291FB3C8C110E5C0C6587099215E5E600A22F00FC2D11634FFBDF9410D761AF3A002C67850F7F21AF540A19B7963B1755272FFC52263247AA3B964514636
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................n0... ...@....... ....................................@................................. 0..K....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P0......H.......T,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6030306404916543
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b11Hq9LUzj6XIMwullPqNKS2pxsrIUgj3qXp2qwz2/UbGp0JJ2Y:+/sgX6YMw0lPm2cNlBZq
                                                                                    MD5:335A00AED1F5DF1C1484AD887B808699
                                                                                    SHA1:EB2B942F1AB27D9E02C63F72F47F3ABEB23553C7
                                                                                    SHA-256:A8EB1D010C3A528B48EB20FD2A641A2E61CAA956E451D1B4CD067E616C512D52
                                                                                    SHA-512:AF8801D0A64D852C519DA2F1381D6C650266DF30B3BA74A12767FED7CA37F4D735D832BF0A707FA0F884013188F52C3F6BADCFC6673EC6DD1DFD24006EBA44A5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................H(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..1...........................................-..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835994224355824
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mH/Jn:CuQiS0Mw+f+Sb+jkyNr1rmhn
                                                                                    MD5:1282B07CA5C211DADA29489C3346005E
                                                                                    SHA1:6075EDD0138AAEE77BAF2B7A0791CC8CC2C432F2
                                                                                    SHA-256:2B4531C492CDFDCA6DD63BFD2B30CE2352BD98F3B320E9820CB65C5E0518D504
                                                                                    SHA-512:0BC05DE5F4DB0BC13AB08657CCE36F791C66E8F778825064B81B2701E096F5F36F9476448940DDBA10E5C963DDA9DC154924F0A16B4FEF1A2D17DD1E65BC7A9F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.4975192037969776
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6V1Vn1Hdyypn17dv65JFwakarBlPq02pxQL0BjvqlF8yge2wDGpQBJ2Y:mX9yy517dv658atlPR2cjm5o
                                                                                    MD5:DE0D20EA5F3FCC861E4B12A2EE77D4FC
                                                                                    SHA1:577652BEA400189FA1F9AF5D0148194FC8376A01
                                                                                    SHA-256:D8F67FCDEF13F91295E8A600E65B93968A6BE607FA25CF9FE33906419E4593C4
                                                                                    SHA-512:4CCBF2512E847F8DD48A5883F12AFA1FACE3A117C37494121721477FE7ABF0D3618E2BF3B294DA663B40F7CB572DFDC2F9CFA77DE4DC95BC49486610F1225B95
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...zR.e...........!.................(... ...@....... ....................................@.................................`(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..^...........................................Z..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.(.....L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.724494734770425
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:hCxWHpSpjp69yuiKf/sACWK22llPEQNgX:kxW6AFK28H+
                                                                                    MD5:A2D7AD1B88BB6981E88E46D9A08A441C
                                                                                    SHA1:A688F2CB8B2098EE31702C1927265C5B5C03C0DC
                                                                                    SHA-256:A699B99F91D43AE152EC54114CBC40D6E4B44F7A05982ED177157B0E42832148
                                                                                    SHA-512:7C2B76D1915F0A6E2DBDC83E2714D7843E89AC8FDC5A8C8199CE919E05E78BDBE2443AC54EB4F978756076BAB9A0F67F83545972A9C20D7E381881B9B30D4B5E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................L)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........%..............P ..5...........................................1..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.001844386696812
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:JB5nPlTrz0X3MOAbs2goRzRqkVmUm4pGo1SdekoMOMPleRW/b5d8vyQK15m3FybR:JaL6mNRd1+kBsMYzMYzMPeM7tnM6Puh
                                                                                    MD5:346111BF7AA931CBB8BDB0FA6D5BB9F4
                                                                                    SHA1:0BDAF5CD286648CEE5D99AEE48DC976590AFD3E7
                                                                                    SHA-256:8FF7B1A4BFA01E1999D6BF597E81049B6DED084986C45D51702951B445C8A974
                                                                                    SHA-512:A88335E3C1B09ADE8912F90E37A5051EC0884C877D11537F605D12ABE02C097DF36C66F5B128A3C148E7DEC21A32016675188EBBF51D1DD63CD4087ED1CDE14F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,..........NJ... ...`....... ....................................@..................................I..S....`............................................................................... ............... ..H............text...T*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B................0J......H.......PF..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7934301905896013
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6ZeHpQUFeza7InMHlpObOqOllNRydFdHSMkw4lPqLx/zzcjjSQqcF7JPWSG3RWMb:fJRFeza7ICObOqOFRypvkw4lPt+5
                                                                                    MD5:C10F96EDF1AE091640AD5EEECB4F8EB3
                                                                                    SHA1:834EF17878586FE702647D4FDCF2B4DD0F1BDD5F
                                                                                    SHA-256:2EB264CB29A1F9669672427AA9B709008D5367A4C0E40890951F85F0E7C8A54B
                                                                                    SHA-512:280CDE5F8EAC9C5E9AF5F0FB234F27398BFF8FB4F7B1513C8DF2422226F8C132015982E27EE1E52FE3A35F47161E0B6E9498BDA848E6F78F5E802F182520ADFC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................`+..K....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..c..........................................._..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3254997693815964
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6VNHNoD/g6lPqVx/uzVUIpjzqtE8+6GzaJ2Y:stoD/g6lPDUIz4
                                                                                    MD5:5E1FCCFCA0C2BFEFF6842640E3722247
                                                                                    SHA1:3357D2FE057CAE757B83CF844562978C4D13F571
                                                                                    SHA-256:9D81E8C6E08AC082F2C7A9F6C66E125CA0D963D542F6F3D476E0BDD275F33D16
                                                                                    SHA-512:EDF56F9FC0E753028FFDA6D7F641C11ED76BE351796C2142864D777DF386FEAD48D1195182FD4809E1271CDD0FD103546DB62EA14251FB812E48323E874822E7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!................~&... ...@....... ....................................@.................................0&..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`&......H.......p"..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.642876940558332
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxcvHt1G5ilQ/TQ/KpBwBYpuMlPqfzx/rzUSfujoqN0gyF/GtpJ2Y:Q4NjlQTQKLwB2DlPwa+1mX
                                                                                    MD5:8C035A706046634D9228A8F28CF7548D
                                                                                    SHA1:91292C8C7DAA91EA637DCFA3C9CA75556D2F41BD
                                                                                    SHA-256:BF47E632F104E3EF708341151007657E6B0EC329E9179C2CB93FBC154E0E2261
                                                                                    SHA-512:ACA00FB57313C34531E360014BA5C68BF84D28E13B3F29380E0DB51B18F6CFD3592E3E7473B3541B8EED6862AA6B60EE1C087A3FE343FE3B2052484AEF1EA4BB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@..................................'..K....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8032152674339303
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:9lgYOtEyMURUynqONYEYzfBAbFoE3mMqOWjoFlPwgC2j:HgYOm4qD8b
                                                                                    MD5:7621D349CB5611229DA6FF3DFDB15699
                                                                                    SHA1:0F6147E4EE7FD8B2E63A583DF6E97577B33C6013
                                                                                    SHA-256:8348315B8BF99BA57C93A3D30904C8CEEFBC072BBA17020F54EC1F532438C1E3
                                                                                    SHA-512:573086EB8AD6760AFC04B18F7008BC3224340BB780E445501B052CC0BFBCED228FAF164A2C6DE2E230B6E7D7FB41EF70D804CD76EA882D6D44AAD3A6EDC38EAC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................n1... ...@....... ....................................@..................................1..O....@..h....................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................P1......H........-..............P ..6...........................................2..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.238540416281824
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:SgJo1578XBSVyW6VjiplmGCxkQDjRKVxe0NDnQR4Nlebgd9i4F:SgJo1578XBSVyW6VDoQDjoVhNDnQR4Nn
                                                                                    MD5:55D1AB58F5F1978C4723A7FE39905223
                                                                                    SHA1:07C3F225B87FF0D68227FA29912CB28DBE0A36EC
                                                                                    SHA-256:95CB625669E1232C3138C82B59AAB178645B95F90BFE7DF4D9DF93D5BACACFD2
                                                                                    SHA-512:DFDABE4DA10848E2DF7B82B82E8758FEBD53EADB4B8BFB532BAC72C5AFBB1CE05D1D77CF553C604E9D4AC73AD2181AD1A61C71FBECFB36B592385AF074EB6F8C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p..........>.... ........... ....................................@....................................O.................................................................................... ............... ..H............text...Do... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B................ .......H.......................P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.2011886342484726
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:1fCwcEmiVIVMVnbE9V9w69O9SkyVvemyoQa+adjzGBzfOIGuSy4F:1pY2nbXyVvemyoftRCBLO2Sy4F
                                                                                    MD5:909EE0E14DE2F7012C1B7F63C7D9D836
                                                                                    SHA1:E70C9C14850AE9B545266B92F303FC084E32FE37
                                                                                    SHA-256:766FECC73460CB4C66D67C75C2A11C1D9F006249C338A8AE5ECAB68CD7F61435
                                                                                    SHA-512:5DAE80F10A1EA02E318FF08A55DE5975EB4A2B27EB7A0E2944565EFC6BF31878279B2967A9531715EE6DA0E10EC491615B82FDC05D2E73BD36F4FFEAA4D85CD7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........O... ...`....... ....................................@.................................HO..S....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................O......H........K..............P ..-+..........................................)+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5999227880168805
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E85H2d56R2QlA1gFzF3FKatFQMOprlPqWZlx/4zfznscjMqNvFJm9fWGzFwJ2Y:G5Wd5KlK1nlPkDsDFzFS
                                                                                    MD5:BE3B234BF1FA8246F0A7CD36340A93AC
                                                                                    SHA1:7C394084940E097E8E0D036998C5F4CB93AA941C
                                                                                    SHA-256:15D6C0FDD1A2DB3CC5CFCAA1834B838C7EEA99AD9F65E3935032EDA435C798ED
                                                                                    SHA-512:995D464D93569C3F73655F911D61C0BF0C512A6054128CB940C68DCC7B35021D838465E6E83FE973E8EC368AFB706E05E08C8085B9012C9ABFA656B04D218E6D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..J...........................................F..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5287543406757322
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vIRHer9UloNaCYUfusQElPqWZlx/Xz421sMSjYqNvYJmwfnGzF1J2Y:DR+reluPYUf7QElPc21spg6Fr
                                                                                    MD5:144A792B2902DD1F4A680E9D0F8F17F7
                                                                                    SHA1:73F1718CF5C0DA01D863EE716B58FE7895201FCF
                                                                                    SHA-256:36225C0FF1EFFD87A46FC160FEC00AF5D9AF6CBC593F5956166FD0849CE42158
                                                                                    SHA-512:170CDEF2E2420623A60238D9F3258176460F54CD658C4110C099DA5FD52B467DCF925203C28D72646C567EE25CABF389745FA393E07B065D5A5C0DB7A844668C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................>'... ...@....... ....................................@..................................&..K....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ '......H.......(#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4491935518177588
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzROsajEfqNvjJmbfsGzFCJ2YO:WlviGlPEOsxz1FwY
                                                                                    MD5:E6095E6B812C7D72C3E7F36B7F77F2C6
                                                                                    SHA1:31207821463A5C7463BEC79B15255ACA54598FAF
                                                                                    SHA-256:AA436B2FE96530046623E0BF47095817D7F8C4201804C0495D2886CE418D1162
                                                                                    SHA-512:018145CFFF32EAA43E12C1FA1BD60F52FD1B5406CE85020849AC1988A665293F080D687B5619481552D8766AD0EF8CD1FB2B249164425687777C7165D1785278
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7194082727109414
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:qxk3zsN9R7v885sNVqBsznlP0ZsAmkFh:cWzLqBszn23mkF
                                                                                    MD5:8965D68156A71A726970DDCA508B5E92
                                                                                    SHA1:6329C9EC320976A6CC2B0FE2E51BA1558A24CEF9
                                                                                    SHA-256:1F86277A8CAEE1A5B7139BF70C08293958DA9E4730B250DF41F313823B917A99
                                                                                    SHA-512:3144C780CCCC302217A390C01AEE14CA231D3BB83BCC7A9D5E9E48A72ED6645E087B0CDDB62FCF64AF4876C9379DB476ADEE982AA9E80F2A18B92BB00E2592CB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........&..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.337756964920133
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/UasrjL/qNvcJm0fDGzFBJ2Ye:gNClPMasykWFfI
                                                                                    MD5:DF747EEFAAA0588E4C7B45B5F1467721
                                                                                    SHA1:2813A921EFB71ADF0DF93908F3C18F8AB89D32F5
                                                                                    SHA-256:B9DA045E95A214955DF09F59123748A67AB18425E24B555F8C81B479B4967431
                                                                                    SHA-512:8FEBEA415DA781D1C69F97F0CCC45B5F86528179AC5D2B053D09AD213807AA7C87864673E189899AF05E3023CFF20A2582CA1DABDF1D7FEF568AD50EF03370D5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.236877578473013
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:z2nvlHAHAn4lk25VeVOVWVCxZgMBQwH8Mc1yQgBBAj/:zDg6k25UM04xZgMBQ28Mc1yQgBBAL
                                                                                    MD5:19FF931A1A6174554591EC4498A36E36
                                                                                    SHA1:49385F8D2D5C7C68514F68000ABDDB279BFC53EA
                                                                                    SHA-256:67658FBA88F500247513B7299B6BF56954B4AC128EBFF5657AAFFF4E8A3A52EE
                                                                                    SHA-512:F2E0887C889B60380A01D7A2F37971746F9CBA91B9944B8D83CACB4049F1905479D6AAE3D945F7A5FB10268DBA5976BC9D71E5826163D7A0C5F7D1C5D8D74C12
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......D7..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.775199124098076
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gN6PKH23S+lvgeKlkoEa/flPq+LDJqLhj3vgIU1WyoFp/98P28s9JJ2L:tiKW39G/flPNgNj3YG7T3
                                                                                    MD5:D394F3FF3C36D9DAAE4352683225C955
                                                                                    SHA1:1A4BE2C8B43ABAE0B5CA27CEBC8E5EB13D433158
                                                                                    SHA-256:A30E0A68E0ED335C5F07529F11C0FDA5DEE9367C14C32278AFEAE7D7869ADEB2
                                                                                    SHA-512:CC8E612AAD1FA974CD0C89F01B90406E7A5C39F20EEC31C86488FE4A82F067EFA133156902B31C3248022F9634296D5DC3A4D8291B2FFFD65D00DEC850F0969A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................!..X.3m..Da.........n.:.c}......N..U.G.E.D......R<..{D..l.g.....n......`O..c.h.Y....$.w.^....a...L..)8y.xq...|....Q.j_.L1.".w................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.090141264865196
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Crp1+cWt1eyDw4hSRJQ6sFJ788WlclPNt8jaBlZsKJ:a8cWpDU/S2Gg
                                                                                    MD5:6E2786D15CE907DA2983E5859777F599
                                                                                    SHA1:93B82E7200A6E792777A3376D41C76A4D18B77C2
                                                                                    SHA-256:B29C7FA55190D89BF0A24FFFBAB8752C36CA709BAB085B8F04EF969FD528C6B6
                                                                                    SHA-512:A68862D12620A828B20077CE768D6108785FC6EB3A489B00E34BA658CE954D9F1264C3FAC398B3FEA5FDEBC80B115DEF921C9F1A53ED30A24AE4153C69CEC6F6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ...............................W....@.................................p)..K....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......d%............... ......P ......................................nA!.7..D.....a..Mp.........A.0.8.Uk8.T..r...<......I..y[..Ka.X..ls..Sl....&-..&Q.E.4&(1^zd.9.^....bH.3@&...T.{.....3...9...E...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):31232
                                                                                    Entropy (8bit):4.238540416281824
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:SgJo1578XBSVyW6VjiplmGCxkQDjRKVxe0NDnQR4Nlebgd9i4F:SgJo1578XBSVyW6VDoQDjoVhNDnQR4Nn
                                                                                    MD5:55D1AB58F5F1978C4723A7FE39905223
                                                                                    SHA1:07C3F225B87FF0D68227FA29912CB28DBE0A36EC
                                                                                    SHA-256:95CB625669E1232C3138C82B59AAB178645B95F90BFE7DF4D9DF93D5BACACFD2
                                                                                    SHA-512:DFDABE4DA10848E2DF7B82B82E8758FEBD53EADB4B8BFB532BAC72C5AFBB1CE05D1D77CF553C604E9D4AC73AD2181AD1A61C71FBECFB36B592385AF074EB6F8C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....p..........>.... ........... ....................................@....................................O.................................................................................... ............... ..H............text...Do... ...p.................. ..`.rsrc................r..............@..@.reloc...............x..............@..B................ .......H.......................P ...j...........................................j.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..E.....o....U.A.P.q..v..Q.....Q....c.....].h../P!."...O?..O?...A...E.8E4.3...L.$..m..L.\...j.H.o.............o<.........1(.p#:.X.R..%..D..#.......W..?........@...^.....0.....(..J.&.8........q.....IX.......\(..|..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.724494734770425
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:hCxWHpSpjp69yuiKf/sACWK22llPEQNgX:kxW6AFK28H+
                                                                                    MD5:A2D7AD1B88BB6981E88E46D9A08A441C
                                                                                    SHA1:A688F2CB8B2098EE31702C1927265C5B5C03C0DC
                                                                                    SHA-256:A699B99F91D43AE152EC54114CBC40D6E4B44F7A05982ED177157B0E42832148
                                                                                    SHA-512:7C2B76D1915F0A6E2DBDC83E2714D7843E89AC8FDC5A8C8199CE919E05E78BDBE2443AC54EB4F978756076BAB9A0F67F83545972A9C20D7E381881B9B30D4B5E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...wR.e...........!.................)... ...@....... ....................................@.................................L)..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........%..............P ..5...........................................1..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..w......U.+F.[7.n.RX[.iKs.m]...............v...o...........jL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.d.a.t.e.I.p.A.d.d.r.e.s.s._.F.o.r.m.a.t.E.r.r.o.r.....nL.x.C.o.n.n.e.c.t.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.V.a.l.i.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.775199124098076
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6gN6PKH23S+lvgeKlkoEa/flPq+LDJqLhj3vgIU1WyoFp/98P28s9JJ2L:tiKW39G/flPNgNj3YG7T3
                                                                                    MD5:D394F3FF3C36D9DAAE4352683225C955
                                                                                    SHA1:1A4BE2C8B43ABAE0B5CA27CEBC8E5EB13D433158
                                                                                    SHA-256:A30E0A68E0ED335C5F07529F11C0FDA5DEE9367C14C32278AFEAE7D7869ADEB2
                                                                                    SHA-512:CC8E612AAD1FA974CD0C89F01B90406E7A5C39F20EEC31C86488FE4A82F067EFA133156902B31C3248022F9634296D5DC3A4D8291B2FFFD65D00DEC850F0969A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!................n(... ...@....... ...................................@..................................(..W....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P(......H........#..X............ ......P ......................................!..X.3m..Da.........n.:.c}......N..U.G.E.D......R<..{D..l.g.....n......`O..c.h.Y....$.w.^....a...L..)8y.xq...|....Q.j_.L1.".w................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..."....g..d..k0^*...@~.2Tx...z...9...........=...........8W.e.e.k.l.y.P.e.r.i.o.d.D.a.y.O.f.W.e.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):9216
                                                                                    Entropy (8bit):4.236877578473013
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:z2nvlHAHAn4lk25VeVOVWVCxZgMBQwH8Mc1yQgBBAj/:zDg6k25UM04xZgMBQ28Mc1yQgBBAL
                                                                                    MD5:19FF931A1A6174554591EC4498A36E36
                                                                                    SHA1:49385F8D2D5C7C68514F68000ABDDB279BFC53EA
                                                                                    SHA-256:67658FBA88F500247513B7299B6BF56954B4AC128EBFF5657AAFFF4E8A3A52EE
                                                                                    SHA-512:F2E0887C889B60380A01D7A2F37971746F9CBA91B9944B8D83CACB4049F1905479D6AAE3D945F7A5FB10268DBA5976BC9D71E5826163D7A0C5F7D1C5D8D74C12
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ZR.e...........!.................:... ...@....... ....................................@..................................:..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................:......H.......D7..P...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....:.......PADPADPB....p.%)...0.&.....8...[.`.(.@....a...a...a.=8k......k..."...~.w'...|.....Gp..5.. ]Z..j..K.,..=/.......z..H.p`.....p5.asY._...J............)6..)6......G.......7.!...!..R,...-1a.8O.HG..RVkI&Y.t.[..X\...iN..s.G.x'..y..Zz
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.337756964920133
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6W4XNH1UlPqWZlx//rz/UasrjL/qNvcJm0fDGzFBJ2Ye:gNClPMasykWFfI
                                                                                    MD5:DF747EEFAAA0588E4C7B45B5F1467721
                                                                                    SHA1:2813A921EFB71ADF0DF93908F3C18F8AB89D32F5
                                                                                    SHA-256:B9DA045E95A214955DF09F59123748A67AB18425E24B555F8C81B479B4967431
                                                                                    SHA-512:8FEBEA415DA781D1C69F97F0CCC45B5F86528179AC5D2B053D09AD213807AA7C87864673E189899AF05E3023CFF20A2582CA1DABDF1D7FEF568AD50EF03370D5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@..................................$..K....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUID...........#Blob.....................%3................................................%.....B....._.....x.............................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5999227880168805
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6E85H2d56R2QlA1gFzF3FKatFQMOprlPqWZlx/4zfznscjMqNvFJm9fWGzFwJ2Y:G5Wd5KlK1nlPkDsDFzFS
                                                                                    MD5:BE3B234BF1FA8246F0A7CD36340A93AC
                                                                                    SHA1:7C394084940E097E8E0D036998C5F4CB93AA941C
                                                                                    SHA-256:15D6C0FDD1A2DB3CC5CFCAA1834B838C7EEA99AD9F65E3935032EDA435C798ED
                                                                                    SHA-512:995D464D93569C3F73655F911D61C0BF0C512A6054128CB940C68DCC7B35021D838465E6E83FE973E8EC368AFB706E05E08C8085B9012C9ABFA656B04D218E6D
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@.................................d'..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H........#..............P ..J...........................................F..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.!u..z."{..w..H..+AB@..Sb....[.......p.......9...........4D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.D.i.s.a.b.l.e.d.....2D.e.r.o.g.a.t.i.o.n.S.t.a.t.e.V.3._.E.n.a.b.l.e.d.....FW.e.e.k.l.y.P.e.r.i.o.d.D.i.a.l.o.g.V.3._.D.e.r.o.g.a.t
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):14848
                                                                                    Entropy (8bit):4.2011886342484726
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:1fCwcEmiVIVMVnbE9V9w69O9SkyVvemyoQa+adjzGBzfOIGuSy4F:1pY2nbXyVvemyoftRCBLO2Sy4F
                                                                                    MD5:909EE0E14DE2F7012C1B7F63C7D9D836
                                                                                    SHA1:E70C9C14850AE9B545266B92F303FC084E32FE37
                                                                                    SHA-256:766FECC73460CB4C66D67C75C2A11C1D9F006249C338A8AE5ECAB68CD7F61435
                                                                                    SHA-512:5DAE80F10A1EA02E318FF08A55DE5975EB4A2B27EB7A0E2944565EFC6BF31878279B2967A9531715EE6DA0E10EC491615B82FDC05D2E73BD36F4FFEAA4D85CD7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.....0...........O... ...`....... ....................................@.................................HO..S....`............................................................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................O......H........K..............P ..-+..........................................)+.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP...\....!.6...g.;......;..e2.0.?..M}.A..............5(.CI.........mV..b.........4.....+..:.6.......i...N.f..b..y..O...*..hP._..2nX.@...Py...Mw......`......0........c.s.....W..^...H..gn.......f....f..E...]...@.'
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.5287543406757322
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vIRHer9UloNaCYUfusQElPqWZlx/Xz421sMSjYqNvYJmwfnGzF1J2Y:DR+reluPYUf7QElPc21spg6Fr
                                                                                    MD5:144A792B2902DD1F4A680E9D0F8F17F7
                                                                                    SHA1:73F1718CF5C0DA01D863EE716B58FE7895201FCF
                                                                                    SHA-256:36225C0FF1EFFD87A46FC160FEC00AF5D9AF6CBC593F5956166FD0849CE42158
                                                                                    SHA-512:170CDEF2E2420623A60238D9F3258176460F54CD658C4110C099DA5FD52B467DCF925203C28D72646C567EE25CABF389745FA393E07B065D5A5C0DB7A844668C
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!................>'... ...@....... ....................................@..................................&..K....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ '......H.......(#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Ja..@....`.1..Vv..W4...i...............c...dI.n.d.e.x.I.n.f.o.r.m.a.t.i.o.n.V.i.e.w.M.o.d.e.l.V.4._.B.o.a.r.d.L.a.b.e.l._.S.5.0.0.I.o.B.o.a.r.d.....:M.a.t.e.r.i.a.l.C.o.m.m.M.o.d.u.l.e.T.y.p.e.V.4._.S.5.0.0.....FS.5.0.0.D.i.T.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):4.090141264865196
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:Crp1+cWt1eyDw4hSRJQ6sFJ788WlclPNt8jaBlZsKJ:a8cWpDU/S2Gg
                                                                                    MD5:6E2786D15CE907DA2983E5859777F599
                                                                                    SHA1:93B82E7200A6E792777A3376D41C76A4D18B77C2
                                                                                    SHA-256:B29C7FA55190D89BF0A24FFFBAB8752C36CA709BAB085B8F04EF969FD528C6B6
                                                                                    SHA-512:A68862D12620A828B20077CE768D6108785FC6EB3A489B00E34BA658CE954D9F1264C3FAC398B3FEA5FDEBC80B115DEF921C9F1A53ED30A24AE4153C69CEC6F6
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....\.e...........!.................)... ...@....... ...............................W....@.................................p)..K....@.. ....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................)......H.......d%............... ......P ......................................nA!.7..D.....a..Mp.........A.0.8.Uk8.T..r...<......I..y[..Ka.X..ls..Sl....&-..&Q.E.4&(1^zd.9.^....bH.3@&...T.{.....3...9...E...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.j...T......h.\.F....H..&|?...................K...........FT.l.s.C.a.l.l.b.a.c.k._.C.e.r.t.i.f.i.c
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):11264
                                                                                    Entropy (8bit):4.835994224355824
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:CuQi4TlRYMw+f+Sb+jkfqtTrf9t1mH/Jn:CuQiS0Mw+f+Sb+jkyNr1rmhn
                                                                                    MD5:1282B07CA5C211DADA29489C3346005E
                                                                                    SHA1:6075EDD0138AAEE77BAF2B7A0791CC8CC2C432F2
                                                                                    SHA-256:2B4531C492CDFDCA6DD63BFD2B30CE2352BD98F3B320E9820CB65C5E0518D504
                                                                                    SHA-512:0BC05DE5F4DB0BC13AB08657CCE36F791C66E8F778825064B81B2701E096F5F36F9476448940DDBA10E5C963DDA9DC154924F0A16B4FEF1A2D17DD1E65BC7A9F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!....."...........@... ...`....... ....................................@..................................?..K....`............................................................................... ............... ..H............text...$ ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPtm..........(I.n.i.t.i.a.l.V.a.l.u.e.L.i.s.t.V.1.1.0.......5<?xml version="1.0" encoding="UTF-8"?>..<xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://www.sofrel.com/SNEInitializationValue/V110/" targetNamesp
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.819954761317961
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:m58AYPY+n+Zy+D9PfYPFdlP0OIgcOnwa:m58wYjkS
                                                                                    MD5:F989BC031F487F9367D86B10853DA339
                                                                                    SHA1:0F582C96068414147C269E4C39C3B548C6783D26
                                                                                    SHA-256:CE9963B629113FDE6B675FFC0EC55194823FED65EFFD08DE376F163CBC5A64F8
                                                                                    SHA-512:E797AF33CAB09B77412FE5C44461F95B18F487BF42A11F87C3F03CBC5962BA478E77937684E4C0878BD2BFDC1C07DD0982E0FCE8823B8D4BFF1D5AB85EAB79A7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sR.e...........!.................+... ...@....... ....................................@..................................+..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..]...........................................Y..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.Z..RTP.....&..T....=......o.......$p.@.JCT3...Y.......1.......@.......................%...TC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.a.n.c.e.l.....XC.h.a.n.g.e.P.a.s.s.w.o.r.d.D.i.a.l.o.g._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.6030306404916543
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6b11Hq9LUzj6XIMwullPqNKS2pxsrIUgj3qXp2qwz2/UbGp0JJ2Y:+/sgX6YMw0lPm2cNlBZq
                                                                                    MD5:335A00AED1F5DF1C1484AD887B808699
                                                                                    SHA1:EB2B942F1AB27D9E02C63F72F47F3ABEB23553C7
                                                                                    SHA-256:A8EB1D010C3A528B48EB20FD2A641A2E61CAA956E451D1B4CD067E616C512D52
                                                                                    SHA-512:AF8801D0A64D852C519DA2F1381D6C650266DF30B3BA74A12767FED7CA37F4D735D832BF0A707FA0F884013188F52C3F6BADCFC6673EC6DD1DFD24006EBA44A5
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...rR.e...........!.................(... ...@....... ....................................@.................................H(..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..1...........................................-..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....-Q...y...J.~........o...e.......jV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.F.o.r.m.a.t.E.r.r.o.r.M.e.s.s.a.g.e.....vV.a.l.i.d.a.t.e.P.a.s.s.w.o.r.d.U.t.i.l._.V.a.l.i.d.a.t.e.L.o.g.i.n._.S.t.r.i.n.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4096
                                                                                    Entropy (8bit):3.4491935518177588
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6Q4/lXHPiWqtclPqWZlx/SzROsajEfqNvjJmbfsGzFCJ2YO:WlviGlPEOsxz1FwY
                                                                                    MD5:E6095E6B812C7D72C3E7F36B7F77F2C6
                                                                                    SHA1:31207821463A5C7463BEC79B15255ACA54598FAF
                                                                                    SHA-256:AA436B2FE96530046623E0BF47095817D7F8C4201804C0495D2886CE418D1162
                                                                                    SHA-512:018145CFFF32EAA43E12C1FA1BD60F52FD1B5406CE85020849AC1988A665293F080D687B5619481552D8766AD0EF8CD1FB2B249164425687777C7165D1785278
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................%... ...@....... ....................................@.................................X%..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H........!..............P ..?...........................................;..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.?4n....5...tB.o.a.r.d.A.i.C.o.n.t.r.o.l.l.e.r.V.5._.L.o.a.d.C.o.n.f.i.g.u.r.a.t.i.o.n._.A.i.V.o.l.t.L.a.b.e.l.E.x.t.e.n.s.i.o.n.......AI-V.BSJB............v4.0.30319......l.......#~..`...t...#Strings............#US.........#GUI
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.8032152674339303
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:9lgYOtEyMURUynqONYEYzfBAbFoE3mMqOWjoFlPwgC2j:HgYOm4qD8b
                                                                                    MD5:7621D349CB5611229DA6FF3DFDB15699
                                                                                    SHA1:0F6147E4EE7FD8B2E63A583DF6E97577B33C6013
                                                                                    SHA-256:8348315B8BF99BA57C93A3D30904C8CEEFBC072BBA17020F54EC1F532438C1E3
                                                                                    SHA-512:573086EB8AD6760AFC04B18F7008BC3224340BB780E445501B052CC0BFBCED228FAF164A2C6DE2E230B6E7D7FB41EF70D804CD76EA882D6D44AAD3A6EDC38EAC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}R.e...........!................n1... ...@....... ....................................@..................................1..O....@..h....................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................P1......H........-..............P ..6...........................................2..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.L]..................._.'..{.w..cJ...j.....W.6....0.$F1...1\.^38./?Z*.@.a.G}}.\..._a..m.#.{U.......:...................S...j...............H.......................5.......F....... ...........NG.e.n.e.r.a.l.P.a.r.a.m.V.i.e.w
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):13824
                                                                                    Entropy (8bit):4.001844386696812
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:JB5nPlTrz0X3MOAbs2goRzRqkVmUm4pGo1SdekoMOMPleRW/b5d8vyQK15m3FybR:JaL6mNRd1+kBsMYzMYzMPeM7tnM6Puh
                                                                                    MD5:346111BF7AA931CBB8BDB0FA6D5BB9F4
                                                                                    SHA1:0BDAF5CD286648CEE5D99AEE48DC976590AFD3E7
                                                                                    SHA-256:8FF7B1A4BFA01E1999D6BF597E81049B6DED084986C45D51702951B445C8A974
                                                                                    SHA-512:A88335E3C1B09ADE8912F90E37A5051EC0884C877D11537F605D12ABE02C097DF36C66F5B128A3C148E7DEC21A32016675188EBBF51D1DD63CD4087ED1CDE14F
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...xR.e...........!.....,..........NJ... ...`....... ....................................@..................................I..S....`............................................................................... ............... ..H............text...T*... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B................0J......H.......PF..............P ...%...........................................%.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....<.......PADPADP."|...l.....Kx..............$...$...$...=.ot.."..W.Y..p..P/...W..(.c...........*...a.....v....*b..9.+d.+d......o.Tk.w...L.a...g.MOr.....F.....]......."..."q..&@P%(...+z.&...[/#4.5.[.=..@...E"..Q..qWj.G_:..i...l.2.n
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.642876940558332
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6lxcvHt1G5ilQ/TQ/KpBwBYpuMlPqfzx/rzUSfujoqN0gyF/GtpJ2Y:Q4NjlQTQKLwB2DlPwa+1mX
                                                                                    MD5:8C035A706046634D9228A8F28CF7548D
                                                                                    SHA1:91292C8C7DAA91EA637DCFA3C9CA75556D2F41BD
                                                                                    SHA-256:BF47E632F104E3EF708341151007657E6B0EC329E9179C2CB93FBC154E0E2261
                                                                                    SHA-512:ACA00FB57313C34531E360014BA5C68BF84D28E13B3F29380E0DB51B18F6CFD3592E3E7473B3541B8EED6862AA6B60EE1C087A3FE343FE3B2052484AEF1EA4BB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................'... ...@....... ....................................@..................................'..K....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................'......H........#..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.I.......4..\.!..3Z...z............;...9...n...v...4A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.M.e.s.s.a.g.e.....0A.p.p._.S.h.o.w.D.i.a.l.g.E.r.r.o.r._.T.i.t.l.e.....>D.i.a.l.o.g.E.r.r.o.r._.B.u.t.t.o.n._.C.o.n.t.e.n.t._.C.o.p.y....
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5120
                                                                                    Entropy (8bit):3.4975192037969776
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6V1Vn1Hdyypn17dv65JFwakarBlPq02pxQL0BjvqlF8yge2wDGpQBJ2Y:mX9yy517dv658atlPR2cjm5o
                                                                                    MD5:DE0D20EA5F3FCC861E4B12A2EE77D4FC
                                                                                    SHA1:577652BEA400189FA1F9AF5D0148194FC8376A01
                                                                                    SHA-256:D8F67FCDEF13F91295E8A600E65B93968A6BE607FA25CF9FE33906419E4593C4
                                                                                    SHA-512:4CCBF2512E847F8DD48A5883F12AFA1FACE3A117C37494121721477FE7ABF0D3618E2BF3B294DA663B40F7CB572DFDC2F9CFA77DE4DC95BC49486610F1225B95
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...zR.e...........!.................(... ...@....... ....................................@.................................`(..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H........$..............P ..^...........................................Z..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......8..=.....`..K.,..7.!..ALO...n.................../...Z.......*I.n.t.S.t.r.i.n.g.P.a.r.s.i.n.g.E.r.r.o.r.....&I.n.t.S.t.r.i.n.g.R.a.n.g.e.E.r.r.o.r.(.....L.x.C.o.n.n.e.c.t.S.e.t.t.i.n.g.s.V.a.l.i.d.a.t.i.o.n.U.t.i.l._.B.u.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7934301905896013
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6ZeHpQUFeza7InMHlpObOqOllNRydFdHSMkw4lPqLx/zzcjjSQqcF7JPWSG3RWMb:fJRFeza7ICObOqOFRypvkw4lPt+5
                                                                                    MD5:C10F96EDF1AE091640AD5EEECB4F8EB3
                                                                                    SHA1:834EF17878586FE702647D4FDCF2B4DD0F1BDD5F
                                                                                    SHA-256:2EB264CB29A1F9669672427AA9B709008D5367A4C0E40890951F85F0E7C8A54B
                                                                                    SHA-512:280CDE5F8EAC9C5E9AF5F0FB234F27398BFF8FB4F7B1513C8DF2422226F8C132015982E27EE1E52FE3A35F47161E0B6E9498BDA848E6F78F5E802F182520ADFC
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tR.e...........!.................+... ...@....... ....................................@.................................`+..K....@..p....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................+......H........'..............P ..c..........................................._..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP......s...R.8...{./...&..&...z.?.K...^..z.y....E,.A...DH.2.H.2 M.2:..]..z........................9...v.......e.......2..._..."...].......U...............p...4C.o.m.m.u.n.i.c.a.t.i.o.n.M.o.d.e.E.n.u.m._.A.u.t.o.....8C.o.m.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):4608
                                                                                    Entropy (8bit):3.3254997693815964
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6VNHNoD/g6lPqVx/uzVUIpjzqtE8+6GzaJ2Y:stoD/g6lPDUIz4
                                                                                    MD5:5E1FCCFCA0C2BFEFF6842640E3722247
                                                                                    SHA1:3357D2FE057CAE757B83CF844562978C4D13F571
                                                                                    SHA-256:9D81E8C6E08AC082F2C7A9F6C66E125CA0D963D542F6F3D476E0BDD275F33D16
                                                                                    SHA-512:EDF56F9FC0E753028FFDA6D7F641C11ED76BE351796C2142864D777DF386FEAD48D1195182FD4809E1271CDD0FD103546DB62EA14251FB812E48323E874822E7
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|R.e...........!................~&... ...@....... ....................................@.................................0&..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`&......H.......p"..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPE.g.@Q.....4S...............NG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.C.o.n.t.r.o.l.l.e.r._.T.o.o.l.B.a.r._.T.i.t.l.e.....hG.e.n.e.r.a.l.S.e.t.t.i.n.g.s.V.i.e.w._.E.x.p.a.n.d.e.r._.H.e.a.d.e.r._.A.u.t.h.e.n.t.i.f.i.c.a.t.i.o.n.....ZG.e.n.e
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.7194082727109414
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:qxk3zsN9R7v885sNVqBsznlP0ZsAmkFh:cWzLqBszn23mkF
                                                                                    MD5:8965D68156A71A726970DDCA508B5E92
                                                                                    SHA1:6329C9EC320976A6CC2B0FE2E51BA1558A24CEF9
                                                                                    SHA-256:1F86277A8CAEE1A5B7139BF70C08293958DA9E4730B250DF41F313823B917A99
                                                                                    SHA-512:3144C780CCCC302217A390C01AEE14CA231D3BB83BCC7A9D5E9E48A72ED6645E087B0CDDB62FCF64AF4876C9379DB476ADEE982AA9E80F2A18B92BB00E2592CB
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....R.e...........!.................+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H........&..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP..K.^./.._;.Oo..YlR.....59.*....a..xX.K...K:e!2.D"c.]\.k._...j............*......."...p...(...................a...K...M.......v...HA.r.c.h.i.v.e.E.x.p.o.r.t.C.o.n.t.r.o.l.l.e.r.V.6._.D.a.t.e.H.e.a.d.e.r.....NA.r.c.h.i.v.e.E.x.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):7168
                                                                                    Entropy (8bit):3.7829722115887696
                                                                                    Encrypted:false
                                                                                    SSDEEP:48:6vMHo6cs+TcW5cyLcQQ5cGcSSLcdcc7Ac6cWpc4cTcyc3Gc+cSGcfAdc/cFUuCWR:3SYpA9ZS6R8jlPgw0xUdnK
                                                                                    MD5:DA3AEDB793E7A652125FEEA58C8CA668
                                                                                    SHA1:39505321C2B90575C8F5125E1739FF720EC9E5FE
                                                                                    SHA-256:5AC1F7DF23CAAB0D8DA0FC9286BB8E84C09AE22B1FD5BA4C50F3D01DA4E61B6B
                                                                                    SHA-512:AC92291FB3C8C110E5C0C6587099215E5E600A22F00FC2D11634FFBDF9410D761AF3A002C67850F7F21AF540A19B7963B1755272FFC52263247AA3B964514636
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\R.e...........!................n0... ...@....... ....................................@................................. 0..K....@.......................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................P0......H.......T,..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPn....E.g....?...8...^>..x..*eM.G...F6...t.5vL.TH...k..]n.!...&.U...mDM.Z...{........~.......[.......}.......L...........N...K.........../...............y...8...VC.o.m.m.U.i.E.r.r.o.r.H.a.n.d.l.e.r._.E.r.r.o.r.D.i.a.l.o.g._.D
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):5632
                                                                                    Entropy (8bit):3.6958695447362193
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:zXmayK6ryXX0A3GrXrQXyTAxJlPdOoeQr:zXGrYX0A3GrXMXHfqoeQ
                                                                                    MD5:E2785675831C1F909579ECFAB1D7E959
                                                                                    SHA1:F99B843C033804A4E4D3F702C0EC033B66A6333F
                                                                                    SHA-256:808A662089A1589365B99F11BBCA2400F01CED84D053CC81B18C28DD5CDEE326
                                                                                    SHA-512:14CDAB4D6A3D5539CB7FA4E250FEC960930423586EEEE764BE730803B9A2AEFDC6BE8C63F161B790D6E53874A2CF649C35B7A3DF0F3B0DEBCEA8732C9201E4B4
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[R.e...........!................N+... ...@....... ....................................@..................................*..W....@.......................`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0+......H.......('..............P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPCD..X....6.."..5..Y....|y......j.......5431..5d.tG........m...!...............H...........x.......(.........I.d.e.n.t.i.t.y.C.a.r.d.O.p.t.i.o.n.s.D.e.s.c.B.u.i.l.d.e.r._.K.n.o.w.n.O.p.t.i.o.n.L.o.g.i.c.D.e.s.c.r.i.p.t.i.o.n.F.
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):358912
                                                                                    Entropy (8bit):5.887222802567272
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:CCq8eBDTLHitSpUWF7oqtnTawrJqSceW47Xx1367A:LdeB7idWqqteMLD7q
                                                                                    MD5:9277D6A62D6A0E8E47C3E6A604E89A8C
                                                                                    SHA1:0554F579C4E609023AEDDFAFF200D8FC12AE0EAA
                                                                                    SHA-256:348CBF741BF59C360B2598574C10C71B4D9B40FECF48E96CB023FEF26A2F9574
                                                                                    SHA-512:A385393BC1EA618CCA05C3E8568E53A8970B40427223B3C3258C60B326BD93B2CFAB9A72AB5767FD5961752B808EDF063235040000A11BBE1F132008F7A68C07
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......M.-...C...C...C.O...|.C.O.....C.O...&.C..:....C..:....C...B.^.C.t.....C.t.....C.......C.t.....C.Rich..C.........PE..d...s..T.........." ......................................................................`.............................................t...t...<............p...$...............%......8...........................@...p...............(............................text...z........................... ..`.rdata.............................@..@.data...X...........................@....pdata...$...p...&...,..............@..@.rsrc................R..............@..@.reloc...%.......&...T..............@..B................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):298496
                                                                                    Entropy (8bit):6.531291714253338
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:udNe8OCNTjBES0Ib6D4b3HlsmrS+Gv6k59:udNe8OCNTjj0Ib6DAHlsczSl
                                                                                    MD5:830DB1F25A4D2B13668FFC7A7B7B7821
                                                                                    SHA1:2C968750C2B2BD1A7644852E68194E795ED8210B
                                                                                    SHA-256:1478C20A4B9F57B4AC7FEB1150EC2976B4735B1F25A455B3C722D6CB221D5A9D
                                                                                    SHA-512:FEC2CAC4C86E972067AD572CBEF25228AD9319ADD643B4CFBA595990C53589385656E2A99975DDE781ECC11B2FD4C22F872C4D3324AD4A621C6485EAD9251013
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........f5...[...[...[..U....[..U....[..U....[.......[.......[...Z...[..~....[..~....[..U....[..~....[.Rich..[.........................PE..L......T.........."!......................................................................@.............................t.......<...............................HO..P...8............................[..@............................................text...^........................... ..`.rdata..............................@..@.data...............................@....rsrc................<..............@..@.reloc..HO.......P...>..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:InnoSetup Log 64-bit S4-View-Package {9E82D52C-73A8-4180-844B-564D36F24BDE}, version 0x30, 7787 bytes, 468325\user, "C:\Program Files\LACROIX Sofrel\S4-View"
                                                                                    Category:dropped
                                                                                    Size (bytes):7787
                                                                                    Entropy (8bit):4.699802215960504
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:ZW2CojqHUYwJxSG1N0SIj/h5LndqX/uIb84cVSQs0LnJ7it6w6C:o2CBHFwJkCNU/dIVcVSQ1nxit6wb
                                                                                    MD5:54A680B23A9418554771C8D314B4F994
                                                                                    SHA1:242B7F42017C2B60B1E35677E3D997A4809B55C2
                                                                                    SHA-256:638DED84778E346709159BACEEFD5E41B0C9BD971BEA2787B64DFAA2DB6A4AD7
                                                                                    SHA-512:C56B96AC30BD76C4EF1C9821DD36B6F939B247F34BF1E074AE5021F7A66A09FBA8FB71F1EA08C8C812B0C31D3F2D72C907FF2784C3D899387093804E4F2C4A62
                                                                                    Malicious:false
                                                                                    Preview:Inno Setup Uninstall Log (b) 64-bit.............................{9E82D52C-73A8-4180-844B-564D36F24BDE}..........................................................................................S4-View-Package.................................................................................................................0.......k...%.................................................................................................................B..........+........F....468325.user'C:\Program Files\LACROIX Sofrel\S4-View...........0.'.3.. ............IFPS.............................................................................................................BOOLEAN.....................................................................................!OPENARRAYOFCONST...................*...........!MAIN....-1.+...r.......MYBEFOREINSTALL_DLEC....-1 @8..MSGBOX.............=.......CHECKFRAMEWORK48....16..LOG........REGQUERYDWORDVALUE...........EXPANDCONSTANT...........q.......INITIALIZESETUP
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):725157
                                                                                    Entropy (8bit):6.524824306128734
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:2sMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyR5:xMcMoi3rPR37dzHRA6G7WbuSEmK50syM
                                                                                    MD5:5A98B1129C909A92BCC21B2568AED759
                                                                                    SHA1:0F6FBD380411EBCC4C719E1C737FF24542AB844D
                                                                                    SHA-256:BE2DB372054BBEDFEA631EE883FA4BD4DFC29311521BA1E156843A05A3C181CD
                                                                                    SHA-512:34B20B940A8E0B9A621B83808FB01C165F2F1174F6E175C98E31D1CB9D861DD9DD076D06812A7BE6D197BFECBAEE4E1F653D00DDBF072193FFC74E4D7B91A5F7
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:InnoSetup Log 64-bit S4-View {4928A9CA-81FE-4708-8B4C-2C77A0B95930}, version 0x30, 51250 bytes, 468325\user, "C:\Program Files\LACROIX Sofrel\S4-View"
                                                                                    Category:dropped
                                                                                    Size (bytes):51250
                                                                                    Entropy (8bit):5.1831643782494385
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:U2SfviKLKg5gfLbkg/rnnNH7NVCmk/r0nNHgNVCk9f4QcJEu5UEPMk2MEsE2Ei37:QGEgzs9zmAf4QuNKu72MEsE2Ei3jjoe
                                                                                    MD5:7568C08A32E17A6DA558D7258699B3B6
                                                                                    SHA1:70586DB2557B9FB7F3F9FACAB67CA1A02BBAD5A6
                                                                                    SHA-256:77E763DE3A13DB9F8A4B42B42EBC29B827C06F5C87E50B1ADBA250C2584CBBA9
                                                                                    SHA-512:006EBC5F45036B27887C5FD8391909C533593B5B5567D825A44EA84E21A329889F5BE1603101951FBED5D5215E9E1EF0AB31A6D757E51742332E25926C889CF5
                                                                                    Malicious:false
                                                                                    Preview:Inno Setup Uninstall Log (b) 64-bit.............................{4928A9CA-81FE-4708-8B4C-2C77A0B95930}..........................................................................................S4-View.........................................................................................................................0...d...2...%................................................................................................................]E..................F....468325.user'C:\Program Files\LACROIX Sofrel\S4-View...........0.+.... ......D....<IFPS.............................................................................................................BOOLEAN.........................F....IDISPATCH.............!OPENARRAYOFVARIANT.........................................!MAIN....-1.....I.......GETELEMENTCONFIGFROMKEY....8 @8 @8 @8..LOG........CREATEOLEOBJECT........IDISPATCHINVOKE...........SETARRAYLENGTH.......RAISEEXCEPTION........INTTOSTR...........Z.......SETELEMENTCONFIGFROMKE
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):725157
                                                                                    Entropy (8bit):6.524818615519142
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:2sMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyRj:xMcMoi3rPR37dzHRA6G7WbuSEmK50syO
                                                                                    MD5:F403E2C6DBBF42ABEC4E5B652214B871
                                                                                    SHA1:0ADBEEF61C281FBDCF573FC82B36991DCFE36205
                                                                                    SHA-256:442A9BEE6C3C457C3DBA7C918B26A64B6A40CAC10FE074EA9143D528C14E2CAF
                                                                                    SHA-512:585881B7D5AD71277420E899C6C0F812BD392B00955DBC81C26FAD7D0149728E9D610EB283469356F83E0D942FA229AE44C8768CB715BBB0C88ECA86EDAD82EB
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Oct 14 06:48:45 2024, mtime=Mon Oct 14 06:48:45 2024, atime=Fri Mar 22 13:42:34 2024, length=58880, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):1090
                                                                                    Entropy (8bit):4.498309914544939
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:8mKud+d7EVLfRAyKT2Nc0dsBQdsB7iZSm:8m9dqeGtT2dd/dlZS
                                                                                    MD5:F6198A788B2F7E4FE08DF94FC7AF8F5D
                                                                                    SHA1:B003021B050FF0C5B8D65A1EBE81C7C98994C91A
                                                                                    SHA-256:A579EBF741B12BD9CBBF1F2B97A71251D5EA6E1D4DF531B809CE8C76D7ABBBC7
                                                                                    SHA-512:28C56F0FD87F41E30979D8984BF994721652D968DA6A38B52A6EA234CEBE21DC8E60BDAA59B318F4A7134EEDE96A3B80E19B11F67DFD72502E0727FE76CD9FA2
                                                                                    Malicious:false
                                                                                    Preview:L..................F.... .....A.......A........-g|...............................P.O. .:i.....+00.../C:\.....................1.....EW.I..PROGRA~1..t......O.IEW.J....B...............J.....\...P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....f.1.....NY.>..LACROI~1..N......NY.>NY.>.....'.....................e?.L.A.C.R.O.I.X. .S.o.f.r.e.l.....V.1.....NY.>..S4-View.@......NY.>NY.>.....'......................{.S.4.-.V.i.e.w.....x.2.....vXQu .SNAOPE~1.EXE..\......NY.>NY.>.....)........................S.N.A.O.p.e.r.a.t.i.o.n.S.h.e.l.l...e.x.e.......l...............-.......k.............C......C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationShell.exe..O.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.L.A.C.R.O.I.X. .S.o.f.r.e.l.\.S.4.-.V.i.e.w.\.S.N.A.O.p.e.r.a.t.i.o.n.S.h.e.l.l...e.x.e.'.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.L.A.C.R.O.I.X. .S.o.f.r.e.l.\.S.4.-.V.i.e.w.`.......X.......468325...........hT..CrF.f4... .o.......,...E...hT..CrF.f4...
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Oct 14 06:48:45 2024, mtime=Mon Oct 14 06:48:49 2024, atime=Fri Mar 22 13:42:34 2024, length=58880, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):1066
                                                                                    Entropy (8bit):4.515699809064325
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:8mXtNd+vm21efRAyKT2NuR0dsBQdsB7iZSm:8mbd0T1btT2MR0d/dlZS
                                                                                    MD5:B20BAA459A0E22DCD7AF1C1194D1DA56
                                                                                    SHA1:D713A7A3D1C2C62D40A781986037566D9B3BE6CC
                                                                                    SHA-256:3DFC708FAB583692D6AF17319811B3ED8EC71CD38003337172B0E1208FA1873E
                                                                                    SHA-512:2ABE42A2BF52FDFAB9450F5E689AB84F582790FF7F7A91A3A7F2B6120ED87FCBB92FFD994D36F2BD96F08670032619DC1D98DF5FDA9301D0959DCA4F241B8DCC
                                                                                    Malicious:false
                                                                                    Preview:L..................F.... .....A.....N..........-g|...............................P.O. .:i.....+00.../C:\.....................1.....NY.>..PROGRA~1..t......O.INY.>....B...............J......e?.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....f.1.....NY.>..LACROI~1..N......NY.>NY.>.....'.....................e?.L.A.C.R.O.I.X. .S.o.f.r.e.l.....V.1.....NY.>..S4-View.@......NY.>NY.>.....'......................Y.S.4.-.V.i.e.w.....x.2.....vXQu .SNAOPE~1.EXE..\......NY.>NY.>.....)........................S.N.A.O.p.e.r.a.t.i.o.n.S.h.e.l.l...e.x.e.......l...............-.......k.............C......C:\Program Files\LACROIX Sofrel\S4-View\SNAOperationShell.exe..C.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.L.A.C.R.O.I.X. .S.o.f.r.e.l.\.S.4.-.V.i.e.w.\.S.N.A.O.p.e.r.a.t.i.o.n.S.h.e.l.l...e.x.e.'.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.L.A.C.R.O.I.X. .S.o.f.r.e.l.\.S.4.-.V.i.e.w.`.......X.......468325...........hT..CrF.f4... .o.......,...E...hT..CrF.f4... .o.......,...E..E......
                                                                                    Process:C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):932
                                                                                    Entropy (8bit):5.341349756955458
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:ML9E4KlKDE4KhKiKhPKIE4oKNzKo6E4qpAE4KzeR:MxHKlYHKh3oPtHo6SHmAHKzeR
                                                                                    MD5:E65078D0C378AF48F2B5768CA61F296E
                                                                                    SHA1:BCD0F782F367B69DDC4636BDE5000AB0F2C6840E
                                                                                    SHA-256:2DB467A406B123CD7C27008EB77357D108702DF63ED9DE0B2ED82FB180B01F2E
                                                                                    SHA-512:D0CCAD0E6AC781D96675CC107B973F0E813B9CD81930D9791EC8058F8A878A35A0244F8C86F56D331B8ADC97018580C82C6D29F15AE15B7255BAD52C4FB0CC07
                                                                                    Malicious:false
                                                                                    Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..2,"System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02b0c61bb4\System.Xml.ni.dll",0..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):8664
                                                                                    Entropy (8bit):5.240966230842169
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:AHhTw8bd0jJUdJxdnpQE8JfyDNWlN1/GWzF6vedGlbG/oj:kFw8bd0jJUdJxdpQLJqh2N1/GWzFoiGj
                                                                                    MD5:30B64CA8F439563CA5ECFC1BC3E156D4
                                                                                    SHA1:E8F90B44700BD18C3EA425E940CB4A2FC592C912
                                                                                    SHA-256:B90B448019644B031732239683ECF70A767FF9C694978F921E26FD4E19931F99
                                                                                    SHA-512:305A31ADFB456A93284080BB96C98266AB547B09E4275DC0D996F8D7D66C2C09FB16B0EA8C816B5E0C22443565EA8705552469D4E21D90D9C939E36BB159388C
                                                                                    Malicious:false
                                                                                    Preview:2024-10-14 03:48:18.360 Log opened. (Time zone: UTC-04:00)..2024-10-14 03:48:18.360 Setup version: Inno Setup version 5.5.9 (a)..2024-10-14 03:48:18.360 Original Setup EXE: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe..2024-10-14 03:48:18.360 Setup command line: /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe" ..2024-10-14 03:48:18.360 Windows version: 10.0.19045 (NT platform: Yes)..2024-10-14 03:48:18.360 64-bit Windows: Yes..2024-10-14 03:48:18.360 Processor architecture: x64..2024-10-14 03:48:18.360 User privileges: Administrative..2024-10-14 03:48:18.406 64-bit install mode: Yes..2024-10-14 03:48:22.469 Created temporary directory: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp..2024-10-14 03:48:22.485 InitializeSetup Call..2024-10-14 03:48:22.485 GUID de l application : {9E82D52C-73A8-4180-844B-564D36F24BDE}_is1..2024-10-14 03:48:22.485 CheckFramework48 Call..2024-10-14 03:48:39.563 CurStepChanged(1) call
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:modified
                                                                                    Size (bytes):119369
                                                                                    Entropy (8bit):5.0534300304583395
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:OJddI7vxQGjGKKfpfNAfpf2onqQeoZqQeoFqsV5UsAXKbrrn8:rxQGjZUsAQrr8
                                                                                    MD5:550AAAD4D75859ED186FAAC028D3E701
                                                                                    SHA1:30FE4755ADB698E758054DC686CECE44850E2360
                                                                                    SHA-256:78D1E20101B89E3B1F17370DF7DDF7A56924703982894741C1016BF9BBF4DF29
                                                                                    SHA-512:333F54F15222DCA0FD820D9752D6037B85C7EA5B0593A0FC859983C3ED513AFF71F6BE09C43736B8A031AF145BE29FF12614675E95BD4CB537D318BD5C910489
                                                                                    Malicious:false
                                                                                    Preview:2024-10-14 03:48:43.352 Log opened. (Time zone: UTC-04:00)..2024-10-14 03:48:43.352 Setup version: Inno Setup version 5.5.9 (a)..2024-10-14 03:48:43.352 Original Setup EXE: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe..2024-10-14 03:48:43.352 Setup command line: /SL5="$10444,15151522,57856,C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"..2024-10-14 03:48:43.352 Windows version: 10.0.19045 (NT platform: Yes)..2024-10-14 03:48:43.352 64-bit Windows: Yes..2024-10-14 03:48:43.352 Processor architecture: x64..2024-10-14 03:48:43.352 User privileges: Administrative..2024-10-14 03:48:43.415 64-bit install mode: Yes..2024-10-14 03:48:43.431 Created temporary directory: C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp..2024-10-14 03:48:43.431 InitializeSetup Call..2024-10-14 03:48:43.431 GUID de l application : {4928A9CA-81FE-4708-8B4C-2C77A0B95930}_is1..2024-10-14 0
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):323
                                                                                    Entropy (8bit):5.131606066343924
                                                                                    Encrypted:false
                                                                                    SSDEEP:6:BMth7L2VPi4TPCXw/IL/XTbJRLOCcWOM1mUi9t9VZAZy52Z:672RTI1azzO
                                                                                    MD5:65705D25741C77B55621F96CE9B45AE4
                                                                                    SHA1:B24EE24D35670D1298EFD0A0618297B802207D50
                                                                                    SHA-256:14833253161F174C22205B065BA6A56E1D5C0ED2951B1796EF08E5EC50CB402D
                                                                                    SHA-512:4BAF266D9E3E551F9F67951D52038031D16E2C8B9F2E0DDEEA4E55CA1DEB5A89A2F25CABECCDB17E42CE73A6EA16EAE789E97AA5D5F96CD0A6B1BC9D95CFD423
                                                                                    Malicious:false
                                                                                    Preview:.<environment>.. Culture et language de l'application-->.. <culture Language="fr" LanguageResourceFolder="fr"/>.. Contrainte OEM pour la personalisation lors de l'installation-->.. <oem Company="LACROIX Sofrel" Product="S4-View" Copyright="Copyright (C) LACROIX Sofrel 2014-2021. (France)"/>..</environment>..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):24240
                                                                                    Entropy (8bit):6.823338888710406
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:BHvhMwoSitz/bjx7yxnbdn+EHvbsHoOODCgcoSmonTpXoi+Pbd0ia:BJ7FEAbd+EDsIO7oST1Yi+Ph0i
                                                                                    MD5:77D6D961F71A8C558513BED6FD0AD6F1
                                                                                    SHA1:122BB9ED6704B72250E4E31B5D5FC2F0476C4B6A
                                                                                    SHA-256:5DA7C8D33D3B7DB46277012D92875C0B850C8ABF1EB3C8C9C5B9532089A0BCF0
                                                                                    SHA-512:B0921E2442B4CDEC8CC479BA3751A01C0646A4804E2F4A5D5632FA2DBF54CC45D4CCCFFA4D5B522D42AFC2F6A622E07882ED7E663C8462333B082E82503F335A
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........I...(...(...(..n ..(...(...(...$..(...$..(...$..(..Rich.(..................PE..L......B...........!..... ..........p........0....P..........................P......K................................;.......;..(....................4...*...@.......0...............................................0...............................text............ .................. ..`.rdata.......0.......$..............@..@.reloc.......@.......2..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.720366600008286
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                                                    MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                    SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                                                    SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                                                    SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):713728
                                                                                    Entropy (8bit):6.516598351135674
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:usMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyR:JMcMoi3rPR37dzHRA6G7WbuSEmK50syQ
                                                                                    MD5:832DAB307E54AA08F4B6CDD9B9720361
                                                                                    SHA1:EBD007FB7482040ECF34339E4BF917209C1018DF
                                                                                    SHA-256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3
                                                                                    SHA-512:358D43522FD460EB1511708E4DF22EA454A95E5BC3C4841931027B5FA3FB1DDA05D496D8AD0A8B9279B99E6BE74220FE243DB8F08EF49845E9FB35C350EF4B49
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):15509297
                                                                                    Entropy (8bit):7.998396567947374
                                                                                    Encrypted:true
                                                                                    SSDEEP:393216:2NomWyHMLcCS7633GylykNLi8HzZku3WidaYJ5rol9DAdtH:2NZPMweTRN7TH9daE5ko
                                                                                    MD5:6E1FA307C84ABA5C57F5C32F237DBB3B
                                                                                    SHA1:5914C2F6671B57E47BE9A49BEA4CBC289C88F255
                                                                                    SHA-256:428D6FF014E18E8AB72E9B7D53EF23EBF182E306661F582F8C22E126578E5D6E
                                                                                    SHA-512:4487587182F1EDB3451A8AD506E181BF23733B7E09233D317C50E6A415B9B781DAA1C7DED01F55F7FB34C130068313170F71CA33683835AD6FF18F5837113DDE
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.....................F....................@..........................P............@......@..............................|.... ...,..........................................................................................................CODE............................... ..`DATA....P...........................@...BSS......................................idata..|...........................@....tls.....................................rdata..............................@..P.reloc..............................@..P.rsrc....,... ...,..................@..P.............P......................@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):27
                                                                                    Entropy (8bit):4.032303242743954
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:0gfJPTtlvn:0gBplv
                                                                                    MD5:11C33ECF9CC37CC85FDBB7A0CA0BF68A
                                                                                    SHA1:82C0DDF7240D1601C71170990F064C3C7DB7DE3B
                                                                                    SHA-256:F8E7507A56A4F6851CD1B3E749F9ABBB43C9D9CD77F59613917B4F68BE08C5F5
                                                                                    SHA-512:DFAA96C04BDD112ADEE57E5D206D7A68C4ABADE0C485287A5D04BED55831D4A58E49D01CE03E5E975A07616123A97B1E7FFAD44BDD75EA7055939DEFAC291141
                                                                                    Malicious:false
                                                                                    Preview:Package : V4.20.13.241602..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4435
                                                                                    Entropy (8bit):5.041234547281355
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JdJo8oHeJk+Okv3AvtiI6jS0rw4I0tHBS/NGudf/81/K31JMJ2NeXvSnT/4l6O1o:3u8E+jrc2t/D6YKIlDqarA
                                                                                    MD5:93A53B2B4B8B91292CE112E3EC1749DE
                                                                                    SHA1:CF42645FFDE1A4BF2309006E9C17CFF76B521B74
                                                                                    SHA-256:F94FC0202B9CA55F73B589108955F878AE37ADF275792CF3FF650DE5C6F90159
                                                                                    SHA-512:8F1F0353504CAA44C72980411960064A7D7319B0B4B162A0574B076C47ED40E8D43D7EF7709E768FCBD004B6F42F7097648C1398368D094E52595548BBB9F287
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="UTF-8"?>..<ArrayOfSerialNumberDescription xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.... <SerialNumberDescription Product="3100" Model="S4W 8-0-0 GSM-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.... <SerialNumberDescription Product="3101" Model="S4W 8-2-2 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescription Product="3102" Model="S4W 12-2-4 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="4" DiCount="12"/>.... <SerialNumberDescription Product="3103" Model="S4W 16-4-4 GSM-XIO" Market="1" AoCount="0" AiCount="4" DoCount="4" DiCount="16"/>... <SerialNumberDescription Product="3104" Model="S4W 8-0-0 4G-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.. <SerialNumberDescription Product="3105" Model="S4W 8-2-2 4G-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescriptio
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146874
                                                                                    Entropy (8bit):5.030528522591216
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrErnmt/3mUUQargP7/vhpdVB6CIxumugPDtAwN7:YZmUDIgP7/vhpdVB6CIxumHPN7
                                                                                    MD5:39CABAE4F278D1F95DC3D86C45FEDD38
                                                                                    SHA1:D4A7236D59DD94DBFCAC61765E77E38460C11FE2
                                                                                    SHA-256:30382A9B8678F3C6506F7F08F447C39986584F5264EE2962C984077140050462
                                                                                    SHA-512:1E65129381B8D6164DA4D8E4AB556BE39684D346AAA396C029EE49E1AD187EC2B3693554D14E0D7205D41096B2F2D0ACEA3826DEA7CF05029681F32F50DFF99C
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146874
                                                                                    Entropy (8bit):5.030528522591216
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrErnmt/3mUUQargP7/vhpdVB6CIxumugPDtAwN7:YZmUDIgP7/vhpdVB6CIxumHPN7
                                                                                    MD5:39CABAE4F278D1F95DC3D86C45FEDD38
                                                                                    SHA1:D4A7236D59DD94DBFCAC61765E77E38460C11FE2
                                                                                    SHA-256:30382A9B8678F3C6506F7F08F447C39986584F5264EE2962C984077140050462
                                                                                    SHA-512:1E65129381B8D6164DA4D8E4AB556BE39684D346AAA396C029EE49E1AD187EC2B3693554D14E0D7205D41096B2F2D0ACEA3826DEA7CF05029681F32F50DFF99C
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):142975
                                                                                    Entropy (8bit):4.966849523029269
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YMMP8lxm4xLZxpKiqaUCSONPu09geb3AOMo6H8sj:uz4xLtMPoIj
                                                                                    MD5:C27C08E57059357B781CEB4E83B6DAB5
                                                                                    SHA1:8366633C00515C4578BAC0FED604E65ACB413485
                                                                                    SHA-256:F898A93FDAD3FF4FEAE3727FEE4ED4E8F79471601DA2AE72F3DBB170B27384F6
                                                                                    SHA-512:472C0E758A0BFC272EE4CB8206D8360A61740594C0F41122E49A727D6E1A29A4F2270823BF9464C417A60FAFE6B5459F8826C03560774BC54028C3775D967CF1
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):142975
                                                                                    Entropy (8bit):4.966849523029269
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YMMP8lxm4xLZxpKiqaUCSONPu09geb3AOMo6H8sj:uz4xLtMPoIj
                                                                                    MD5:C27C08E57059357B781CEB4E83B6DAB5
                                                                                    SHA1:8366633C00515C4578BAC0FED604E65ACB413485
                                                                                    SHA-256:F898A93FDAD3FF4FEAE3727FEE4ED4E8F79471601DA2AE72F3DBB170B27384F6
                                                                                    SHA-512:472C0E758A0BFC272EE4CB8206D8360A61740594C0F41122E49A727D6E1A29A4F2270823BF9464C417A60FAFE6B5459F8826C03560774BC54028C3775D967CF1
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146478
                                                                                    Entropy (8bit):5.022669204701854
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YHhUfGiw9Xw/8hqRk3cPO0rb8ZZHPkbBO9E7//CB:wkGiwl+8YqM//CB
                                                                                    MD5:E78740BBABACCBEDDB3B10985D7E4C50
                                                                                    SHA1:EFC947D5BAE52C80D3B7D48368A637B2F1F66398
                                                                                    SHA-256:8EC64246EFB29D7D7F48FB7DAA700AF486E952BAC0AE13F8916B00977D3996C5
                                                                                    SHA-512:521229F993BDF612D58BEBF2B545C2E2CDA488A07BCFD953A09DD6B5340304A2B09D1E3AA5BF11EBB276613262718F8425AEF9066E04FC180DE3323CF1E83228
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):146478
                                                                                    Entropy (8bit):5.022669204701854
                                                                                    Encrypted:false
                                                                                    SSDEEP:1536:YHhUfGiw9Xw/8hqRk3cPO0rb8ZZHPkbBO9E7//CB:wkGiwl+8YqM//CB
                                                                                    MD5:E78740BBABACCBEDDB3B10985D7E4C50
                                                                                    SHA1:EFC947D5BAE52C80D3B7D48368A637B2F1F66398
                                                                                    SHA-256:8EC64246EFB29D7D7F48FB7DAA700AF486E952BAC0AE13F8916B00977D3996C5
                                                                                    SHA-512:521229F993BDF612D58BEBF2B545C2E2CDA488A07BCFD953A09DD6B5340304A2B09D1E3AA5BF11EBB276613262718F8425AEF9066E04FC180DE3323CF1E83228
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):140177
                                                                                    Entropy (8bit):5.0105247259887
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:ISq8lJH/U99Xl6F92R8dzXFrIj2I3ldwzG3LPf0T8gVQPQBUCbURNhyxJ9FRr:IF9Xl6F9mo4wzG3LPf0T8gVQPQeCl3
                                                                                    MD5:1776E84B2665C7B16E3D16D70494DFF5
                                                                                    SHA1:B27308CDDC32C22D426E74490458BCA4F9792235
                                                                                    SHA-256:B35890427D2336E889A03E6DFF6B51268E49A1281B326EE6BD64B54E9DB8D576
                                                                                    SHA-512:76D4BC644AF0B37784DCB9A28E5A615625F61F951D18541695C455C0614AE5651C8904C079DE8EC682A1AC9B73A02F73130D5ADC95F6DB1229D3C7DE0F8A3D9C
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument" />.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Trace ordre 2 {0} {1} {2}">..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):140177
                                                                                    Entropy (8bit):5.0105247259887
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:ISq8lJH/U99Xl6F92R8dzXFrIj2I3ldwzG3LPf0T8gVQPQBUCbURNhyxJ9FRr:IF9Xl6F9mo4wzG3LPf0T8gVQPQeCl3
                                                                                    MD5:1776E84B2665C7B16E3D16D70494DFF5
                                                                                    SHA1:B27308CDDC32C22D426E74490458BCA4F9792235
                                                                                    SHA-256:B35890427D2336E889A03E6DFF6B51268E49A1281B326EE6BD64B54E9DB8D576
                                                                                    SHA-512:76D4BC644AF0B37784DCB9A28E5A615625F61F951D18541695C455C0614AE5651C8904C079DE8EC682A1AC9B73A02F73130D5ADC95F6DB1229D3C7DE0F8A3D9C
                                                                                    Malicious:false
                                                                                    Preview:<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument" />.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Trace ordre 2 {0} {1} {2}">..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):27
                                                                                    Entropy (8bit):4.032303242743954
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:0gfJPTtlvn:0gBplv
                                                                                    MD5:11C33ECF9CC37CC85FDBB7A0CA0BF68A
                                                                                    SHA1:82C0DDF7240D1601C71170990F064C3C7DB7DE3B
                                                                                    SHA-256:F8E7507A56A4F6851CD1B3E749F9ABBB43C9D9CD77F59613917B4F68BE08C5F5
                                                                                    SHA-512:DFAA96C04BDD112ADEE57E5D206D7A68C4ABADE0C485287A5D04BED55831D4A58E49D01CE03E5E975A07616123A97B1E7FFAD44BDD75EA7055939DEFAC291141
                                                                                    Malicious:false
                                                                                    Preview:Package : V4.20.13.241602..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):4435
                                                                                    Entropy (8bit):5.041234547281355
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:JdJo8oHeJk+Okv3AvtiI6jS0rw4I0tHBS/NGudf/81/K31JMJ2NeXvSnT/4l6O1o:3u8E+jrc2t/D6YKIlDqarA
                                                                                    MD5:93A53B2B4B8B91292CE112E3EC1749DE
                                                                                    SHA1:CF42645FFDE1A4BF2309006E9C17CFF76B521B74
                                                                                    SHA-256:F94FC0202B9CA55F73B589108955F878AE37ADF275792CF3FF650DE5C6F90159
                                                                                    SHA-512:8F1F0353504CAA44C72980411960064A7D7319B0B4B162A0574B076C47ED40E8D43D7EF7709E768FCBD004B6F42F7097648C1398368D094E52595548BBB9F287
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="UTF-8"?>..<ArrayOfSerialNumberDescription xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.... <SerialNumberDescription Product="3100" Model="S4W 8-0-0 GSM-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.... <SerialNumberDescription Product="3101" Model="S4W 8-2-2 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescription Product="3102" Model="S4W 12-2-4 GSM-XIO" Market="1" AoCount="0" AiCount="2" DoCount="4" DiCount="12"/>.... <SerialNumberDescription Product="3103" Model="S4W 16-4-4 GSM-XIO" Market="1" AoCount="0" AiCount="4" DoCount="4" DiCount="16"/>... <SerialNumberDescription Product="3104" Model="S4W 8-0-0 4G-XIO" Market="1" AoCount="0" AiCount="0" DoCount="0" DiCount="8"/>.. <SerialNumberDescription Product="3105" Model="S4W 8-2-2 4G-XIO" Market="1" AoCount="0" AiCount="2" DoCount="2" DiCount="8"/>.... <SerialNumberDescriptio
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):145632
                                                                                    Entropy (8bit):4.9623843976202675
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrjsUG1ERvDa6NVLnT9arjGoX3g6dyTE8sXjyYF9zRaTFvvZn:YXqERvGYnT9arjGoX3g6dyTE8uF9z+
                                                                                    MD5:620F8575F763F734E54D259CB7D279AD
                                                                                    SHA1:FD31BD53A90B15B41C4BE279B1719B20ADFD6D3E
                                                                                    SHA-256:F8A3D3136D1C39922BE95A745AAA0F28621252575CE6CFBB4E65FD8BA78840C3
                                                                                    SHA-512:3CFBF74907245030D8FCCD2D3B023F49A1565D0A3843DFD6B3A15A2CD666BFDFD582194209AB87908CBA2822EF571942D4578BBF0CD3CCAE23ED075DBA91A87B
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):145632
                                                                                    Entropy (8bit):4.9623843976202675
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:YrjsUG1ERvDa6NVLnT9arjGoX3g6dyTE8sXjyYF9zRaTFvvZn:YXqERvGYnT9arjGoX3g6dyTE8uF9z+
                                                                                    MD5:620F8575F763F734E54D259CB7D279AD
                                                                                    SHA1:FD31BD53A90B15B41C4BE279B1719B20ADFD6D3E
                                                                                    SHA-256:F8A3D3136D1C39922BE95A745AAA0F28621252575CE6CFBB4E65FD8BA78840C3
                                                                                    SHA-512:3CFBF74907245030D8FCCD2D3B023F49A1565D0A3843DFD6B3A15A2CD666BFDFD582194209AB87908CBA2822EF571942D4578BBF0CD3CCAE23ED075DBA91A87B
                                                                                    Malicious:false
                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<EmbededResourceList xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">.. <StringDescriptionList>.. <EmbededStringDescription Id="10001" Message="Trace sans argument"></EmbededStringDescription>.. <EmbededStringDescription Id="10002" Message="Trace 5 arguments {0} {1} {2} {3} {4}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10003" Message="Trace ordre 1 {0} {1} {2}">.. <ArgTypeList>.. <TokenType>ResourceId</TokenType>.. <TokenType>String</TokenType>.. <TokenType>StringValue</TokenType>.. </ArgTypeList>.. </EmbededStringDescription>.. <EmbededStringDescription Id="10004" Message="Tr
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.720366600008286
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                                                    MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                    SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                                                    SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                                                    SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                                                    Malicious:false
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):15509297
                                                                                    Entropy (8bit):7.998396567947374
                                                                                    Encrypted:true
                                                                                    SSDEEP:393216:2NomWyHMLcCS7633GylykNLi8HzZku3WidaYJ5rol9DAdtH:2NZPMweTRN7TH9daE5ko
                                                                                    MD5:6E1FA307C84ABA5C57F5C32F237DBB3B
                                                                                    SHA1:5914C2F6671B57E47BE9A49BEA4CBC289C88F255
                                                                                    SHA-256:428D6FF014E18E8AB72E9B7D53EF23EBF182E306661F582F8C22E126578E5D6E
                                                                                    SHA-512:4487587182F1EDB3451A8AD506E181BF23733B7E09233D317C50E6A415B9B781DAA1C7DED01F55F7FB34C130068313170F71CA33683835AD6FF18F5837113DDE
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*.....................F....................@..........................P............@......@..............................|.... ...,..........................................................................................................CODE............................... ..`DATA....P...........................@...BSS......................................idata..|...........................@....tls.....................................rdata..............................@..P.reloc..............................@..P.rsrc....,... ...,..................@..P.............P......................@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):713728
                                                                                    Entropy (8bit):6.516598351135674
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:usMLIMoi3rPR37dzHRA6nX0D9OKWbO7SERb5rNUK1bce0syxyR:JMcMoi3rPR37dzHRA6G7WbuSEmK50syQ
                                                                                    MD5:832DAB307E54AA08F4B6CDD9B9720361
                                                                                    SHA1:EBD007FB7482040ECF34339E4BF917209C1018DF
                                                                                    SHA-256:CC783A04CCBCA4EDD06564F8EC88FE5A15F1E3BB26CEC7DE5E090313520D98F3
                                                                                    SHA-512:358D43522FD460EB1511708E4DF22EA454A95E5BC3C4841931027B5FA3FB1DDA05D496D8AD0A8B9279B99E6BE74220FE243DB8F08EF49845E9FB35C350EF4B49
                                                                                    Malicious:false
                                                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&...........................................................0......................................................CODE............................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..P....@......................@..P.rsrc...............................@..P.....................r..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    File Type:ASCII text, with CRLF line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):8625
                                                                                    Entropy (8bit):5.241772944067223
                                                                                    Encrypted:false
                                                                                    SSDEEP:192:AHhTw8bd0jJUdJxdnpQE8JfyDNWlN1/GWzF6vedGlbG/oe:kFw8bd0jJUdJxdpQLJqh2N1/GWzFoiGe
                                                                                    MD5:3561266085877662C843560444307898
                                                                                    SHA1:331BCA2A1EC811E87292641CD3FD65112AA264B1
                                                                                    SHA-256:C747E3EEF681BA34269A67BE17C3644EF3796C3495F854106D355A3780BB3A28
                                                                                    SHA-512:6E95C651E3FDF9A93303FCCAF6E706F4604D41222930E5AC4C878124553402CB4DE392FCB86B6C72DD6BE0C83AEFBEA26F5F16C0E07D52CE8CB5431DDEEFA917
                                                                                    Malicious:false
                                                                                    Preview:2024-10-14 03:48:18.360 Log opened. (Time zone: UTC-04:00)..2024-10-14 03:48:18.360 Setup version: Inno Setup version 5.5.9 (a)..2024-10-14 03:48:18.360 Original Setup EXE: C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe..2024-10-14 03:48:18.360 Setup command line: /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe" ..2024-10-14 03:48:18.360 Windows version: 10.0.19045 (NT platform: Yes)..2024-10-14 03:48:18.360 64-bit Windows: Yes..2024-10-14 03:48:18.360 Processor architecture: x64..2024-10-14 03:48:18.360 User privileges: Administrative..2024-10-14 03:48:18.406 64-bit install mode: Yes..2024-10-14 03:48:22.469 Created temporary directory: C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp..2024-10-14 03:48:22.485 InitializeSetup Call..2024-10-14 03:48:22.485 GUID de l application : {9E82D52C-73A8-4180-844B-564D36F24BDE}_is1..2024-10-14 03:48:22.485 CheckFramework48 Call..2024-10-14 03:48:39.563 CurStepChanged(1) call
                                                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Entropy (8bit):7.9998664083416315
                                                                                    TrID:
                                                                                    • Win32 Executable (generic) a (10002005/4) 98.86%
                                                                                    • Inno Setup installer (109748/4) 1.08%
                                                                                    • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                    • DOS Executable Generic (2002/1) 0.02%
                                                                                    File name:2024_04_Setup-S4-View-V4.20.13.exe
                                                                                    File size:15'783'365 bytes
                                                                                    MD5:cff2c405dcf893d747b92c600d4dc26a
                                                                                    SHA1:95425a08cbcb8c9ed1f085b62f5c69937d253347
                                                                                    SHA256:d34011319c9faf5400cfb72ccfd04e445b80515bbfade3f9164d08f91b8b63d0
                                                                                    SHA512:bb42bbbe23f019d093251ea6987aa79c48ccffa614279f8afb4ca7fe925ddc3ca3b3b845298027aeefe53fe5e8c8fbb206c7b252841070aa6f36b60534f3b8df
                                                                                    SSDEEP:393216:1f9X8WYqlbDpGZObdkIUpCK6CXH/QXYKtx7HiCUaEORDH:rXAO0vIUpCNC3/Ql7HiCUTOV
                                                                                    TLSH:F3F63324E20A41A2C7708CF46C4B5C298A59F7FD622D193EBD1DDD2473F7643B14AB2A
                                                                                    File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                                                    Icon Hash:2d2e3797b32b2b99
                                                                                    Entrypoint:0x40aa98
                                                                                    Entrypoint Section:CODE
                                                                                    Digitally signed:false
                                                                                    Imagebase:0x400000
                                                                                    Subsystem:windows gui
                                                                                    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                    Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
                                                                                    TLS Callbacks:
                                                                                    CLR (.Net) Version:
                                                                                    OS Version Major:1
                                                                                    OS Version Minor:0
                                                                                    File Version Major:1
                                                                                    File Version Minor:0
                                                                                    Subsystem Version Major:1
                                                                                    Subsystem Version Minor:0
                                                                                    Import Hash:2fb819a19fe4dee5c03e8c6a79342f79
                                                                                    Instruction
                                                                                    push ebp
                                                                                    mov ebp, esp
                                                                                    add esp, FFFFFFC4h
                                                                                    push ebx
                                                                                    push esi
                                                                                    push edi
                                                                                    xor eax, eax
                                                                                    mov dword ptr [ebp-10h], eax
                                                                                    mov dword ptr [ebp-24h], eax
                                                                                    call 00007F70F8CFA693h
                                                                                    call 00007F70F8CFB89Ah
                                                                                    call 00007F70F8CFBC01h
                                                                                    call 00007F70F8CFC01Ch
                                                                                    call 00007F70F8CFDFBBh
                                                                                    call 00007F70F8D00952h
                                                                                    call 00007F70F8D00AB9h
                                                                                    xor eax, eax
                                                                                    push ebp
                                                                                    push 0040B169h
                                                                                    push dword ptr fs:[eax]
                                                                                    mov dword ptr fs:[eax], esp
                                                                                    xor edx, edx
                                                                                    push ebp
                                                                                    push 0040B132h
                                                                                    push dword ptr fs:[edx]
                                                                                    mov dword ptr fs:[edx], esp
                                                                                    mov eax, dword ptr [0040D014h]
                                                                                    call 00007F70F8D0158Bh
                                                                                    call 00007F70F8D01176h
                                                                                    cmp byte ptr [0040C234h], 00000000h
                                                                                    je 00007F70F8D0206Eh
                                                                                    call 00007F70F8D01688h
                                                                                    xor eax, eax
                                                                                    call 00007F70F8CFB389h
                                                                                    lea edx, dword ptr [ebp-10h]
                                                                                    xor eax, eax
                                                                                    call 00007F70F8CFE5CBh
                                                                                    mov edx, dword ptr [ebp-10h]
                                                                                    mov eax, 0040DE30h
                                                                                    call 00007F70F8CFA72Ah
                                                                                    push 00000002h
                                                                                    push 00000000h
                                                                                    push 00000001h
                                                                                    mov ecx, dword ptr [0040DE30h]
                                                                                    mov dl, 01h
                                                                                    mov eax, 00407808h
                                                                                    call 00007F70F8CFEE86h
                                                                                    mov dword ptr [0040DE34h], eax
                                                                                    xor edx, edx
                                                                                    push ebp
                                                                                    push 0040B0EAh
                                                                                    push dword ptr fs:[edx]
                                                                                    mov dword ptr fs:[edx], esp
                                                                                    call 00007F70F8D015E6h
                                                                                    mov dword ptr [0040DE3Ch], eax
                                                                                    mov eax, dword ptr [0040DE3Ch]
                                                                                    cmp dword ptr [eax+0Ch], 00000000h
                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xe0000x97c.idata
                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x120000x2c00.rsrc
                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0x100000x18.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                    CODE0x10000xa1d00xa200b7ea439d9c6d5ec722056c9243fb3054False0.6025028935185185data6.643749028594943IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                    DATA0xc0000x2500x4009b2268ed5360951559d8041925d025fbFalse0.3037109375data2.740124513017086IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    BSS0xd0000xe940x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .idata0xe0000x97c0xa00df5f31e62e05c787fd29eed7071bf556False0.41796875data4.486076246232586IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .tls0xf0000x80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .rdata0x100000x180x20014dfa4128117e7f94fe2f8d7dea374a0False0.05078125data0.190488766434666IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    .reloc0x110000x91c0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    .rsrc0x120000x2c000x2c00da647efdfec0462f896a352682cce1e2False0.3378018465909091data4.609557039010028IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                    RT_ICON0x123540x128Device independent bitmap graphic, 16 x 32 x 4, image size 192DutchNetherlands0.5675675675675675
                                                                                    RT_ICON0x1247c0x568Device independent bitmap graphic, 16 x 32 x 8, image size 320DutchNetherlands0.4486994219653179
                                                                                    RT_ICON0x129e40x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640DutchNetherlands0.4637096774193548
                                                                                    RT_ICON0x12ccc0x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152DutchNetherlands0.3935018050541516
                                                                                    RT_STRING0x135740x2f2data0.35543766578249336
                                                                                    RT_STRING0x138680x30cdata0.3871794871794872
                                                                                    RT_STRING0x13b740x2cedata0.42618384401114207
                                                                                    RT_STRING0x13e440x68data0.75
                                                                                    RT_STRING0x13eac0xb4data0.6277777777777778
                                                                                    RT_STRING0x13f600xaedata0.5344827586206896
                                                                                    RT_RCDATA0x140100x2cdata1.25
                                                                                    RT_GROUP_ICON0x1403c0x3edataEnglishUnited States0.8387096774193549
                                                                                    RT_VERSION0x1407c0x4f4dataEnglishUnited States0.31545741324921134
                                                                                    RT_MANIFEST0x145700x62cXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4240506329113924
                                                                                    DLLImport
                                                                                    kernel32.dllDeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle
                                                                                    user32.dllMessageBoxA
                                                                                    oleaut32.dllVariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
                                                                                    advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA
                                                                                    kernel32.dllWriteFile, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, Sleep, SizeofResource, SetLastError, SetFilePointer, SetErrorMode, SetEndOfFile, RemoveDirectoryA, ReadFile, LockResource, LoadResource, LoadLibraryA, IsDBCSLeadByte, GetWindowsDirectoryA, GetVersionExA, GetVersion, GetUserDefaultLangID, GetSystemInfo, GetSystemDirectoryA, GetSystemDefaultLCID, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetACP, InterlockedExchange, FormatMessageA, FindResourceA, DeleteFileA, CreateProcessA, CreateFileA, CreateDirectoryA, CloseHandle
                                                                                    user32.dllTranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA
                                                                                    comctl32.dllInitCommonControls
                                                                                    advapi32.dllAdjustTokenPrivileges
                                                                                    Language of compilation systemCountry where language is spokenMap
                                                                                    DutchNetherlands
                                                                                    EnglishUnited States
                                                                                    No network behavior found

                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Click to dive into process behavior distribution

                                                                                    Click to jump to process

                                                                                    Target ID:0
                                                                                    Start time:03:48:18
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe"
                                                                                    Imagebase:0x400000
                                                                                    File size:15'783'365 bytes
                                                                                    MD5 hash:CFF2C405DCF893D747B92C600D4DC26A
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:true

                                                                                    Target ID:2
                                                                                    Start time:03:48:18
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Local\Temp\is-7ILSV.tmp\2024_04_Setup-S4-View-V4.20.13.tmp" /SL5="$103CC,15449307,57856,C:\Users\user\Desktop\2024_04_Setup-S4-View-V4.20.13.exe"
                                                                                    Imagebase:0x400000
                                                                                    File size:713'728 bytes
                                                                                    MD5 hash:832DAB307E54AA08F4B6CDD9B9720361
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:6
                                                                                    Start time:03:48:42
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"
                                                                                    Imagebase:0x400000
                                                                                    File size:15'509'297 bytes
                                                                                    MD5 hash:6E1FA307C84ABA5C57F5C32F237DBB3B
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:true

                                                                                    Target ID:7
                                                                                    Start time:03:48:43
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Local\Temp\is-S156G.tmp\Setup-S4-View.tmp" /SL5="$10444,15151522,57856,C:\Users\user\AppData\Local\Temp\is-AGO5O.tmp\Setup-S4-View.exe" /SILENT /LANG=en "/DIR=expand:C:\Program Files\LACROIX Sofrel\S4-View\"
                                                                                    Imagebase:0x400000
                                                                                    File size:713'728 bytes
                                                                                    MD5 hash:832DAB307E54AA08F4B6CDD9B9720361
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:8
                                                                                    Start time:03:48:43
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Users\user\AppData\Local\Temp\is-2G8G9.tmp\_isetup\_setup64.tmp
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:helper 105 0x404
                                                                                    Imagebase:0x140000000
                                                                                    File size:6'144 bytes
                                                                                    MD5 hash:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:moderate
                                                                                    Has exited:true

                                                                                    Target ID:9
                                                                                    Start time:03:48:44
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff70f010000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    Target ID:10
                                                                                    Start time:03:48:49
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Program Files\LACROIX Sofrel\S4-View\TrustZoneMigrate\SNTOperationTrustZoneMigrate.exe"
                                                                                    Imagebase:0x290000
                                                                                    File size:13'824 bytes
                                                                                    MD5 hash:DD9DD242A4F7AA3083435FCE216BCB25
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:true

                                                                                    Target ID:11
                                                                                    Start time:03:48:49
                                                                                    Start date:14/10/2024
                                                                                    Path:C:\Windows\System32\conhost.exe
                                                                                    Wow64 process (32bit):false
                                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                    Imagebase:0x7ff70f010000
                                                                                    File size:862'208 bytes
                                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:high
                                                                                    Has exited:true

                                                                                    No disassembly