Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
revosetup.exe

Overview

General Information

Sample name:revosetup.exe
Analysis ID:1432131
MD5:63150c4846bfbcf27fa70ccaa8a01943
SHA1:bfe32dcc00b041e0007a883af1588f354bb9f032
SHA256:a05acc9172e98ec6a6a7f923f5c648cc7a7c4e02bbcaaa5a6d9663229e662c24
Infos:

Detection

Score:24
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Monitors registry run keys for changes
Tries to harvest and steal browser information (history, passwords, etc)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found dropped PE file which has not been started or loaded
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample searches for specific file, try point organization specific fake files to the analysis machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
  • System is w10x64_ra
  • revosetup.exe (PID: 1796 cmdline: "C:\Users\user\Desktop\revosetup.exe" MD5: 63150C4846BFBCF27FA70CCAA8A01943)
    • revosetup.tmp (PID: 2816 cmdline: "C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp" /SL5="$202EE,6355320,266240,C:\Users\user\Desktop\revosetup.exe" MD5: 7B77E7C3EBD213D95C4D909716F10030)
      • RevoUnin.exe (PID: 6532 cmdline: "C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe" MD5: A9CCD5974308C40CBE6946B5E53D2DE9)
      • chrome.exe (PID: 6604 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.revouninstaller.com/free-install-thankyou/ MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
        • chrome.exe (PID: 6792 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=1828,i,11340438784122239940,8123972705045919978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: about:blankHTTP Parser: No favicon
Source: revosetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.LICENSE AGREEMENT AND COPYRIGHT========================IMPORTANT - READ CAREFULLY:This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd. the vendor of the software product Revo Uninstaller"."the Vendor" means the developer of the "Revo Uninstaller" software product VS Revo Group Ltd.YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING COPYING DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE DO NOT INSTALL DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.This is not public domain software. The software is owned by the author and protected by copyright law. The Software is licensed not sold to You for Your use only under the terms of this Agreement and VS Revo Group Ltd. reserves all rights not expressly granted to You. You are NOT allowed to:1. Modify reverse engineer decompile disassemble or otherwise attempt to reconstruct or discover the source code or any parts of it from the binaries of Revo Uninstaller.2. Remove any product identification copyright proprietary notices or labels from Revo Uninstaller.3. Distribute Revo Uninstaller in any other form than in the official distribution packages without a written permission from the Vendor.4. Use run copy distribute or store Revo Uninstaller in your computer if this license agreement is violated in any ways.THE APPLICATION AND ANY RELATED DOCUMENTATION IS PROVIDED "AS IS" WITHOUT ANY WARRANTIES. AND THAT THE VENDOR DOES NOT WARRANT THAT REVO UNINSTALLER WILL RUN UNINTERRUPTED OR ERROR FREE NOR THAT REVO UNINSTALLER WILL OPERATE WITH HARDWARE AND/OR SOFTWARE NOT PROVIDED BY THE VENDOR EITHER EXPRESS OR IMPLIED INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK ARISING OUT OF USE OR PERFORMANCE OF THE SOFTWARE REMAINS WITH YOUThe Agreement becomes effective when You agree to the terms and conditions of this Agreement by opening installing using accessing or manipulating the Software (the " Effective Date ") and this Agreement will terminate immediately upon notice to You if You materially breach any term or condition of this Agreement. You agree upon termination to promptly destroy the Software and all copies thereof.NOTE: REVO UNINSTALLER MAY CONNECT BY USERS REQUEST THROUGH THE INTERNET TO WWW.REVOUNINSTALLER.COM TO CHECK FOR UPDATES. DURING THIS PROCESS IT WILL DOWNLOAD A SMALL FILE THAT
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.LICENSE AGREEMENT AND COPYRIGHT========================IMPORTANT - READ CAREFULLY:This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd. the vendor of the software product Revo Uninstaller"."the Vendor" means the developer of the "Revo Uninstaller" software product VS Revo Group Ltd.YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING COPYING DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE DO NOT INSTALL DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.This is not public domain software. The software is owned by the author and protected by copyright law. The Software is licensed not sold to You for Your use only under the terms of this Agreement and VS Revo Group Ltd. reserves all rights not expressly granted to You. You are NOT allowed to:1. Modify reverse engineer decompile disassemble or otherwise attempt to reconstruct or discover the source code or any parts of it from the binaries of Revo Uninstaller.2. Remove any product identification copyright proprietary notices or labels from Revo Uninstaller.3. Distribute Revo Uninstaller in any other form than in the official distribution packages without a written permission from the Vendor.4. Use run copy distribute or store Revo Uninstaller in your computer if this license agreement is violated in any ways.THE APPLICATION AND ANY RELATED DOCUMENTATION IS PROVIDED "AS IS" WITHOUT ANY WARRANTIES. AND THAT THE VENDOR DOES NOT WARRANT THAT REVO UNINSTALLER WILL RUN UNINTERRUPTED OR ERROR FREE NOR THAT REVO UNINSTALLER WILL OPERATE WITH HARDWARE AND/OR SOFTWARE NOT PROVIDED BY THE VENDOR EITHER EXPRESS OR IMPLIED INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK ARISING OUT OF USE OR PERFORMANCE OF THE SOFTWARE REMAINS WITH YOUThe Agreement becomes effective when You agree to the terms and conditions of this Agreement by opening installing using accessing or manipulating the Software (the " Effective Date ") and this Agreement will terminate immediately upon notice to You if You materially breach any term or condition of this Agreement. You agree upon termination to promptly destroy the Software and all copies thereof.NOTE: REVO UNINSTALLER MAY CONNECT BY USERS REQUEST THROUGH THE INTERNET TO WWW.REVOUNINSTALLER.COM TO CHECK FOR UPDATES. DURING THIS PROCESS IT WILL DOWNLOAD A SMALL FILE THAT
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-930TG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-SRMPO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-QNP87.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-1GMMQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-LQ7V0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-8HS44.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6JUB1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-TF4FP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-JLIIP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-51DQ4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-ON5O0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-89KBO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-H8O5L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-BHORG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-NU8DV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-86R4G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-O6OOC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-OQLC1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-BRMVK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-IE3NO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-NA2VL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6D4JF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-P4FJN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-F6T79.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-4HQ49.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-Q5ETH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-D9K51.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-AP8OQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-03S2V.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-RM1PV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-7F029.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-MV7M3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-A47CF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6RDSI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-JEUE8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-8N9CU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-4H15I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-R94T1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-KQVVL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-57PF0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-2JR70.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-FVNN5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-79H19.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-Q3DI4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-FNPTG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-QRKAM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-20FHR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-3UJFV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-UKQ9R.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-3D3RB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.msg
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-04-26 #001.txt
Source: revosetup.exeStatic PE information: certificate valid
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49804 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.29.8:443 -> 192.168.2.17:49808 version: TLS 1.2
Source: revosetup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl32.DllA\OpenSSL32.DllA\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\1033\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl32.DllA\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.6.208
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.6.208
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.revouninstaller.com
Source: global trafficDNS traffic detected: DNS query: stackpath.bootstrapcdn.com
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com
Source: global trafficDNS traffic detected: DNS query: static.zdassets.com
Source: global trafficDNS traffic detected: DNS query: ekr.zdassets.com
Source: global trafficDNS traffic detected: DNS query: widget.trustpilot.com
Source: global trafficDNS traffic detected: DNS query: vsrevogroup.zendesk.com
Source: global trafficDNS traffic detected: DNS query: static.hotjar.com
Source: global trafficDNS traffic detected: DNS query: widget-mediator.zopim.com
Source: global trafficDNS traffic detected: DNS query: connect.facebook.net
Source: global trafficDNS traffic detected: DNS query: static.ads-twitter.com
Source: global trafficDNS traffic detected: DNS query: td.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: analytics.google.com
Source: global trafficDNS traffic detected: DNS query: stats.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: script.hotjar.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: v2assets.zopim.io
Source: global trafficDNS traffic detected: DNS query: www.facebook.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49804 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.29.8:443 -> 192.168.2.17:49808 version: TLS 1.2
Source: revosetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engineClassification label: sus24.spyw.winEXE@21/109@60/309
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Program Files\VS Revo Group
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Users\user\AppData\Local\Programs
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeMutant created: \Sessions\1\BaseNamedObjects\Local\RevoUninstallerFree}
Source: C:\Users\user\Desktop\revosetup.exeFile created: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp
Source: C:\Users\user\Desktop\revosetup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile read: C:\Program Files\desktop.ini
Source: C:\Users\user\Desktop\revosetup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\user\Desktop\revosetup.exeFile read: C:\Users\user\Desktop\revosetup.exe
Source: unknownProcess created: C:\Users\user\Desktop\revosetup.exe "C:\Users\user\Desktop\revosetup.exe"
Source: C:\Users\user\Desktop\revosetup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp "C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp" /SL5="$202EE,6355320,266240,C:\Users\user\Desktop\revosetup.exe"
Source: C:\Users\user\Desktop\revosetup.exeProcess created: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp "C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp" /SL5="$202EE,6355320,266240,C:\Users\user\Desktop\revosetup.exe"
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess created: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe "C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe"
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.revouninstaller.com/free-install-thankyou/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=1828,i,11340438784122239940,8123972705045919978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess created: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe "C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe"
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.revouninstaller.com/free-install-thankyou/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=1828,i,11340438784122239940,8123972705045919978,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Users\user\Desktop\revosetup.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\revosetup.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: msimg32.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: shfolder.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: msftedit.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windows.globalization.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: bcp47mrm.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: globinputhost.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: ntshrui.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windows.shell.servicehostbuilder.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: ieframe.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: mlang.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpSection loaded: onecorecommonproxystub.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: apphelp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: msi.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wininet.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: msimg32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: oledlg.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: urlmon.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: version.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winmm.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: iertutil.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: srvcli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netutils.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: uxtheme.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: dwmapi.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: textshaping.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: textinputframework.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: coremessaging.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ntmarta.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wintypes.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wintypes.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wintypes.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: dataexchange.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: d3d11.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: dcomp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: dxgi.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: windows.storage.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wldp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: propsys.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: profapi.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: windowscodecs.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: thumbcache.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: policymanager.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: sspicli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: linkinfo.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: msiso.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: ieframe.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: netapi32.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: userenv.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: winhttp.dll
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeSection loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpWindow found: window name: TSelectLanguageForm
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.LICENSE AGREEMENT AND COPYRIGHT========================IMPORTANT - READ CAREFULLY:This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd. the vendor of the software product Revo Uninstaller"."the Vendor" means the developer of the "Revo Uninstaller" software product VS Revo Group Ltd.YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING COPYING DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE DO NOT INSTALL DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.This is not public domain software. The software is owned by the author and protected by copyright law. The Software is licensed not sold to You for Your use only under the terms of this Agreement and VS Revo Group Ltd. reserves all rights not expressly granted to You. You are NOT allowed to:1. Modify reverse engineer decompile disassemble or otherwise attempt to reconstruct or discover the source code or any parts of it from the binaries of Revo Uninstaller.2. Remove any product identification copyright proprietary notices or labels from Revo Uninstaller.3. Distribute Revo Uninstaller in any other form than in the official distribution packages without a written permission from the Vendor.4. Use run copy distribute or store Revo Uninstaller in your computer if this license agreement is violated in any ways.THE APPLICATION AND ANY RELATED DOCUMENTATION IS PROVIDED "AS IS" WITHOUT ANY WARRANTIES. AND THAT THE VENDOR DOES NOT WARRANT THAT REVO UNINSTALLER WILL RUN UNINTERRUPTED OR ERROR FREE NOR THAT REVO UNINSTALLER WILL OPERATE WITH HARDWARE AND/OR SOFTWARE NOT PROVIDED BY THE VENDOR EITHER EXPRESS OR IMPLIED INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK ARISING OUT OF USE OR PERFORMANCE OF THE SOFTWARE REMAINS WITH YOUThe Agreement becomes effective when You agree to the terms and conditions of this Agreement by opening installing using accessing or manipulating the Software (the " Effective Date ") and this Agreement will terminate immediately upon notice to You if You materially breach any term or condition of this Agreement. You agree upon termination to promptly destroy the Software and all copies thereof.NOTE: REVO UNINSTALLER MAY CONNECT BY USERS REQUEST THROUGH THE INTERNET TO WWW.REVOUNINSTALLER.COM TO CHECK FOR UPDATES. DURING THIS PROCESS IT WILL DOWNLOAD A SMALL FILE THAT
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpWindow detected: License AgreementPlease read the following important information before continuing.Please read the following License Agreement. You must accept the terms of this agreement before continuing with the installation.LICENSE AGREEMENT AND COPYRIGHT========================IMPORTANT - READ CAREFULLY:This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd. the vendor of the software product Revo Uninstaller"."the Vendor" means the developer of the "Revo Uninstaller" software product VS Revo Group Ltd.YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING COPYING DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE DO NOT INSTALL DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.This is not public domain software. The software is owned by the author and protected by copyright law. The Software is licensed not sold to You for Your use only under the terms of this Agreement and VS Revo Group Ltd. reserves all rights not expressly granted to You. You are NOT allowed to:1. Modify reverse engineer decompile disassemble or otherwise attempt to reconstruct or discover the source code or any parts of it from the binaries of Revo Uninstaller.2. Remove any product identification copyright proprietary notices or labels from Revo Uninstaller.3. Distribute Revo Uninstaller in any other form than in the official distribution packages without a written permission from the Vendor.4. Use run copy distribute or store Revo Uninstaller in your computer if this license agreement is violated in any ways.THE APPLICATION AND ANY RELATED DOCUMENTATION IS PROVIDED "AS IS" WITHOUT ANY WARRANTIES. AND THAT THE VENDOR DOES NOT WARRANT THAT REVO UNINSTALLER WILL RUN UNINTERRUPTED OR ERROR FREE NOR THAT REVO UNINSTALLER WILL OPERATE WITH HARDWARE AND/OR SOFTWARE NOT PROVIDED BY THE VENDOR EITHER EXPRESS OR IMPLIED INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK ARISING OUT OF USE OR PERFORMANCE OF THE SOFTWARE REMAINS WITH YOUThe Agreement becomes effective when You agree to the terms and conditions of this Agreement by opening installing using accessing or manipulating the Software (the " Effective Date ") and this Agreement will terminate immediately upon notice to You if You materially breach any term or condition of this Agreement. You agree upon termination to promptly destroy the Software and all copies thereof.NOTE: REVO UNINSTALLER MAY CONNECT BY USERS REQUEST THROUGH THE INTERNET TO WWW.REVOUNINSTALLER.COM TO CHECK FOR UPDATES. DURING THIS PROCESS IT WILL DOWNLOAD A SMALL FILE THAT
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.dat
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-930TG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-SRMPO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-QNP87.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-1GMMQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-LQ7V0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-8HS44.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6JUB1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-TF4FP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-JLIIP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-51DQ4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-ON5O0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-89KBO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-H8O5L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-BHORG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-NU8DV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-86R4G.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-O6OOC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-OQLC1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-BRMVK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-IE3NO.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-NA2VL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6D4JF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-P4FJN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-F6T79.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-4HQ49.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-Q5ETH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-D9K51.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-AP8OQ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-03S2V.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-RM1PV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-7F029.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-MV7M3.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-A47CF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-6RDSI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-JEUE8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-8N9CU.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-4H15I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-R94T1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-KQVVL.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-57PF0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-2JR70.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-FVNN5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-79H19.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-Q3DI4.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-FNPTG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-QRKAM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\lang\is-20FHR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-3UJFV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-UKQ9R.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-3D3RB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDirectory created: C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.msg
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1
Source: revosetup.exeStatic PE information: certificate valid
Source: revosetup.exeStatic file information: File size 6970144 > 1048576
Source: revosetup.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Program Files\VS Revo Group\Revo Uninstaller\is-3UJFV.tmpJump to dropped file
Source: C:\Users\user\Desktop\revosetup.exeFile created: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Users\user\AppData\Local\Temp\is-APUB4.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\Users\user\AppData\Local\Temp\Setup Log 2024-04-26 #001.txt

Boot Survival

barindex
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller.lnk
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller on the Web.url
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Uninstall Revo Uninstaller.lnk
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller Help.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored for changes: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeRegistry key monitored for changes: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\Desktop\revosetup.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-APUB4.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl32.DllA\OpenSSL32.DllA\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\1033\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\lib\LibCurl32.DllA\
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Program Files (x86)\Microsoft Office\root\Office16\ODBC Drivers\Salesforce\
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.revouninstaller.com/free-install-thankyou/
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmpQueries volume information: C:\ VolumeInformation

Stealing of Sensitive Information

barindex
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfak\Google Drive.ico
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjb\Docs.ico
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibag\Slides.ico
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldooml\YouTube.ico
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjf\Sheets.ico
Source: C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm\Gmail.ico
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Windows Service
1
Windows Service
3
Masquerading
1
OS Credential Dumping
11
Query Registry
Remote Services1
Data from Local System
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
11
Process Injection
11
Process Injection
LSASS Memory2
System Owner/User Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
DLL Side-Loading
Binary PaddingNTDS21
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
revosetup.exe3%ReversingLabs
revosetup.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp3%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\is-APUB4.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-APUB4.tmp\_isetup\_setup64.tmp0%VirustotalBrowse
C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe (copy)0%ReversingLabs
C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe (copy)0%VirustotalBrowse
No Antivirus matches
SourceDetectionScannerLabelLink
jsdelivr.map.fastly.net0%VirustotalBrowse
platform.twitter.map.fastly.net0%VirustotalBrowse
static.ads-twitter.com0%VirustotalBrowse
SourceDetectionScannerLabelLink
about:blank0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
stackpath.bootstrapcdn.com
104.18.11.207
truefalse
    high
    jsdelivr.map.fastly.net
    151.101.129.229
    truefalseunknown
    star-mini.c10r.facebook.com
    157.240.14.35
    truefalse
      high
      v2assets.zopim.io
      104.16.200.19
      truefalse
        high
        vsrevogroup.zendesk.com
        104.16.53.111
        truefalse
          high
          platform.twitter.map.fastly.net
          146.75.124.157
          truefalseunknown
          stats.g.doubleclick.net
          173.194.216.156
          truefalse
            high
            static.zdassets.com
            104.18.72.113
            truefalse
              high
              scontent.xx.fbcdn.net
              31.13.67.20
              truefalse
                high
                script.hotjar.com
                13.226.52.129
                truefalse
                  high
                  widget-mediator.zopim.com
                  54.145.171.210
                  truefalse
                    high
                    ekr.zdassets.com
                    104.18.70.113
                    truefalse
                      high
                      td.doubleclick.net
                      142.250.217.162
                      truefalse
                        high
                        analytics.google.com
                        142.250.217.174
                        truefalse
                          high
                          www.google.com
                          142.250.189.132
                          truefalse
                            high
                            widget.trustpilot.com
                            18.66.255.92
                            truefalse
                              high
                              revouninstaller.com
                              146.20.152.114
                              truefalse
                                high
                                static-cdn.hotjar.com
                                108.157.173.76
                                truefalse
                                  high
                                  static.ads-twitter.com
                                  unknown
                                  unknownfalseunknown
                                  www.facebook.com
                                  unknown
                                  unknownfalse
                                    high
                                    cdn.jsdelivr.net
                                    unknown
                                    unknownfalse
                                      high
                                      f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com
                                      unknown
                                      unknownfalse
                                        high
                                        connect.facebook.net
                                        unknown
                                        unknownfalse
                                          high
                                          www.revouninstaller.com
                                          unknown
                                          unknownfalse
                                            high
                                            static.hotjar.com
                                            unknown
                                            unknownfalse
                                              high
                                              NameMaliciousAntivirus DetectionReputation
                                              about:blankfalse
                                              • Avira URL Cloud: safe
                                              low
                                              https://td.doubleclick.net/td/ga/rul?tid=G-P73P80145H&gacid=1413362299.1714136623&gtm=45je44o0v869118035z871855269za200&dma=0&gcd=13l3l3l3l1&npa=0&pscdl=noapi&aip=1&fledge=1&z=820655299false
                                                high
                                                • No. of IPs < 25%
                                                • 25% < No. of IPs < 50%
                                                • 50% < No. of IPs < 75%
                                                • 75% < No. of IPs
                                                IPDomainCountryFlagASNASN NameMalicious
                                                13.226.52.129
                                                script.hotjar.comUnited States
                                                16509AMAZON-02USfalse
                                                31.13.67.35
                                                unknownIreland
                                                32934FACEBOOKUSfalse
                                                142.250.189.142
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                18.66.255.92
                                                widget.trustpilot.comUnited States
                                                3MIT-GATEWAYSUSfalse
                                                146.20.152.114
                                                revouninstaller.comUnited States
                                                27357RACKSPACEUSfalse
                                                146.75.124.157
                                                platform.twitter.map.fastly.netSweden
                                                30051SCCGOVUSfalse
                                                151.101.129.229
                                                jsdelivr.map.fastly.netUnited States
                                                54113FASTLYUSfalse
                                                104.71.249.186
                                                unknownUnited States
                                                16625AKAMAI-ASUSfalse
                                                142.250.217.238
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                157.240.14.35
                                                star-mini.c10r.facebook.comUnited States
                                                32934FACEBOOKUSfalse
                                                142.250.64.142
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                142.251.35.238
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                142.251.35.234
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                54.145.171.210
                                                widget-mediator.zopim.comUnited States
                                                14618AMAZON-AESUSfalse
                                                104.18.72.113
                                                static.zdassets.comUnited States
                                                13335CLOUDFLARENETUSfalse
                                                104.16.200.19
                                                v2assets.zopim.ioUnited States
                                                13335CLOUDFLARENETUSfalse
                                                142.250.217.162
                                                td.doubleclick.netUnited States
                                                15169GOOGLEUSfalse
                                                108.157.173.76
                                                static-cdn.hotjar.comUnited States
                                                16509AMAZON-02USfalse
                                                172.253.123.84
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                142.250.189.131
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                192.178.50.67
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                1.1.1.1
                                                unknownAustralia
                                                13335CLOUDFLARENETUSfalse
                                                172.217.3.72
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                104.16.53.111
                                                vsrevogroup.zendesk.comUnited States
                                                13335CLOUDFLARENETUSfalse
                                                142.250.189.132
                                                www.google.comUnited States
                                                15169GOOGLEUSfalse
                                                142.250.189.138
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                104.18.11.207
                                                stackpath.bootstrapcdn.comUnited States
                                                13335CLOUDFLARENETUSfalse
                                                142.250.217.174
                                                analytics.google.comUnited States
                                                15169GOOGLEUSfalse
                                                239.255.255.250
                                                unknownReserved
                                                unknownunknownfalse
                                                104.18.70.113
                                                ekr.zdassets.comUnited States
                                                13335CLOUDFLARENETUSfalse
                                                173.194.216.156
                                                stats.g.doubleclick.netUnited States
                                                15169GOOGLEUSfalse
                                                173.194.216.157
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                142.251.35.228
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                192.178.50.40
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                18.66.255.15
                                                unknownUnited States
                                                3MIT-GATEWAYSUSfalse
                                                142.250.217.195
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                31.13.67.20
                                                scontent.xx.fbcdn.netIreland
                                                32934FACEBOOKUSfalse
                                                23.22.231.22
                                                unknownUnited States
                                                14618AMAZON-AESUSfalse
                                                18.66.255.55
                                                unknownUnited States
                                                3MIT-GATEWAYSUSfalse
                                                142.250.217.170
                                                unknownUnited States
                                                15169GOOGLEUSfalse
                                                IP
                                                192.168.2.17
                                                Joe Sandbox version:40.0.0 Tourmaline
                                                Analysis ID:1432131
                                                Start date and time:2024-04-26 15:02:32 +02:00
                                                Joe Sandbox product:CloudBasic
                                                Overall analysis duration:
                                                Hypervisor based Inspection enabled:false
                                                Report type:full
                                                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                Number of analysed new started processes analysed:24
                                                Number of new started drivers analysed:0
                                                Number of existing processes analysed:0
                                                Number of existing drivers analysed:0
                                                Number of injected processes analysed:0
                                                Technologies:
                                                • EGA enabled
                                                Analysis Mode:stream
                                                Analysis stop reason:Timeout
                                                Sample name:revosetup.exe
                                                Detection:SUS
                                                Classification:sus24.spyw.winEXE@21/109@60/309
                                                Cookbook Comments:
                                                • Found application associated with file extension: .exe
                                                • Exclude process from analysis (whitelisted): dllhost.exe
                                                • Excluded IPs from analysis (whitelisted): 192.178.50.67, 172.253.123.84, 142.251.35.238, 34.104.35.123, 142.250.217.195, 142.251.35.234, 104.71.249.186
                                                • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
                                                • Not all processes where analyzed, report is missing behavior information
                                                • Report size getting too big, too many NtOpenFile calls found.
                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Non-ISO extended-ASCII text, with very long lines (479), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C1459801E75F90321DAA2BE48EC50B14
                                                SHA1:FFFCF28465FFDFE6A2F286BD6E5E534472863852
                                                SHA-256:18F086240EC88DDAB6F0C9597B3A7B6F99DF38465A1207F9CA89A751A375B3D5
                                                SHA-512:2686D8DF5F59E67D2DA89EABF28197C2512BCD41AA06FB5878A056FAE2AF8B84115BD379F2E8CCA38D5103D74F97D71289E77FDE29008A72C8B0AD4B5FE9E923
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:LICENSE AGREEMENT AND COPYRIGHT..========================....IMPORTANT - READ CAREFULLY:..This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd., the vendor of the software product .Revo Uninstaller."....."the Vendor" means the developer of the "Revo Uninstaller" software product, VS Revo Group Ltd.....YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING, COPYING, DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE, DO NOT INSTALL, DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.....Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents, no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.....This is not public domain software. The software is o
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:PDF document, version 1.7, 34 pages
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7C770B8371E21BA771F108549941B063
                                                SHA1:44E44E7A8100C0540572CF8314DD1F39211F1134
                                                SHA-256:47B002D89DA453EB352B176D63E08960EA3E3AA3D7069C8A5E8872621568AC87
                                                SHA-512:96691912F5F7DC1EB7E851E8EA6FCDAC82D6C92740A2ACCF0F1A01A4F9F617140FE7E77704E41E918286564606E6065307FDBDF2A6F1AD384B1CFC7CFD4C5B81
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:%PDF-1.7..%......1 0 obj..<</Type/Catalog/Pages 2 0 R/Lang(bg-BG) /StructTreeRoot 164 0 R/MarkInfo<</Marked true>>/Metadata 1740 0 R/ViewerPreferences 1741 0 R>>..endobj..2 0 obj..<</Type/Pages/Count 34/Kids[ 3 0 R 17 0 R 20 0 R 21 0 R 27 0 R 29 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R 38 0 R 39 0 R 41 0 R 44 0 R 45 0 R 46 0 R 48 0 R 50 0 R 52 0 R 57 0 R 62 0 R 66 0 R 72 0 R 75 0 R 77 0 R 79 0 R 82 0 R 84 0 R 86 0 R 90 0 R 92 0 R 96 0 R] >>..endobj..3 0 obj..<</Type/Page/Parent 2 0 R/Resources<</Font<</F1 5 0 R/F2 9 0 R/F3 11 0 R/F4 13 0 R>>/ExtGState<</GS7 7 0 R/GS8 8 0 R>>/XObject<</Image15 15 0 R>>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/MediaBox[ 0 0 612 792] /Contents 4 0 R/Group<</Type/Group/S/Transparency/CS/DeviceRGB>>/Tabs/S/StructParents 0>>..endobj..4 0 obj..<</Filter/FlateDecode/Length 598>>..stream..x....o.0...#....%.b.;......uZ......!..........)...)k....'.~.|.7z(k8;.]....{..z.IUg.Qz~...>..#.....A.V..U.G_.C.G..8.}. $...?.H..8...8J.\.B.xa...4..nNt.1.d.\.X...3|3
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A9CCD5974308C40CBE6946B5E53D2DE9
                                                SHA1:3560538B946953C8B0FF7DD63B5BC4E088BA8240
                                                SHA-256:2DF4DD7200737FEAB6E9DD77026584DDB328AD580C68205467356AC390A8F775
                                                SHA-512:866C2565F6C7FCC969D4C5DB84FCB92E43EF4E8885EC129DC528020DA8DF599977B75B748ABC0620B30E01A3F2980FFDC37731DFE4878B778DFDAEF7911097AB
                                                Malicious:false
                                                Antivirus:
                                                • Antivirus: ReversingLabs, Detection: 0%
                                                • Antivirus: Virustotal, Detection: 0%, Browse
                                                Reputation:unknown
                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........#..yM..yM..yM... ..yM.....yM....$yM.....yM.....xM..+..yM...6..yM..yL.xzM.....yM..+..yM.....yM.Rich.yM.........PE..d.....~d..........#.......P....................@.............................@......6.........................................................i.......q.l.u...l.@....T...@..........p.Q...............................................P.......i.@....................text.....P.......P................. ..`.rdata...]....P..^....P.............@..@.data....r...@j......2j.............@....pdata..@.....l.......k.............@..@text..........q.......p.............@.. data....`.....q.......p.............@..@.rsrc...l.u...q...u...p.............@..@................................................................................................................................................................................................................
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Non-ISO extended-ASCII text, with very long lines (479), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):3256
                                                Entropy (8bit):5.115556088921706
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C1459801E75F90321DAA2BE48EC50B14
                                                SHA1:FFFCF28465FFDFE6A2F286BD6E5E534472863852
                                                SHA-256:18F086240EC88DDAB6F0C9597B3A7B6F99DF38465A1207F9CA89A751A375B3D5
                                                SHA-512:2686D8DF5F59E67D2DA89EABF28197C2512BCD41AA06FB5878A056FAE2AF8B84115BD379F2E8CCA38D5103D74F97D71289E77FDE29008A72C8B0AD4B5FE9E923
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:LICENSE AGREEMENT AND COPYRIGHT..========================....IMPORTANT - READ CAREFULLY:..This license agreement is a legal agreement between you (either personal or corporate) and VS Revo Group Ltd., the vendor of the software product .Revo Uninstaller."....."the Vendor" means the developer of the "Revo Uninstaller" software product, VS Revo Group Ltd.....YOU AGREE TO BE BOUND BY THE TERMS OF THIS LICENSE AGREEMENT AND THE LIMITATIONS OF YOUR LICENSE BY INSTALLING, COPYING, DISTRIBUTING OR OTHERWISE USING REVO UNINSTALLER. IF YOU DO NOT AGREE, DO NOT INSTALL, DISTRIBUTE OR USE REVO UNINSATALLER IN ANY WAYS.....Revo Uninstaller is FREEWARE. You can freely use this software and distribute copies of the ORIGINAL DISTRIBUTION FILE as long as NO ALTERATIONS are made to the file and its contents, no charge is raised and that this license agreement is not violated in any ways. Any other way of distributing this software is prohibited.....This is not public domain software. The software is o
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                Category:dropped
                                                Size (bytes):15111408
                                                Entropy (8bit):6.481455587338639
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A9CCD5974308C40CBE6946B5E53D2DE9
                                                SHA1:3560538B946953C8B0FF7DD63B5BC4E088BA8240
                                                SHA-256:2DF4DD7200737FEAB6E9DD77026584DDB328AD580C68205467356AC390A8F775
                                                SHA-512:866C2565F6C7FCC969D4C5DB84FCB92E43EF4E8885EC129DC528020DA8DF599977B75B748ABC0620B30E01A3F2980FFDC37731DFE4878B778DFDAEF7911097AB
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........#..yM..yM..yM... ..yM.....yM....$yM.....yM.....xM..+..yM...6..yM..yL.xzM.....yM..+..yM.....yM.Rich.yM.........PE..d.....~d..........#.......P....................@.............................@......6.........................................................i.......q.l.u...l.@....T...@..........p.Q...............................................P.......i.@....................text.....P.......P................. ..`.rdata...]....P..^....P.............@..@.data....r...@j......2j.............@....pdata..@.....l.......k.............@..@text..........q.......p.............@.. data....`.....q.......p.............@..@.rsrc...l.u...q...u...p.............@..@................................................................................................................................................................................................................
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:PDF document, version 1.7, 34 pages
                                                Category:dropped
                                                Size (bytes):1467128
                                                Entropy (8bit):7.961444134375944
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7C770B8371E21BA771F108549941B063
                                                SHA1:44E44E7A8100C0540572CF8314DD1F39211F1134
                                                SHA-256:47B002D89DA453EB352B176D63E08960EA3E3AA3D7069C8A5E8872621568AC87
                                                SHA-512:96691912F5F7DC1EB7E851E8EA6FCDAC82D6C92740A2ACCF0F1A01A4F9F617140FE7E77704E41E918286564606E6065307FDBDF2A6F1AD384B1CFC7CFD4C5B81
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:%PDF-1.7..%......1 0 obj..<</Type/Catalog/Pages 2 0 R/Lang(bg-BG) /StructTreeRoot 164 0 R/MarkInfo<</Marked true>>/Metadata 1740 0 R/ViewerPreferences 1741 0 R>>..endobj..2 0 obj..<</Type/Pages/Count 34/Kids[ 3 0 R 17 0 R 20 0 R 21 0 R 27 0 R 29 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R 38 0 R 39 0 R 41 0 R 44 0 R 45 0 R 46 0 R 48 0 R 50 0 R 52 0 R 57 0 R 62 0 R 66 0 R 72 0 R 75 0 R 77 0 R 79 0 R 82 0 R 84 0 R 86 0 R 90 0 R 92 0 R 96 0 R] >>..endobj..3 0 obj..<</Type/Page/Parent 2 0 R/Resources<</Font<</F1 5 0 R/F2 9 0 R/F3 11 0 R/F4 13 0 R>>/ExtGState<</GS7 7 0 R/GS8 8 0 R>>/XObject<</Image15 15 0 R>>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/MediaBox[ 0 0 612 792] /Contents 4 0 R/Group<</Type/Group/S/Transparency/CS/DeviceRGB>>/Tabs/S/StructParents 0>>..endobj..4 0 obj..<</Filter/FlateDecode/Length 598>>..stream..x....o.0...#....%.b.;......uZ......!..........)...)k....'.~.|.7z(k8;.]....{..z.IUg.Qz~...>..#.....A.V..U.G_.C.G..8.}. $...?.H..8...8J.\.B.xa...4..nNt.1.d.\.X...3|3
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (601), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:CD86D5DF4564A5D91934B3383A2B342E
                                                SHA1:D278404BF4412D00E07839911CFF8A9F0C3AFC2A
                                                SHA-256:09FE4F2A0D1D54C5D374DB235F07F06642404A630F8B981461B0F7998B7C753B
                                                SHA-512:7FC876B6637897CE0AA46D947764DA63616978F0F5BBC71B0BF1E6B7B1FC8680FF0A5E1B691737B4D0F75920B1C854CEC150DFD27E599C326FBFD5277609ECA1
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.D.o.k.u.m.e.n.t.i. .i. .g.j.u.h.e.s. .i. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....;.T.r.a.n.s.l.a.t.e.d. .b.y. .K.l.a.u.s. .V.e.l.i.u.....;.C.o.n.t.a.c.t. .k.l.a.u.s.v.e.l.i.u.@.h.o.t.m.a.i.l...c.o.m.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .S.h.q.i.p./.A.l.b.a.n.i.a.n.....W.e.b.L.a.n.g.=.A.L.....T.r.a.n.s.l.a.t.o.r.=.K.l.a.u.s. .V.e.l.i.u. .e.-.m.a.i.l.:. .k.l.a.u.s.v.e.l.i.u.@.h.o.t.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[...i.n.s.t.a.l.u.e.s.i. .T.o.o.l.b.a.r.].....1.0.2. .=. .P.a.m.j.a.....1.0.3. .=. .O.p.s.i.o.n.e.t.....1.0.4. .=. ...i.n.s.t.a.l.u.e.s.i.....1.0.5. .=. .M.j.e.t.e.t.....1.0.6. .=. .M.e.n.y.r.a. .e. .g.j.u.e.t.a.r.i.t.....1.0.7. .=. .M.e. .l.i.s.t.i.m.....1.0.8. .=. .M.e. .i.n.k.o.n.a.....1.0.9. .=. .M.e. .d.e.t.a.j.e.....1.1.0. .=. ...i.n.s.t.a.l.o.....1.1.1. .=. .H.i.q. .s.h.e.n.i.m.i.n.....1.1.2. .=. .R.i.f.r.e.s.k.o.....1.1.3. .=. .J.e.n.i. .t.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (437), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C75676D808ED8D88ADD598CC51F79769
                                                SHA1:418CC54489003C093D391B5DA26105BCD0F13870
                                                SHA-256:D8D0C60EAD40825B14D3218AD5A17870F51D602653A397F2162F31B0150E6915
                                                SHA-512:E598EBDC0CEA722BA3811C1B1A13E256C940002CA5386FC6374CFFD8EE0CD414FAC300B638F0FA78EBD724720EC1FD865460CD3AB59923D62F1DBA050453B8C6
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .9.1.(.J./.A.r.a.b.i.c.....W.e.b.L.a.n.g.=.A.R.A.....T.r.a.n.s.l.a.t.o.r.=.'.D.#.3.*.'.0. .9.H.6. .".D.-.9.'.&.6. .'.D.:.'.E./.J.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=.9.1.6.....1.0.3. .=...J.'.1.'.*.....1.0.4. .=.%.D.:.'.!. .'.D.*.+.(.J.*.....1.0.5. .=.#./.H.'.*.....1.0.6. .=.F.E.7. .'.D.5.J.'./.....1.0.7. .=.B.'.&.E.).....1.0.8. .=.1.E.H.2.....1.0.9. .=.*.A.'.5.J.D.....1.1.0. .=.%.D.:.'.!. .'.D.*.+.(.J.*.....1.1.1. .=.%.2.'.D.). .'.D.E./...D.).....1.1.2. .=.*.-./.J.+.....1.1.3. .=.G.D. .*.1.J./. .A.9.D.'. .-.0.A. .'.D.E./...D.'.*. .'.D.E.-././.). .......1.1.4. .=.G.D. .*.1.J./. .A.9.D.'. .%.2.'.D.). .'.D.(.1.F.'.E.,. .'.D.E.-././. .......1.1.5. .=.*.-./.J.+. .*.D.B.'.&.J.....1.1.6. .=.*.9.D.J.E.'.*.....1.1.7. .=.*.9.D.J.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (638), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C2E52ABF76949AC22C6A1065B6B31C26
                                                SHA1:6379C1CEA97C9B7C2A3FC7109BD737A5636E75F4
                                                SHA-256:1DA3E26753481F5B8C46D4FAE24DE4C64272B94E5F8EFBA57D023D95D45AF71C
                                                SHA-512:9E7268F2BE2AF7E6337B0B3A46F337F22E539249BE20A8C98447122491C0854C195D658C17C7FDF7937B5DD06C3B29FCE1021FF0D9056730811E3362AC63B6A2
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.@.a.u.e...e.v./.A.r.m.e.n.i.a.n.....W.e.b.L.a.n.g.=.a.r.m.....T.r.a.n.s.l.a.t.o.r.=.H.r.a.n.t. .O.h.a.n.y.a.n. ....... .h...o.h.a.n.y.a.n.@.h.a.y.s.o.f.t...o.r.g.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .O.e.}.......1.0.3. .=. .?.a...c.a.~.x...x...t.v.e.......1.0.4. .=. .1.z.a...e.r.a.d...k.y.....1.0.5. .=. .3.x...n.k...v.e.......1.0.6. .=. .H.P.M.....1.0.7. .=. .Q.a.v.o.x.~.....1.0.8. .=. .J.a...o.e...a.o.v.e.......1.0.9. .=. .D.a.v...a.t.a.}.v.....1.1.0. .=. .1.z.a...e.r.a.d...e.l.....1.1.1. .=. .K.v.{.e.l. ...a.u.l.h.....1.1.2. .=. .9.a...t.a...v.e.l.....1.1.3. .=. .K.v.{.e.^.l. .h.v.....~.a.n. .n...a.c...e...h.:.....1.1.4. .=. .K.v.{.e.^.l. .h.v.....~.a.n. .n...a.c.k...h.:.....1.1.5. .=. .;.v...v.a.i.a...t.a...x...t.....1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (562), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2952EBFB627A4E0ECA6AE36179FB77E8
                                                SHA1:44E1DC938E9D4760EB3BC7B7A57BAFFA93ECF124
                                                SHA-256:104F10070994CA92176913A71726590DF2487BA756512CE6B3ABAA50CED8679B
                                                SHA-512:EA8F916977CEDBB7A6436FEFF19A2377266396799B11775FB00225854AFC5775018E2D8F0AC8CEF9E0D56CDC331C24825336A295AEE0A2E7314BF39FB91A7B84
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e. .=. .A.z.Y.r.b.a.y.c.a.n./.A.z.e.r.b.a.i.j.a.n.i.....W.e.b.L.a.n.g. .=. .A.Z.....T.r.a.n.s.l.a.t.o.r. .=. .M.a.h.i.r. .H.u.s.e.y.n.o.v. .(.u.r.o.b.o.r.o.s.1.3.0.8.7.5.@.g.m.a.i.l...c.o.m.). .....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E. .....V.e.r.s.i.o.n. .=. .2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .G...r...n.t.......1.0.3. .=. .T.Y.n.z.i.m.l.Y.m.Y.l.Y.r.....1.0.4. .=. .P.r.o.q.r.a.m. .s.i.l.Y.n.....1.0.5. .=. .A.l.Y.t.l.Y.r.....1.0.6. .=. .O.v...u. .r.e.j.i.m.i.....1.0.7. .=. .S.i.y.a.h.1.....1.0.8. .=. .N.i._.a.n.l.a.r.....1.0.9. .=. .T.Y.f.Y.r.r...a.t.1. .i.l.Y.....1.1.0. .=. .S.i.l.m.Y.k.....1.1.1. .=. .Y.a.z.1.n.1. .s.i.l.m.Y.k. .....1.1.2. .=. .Y.e.n.i.l.Y.m.Y.k.....1.1.3. .=. .S.i.z. . .s.e...i.l.m.i._. .e.l.e.m.e.n.t.i. .s.i.l.m.Y.k. .i.s.t.Y.d.i.y.i.n.i.z.Y. .Y.m.i.n.s.i.n.i.z.m.i.?.....1.1.4. .=. .S.i.z. . .s.e...i.l.m.i._. .p.r.o.q.r.a.m.1. .s.i.l.m.Y.k. .i.s.t.Y.d.i.y.i.n.i.z.Y. .Y.m.i.n.s.i.n.i.z.m.i.?.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (739), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:966C8ECA86F43A502D9836709ED34D6E
                                                SHA1:014FA738E95E543E7A6DB68EE4F5F21F9A4CE823
                                                SHA-256:25205DBA08243AEEB6516221847738D47F3C72C295F7D973E09433E2635C943D
                                                SHA-512:F85DE756FC15458AF86955B555A8EC3E0E29A2EBEF2917AF200A172279362B7A40D874D6F5025A2BFC7B7539B2818053BCF7CA3B077E64EC786289604F0F8113
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=........... ./.B.e.n.g.a.l.i.....W.e.b.L.a.n.g.=.B.N.....T.r.a.n.s.l.a.t.o.r.=.G.o.u.t.a.m. .R.o.y.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...............1.0.3. .=. .........................1.0.4. .=. .........................1.0.5. .=. .............1.0.6. .=. ............. ...........1.0.7. .=. .................1.0.8. .=. .....................1.0.9. .=. .......................1.1.0. .=. .....................1.1.1. .=. ............... ....... .............1.1.2. .=. .............1.1.3. .=. ......... ..... ............... ..... ......... ................... ............... ........... .......?.....1.1.4. .=. ......... ..... ............... ..... ......... ................... ................... ................. ...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (705), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:29C6FA77CAFF22CEBEF89FE7CBB7E564
                                                SHA1:02521C2CF3C8D1C6CB88FB256EBD6EA26000F8D2
                                                SHA-256:8AD919E2DF77256C9DE97E5AB3BCB62669517360051E1F8C3444D2BDCDC9E824
                                                SHA-512:C3773E31FBE79BB2B5A1D6F74AA6B20087243C1884C4C2FDBEC88AE986EC04CADEC1341BA1532895DBE3D88100B6385498E722FC4AF2902CC898166A0559739E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. ...J.;.3.0.@.A.:.8./.B.u.l.g.a.r.i.a.n. .....W.e.b.L.a.n.g.=.B.G.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...0.A.B.@.>.9.:.8.....1.0.4. .=. ...5.8.=.A.B.0.;.0.B.>.@.....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.8.....1.0.6. .=. ...8.H.5.=.0.....1.0.7. .=. .!.?.8.A.J.:.....1.0.8. .=. ...:.>.=.8.....1.0.9. .=. ...5.B.0.9.;.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.9.....1.1.1. .=. ...@.5.<.0.E.=.8.....1.1.2. .=. ...?.@.5.A.=.8.....1.1.3. .=. .!.8.3.C.@.=.8. .;.8. .A.B.5.,.G.5. .8.A.:.0.B.5. .4.0. .8.7.B.@.8.5.B.5. .8.7.1.@.0.=.8.O. .5.;.5.<.5.=.B.?.....1.1.4. .=. .!.8.3.C.@.=.8. .;.8. .A.B.5.,.G.5. .8.A.:.0.B.5. .4.0. .4.5.8.=.A.B.0.;.8.@.0.B.5. .8.7.1.@.0.=.0.B.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (668), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:EDF65AA9E3901E57E6290C53D9B18F19
                                                SHA1:C22A962518F577F96D187831C4009D807F5F8B6D
                                                SHA-256:AA6B1D30A2ADC755A44122ACA13C7CA56C740C6E69F9B799EA6FD5CA7109DC4E
                                                SHA-512:0BE4B66E464CCC6108DF33156EEF18E473424E8EBE832060321DEA50BE93E2A8E1AA81801AB44D545E24654CB112ABF302D983345936DC2E8A73B0ABBD4A9505
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. ...e.a.t.i.n.a./.C.z.e.c.h.....W.e.b.L.a.n.g.=.C.Z.....T.r.a.n.s.l.a.t.o.r.=. .=.M.r...=.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .Z.o.b.r.a.z.e.n.......1.0.3. .=. .N.a.s.t.a.v.e.n.......1.0.4. .=. .O.d.i.n.s.t.a.l...t.o.r.....1.0.5. .=. .N...s.t.r.o.j.e.....1.0.6. .=. .R.e.~.i.m. .L.o.v.e.c.....1.0.7. .=. .S.e.z.n.a.m.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .D.e.t.a.i.l.y.....1.1.0. .=. .O.d.i.n.s.t.a.l.o.v.a.t.....1.1.1. .=. .O.d.s.t.r.a.n.i.t. .z...z.n.a.m.....1.1.2. .=. .O.b.n.o.v.i.t.....1.1.3. .=. .O.p.r.a.v.d.u. .m...m. .o.z.n.a...e.n... .z...z.n.a.m. .o.d.s.t.r.a.n.i.t.?.....1.1.4. .=. .O.p.r.a.v.d.u. .m...m. .t.e.n.t.o. .p.r.o.g.r.a.m. .o.d.i.n.s.t.a.l.o.v.a.t.?.....1.1.5. .=. .A.u.t.o.a.k.t.u.a.l.i.z.a.c.e.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (431), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B460A1121BDB6806E308212EB9F63F8F
                                                SHA1:B42175BF8208C16669434F49EE46FDAADCDAFE6A
                                                SHA-256:7A2F9651F01898D76E4B0AD81272D12602162AAB0AF87EB7E0294ED345C1A6B2
                                                SHA-512:D826B851FDFF9B77211A264E593921B2239F1FB20278524E091459941A6EF69AE1BFBF227A1D5C243366A51A3F87F4E474E95BE0A6532140DB268D7F537DA806
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .D.a.n.s.k./.D.a.n.i.s.h.....W.e.b.L.a.n.g.=.D.A.N.....T.r.a.n.s.l.a.t.o.r.=.H.o.l.g.e.r. .T.e.r.k.e.l.s.e.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.....1.0.3. .=. .I.n.d.s.t.i.l.l.i.n.g.e.r.....1.0.4. .=. .A.f.i.n.s.t.a.l.l.e.r.i.n.g.....1.0.5. .=. .V...r.k.t...j.....1.0.6. .=. .J.a.g.t.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.f.i.n.s.t.a.l.l.e.r.....1.1.1. .=. .F.j.e.r.n. .e.m.n.e.....1.1.2. .=. .O.p.d.a.t.e.r.....1.1.3. .=. .E.r. .d.u. .s.i.k.k.e.r. .p... .d.u. .v.i.l. .f.j.e.r.n.e. .d.e.t. .v.a.l.g.t.e. .e.m.n.e.?.....1.1.4. .=. .E.r. .d.u. .s.i.k.k.e.r. .p... .d.u. .v.i.l. .a.f.i.n.s.t.a.l.l.e.r.e. .d.e.t. .v.a.l.g.t.e. .p.r.o.g.r.a.m.?.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (782), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:484AAB4E4A291B4C2F2D1718B3754D2B
                                                SHA1:13620CD1D36FC3B90EC7A9E48BE589B605407A1D
                                                SHA-256:7A47C9E44EF1E4CE0D5FC678DDF505D8213995E55599D7F4779E10462C002880
                                                SHA-512:EA294672C96892C1F5C36CFB16EA23352CBAC61F082F71904074A0BE9A5A8237685BE7F7FAFFA5EA652CC2403C1011340D3399E676A78D0350EFBD744C4292BD
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .N.e.d.e.r.l.a.n.d.s./.D.u.t.c.h.....W.e.b.L.a.n.g.=.N.L.....T.r.a.n.s.l.a.t.o.r.=.J.a.n. .V.e.r.h.e.i.j.e.n.,. .P.i.e.r.r.e. .M.e.l.s.e.r.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .B.e.e.l.d.....1.0.3. .=. .O.p.t.i.e.s.....1.0.4. .=. .D.e.-.i.n.s.t.a.l.l.a.t.i.e.....1.0.5. .=. .H.u.l.p.p.r.o.g.r.a.m.m.a.'.s.....1.0.6. .=. .J.a.c.h.t.m.o.d.u.s.....1.0.7. .=. .L.i.j.s.t.....1.0.8. .=. .P.i.c.t.o.g.r.a.m.m.e.n.....1.0.9. .=. .D.e.t.a.i.l.s.....1.1.0. .=. .D.e.-.i.n.s.t.a.l.l.e.r.e.n.....1.1.1. .=. .I.t.e.m. .v.e.r.w.i.j.d.e.r.e.n.....1.1.2. .=. .V.e.r.n.i.e.u.w.e.n.....1.1.3. .=. .W.e.e.t. .u. .z.e.k.e.r. .d.a.t. .u. .d.i.t. .w.i.l.t. .v.e.r.w.i.j.d.e.r.e.n.?.....1.1.4. .=. .W.e.e.t. .u. .z.e.k.e.r. .d.a.t. .u. .h.e.t. .g.e.s.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (662), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:5F57E969CB8F3AD0BBD859207A283BD5
                                                SHA1:5A232B0EED2D7437513010C7A0AF05CC4DE3D90F
                                                SHA-256:F2E8F9E5CF4F057E3399FF66485A485CBA419881AEEAC997049941396BDF63D8
                                                SHA-512:C48EC65D7DC7F1EF77BC708CDB6F49106651FB6D715450168F4D5FA8105C24DFB43D7378D8B0CEBA567942FD73FC95F7D41FD75C0824E619609981710B504CD0
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.n.g.l.i.s.h.....W.e.b.L.a.n.g.=.E.N.G.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.e.w.....1.0.3. .=. .O.p.t.i.o.n.s.....1.0.4. .=. .U.n.i.n.s.t.a.l.l.e.r.....1.0.5. .=. .T.o.o.l.s.....1.0.6. .=. .H.u.n.t.e.r. .M.o.d.e.....1.0.7. .=. .L.i.s.t.....1.0.8. .=. .I.c.o.n.s.....1.0.9. .=. .D.e.t.a.i.l.s.....1.1.0. .=. .U.n.i.n.s.t.a.l.l.....1.1.1. .=. .R.e.m.o.v.e. .E.n.t.r.y.....1.1.2. .=. .R.e.f.r.e.s.h.....1.1.3. .=. .A.r.e. .y.o.u. .s.u.r.e. .t.h.a.t. .y.o.u. .w.a.n.t. .t.o. .r.e.m.o.v.e. .t.h.e. .s.e.l.e.c.t.e.d. .e.n.t.r.y.?.....1.1.4. .=. .A.r.e. .y.o.u. .s.u.r.e. .t.h.a.t. .y.o.u. .w.a.n.t. .t.o. .u.n.i.n.s.t.a.l.l. .t.h.e. .s.e.l.e.c.t.e.d. .p.r.o.g.r.a.m.?.....1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (602), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:FB4844267D83DE0565C5AB8D8475605F
                                                SHA1:CFA437A8AC17216CB9E965F7305363F459E69572
                                                SHA-256:1899006AAB38B129BAC93E3935BEF214ACCC31D7FBE08FEE733E7A89EEEF9E08
                                                SHA-512:A6655508CBC8ECACD6DA3D0D4741F3C7B20294CCAD932F761D1CEE16477970C937034804E9D5360D164C7CD999D66CA5CF88A04431985F38DA85600794D8154C
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.e.s.t.i./.E.s.t.o.n.i.a.n.....W.e.b.L.a.n.g.=.E.S.T.....T.r.a.n.s.l.a.t.o.r.=.t.u.d.i.l.u.d.i. .-. .t.u.d.i.l.u.d.i...e.s.t.o.n.i.a.@.m.a.i.l...e.e.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.a.a.d.e.....1.0.3. .=. .S.u.v.a.n.d.i.d.....1.0.4. .=. .E.e.m.a.l.d.a.j.a.....1.0.5. .=. .T.....r.i.i.s.t.a.d.....1.0.6. .=. .J...l.i.t.a.j.a. .r.e.~.i.i.m.....1.0.7. .=. .N.i.m.e.k.i.r.i.....1.0.8. .=. .I.k.o.o.n.i.d.....1.0.9. .=. .D.e.t.a.i.l.i.d.....1.1.0. .=. .E.e.m.a.l.d.a.....1.1.1. .=. .K.u.s.t.u.t.a. .s.i.s.s.e.k.a.n.n.e.....1.1.2. .=. .V...r.s.k.e.n.d.a.....1.1.3. .=. .O.l.e.d. .k.i.n.d.e.l.,. .e.t. .s.o.o.v.i.d. .v.a.l.i.t.u.d. .s.i.s.s.e.k.a.n.d.e. .k.u.s.t.u.t.a.d.a.?.....1.1.4. .=. .O.l.e.d. .k.i.n.d.e.l.,. .e.t. .s.o.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (552), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A3D974340201C1D00AF3A87F4D3DA6DC
                                                SHA1:5A7B7EFFC4E0F4BF37672C57F859AF4E370D0F64
                                                SHA-256:FEDCC719AC22D45A77F117372E0E124AA0EDE73DFC0768E7CDF7420539140731
                                                SHA-512:DB2570F00A443F52C5F59DA1C90721E31B9C094E50E17BF2552C59D4AEC05EEB28301A6D9CFA1AE09140E141DA7E6AC92565DA10B18C5B26DC40596B7F1ADF08
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.u.o.m.i./.F.i.n.n.i.s.h.....W.e.b.L.a.n.g.=.F.I.N.....T.r.a.n.s.l.a.t.o.r.=.O.l.l.i. .(.o.l.l.i.n.p.o.s.t.i.t.@.g.m.a.i.l...c.o.m.).....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .N...y.t.......1.0.3. .=. .A.s.e.t.u.k.s.e.t.....1.0.4. .=. .S.o.v.e.l.l.u.s.t.e.n. .p.o.i.s.t.o.....1.0.5. .=. .T.y...k.a.l.u.t.....1.0.6. .=. .O.s.o.i.t.u.s.t.o.i.m.i.n.t.o.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .K.u.v.a.k.k.e.e.t.....1.0.9. .=. .T.i.e.d.o.t.....1.1.0. .=. .P.o.i.s.t.a. .s.o.v.e.l.l.u.s.....1.1.1. .=. .P.o.i.s.t.a. .r.e.k.i.s.t.e.r.i.m.e.r.k.i.n.t.......1.1.2. .=. .P...i.v.i.t... .l.u.e.t.t.e.l.o.....1.1.3. .=. .O.l.e.t.k.o. .v.a.r.m.a.,. .e.t.t... .h.a.l.u.a.t. .p.o.i.s.t.a.a. .v.a.l.i.t.u.n. .r.e.k.i.s.t.e.r.i.m.e.r.k.i.n.n...n.?...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (653), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:267BCE0C687901EF0C9B94853164FF22
                                                SHA1:5B7AE98C1E4E0DF851D1CF1D81DE3CA7E2BA96D8
                                                SHA-256:F7B544068FCFE69F5A718A9EE0B790620F85477AFBF0C5DB5215A318C67E3B7F
                                                SHA-512:252F8A49D767E8ECAB0610EEF60B762383F1B4E16ED15614AAF5C92446AEEF74705A4391DD5AB41FA6844A2D25A719DA733D404DB6AF8CBC3504575BF7446767
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .F.r.a.n...a.i.s./.F.r.e.n.c.h.....W.e.b.L.a.n.g.=.F.R.A.....T.r.a.n.s.l.a.t.o.r.=.N.i.g.h.t.l.i.g.h.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.u.e.....1.0.3. .=. .O.p.t.i.o.n.s.....1.0.4. .=. .D...s.i.n.s.t.a.l.l.e.u.r.....1.0.5. .=. .O.u.t.i.l.s.....1.0.6. .=. .M.o.d.e. .C.h.a.s.s.e.u.r.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.c...n.e.s.....1.0.9. .=. .D...t.a.i.l.l...e. .....1.1.0. .=. .D...s.i.n.s.t.a.l.l.e.r.....1.1.1. .=. .S.u.p.p.r.i.m.e.r. .l.'.e.n.t.r...e.....1.1.2. .=. .R.a.f.r.a...c.h.i.r.....1.1.3. .=. .E.t.e.s.-.v.o.u.s. .s...r. .d.e. .v.o.u.l.o.i.r. .s.u.p.p.r.i.m.e.r. .l.'.e.n.t.r...e. .s...l.e.c.t.i.o.n.n...e. .?.....1.1.4. .=. .E.t.e.s.-.v.o.u.s. .s...r. .d.e. .v.o.u.l.o.i.r. .d...s.i.n.s.t.a.l.l.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (896), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:00155578B98E07FC6288870E2AECCA68
                                                SHA1:FD934E59DA0813D7AB2E763BFCBA30DBB67D7721
                                                SHA-256:8CEF19D9D89BE0528643C45647085A85B136DF74987F7D25483732D431C70D12
                                                SHA-512:CDE580409DA144A7E9B0485EDB2610FCA23631712AB87A6FE727F3E5673357B315AB01B28C870815A985DA156251E68B2E20DEF1E7A0F919AA942EA0986BE446
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.D.e.u.t.s.c.h./.G.e.r.m.a.n.....W.e.b.L.a.n.g.=.G.E.R.....T.r.a.n.s.l.a.t.o.r.=.D.i.r.k. .P.a.u.l.s.e.n. . ..% .A.n.d.y. .K.l.e.i.n.e.r.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .A.n.s.i.c.h.t.....1.0.3. .=. .E.i.n.s.t.e.l.l.u.n.g.e.n.....1.0.4. .=. .A.n.w.e.n.d.u.n.g.e.n.\.n. .d.e.i.n.s.t.a.l.l.i.e.r.e.n.& ....1.0.5. .=. .E.x.t.r.a.s.....1.0.6. .=. .J.a.g.d.-.\.n.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.n.a.n.s.i.c.h.t.....1.0.8. .=. .S.y.m.b.o.l.a.n.s.i.c.h.t.....1.0.9. .=. .D.e.t.a.i.l.a.n.s.i.c.h.t.....1.1.0. .=. .A.n.w.e.n.d.u.n.g.\.n. .d.e.i.n.s.t.a.l.l.i.e.r.e.n.....1.1.1. .=. .E.l.e.m.e.n.t. .l...s.c.h.e.n.....1.1.2. .=. .A.k.t.u.a.l.i.s.i.e.r.e.n.....1.1.3. .=. .M...c.h.t.e.n. .S.i.e. .d.a.s. .a.u.s.g.e.w...h.l.t.e. .E.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (758), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A6A6DB6E56550D0B4CF20C1786C7CB63
                                                SHA1:37923A750B12A965BD16AE935A6170975AFE6D28
                                                SHA-256:CB52898DE275EFDECA666D5DC8B6CA70CE272D5903F54CFA675EC4A60A17E59F
                                                SHA-512:F8E684DFC84141FE8FDBE1664CD2CC7E267E5DB4CD2212E1D85B03C599B82B3EEFA72E8637D26FD9033BA5D1E757FCEA7FF608EA0591C0C46C19D21B14637DFC
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .............../.G.u.j.a.r.a.t.i.....W.e.b.L.a.n.g.=.G.U.J.....T.r.a.n.s.l.a.t.o.r.=.K.u.m.a.r.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...........1.0.3. .=. ...................1.0.4. .=. ...........................1.0.5. .=. ...............1.0.6. .=. ............. ...........1.0.7. .=. .............1.0.8. .=. ...................1.0.9. .=. ...............1.1.0. .=. ..................... ...........1.1.1. .=. ............... ....... ...........1.1.2. .=. ............... ...........1.1.3. .=. ....... ....... ........... ......... ........... ................... ....... ......... ........... .....?.....1.1.4. .=. ....... ....... ........... ......... ........... ....................... ..................... ......... .......
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (400), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9D97E4DA88F7417381E9271B2A5FACC0
                                                SHA1:5B7019C9992ABF72147792DA5E264A3DD92DFCFD
                                                SHA-256:6AFA576FEADAF7AABE5FC735155523ED724ABC7871A899FBCA7A3F5AA1CFB8A8
                                                SHA-512:46BAB97CF5B825939A8CD0B8463DA22FF7626E06E0F7602A7D82AED8211608D8C94EBDB62C491A0C0CA7FB29AF025C2E837D7FE012B2FCCAAD8DD371D591643B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.........../.H.e.b.r.e.w.....W.e.b.L.a.n.g.=.H.E.B.....T.r.a.n.s.l.a.t.o.r.=.A.r.i.e.l. .N.e.m.t.z.o.v. ........... ...............C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...............1.0.3. .=. .....................1.0.4. .=. ......... ...................1.0.5. .=. .............1.0.6. .=. ."....... .".............1.0.7. .=. ...............1.0.8. .=. .....................1.0.9. .=. ...............1.1.0. .=. ...........1.1.1. .=. ....... ...........1.1.2. .=. .............1.1.3. .=.?. ....... ...../... ........./... ............... ........... ..... ......... ...............1.1.4. .=.?. ....... ...../... ........./... ............... ........... ..... ............. .................1.1.5. .=........... ...................1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (868), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2750A46C066CE37250BE338D2D4B2C28
                                                SHA1:70A26F9D3E3E418DBC6B16C785B25B6E0EDE57B0
                                                SHA-256:1FBFEE3E9FB3D7E4BAC9AB89C49B25B1D93D65389A1DB3D9276C0B8C1A9C363B
                                                SHA-512:0856E4F4D81F1BF731B56C3A24E6A6D48726B89869012D8A63499D003B55303E9B0287291C11ACF6F2A940229204BB5FA7B694698E87D8997A703D531538CEFF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=................./.G.r.e.e.k.(.H.e.l.l.e.n.i.c.).....W.e.b.L.a.n.g.=.G.R.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...................1.0.3. .=. .....................1.0.4. .=. .................................1.0.5. .=. .....................1.0.6. .=. ..................... .........................1.0.7. .=. .......................1.0.8. .=. .......................1.0.9. .=. .............................1.1.0. .=. ...............................1.1.1. .=. ................. ...........................1.1.2. .=. .....................1.1.3. .=. ........... ............... ....... ............. ..... ..................... ....... ..................... .....................;...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (754), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B60047B3D741996398758836EF7C27B5
                                                SHA1:5C19FD1306234D5AAA6B98172BB8CB2E0B52093D
                                                SHA-256:79575B64A5B2A340D0BB5E9C0499FC47EE704748B182374EB1A916CC448704F3
                                                SHA-512:015E7EA248523D540F0B2993A0178D7D05F5BAA75AD3A4FF35711D30C3F2AFE0B12DB45772FEB99CD5B4DF3C56DE6421B8271CCA3499FEB84990CD25527016F5
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.9.?.(.M.&.@./.H.i.n.d.i.....W.e.b.L.a.n.g.=.H.I.N.....T.r.a.n.s.l.a.t.o.r.=.J...K.i.s.h.o.r.e. .R.e.d.d.y.,. .a.s.h.i.s.h. .s.h.a.r.m.a.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].............1.0.2. .=. .&.G...G.......1.0.3. .=. .5.?...2.M.*.....1.0.4. .=. ...(.....8.M...>.2.0.....1.0.5. .=. ...*...0.#.....1.0.6. .=. .9.....0. ...K.!.....1.0.7. .=. .8.B...@.....1.0.8. .=. .*.M.0.$.@.......1.0.9. .=. .5.?.5.0.#.....1.1.0. .=. .8.M.%.>.*.(.>. .0.&.M.&. ...0.G.......1.1.1. .=. .*.M.0.5.?.7.M...?. ...K. .9...>.(.G.....1.1.2. .=. .$.>...<.>. ...0.G.....1.1.3. .=. ...M./.>. ...*. .../.(.?.$. .*.M.0.5.?.7.M...?. ...K. .9...>.(.>. ...>.9.$.G. .9.H...?.....1.1.4. .=. ...M./.>. ...*. .../.(.?.$. .*.M.0.K...M.0.>... ...@. .8.M.%.>.*.(.>. .0.&.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (596), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:FEB1E88105E492FCBDD1D6DB74E0E1EA
                                                SHA1:99C21C1DF4DE45D8A49E7CBA1566FF683B420208
                                                SHA-256:7FD712396D175D5FC694D78FDBD5149C955944E7B343143B5215EC6305FA0B71
                                                SHA-512:CAFB9B1609CB9C2758EAC3D92055ACF6602FF6641C4487E9C35DFEBC6AE9451A87698F4AF138471956780F620DE04FEDF4C45DE43AE5EBAD4019551A8E7C8C18
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.H.r.v.a.t.s.k.i./.C.r.o.a.t.i.a.n. .....W.e.b.L.a.n.g.=.H.R.....T.r.a.n.s.l.a.t.o.r.=.H.a.s.a.n. .O.s.m.a.n.a.g.i.......C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .I.z.g.l.e.d.....1.0.3. .=. .P.o.s.t.a.v.k.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.e.r.....1.0.5. .=. .A.l.a.t.i.....1.0.6. .=. .P.r.e.s.r.e.t.a.n.j.e.....1.0.7. .=. .P.o.p.i.s.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .D.e.t.a.l.j.i.....1.1.0. .=. .D.e.i.n.s.t.a.l.i.r.a.j.....1.1.1. .=. .U.k.l.o.n.i. .u.n.o.s.....1.1.2. .=. .O.s.v.j.e.~.i.....1.1.3. .=. .U.k.l.o.n.i.t.i. .o.z.n.a...e.n.i. .u.n.o.s.?.....1.1.4. .=. .D.e.i.n.s.t.a.l.i.r.a.t.i. .o.z.n.a...e.n.i. .p.r.o.g.r.a.m.?.....1.1.5. .=. .D.o.g.r.a.d.n.j.a.....1.1.6. .=. .P.o.m.o.......1.1.7. .=. .U.p.u.t.e...........1.1.8. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (671), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:4D5EB6E082CD530F5594D290BBEFDBF9
                                                SHA1:410F8909B513C5890DD64525098DFA72363480FF
                                                SHA-256:B621D425E8ADA922FF2E75C03385A26D412BF0956B6DCEFD8C769EDD4F44A44D
                                                SHA-512:E4A8D85B5CB48C41CBCE1F36BC7D424EFE6B7CD0E19BFB06CAE85709559FA6E68D17215BC8D5A3024ACE18482CBF42317AFA0C67136A4A004064C4AF8A9EC22E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.M.a.g.y.a.r./.H.u.n.g.a.r.i.a.n.....W.e.b.L.a.n.g.=.H.U.N.....T.r.a.n.s.l.a.t.o.r.=.D...b.r...n.t.e.i. .S...n.d.o.r. .-. .s.a.n.d.o.r...d.o.b.r.o.n.t.e.i.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .N...z.e.t.....1.0.3. .=. .B.e...l.l...t...s.o.k.....1.0.4. .=. .E.l.t...v.o.l...t.......1.0.5. .=. .E.s.z.k...z...k.....1.0.6. .=. .K.e.r.e.s.Q. .m...d.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.o.k.....1.0.9. .=. .R...s.z.l.e.t.e.k.....1.1.0. .=. .E.l.t...v.o.l...t...s.....1.1.1. .=. .B.e.j.e.g.y.z...s. .t...r.l...s.e.....1.1.2. .=. .F.r.i.s.s...t...s.....1.1.3. .=. .B.i.z.t.o.s. .b.e.n.n.e.,. .h.o.g.y. .t...r.l.i. .a. .k.i.j.e.l...l.t. .b.e.j.e.g.y.z...s.t.?.....1.1.4. .=. .B.i.z.t.o.s. .b.e.n.n.e.,. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (713), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:07982EC44C81B46E79709AA7C9D6D75D
                                                SHA1:606484E5E506AAC6C15EC740FA2F3A6651D0F912
                                                SHA-256:FA2ED7FB86F4D52206212A861BF306F3F34F0B2849C4C1AEC0F4E68ABC6D3FF1
                                                SHA-512:17CE8CD3E6A235EEFAA75A3D1C96B639FCC5D832E68398AA2E61AEFCA6DC9C63038F8887AA9C475A7AF6EE40DC07557CE0E1DE7174AF43936353E0AEDBDF31A5
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.a.h.a.s.a. .I.n.d.o.n.e.s.i.a./.I.n.d.o.n.e.s.i.a.n.....W.e.b.L.a.n.g.=.I.N.D.....T.r.a.n.s.l.a.t.o.r.=.P.u.r.w.o. .A.d.i. .N.u.g.r.o.h.o.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .L.i.h.a.t.....1.0.3. .=. .P.i.l.i.h.a.n.....1.0.4. .=. .P.e.n.g.h.a.p.u.s.....1.0.5. .=. .P.e.r.a.l.a.t.a.n.....1.0.6. .=. .M.o.d.e. .P.e.m.b.u.r.u.....1.0.7. .=. .D.a.f.t.a.r.....1.0.8. .=. .I.k.o.n.....1.0.9. .=. .R.i.n.c.i.a.n.....1.1.0. .=. .H.a.p.u.s.....1.1.1. .=. .H.a.p.u.s. .C.a.t.a.t.a.n.....1.1.2. .=. .S.e.g.a.r.k.a.n.....1.1.3. .=. .A.p.a.k.a.h. .a.n.d.a. .y.a.k.i.n. .i.n.g.i.n. .m.e.n.g.h.a.p.u.s. .c.a.t.a.t.a.n. .t.e.r.p.i.l.i.h.?.....1.1.4. .=. .A.p.a.k.a.h. .a.n.d.a. .y.a.k.i.n. .i.n.g.i.n. .m.e.n.g.h.a.p.u.s. .p.r.o.g.r.a.m. .t.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (1970), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):115108
                                                Entropy (8bit):3.8127819512466576
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2624EBD91EC84714395D1C1BB989A14B
                                                SHA1:E4A93AE374A2BA4F9BEAE19D937160535EDA7C20
                                                SHA-256:2B26C5DFACA7A8A89B50026F5C659A7CF8793E96EA70948E8799D58C8E0B92E1
                                                SHA-512:452648B7AE74C3BE3D054703BBA19FB22DD4969BF28A0AF87ACFAB7E00539BF827849FE055202A22C02D39D9CA15ADAE440E358CC1556E8E13419A8F7FE8AC8E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.e.r.s.i.a.n./.A.'.1.3.J.....W.e.b.L.a.n.g.=.F.A.R.....T.r.a.n.s.l.a.t.o.r.=.E.G.F./.3. .9.(./.'.D.1.6.'. .4.A.'.J.J.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .....V.e.r.s.i.o.n.=.2...1...7. .........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2.=.F.E.'.J.4.....1.0.3.=.*.F.8.J.E.'.*.....1.0.4.=.-.0.A. ...F.F./.G.....1.0.5.=.'.(.2.'.1.G.'.....1.0.6.=.-.'.D.*.\.n. .4...'.1...J.....1.0.7.=.A.G.1.3.*.....1.0.8.=.4.E.'.J.D.....1.0.9.=.,.2.&.J.'.*.....1.1.0.=.9.@.2. .D. .(.1.F.'.E.G.....1.1.1.=.-.0.A. .H.1.H./.J. .....1.1.2.=.*.'.2.G. .3.'.2.J.....1.1.3.=.".J.'. .E.7.E.&.F. .(.G. .-.0.A. .H.1.H./.J. .'.F.*...'.(. .4./.G. .G.3.*.J./. .......1.1.4.=.".J.'. .E.7.E.&.F. .(.G. ...1.H.,. .(.1.F.'.E.G. .(.1...2.J./.G. .'.2. .F.5.(. .G.3.*.J./. .......1.1.5.=.(.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (638), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):80710
                                                Entropy (8bit):4.170219497444309
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C2E52ABF76949AC22C6A1065B6B31C26
                                                SHA1:6379C1CEA97C9B7C2A3FC7109BD737A5636E75F4
                                                SHA-256:1DA3E26753481F5B8C46D4FAE24DE4C64272B94E5F8EFBA57D023D95D45AF71C
                                                SHA-512:9E7268F2BE2AF7E6337B0B3A46F337F22E539249BE20A8C98447122491C0854C195D658C17C7FDF7937B5DD06C3B29FCE1021FF0D9056730811E3362AC63B6A2
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.@.a.u.e...e.v./.A.r.m.e.n.i.a.n.....W.e.b.L.a.n.g.=.a.r.m.....T.r.a.n.s.l.a.t.o.r.=.H.r.a.n.t. .O.h.a.n.y.a.n. ....... .h...o.h.a.n.y.a.n.@.h.a.y.s.o.f.t...o.r.g.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .O.e.}.......1.0.3. .=. .?.a...c.a.~.x...x...t.v.e.......1.0.4. .=. .1.z.a...e.r.a.d...k.y.....1.0.5. .=. .3.x...n.k...v.e.......1.0.6. .=. .H.P.M.....1.0.7. .=. .Q.a.v.o.x.~.....1.0.8. .=. .J.a...o.e...a.o.v.e.......1.0.9. .=. .D.a.v...a.t.a.}.v.....1.1.0. .=. .1.z.a...e.r.a.d...e.l.....1.1.1. .=. .K.v.{.e.l. ...a.u.l.h.....1.1.2. .=. .9.a...t.a...v.e.l.....1.1.3. .=. .K.v.{.e.^.l. .h.v.....~.a.n. .n...a.c...e...h.:.....1.1.4. .=. .K.v.{.e.^.l. .h.v.....~.a.n. .n...a.c.k...h.:.....1.1.5. .=. .;.v...v.a.i.a...t.a...x...t.....1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (722), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):99070
                                                Entropy (8bit):4.06159631923588
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7B07AB2945C9171164A749833BEEEA7B
                                                SHA1:8EB3A4EBDDE4ADBA3CACA09B9C6E121E7B38FB26
                                                SHA-256:D79151B253E89F789C5BFDC5BABFDC167F6CAB830216F7D833106D27F14FDD24
                                                SHA-512:4C5E5BBFFB7D8F6926BC46D6F2D3BEFBED14A6CCFCC0F79F1193A26290B64014295047F21A1CF7450276A41919D52465C9E09441765FB8CA5F282499A77EE0AF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T.i...n.g. .V.i...t./.V.i.e.t.n.a.m.e.s.e.....W.e.b.L.a.n.g.=.V.N.....T.r.a.n.s.l.a.t.o.r.=.P.h.a.#.m. .T.u.....n. .K.h.a.n.h. .-. .p.t.k.9.1.1.@.y.a.h.o.o...c.o.m...v.n.,. .l.e.a.n.h.0.3.@.y.a.h.o.o...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .H.i...n. .t.h.......1.0.3. .=. .C...i. .....t.....1.0.4. .=. .G... .b.......1.0.5. .=. .C...n.g. .c.......1.0.6. .=. .S...n. .t...m.....1.0.7. .=. .D.a.n.h. .s...c.h.....1.0.8. .=. .B.i...u. .t.....n.g.....1.0.9. .=. .C.h.i. .t.i...t.....1.1.0. .=. .G... .b.......1.1.1. .=. .X.o...a. .t.r.o.n.g. .r.e.g.i.s.t.r.y.....1.1.2. .=. .L...m. .m...i.....1.1.3. .=. .C... .p.h...i. .b...n. .m.u...n. .x.o...a. .r.e.g.i.s.t.r.y. .m.u.#.c. ..... .c.h...n. .?.....1.1.4. .=. .C... .p.h...i. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (774), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):103356
                                                Entropy (8bit):3.495641951335086
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9D4D0F41350759F705360E889C0EF5E1
                                                SHA1:8A1878835F20A525301556D09E2847942EC960EA
                                                SHA-256:0BA87F5E19BB9DCD8DB42D1051AB232D985EE0713492D59D37ABAF1FF1D9FA72
                                                SHA-512:546DD34D57DAB9D3784A8F17AFE2CBCE1022E07B295BAE4CA663C4E53BD2161B5DA8C5CE84B2A3CFD354C9E1DB7E717BA525F54A13D1753EAE7258DAEC9BBE78
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .S.v.e.n.s.k.a./.S.w.e.d.i.s.h.....W.e.b.L.a.n.g.=.S.W.E.....T.r.a.n.s.l.a.t.o.r.=.S.t.e.f.a.n. .L.j.u.n.g.w.a.l.l. .-. .l.j.u.n.g.w.a.l.l.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.a.....1.0.3. .=. .A.l.t.e.r.n.a.t.i.v.....1.0.4. .=. .A.v.i.n.s.t.a.l.l.e.r.a.r.e.....1.0.5. .=. .V.e.r.k.t.y.g.....1.0.6. .=. .J.a.k.t.l...g.e.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.v.i.n.s.t.a.l.l.e.r.a.....1.1.1. .=. .T.a. .b.o.r.t. .p.o.s.t.....1.1.2. .=. .U.p.p.d.a.t.e.r.a. .p.r.o.g.r.a.m.l.i.s.t.a.n.....1.1.3. .=. .V.i.l.l. .d.u. .v.e.r.k.l.i.g.e.n. .t.a. .b.o.r.t. .m.a.r.k.e.r.a.d. .p.o.s.t.?.....1.1.4. .=. .V.i.l.l. .d.u. .v.e.r.k.l.i.g.e.n. .t.a.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (446), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):97578
                                                Entropy (8bit):3.5384800776793965
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:0370A43B65F652B883EF7FB20BFBB017
                                                SHA1:BA904238476AEF10DB916E1F478FED478E24B2EA
                                                SHA-256:EADC85C8748F3B86297B0F69A04964F5C72A2AF6A39CE3AE62224572750E7C0F
                                                SHA-512:9C9A44FCE1817C4F5D4984E2B3C5AFE5A893B46D87EFC1E100B90DD5E592A9E0D8D6D5F2F2B57B75B97B0D251C6EAB05DB0AD4DD6FE4EC0494AB7D64DEC4CBAA
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.r.p.s.k.i./.S.e.r.b.i.a.n. .....W.e.b.L.a.n.g.=.S.R.B.L.T.....T.r.a.n.s.l.a.t.o.r.=.D.r.a.g.a.n. .B.j.e.d.o.v. .d.r.a.g.a.n.b.j.e.d.o.v.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...0...6.............[.D.e.i.n.s.t.a.l.e.r. .L.i.n.i.j.a. .s.a. .a.l.a.t.k.a.m.a.].....1.0.2. .=. .I.z.g.l.e.d.....1.0.3. .=. .P.o.s.t.a.v.k.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.e.r.....1.0.5. .=. .A.l.a.t.i.....1.0.6. .=. .P.r.e.s.r.e.t.a.n.j.e.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .D.e.t.a.l.j.i.....1.1.0. .=. .D.e.i.n.s.t.a.l.i.r.a.j.....1.1.1. .=. .U.k.l.o.n.i. .u.n.o.s.....1.1.2. .=. .O.s.v.e.~.i.....1.1.3. .=. .U.k.l.o.n.i.t.i. .o.z.n.a...e.n.i. .u.n.o.s.?.....1.1.4. .=. .D.e.i.n.s.t.a.l.i.r.a.t.i. .o.z.n.a...e.n.i. .p.r.o.g.r.a.m.?.....1.1.5. .=. .D.o.g.r.a.d.n.j.a.....1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (400), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):62180
                                                Entropy (8bit):5.362167916248713
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F94E17A85FB506876093C080337ABBD8
                                                SHA1:AEF30BB2D35C29751F169DC4CD69543A1158B78D
                                                SHA-256:A45749730A58A5A8911A98738C7FBD21DA0609A16E8E9FC3F8018BBD19B83C9A
                                                SHA-512:F55B53D24B3AC16BB2A544CF0E7898D8DC85E206101FB0DE738B4D81ADE38E476F4F30DFDEB67589B5E54732C737E314E05B83C0F8A491454E0FFEFD067694DE
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.\.m... ./. .K.o.r.e.a.n.....W.e.b.L.a.n.g.=.K.O.R.....T.r.a.n.s.l.a.t.o.r.=.J.a.e.H.y.u.n.g. .L.e.e. ./. .k.o.l.a.n.p.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...0.....1.0.3. .=. .5.X.....1.0.4. .=. ...p.0.....1.0.5. .=. ..l.....1.0.6. .=. ...0.......1.0.7. .=. .........1.0.8. .=. .D.t.X.....1.0.9. .=. ...8.......1.1.0. .=. ...\..... ...p.....1.1.1. .=. . ... .m.. ...p.....1.1.2. .=. .... ........1.1.3. .=. ....\. . ...\. .m..D. ...p.X.......L.?.....1.1.4. .=. ....\. . ...\. ...\.....D. ...p.X.......L.?.....1.1.5. .=. ...p.t......1.1.6. .=. .........1.1.7. .=. .... ..l. ...............1.1.8. .=. .H..t.............1.1.9. .=. .... ...............1.2.0. .=. ...X.. ......... .D...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (782), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):109348
                                                Entropy (8bit):3.4462174219205997
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:484AAB4E4A291B4C2F2D1718B3754D2B
                                                SHA1:13620CD1D36FC3B90EC7A9E48BE589B605407A1D
                                                SHA-256:7A47C9E44EF1E4CE0D5FC678DDF505D8213995E55599D7F4779E10462C002880
                                                SHA-512:EA294672C96892C1F5C36CFB16EA23352CBAC61F082F71904074A0BE9A5A8237685BE7F7FAFFA5EA652CC2403C1011340D3399E676A78D0350EFBD744C4292BD
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .N.e.d.e.r.l.a.n.d.s./.D.u.t.c.h.....W.e.b.L.a.n.g.=.N.L.....T.r.a.n.s.l.a.t.o.r.=.J.a.n. .V.e.r.h.e.i.j.e.n.,. .P.i.e.r.r.e. .M.e.l.s.e.r.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .B.e.e.l.d.....1.0.3. .=. .O.p.t.i.e.s.....1.0.4. .=. .D.e.-.i.n.s.t.a.l.l.a.t.i.e.....1.0.5. .=. .H.u.l.p.p.r.o.g.r.a.m.m.a.'.s.....1.0.6. .=. .J.a.c.h.t.m.o.d.u.s.....1.0.7. .=. .L.i.j.s.t.....1.0.8. .=. .P.i.c.t.o.g.r.a.m.m.e.n.....1.0.9. .=. .D.e.t.a.i.l.s.....1.1.0. .=. .D.e.-.i.n.s.t.a.l.l.e.r.e.n.....1.1.1. .=. .I.t.e.m. .v.e.r.w.i.j.d.e.r.e.n.....1.1.2. .=. .V.e.r.n.i.e.u.w.e.n.....1.1.3. .=. .W.e.e.t. .u. .z.e.k.e.r. .d.a.t. .u. .d.i.t. .w.i.l.t. .v.e.r.w.i.j.d.e.r.e.n.?.....1.1.4. .=. .W.e.e.t. .u. .z.e.k.e.r. .d.a.t. .u. .h.e.t. .g.e.s.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (675), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):109284
                                                Entropy (8bit):3.513818824865796
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F66C35E147B4BA36B84828F558724FC7
                                                SHA1:BF143C467AE0E394978F5F48CF13067D6ABF5A35
                                                SHA-256:7AC22AE651ED90C1ADFA83945322734D51807814598709ACC0F91804087DA511
                                                SHA-512:AB4CB440E44040CFCA2698740D67B5EA159EB6172DB7CF9B55E577A856C6510459E687D48BFE6BBFFEC1834522654756BB1A87A363294330D0E6C76583AFE456
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n.a...i.n.a./.S.l.o.v.e.n.i.a.n.....W.e.b.L.a.n.g.=.S.I.....T.r.a.n.s.l.a.t.o.r.=.V.i.n.k.o. .K.a.s.t.e.l.i.c.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .P.o.g.l.e.d.....1.0.3. .=. .N.a.s.t.a.v.i.t.v.e.....1.0.4. .=. .O.d.s.t.r.a.n.j.e.v.a.l.n.i.k.....1.0.5. .=. .O.r.o.d.j.a.....1.0.6. .=. .L.o.v.e.c. .....1.0.7. .=. .S.e.z.n.a.m.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .P.o.d.r.o.b.n.o.s.t.i.....1.1.0. .=. .O.d.s.t.r.a.n.i. .\.n.p.r.o.g.r.a.m.....1.1.1. .=. .O.d.s.t.r.a.n.i. .v.n.o.s.....1.1.2. .=. .O.s.v.e.~.i.....1.1.3. .=. .S.t.e. .p.r.e.p.r.i...a.n.i.,. .d.a. .~.e.l.i.t.e. .o.d.s.t.r.a.n.i.t.i. .i.z.b.r.a.n.i. .v.n.o.s.?.....1.1.4. .=. .S.t.e. .p.r.e.p.r.i...a.n.i.,. .d.a. .~.e.l.i.t.e. .o.d.s.t.r.a.n.i.t.i. .i.z.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (787), with CRLF, CR line terminators
                                                Category:dropped
                                                Size (bytes):119576
                                                Entropy (8bit):3.395393124513932
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B1130B82AF1277725D411840C0173265
                                                SHA1:05760EBC0248D176BE83E99744B498C290955F51
                                                SHA-256:6B5A5D57E054CC867DDC276CEA4861FE43656269C18C8FBAEA739C16944E5B47
                                                SHA-512:2553FAE3BF7611FE0C3A73BA4F4E0156D76CFD005490BBE6D057D01949B44143E5EF8081F0E4C6A181E1263C1D5FDCE45131D0987F38A5834703015C3FE75745
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.........................................................................[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.t.a.l.i.a.n.o./.I.t.a.l.i.a.n.....W.e.b.L.a.n.g.=.I.T.A.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.s.s.a.n.d.r.o. .V.i.s.e.n.t.i.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.................................................................................[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.d.i.....1.0.3. .=. .O.p.z.i.o.n.i.....1.0.4. .=. .D.i.s.i.n.s.t.a.l.l.a.t.o.r.e.....1.0.5. .=. .S.t.r.u.m.e.n.t.i.....1.0.6. .=. .M.o.d.o. .M.i.r.i.n.o.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.c.o.n.e.....1.0.9. .=. .D.e.t.t.a.g.l.i.....1.1.0. .=. .D.i.s.i.n.s.t.a.l.l.a.....1.1.1. .=. .R.i.m.u.o.v.i. .v.o.c.e.....1.1.2. .=. .A.g.g.i.o.r.n.a.....1.1.3. .=. .S.i.c.u.r.i. .d.i. .v.o.l.e.r. .r.i.m.u.o.v.e.r.e. .l.a. .v.o.c.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (739), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):121300
                                                Entropy (8bit):4.089798966794834
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:966C8ECA86F43A502D9836709ED34D6E
                                                SHA1:014FA738E95E543E7A6DB68EE4F5F21F9A4CE823
                                                SHA-256:25205DBA08243AEEB6516221847738D47F3C72C295F7D973E09433E2635C943D
                                                SHA-512:F85DE756FC15458AF86955B555A8EC3E0E29A2EBEF2917AF200A172279362B7A40D874D6F5025A2BFC7B7539B2818053BCF7CA3B077E64EC786289604F0F8113
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=........... ./.B.e.n.g.a.l.i.....W.e.b.L.a.n.g.=.B.N.....T.r.a.n.s.l.a.t.o.r.=.G.o.u.t.a.m. .R.o.y.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...............1.0.3. .=. .........................1.0.4. .=. .........................1.0.5. .=. .............1.0.6. .=. ............. ...........1.0.7. .=. .................1.0.8. .=. .....................1.0.9. .=. .......................1.1.0. .=. .....................1.1.1. .=. ............... ....... .............1.1.2. .=. .............1.1.3. .=. ......... ..... ............... ..... ......... ................... ............... ........... .......?.....1.1.4. .=. ......... ..... ............... ..... ......... ................... ................... ................. ...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (742), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):112572
                                                Entropy (8bit):3.5880669944510046
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9F0EC5C7DC7D8E14DD0ED2E590E8326A
                                                SHA1:D9D55B5FEC39CAB7D8373DDAD7EB33BD305EE94A
                                                SHA-256:0BB8B7EB790CBB31605A11EE23B9B4F03ED60E076FABE5A9D82D1B915A3B1B27
                                                SHA-512:D04C74AAA239C4B7E9A022EF34246EB1FCC42B819DD9DAABEA57FACD5DD9B008137E340311EB11E7497F81D1B57E753E0865B6D7130DBEE18A9D44290D3F215D
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.o.m...n... ./. .R.o.m.a.n.i.a.n.....W.e.b.L.a.n.g.=.R.O.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.x.a.n.d.r.u. .B.o.g.d.a.n. .M.u.n.t.e.a.n.u.,. .M.a.r.i.n.e.l. .C.i.p.u.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.d.e.r.e.....1.0.3. .=. .O.p...i.u.n.i.....1.0.4. .=. .D.e.z.i.n.s.t.a.l.a.t.o.r.....1.0.5. .=. .U.n.e.l.t.e.....1.0.6. .=. .V...n...t.o.r.....1.0.7. .=. .L.i.s.t.......1.0.8. .=. .I.c.o.a.n.e.....1.0.9. .=. .D.e.t.a.l.i.i.....1.1.0. .=. .D.e.z.i.n.s.t.a.l.e.a.z.......1.1.1. .=. ...n.l...t.u.r.......1.1.2. .=. ...m.p.r.o.s.p...t.e.a.z.......1.1.3. .=. .S.i.g.u.r. .v.r.e.i. .s... ...n.l...t.u.r.i. .i.n.t.r.a.r.e.a. .s.e.l.e.c.t.a.t...?.....1.1.4. .=. .S.i.g.u.r. .v.r.e.i. .s... .d.e.z.i.n.s.t.a.l.e.z.i. .p.r.o.g.r.a.m.u.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (579), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):106176
                                                Entropy (8bit):4.267992926870908
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7262C82A010789707FCDDAD58EEA61BB
                                                SHA1:054873004D9CD2BD4F60117F8C74F5AA73A94FBA
                                                SHA-256:7F4519B478F322286096DC796529DF25BAB8AABCEB64218908F78DC7507C9A29
                                                SHA-512:FA0F1D78DA928252E7A744469994FF72660E79C3DABE975E725EF654608AD6ED6236A660BC44E5FAABF12F9C1DCAEA2DACDDDAD8166B49BD2171A324627AD5C9
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .2.).2.D..."./.T.h.a.i.....W.e.b.L.a.n.g. .=. .T.H.A.I.....T.r.a.n.s.l.a.t.o.r. .=. .P.o.r.n.c.h.a.i. .P.e.t.t.h.a.v.e.e.p.o.r.n.d.e.j.....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...9.....1.0.3. .=. ...1.'.@.%.7.-.......1.0.4. .=. .B...#.A...#.!...-.....2.#...4.....1.I.......1.0.5. .=. .@...#.7.H.-...!.7.-.....1.0.6. .=. .B.+.!.....1...@...-.#.L.....1.0.7. .=. .#.2."...2.#.....1.0.8. .=. .D.-...-.......1.0.9. .=. .#.2.".%.0.@.-.5.".......1.1.0. .=. ...-.....2.#...4.....1.I.......1.1.1. .=. .%...#.2."...2.#.....1.1.2. .=. .#.5.@...#.......1.1.3. .=. ...8...A...H.C...+.#.7.-.D.!.H.'.H.2...8.....I.-.....2.#.%...#.2."...2.#...5.H.@.%.7.-...?.....1.1.4. .=. ...8...A...H.C...+.#.7.-.D.!.H.'.H.2...I.-.....2.#...-.....2.#...4.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (707), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):114970
                                                Entropy (8bit):3.4538317278524966
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A7E3ACA49F123CA55F3C16D3471B097F
                                                SHA1:CFF36DAFC9DA080C47ABE80D26F63F04B426526B
                                                SHA-256:8AE5848453F428219588D16614FDC145E4E5B2ED9A436524FBB38BFC642F1CD3
                                                SHA-512:3C9DEDE08D83A30F9E03EE903CDE94C3F136B67FC0052B99DCA14C791D7FEBA8F47DDD1F2764C72A1B8084B78B3AF993CC28C2A9396EDD30203A40CB6B292622
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.A.r.q.u.i.v.o. .d.e. .i.d.i.o.m.a. .d.o. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.E.s.t.a. .s.e.....o. .d.e.v.e. .u.s.a.r. .P.o.r.t.u.g.u...s. .B.r.a.s.i.l.e.i.r.o.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .B.r.a.s.i.l.e.i.r.o.....W.e.b.L.a.n.g.=.P.T.-.B.R.....T.r.a.n.s.l.a.t.o.r.=.M.a.r.c.u.s. .V.i.n...c.i.u.s. .R.o.c.h.a. .d.a. .S.i.l.v.a.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .E.x.i.b.i.r.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .d.e. .C.a...a.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r.....1.1.1. .=. .R.e.m.o.v.e.r. .e.n.t.r.a.d.a.....1.1.2. .=. .A.t.u.a.l.i.z.a.r.....1.1.3. .=. .T.e.m. .c.e.r.t.e.z.a. .q.u.e. .d.e.s.e.j.a. .r.e.m.o.v.e.r. .a. .e.n.t.r.a.d.a. .s.e.l.e.c.i.o.n.a.d.a.?.....1.1.4. .=. .T.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (758), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):119300
                                                Entropy (8bit):4.066484266219622
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A6A6DB6E56550D0B4CF20C1786C7CB63
                                                SHA1:37923A750B12A965BD16AE935A6170975AFE6D28
                                                SHA-256:CB52898DE275EFDECA666D5DC8B6CA70CE272D5903F54CFA675EC4A60A17E59F
                                                SHA-512:F8E684DFC84141FE8FDBE1664CD2CC7E267E5DB4CD2212E1D85B03C599B82B3EEFA72E8637D26FD9033BA5D1E757FCEA7FF608EA0591C0C46C19D21B14637DFC
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .............../.G.u.j.a.r.a.t.i.....W.e.b.L.a.n.g.=.G.U.J.....T.r.a.n.s.l.a.t.o.r.=.K.u.m.a.r.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...........1.0.3. .=. ...................1.0.4. .=. ...........................1.0.5. .=. ...............1.0.6. .=. ............. ...........1.0.7. .=. .............1.0.8. .=. ...................1.0.9. .=. ...............1.1.0. .=. ..................... ...........1.1.1. .=. ............... ....... ...........1.1.2. .=. ............... ...........1.1.3. .=. ....... ....... ........... ......... ........... ................... ....... ......... ........... .....?.....1.1.4. .=. ....... ....... ........... ......... ........... ....................... ..................... ......... .......
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (602), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):101916
                                                Entropy (8bit):3.4732487506853236
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:FB4844267D83DE0565C5AB8D8475605F
                                                SHA1:CFA437A8AC17216CB9E965F7305363F459E69572
                                                SHA-256:1899006AAB38B129BAC93E3935BEF214ACCC31D7FBE08FEE733E7A89EEEF9E08
                                                SHA-512:A6655508CBC8ECACD6DA3D0D4741F3C7B20294CCAD932F761D1CEE16477970C937034804E9D5360D164C7CD999D66CA5CF88A04431985F38DA85600794D8154C
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.e.s.t.i./.E.s.t.o.n.i.a.n.....W.e.b.L.a.n.g.=.E.S.T.....T.r.a.n.s.l.a.t.o.r.=.t.u.d.i.l.u.d.i. .-. .t.u.d.i.l.u.d.i...e.s.t.o.n.i.a.@.m.a.i.l...e.e.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.a.a.d.e.....1.0.3. .=. .S.u.v.a.n.d.i.d.....1.0.4. .=. .E.e.m.a.l.d.a.j.a.....1.0.5. .=. .T.....r.i.i.s.t.a.d.....1.0.6. .=. .J...l.i.t.a.j.a. .r.e.~.i.i.m.....1.0.7. .=. .N.i.m.e.k.i.r.i.....1.0.8. .=. .I.k.o.o.n.i.d.....1.0.9. .=. .D.e.t.a.i.l.i.d.....1.1.0. .=. .E.e.m.a.l.d.a.....1.1.1. .=. .K.u.s.t.u.t.a. .s.i.s.s.e.k.a.n.n.e.....1.1.2. .=. .V...r.s.k.e.n.d.a.....1.1.3. .=. .O.l.e.d. .k.i.n.d.e.l.,. .e.t. .s.o.o.v.i.d. .v.a.l.i.t.u.d. .s.i.s.s.e.k.a.n.d.e. .k.u.s.t.u.t.a.d.a.?.....1.1.4. .=. .O.l.e.d. .k.i.n.d.e.l.,. .e.t. .s.o.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (705), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):113206
                                                Entropy (8bit):3.884206514083131
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:29C6FA77CAFF22CEBEF89FE7CBB7E564
                                                SHA1:02521C2CF3C8D1C6CB88FB256EBD6EA26000F8D2
                                                SHA-256:8AD919E2DF77256C9DE97E5AB3BCB62669517360051E1F8C3444D2BDCDC9E824
                                                SHA-512:C3773E31FBE79BB2B5A1D6F74AA6B20087243C1884C4C2FDBEC88AE986EC04CADEC1341BA1532895DBE3D88100B6385498E722FC4AF2902CC898166A0559739E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. ...J.;.3.0.@.A.:.8./.B.u.l.g.a.r.i.a.n. .....W.e.b.L.a.n.g.=.B.G.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...0.A.B.@.>.9.:.8.....1.0.4. .=. ...5.8.=.A.B.0.;.0.B.>.@.....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.8.....1.0.6. .=. ...8.H.5.=.0.....1.0.7. .=. .!.?.8.A.J.:.....1.0.8. .=. ...:.>.=.8.....1.0.9. .=. ...5.B.0.9.;.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.9.....1.1.1. .=. ...@.5.<.0.E.=.8.....1.1.2. .=. ...?.@.5.A.=.8.....1.1.3. .=. .!.8.3.C.@.=.8. .;.8. .A.B.5.,.G.5. .8.A.:.0.B.5. .4.0. .8.7.B.@.8.5.B.5. .8.7.1.@.0.=.8.O. .5.;.5.<.5.=.B.?.....1.1.4. .=. .!.8.3.C.@.=.8. .;.8. .A.B.5.,.G.5. .8.A.:.0.B.5. .4.0. .4.5.8.=.A.B.0.;.8.@.0.B.5. .8.7.1.@.0.=.0.B.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (436), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):96738
                                                Entropy (8bit):3.9507954837296273
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:604CE883FD5E8100F69303F172790F5D
                                                SHA1:6DC166AD68251174A39F22BC955B63A7D9326338
                                                SHA-256:663FEF249682C9DE0819F193EF2B6E2625E2054F093EBA37EF852181CFB61AE0
                                                SHA-512:065D233F4407DCBA1319A515FE05FD6D2C2A1F66C25E1B0F15A7606E833C14CFA41701474C258EE74638E8291D41C2204BAFFF3B8FB107F53E9E2CF5C5E9D334
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.!.@.?.A.:.8./.S.e.r.b.i.a.n. .....W.e.b.L.a.n.g.=.S.R.B.L.T.....T.r.a.n.s.l.a.t.o.r.=.D.r.a.g.a.n. .B.j.e.d.o.v. .d.r.a.g.a.n.b.j.e.d.o.v.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...0...6.............[.D.e.i.n.s.t.a.l.e.r. .L.i.n.i.j.a. .s.a. .a.l.a.t.k.a.m.a.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...>.A.B.0.2.:.5.....1.0.4. .=. ...5.8.=.A.B.0.;.5.@.....1.0.5. .=. ...;.0.B.8.....1.0.6. .=. ...@.5.A.@.5.B.0.Z.5.....1.0.7. .=. ...8.A.B.0.....1.0.8. .=. ...:.>.=.5.....1.0.9. .=. ...5.B.0.Y.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.X.....1.1.1. .=. .#.:.;.>.=.8. .C.=.>.A.....1.1.2. .=. ...A.2.5.6.8.....1.1.3. .=. .#.:.;.>.=.8.B.8. .>.7.=.0.G.5.=.8. .C.=.>.A.?.....1.1.4. .=. ...5.8.=.A.B.0.;.8.@.0.B.8. .>.7.=.0.G.5.=.8. .?.@.>.3.@.0.<.?.....1.1.5. .=. ...>.3.@.0.4.Z.0.....1.1.6. .=.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (768), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):116224
                                                Entropy (8bit):3.4504653272979695
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2BE6DFDA140D556C60980C83958DA5C2
                                                SHA1:139CCE83C93AB264A67F0F53D3BA27AD52C9F370
                                                SHA-256:202DACEEFB06DAFC459FAD9E194643AEEA9D8FB441F898326FC26F27B73FE535
                                                SHA-512:155E4D47089E69C9BB13DA754AAE3AFCD3204C1A241263F8947BEB378F8EA930D7FDEA20E3462B816D1587E98EC6588E417E72A0B5D504F047EF2DB22974387D
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h. .....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .P.o.r.t.u.g.u...s./.P.o.r.t.u.g.u.e.s.e.....W.e.b.L.a.n.g.=.P.T.G.S.T.D.....T.r.a.n.s.l.a.t.o.r.=.L.u.i.s. .N.e.v.e.s. .-. .l.u.i.s...a...n.e.v.e.s.@.s.a.p.o...p.t. ./. .M.a.n.u.e.l.a. .S.i.l.v.a.-.A.l.f.r.e.d.o. .S.i.l.v.a. .(.T.r.a.n.s.l.a.t.i.o.n./.P.r.o.o.f.-.r.e.a.d.e.r.). .-. .2.0.1.5.1.1.1.7.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.u.a.l.i.z.a.....o.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .d.e. .P.e.s.q.u.i.s.a. .....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r. .....1.1.1. .=. .R.e.m.o.v.e.r. .E.n.t.r.a.d.a. .....1.1.2. .=. .A.t.u.a.l.i.z.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (435), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):93310
                                                Entropy (8bit):3.4783245158039575
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3E633737F96D30604CAC348F7C0CA5D3
                                                SHA1:BEFC528C9476A3CABA53128F3EEF58E511F0EF6D
                                                SHA-256:C4DBDE88DFFDA3E9EB139D91E2FF49E736D76D52B46331D10DDE4147911D0428
                                                SHA-512:1667A7CF77FA92E334AE886F8C07E02494C67C38441A73BCA233093EDC91AE66B3D63B3699DD1CC3BE3534F5C0844113838BDE8D969A80A9CB416225C9201ABF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .N.o.r.s.k./.N.o.r.w.e.g.i.a.n.....W.e.b.L.a.n.g.=.N.O.R.....T.r.a.n.s.l.a.t.o.r.=.P.a.a.l. .R.o.n.n.i.n.g.e.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.....1.0.3. .=. .A.l.t.e.r.n.a.t.i.v.....1.0.4. .=. .A.v.i.n.s.t.a.l.l.e.r.e.r.....1.0.5. .=. .V.e.r.k.t...y.....1.0.6. .=. .J.a.k.t.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.v.i.n.s.t.a.l.l.e.r.e.....1.1.1. .=. .T.a. .b.o.r.t. .p.o.s.t.....1.1.2. .=. .O.p.p.d.a.t.e.r.e. .p.r.o.g.r.a.m.l.i.s.t.e.n.....1.1.3. .=. .V.i.l. .d.u. .v.i.r.k.e.l.i.g. .t.a. .b.o.r.t. .V.a.l.g.t. .p.o.s.t.?.....1.1.4. .=. .V.i.l. .d.u. .v.i.r.k.e.l.i.g. .t.a. .b.o.r.t. .V.a.l.g.t. .p.r.o.g.r.a.m.?.....1.1.5. .=. .O.p.p.d.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (653), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):119522
                                                Entropy (8bit):3.447712280671588
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:267BCE0C687901EF0C9B94853164FF22
                                                SHA1:5B7AE98C1E4E0DF851D1CF1D81DE3CA7E2BA96D8
                                                SHA-256:F7B544068FCFE69F5A718A9EE0B790620F85477AFBF0C5DB5215A318C67E3B7F
                                                SHA-512:252F8A49D767E8ECAB0610EEF60B762383F1B4E16ED15614AAF5C92446AEEF74705A4391DD5AB41FA6844A2D25A719DA733D404DB6AF8CBC3504575BF7446767
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .F.r.a.n...a.i.s./.F.r.e.n.c.h.....W.e.b.L.a.n.g.=.F.R.A.....T.r.a.n.s.l.a.t.o.r.=.N.i.g.h.t.l.i.g.h.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.u.e.....1.0.3. .=. .O.p.t.i.o.n.s.....1.0.4. .=. .D...s.i.n.s.t.a.l.l.e.u.r.....1.0.5. .=. .O.u.t.i.l.s.....1.0.6. .=. .M.o.d.e. .C.h.a.s.s.e.u.r.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.c...n.e.s.....1.0.9. .=. .D...t.a.i.l.l...e. .....1.1.0. .=. .D...s.i.n.s.t.a.l.l.e.r.....1.1.1. .=. .S.u.p.p.r.i.m.e.r. .l.'.e.n.t.r...e.....1.1.2. .=. .R.a.f.r.a...c.h.i.r.....1.1.3. .=. .E.t.e.s.-.v.o.u.s. .s...r. .d.e. .v.o.u.l.o.i.r. .s.u.p.p.r.i.m.e.r. .l.'.e.n.t.r...e. .s...l.e.c.t.i.o.n.n...e. .?.....1.1.4. .=. .E.t.e.s.-.v.o.u.s. .s...r. .d.e. .v.o.u.l.o.i.r. .d...s.i.n.s.t.a.l.l.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (754), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):108488
                                                Entropy (8bit):4.090983212305029
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B60047B3D741996398758836EF7C27B5
                                                SHA1:5C19FD1306234D5AAA6B98172BB8CB2E0B52093D
                                                SHA-256:79575B64A5B2A340D0BB5E9C0499FC47EE704748B182374EB1A916CC448704F3
                                                SHA-512:015E7EA248523D540F0B2993A0178D7D05F5BAA75AD3A4FF35711D30C3F2AFE0B12DB45772FEB99CD5B4DF3C56DE6421B8271CCA3499FEB84990CD25527016F5
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .P.r.o.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.9.?.(.M.&.@./.H.i.n.d.i.....W.e.b.L.a.n.g.=.H.I.N.....T.r.a.n.s.l.a.t.o.r.=.J...K.i.s.h.o.r.e. .R.e.d.d.y.,. .a.s.h.i.s.h. .s.h.a.r.m.a.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].............1.0.2. .=. .&.G...G.......1.0.3. .=. .5.?...2.M.*.....1.0.4. .=. ...(.....8.M...>.2.0.....1.0.5. .=. ...*...0.#.....1.0.6. .=. .9.....0. ...K.!.....1.0.7. .=. .8.B...@.....1.0.8. .=. .*.M.0.$.@.......1.0.9. .=. .5.?.5.0.#.....1.1.0. .=. .8.M.%.>.*.(.>. .0.&.M.&. ...0.G.......1.1.1. .=. .*.M.0.5.?.7.M...?. ...K. .9...>.(.G.....1.1.2. .=. .$.>...<.>. ...0.G.....1.1.3. .=. ...M./.>. ...*. .../.(.?.$. .*.M.0.5.?.7.M...?. ...K. .9...>.(.>. ...>.9.$.G. .9.H...?.....1.1.4. .=. ...M./.>. ...*. .../.(.?.$. .*.M.0.K...M.0.>... ...@. .8.M.%.>.*.(.>. .0.&.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (480), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):89354
                                                Entropy (8bit):3.9443468698274993
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:0D49FD507C10E50977B85B4E16E5642A
                                                SHA1:687EE839A15C758B0505A05D7EF7798D7C926EDB
                                                SHA-256:3D97D5206A5997FE80886E6B9782C8A9C0E3BAC5EB1CCB6B68A882E43832B12E
                                                SHA-512:366CE1933EB0946E151BD90DABE9C875AB9191A07E06936899B821F1F2CE29E6628B3F5F960A47ED74E7BDC47C45842C304F849D8CE73A42AF4E7F2E95DCEA31
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...0.:.5.4.>.=.A.:.8./.M.a.c.e.d.o.n.i.a.n.....W.e.b.L.a.n.g.=.M.K.D.....T.r.a.n.s.l.a.t.o.r.=.0.1. .V.l.a.t.c.e.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...?.F.8.8.....1.0.4. .=. ...5.8.=.A.B.0.;.5.@.....1.0.5. .=. ...;.0.B.:.8.....1.0.6. .=. ...>.4. .=.0. .1.0.@.0.Z.5.....1.0.7. .=. ...8.A.B.0.....1.0.8. .=. ...:.>.=.8.....1.0.9. .=. ...5.B.0.;.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.X.....1.1.1. .=. ...B.A.B.@.0.=.8. .3.>. .2.=.5.A.>.B.....1.1.2. .=. ...A.2.5.6.8.....1.1.3. .=. ...0.;.8. .A.B.5. .A.8.3.C.@.=.8. .4.5.:.0. .A.0.:.0.B.5. .4.0. .3.>. .B.@.3.=.5.B.5. .A.5.;.5.:.B.8.@.0.=.8.>.B. .2.=.5.A.?.....1.1.4. .=. ...0.;.8. .A.B.5. .A.8.3.C.@.=.8. .4.5.:.0. .A.0.:.0.B.5. .4.0. .3.>. .4.5.8.=.A.B.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (397), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):63176
                                                Entropy (8bit):5.231829540590785
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C4744120A026563103B7CFF0BB71BD6B
                                                SHA1:8D2DEDE8F14EB8797FBABF7773650F4D0081F8F3
                                                SHA-256:0279CA9EAE7FB271D195ECC5072A48D629FD560B1560BC5C88DD238E992FC436
                                                SHA-512:08E1DB3F5669E3CB53A3560F86B48582C53ACB1F1A18E34A1EB9C8FA6310976CF518BA7447F510FA3321C3A60A3FFC5357D61FD9751D24C624F85B74950EEB79
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=..e,g../.J.a.p.a.n.e.s.e.....W.e.b.L.a.n.g.=.J.P.N.....T.r.a.n.s.l.a.t.o.r.=.T.i.l.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .h.:y-..[....1.0.3. .=. ..0.0.0.0.0....1.0.4. .=. ..0.0.0.0.0.0.0.0....1.0.5. .=. ..0.0.0....1.0.6. .=. ..0.0.0.0.0.0.0....1.0.7. .=. ..N......1.0.8. .=. ..0.0.0.0....1.0.9. .=. .s.0}....1.1.0. .=. ..0.0.0.0.0.0.0.0....1.1.1. .=. ..0.0.0.0.0d..S....1.1.2. .=. ..f.e....1.1.3. .=. .x..bU0.0_0.0.0.0.0.0,gS_k0JRd.W0~0Y0K0?.....1.1.4. .=. .x..bU0.0_0.0.0.0.0.0.0,gS_k0.0.0.0.0.0.0.0.0W0~0Y0K0?.....1.1.5. .=. ..0.0.0.0.0.0....1.1.6. .=. ..0.0.0....1.1.7. .=. ..0.0.0.0.0.0..........1.1.8. .=. ..0.0.0.0.0.0..........1.1.9. .=. ..0.0.0.0.0.`1X..........1.2.0. .=. ..{.t..)jP.g0.0.0.0.0W0f0O0`0U0D0!.....1.2.1. .=.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (550), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):98896
                                                Entropy (8bit):3.6696508961701726
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BB7C613587724040DB123308D4A62FDF
                                                SHA1:190C1738F14952F9AAA5B0900B93E85C00700DE3
                                                SHA-256:5F9E53ABAE5E8F438C1CB01D4DE4C1EB459B340066EF8D19B9F677DD8C8BBDBD
                                                SHA-512:FE0EDFB942BCD54534B20D662B295E6D46D70730E4F865639B34BE8CE86FFCB8FE444615699DA78477A180B19B2165D563831289062E0AE321A714A438099E1E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T...r.k...e./.T.u.r.k.i.s.h.....W.e.b.L.a.n.g.=.T.R.....T.r.a.n.s.l.a.t.o.r.=.G.N.C.,. .s.e.c.r.e.t. .+.+.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .G...r...n...m.....1.0.3. .=. .S.e...e.n.e.k.l.e.r.....1.0.4. .=. .P.r.o.g.r.a.m. .K.a.l.d.1.r.1.c.1.....1.0.5. .=. .A.r.a...l.a.r.....1.0.6. .=. .A.v.c.1. .M.o.d.u.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .S.i.m.g.e.l.e.r.....1.0.9. .=. .A.y.r.1.n.t.1.l.a.r.....1.1.0. .=. .K.a.l.d.1.r. .(.S.i.l.).....1.1.1. .=. .K.a.y.d.1. .S.i.l.....1.1.2. .=. .Y.e.n.i.l.e.....1.1.3. .=. .S.e...i.l.e.n. .k.a.y.d.1. .k.a.l.d.1.r.m.a.k. .i.s.t.e.d.i.g.i.n.i.z.d.e.n. .e.m.i.n. .m.i.s.i.n.i.z.?.....1.1.4. .=. .S.e...i.l.e.n. .p.r.o.g.r.a.m.1. .k.a.l.d.1.r.m.a.k. .i.s.t.e.d.i.g.i.n.i.z.d.e.n. .e.m.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (628), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):119290
                                                Entropy (8bit):3.428275301037861
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:77FC775F98A986CABAA1EF592DF4681E
                                                SHA1:D327461322D20A1BBCEA86BDD27FBC5E2058F043
                                                SHA-256:07CE496FAE3B0F26EF06F20BFE03A8E60FD96BCED6EF61C471CD7AC3BC3C500E
                                                SHA-512:63A93055C1082669D2217F5CE4FEBF0AA82D3A59738C3139916892BED929550BD14B9F5A6DA21480B4753ED5EF6BF5C811AF0A7078AE3EC05A740B7084C0D6BF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l./.S.p.a.n.i.s.h.....W.e.b.L.a.n.g.=.E.S.P.....T.r.a.n.s.l.a.t.o.r.=.F.e.r.n.a.n.d.o. .G.r.e.g.o.i.r.e.,. .J.o.s.e. .V.i.l.l.a.l.b.a. .S.a.n.c.h.e.z.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.r.....1.0.3. .=. .O.p.c.i.o.n.e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .H.e.r.r.a.m.i.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .C.a.z.a.d.o.r.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.c.o.n.o.s.....1.0.9. .=. .D.e.t.a.l.l.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r.....1.1.1. .=. .Q.u.i.t.a.r. .E.n.t.r.a.d.a.....1.1.2. .=. .R.e.f.r.e.s.c.a.r.....1.1.3. .=. ...E.s.t... .s.e.g.u.r.o. .d.e. .q.u.e. .d.e.s.e.a. .q.u.i.t.a.r. .l.a. .e.n.t.r.a.d.a. .s.e.l.e.c.c.i.o.n.a.d.a.?.....1.1.4. .=. ...E.s.t... .s.e.g.u.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (552), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):102284
                                                Entropy (8bit):3.428844247020488
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A3D974340201C1D00AF3A87F4D3DA6DC
                                                SHA1:5A7B7EFFC4E0F4BF37672C57F859AF4E370D0F64
                                                SHA-256:FEDCC719AC22D45A77F117372E0E124AA0EDE73DFC0768E7CDF7420539140731
                                                SHA-512:DB2570F00A443F52C5F59DA1C90721E31B9C094E50E17BF2552C59D4AEC05EEB28301A6D9CFA1AE09140E141DA7E6AC92565DA10B18C5B26DC40596B7F1ADF08
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.u.o.m.i./.F.i.n.n.i.s.h.....W.e.b.L.a.n.g.=.F.I.N.....T.r.a.n.s.l.a.t.o.r.=.O.l.l.i. .(.o.l.l.i.n.p.o.s.t.i.t.@.g.m.a.i.l...c.o.m.).....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .N...y.t.......1.0.3. .=. .A.s.e.t.u.k.s.e.t.....1.0.4. .=. .S.o.v.e.l.l.u.s.t.e.n. .p.o.i.s.t.o.....1.0.5. .=. .T.y...k.a.l.u.t.....1.0.6. .=. .O.s.o.i.t.u.s.t.o.i.m.i.n.t.o.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .K.u.v.a.k.k.e.e.t.....1.0.9. .=. .T.i.e.d.o.t.....1.1.0. .=. .P.o.i.s.t.a. .s.o.v.e.l.l.u.s.....1.1.1. .=. .P.o.i.s.t.a. .r.e.k.i.s.t.e.r.i.m.e.r.k.i.n.t.......1.1.2. .=. .P...i.v.i.t... .l.u.e.t.t.e.l.o.....1.1.3. .=. .O.l.e.t.k.o. .v.a.r.m.a.,. .e.t.t... .h.a.l.u.a.t. .p.o.i.s.t.a.a. .v.a.l.i.t.u.n. .r.e.k.i.s.t.e.r.i.m.e.r.k.i.n.n...n.?...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (596), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):93622
                                                Entropy (8bit):3.548594090036556
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:FEB1E88105E492FCBDD1D6DB74E0E1EA
                                                SHA1:99C21C1DF4DE45D8A49E7CBA1566FF683B420208
                                                SHA-256:7FD712396D175D5FC694D78FDBD5149C955944E7B343143B5215EC6305FA0B71
                                                SHA-512:CAFB9B1609CB9C2758EAC3D92055ACF6602FF6641C4487E9C35DFEBC6AE9451A87698F4AF138471956780F620DE04FEDF4C45DE43AE5EBAD4019551A8E7C8C18
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.H.r.v.a.t.s.k.i./.C.r.o.a.t.i.a.n. .....W.e.b.L.a.n.g.=.H.R.....T.r.a.n.s.l.a.t.o.r.=.H.a.s.a.n. .O.s.m.a.n.a.g.i.......C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .I.z.g.l.e.d.....1.0.3. .=. .P.o.s.t.a.v.k.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.e.r.....1.0.5. .=. .A.l.a.t.i.....1.0.6. .=. .P.r.e.s.r.e.t.a.n.j.e.....1.0.7. .=. .P.o.p.i.s.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .D.e.t.a.l.j.i.....1.1.0. .=. .D.e.i.n.s.t.a.l.i.r.a.j.....1.1.1. .=. .U.k.l.o.n.i. .u.n.o.s.....1.1.2. .=. .O.s.v.j.e.~.i.....1.1.3. .=. .U.k.l.o.n.i.t.i. .o.z.n.a...e.n.i. .u.n.o.s.?.....1.1.4. .=. .D.e.i.n.s.t.a.l.i.r.a.t.i. .o.z.n.a...e.n.i. .p.r.o.g.r.a.m.?.....1.1.5. .=. .D.o.g.r.a.d.n.j.a.....1.1.6. .=. .P.o.m.o.......1.1.7. .=. .U.p.u.t.e...........1.1.8. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (488), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):105328
                                                Entropy (8bit):3.977837553872142
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BDA9820021C13CB5F7653D3CF5567A63
                                                SHA1:2F9C9598A669D3F39B1E6EDE5ABFCCA221AA0A4B
                                                SHA-256:8A93EF905E3CB63105E98CA4D4EE0FAAAD7286D8C347AD975830A1F57A816F66
                                                SHA-512:27AB0C40CA4FF6D7B6C50D2CFAD372F2FA9520D631DB043DDF88A6C6C8674EFD65DCEA4B259169A743FEDBF19D617140F14C0F71F80B58117200F8EED6AEFC69
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e. .=. . .C.A.A.:.8.9./.R.u.s.s.i.a.n.....W.e.b.L.a.n.g. .=. .R.U.S.....T.r.a.n.s.l.a.t.o.r. .=. .K.p.o.J.I.u.K.,. .G.o.d.c.a.t. .(.g.o.d.c.a.t.@.b.k...r.u.).,. .S.e.T.V.e.l.....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E. .....V.e.r.s.i.o.n. .=. .2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...8.4.....1.0.3. .=. ...0.A.B.@.>.9.:.8.....1.0.4. .=. ...5.8.=.A.B.0.;.;.O.B.>.@.....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.K.....1.0.6. .=. . .5.6.8.<. .>.E.>.B.=.8.:.0.....1.0.7. .=. .!.?.8.A.>.:.....1.0.8. .=. ...=.0.G.:.8.....1.0.9. .=. ...>.4.@.>.1.=.>.....1.1.0. .=. .#.4.0.;.8.B.L.....1.1.1. .=. .#.4.0.;.8.B.L. .7.0.?.8.A.L.....1.1.2. .=. ...1.=.>.2.8.B.L.....1.1.3. .=. ...K. .C.2.5.@.5.=.K.,. .G.B.>. .E.>.B.8.B.5. .C.4.0.;.8.B.L. .2.K.1.@.0.=.=.K.9. .M.;.5.<.5.=.B.?.....1.1.4. .=. ...K. .C.2.5.@.5.=.K.,. .G.B.>. .E.>.B.8.B.5. .4.5.8.=.A.B.0.;.;.8.@.>.2.0.B.L. .2.K.1.@.0.=.=.C.N. .?.@.>.3.@.0.<.<.C.?.....1.1.5. .=. ...2.B.>.<.0.B.8.G.5.A.:.>.5.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (431), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):89136
                                                Entropy (8bit):3.486819796164331
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B460A1121BDB6806E308212EB9F63F8F
                                                SHA1:B42175BF8208C16669434F49EE46FDAADCDAFE6A
                                                SHA-256:7A2F9651F01898D76E4B0AD81272D12602162AAB0AF87EB7E0294ED345C1A6B2
                                                SHA-512:D826B851FDFF9B77211A264E593921B2239F1FB20278524E091459941A6EF69AE1BFBF227A1D5C243366A51A3F87F4E474E95BE0A6532140DB268D7F537DA806
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .D.a.n.s.k./.D.a.n.i.s.h.....W.e.b.L.a.n.g.=.D.A.N.....T.r.a.n.s.l.a.t.o.r.=.H.o.l.g.e.r. .T.e.r.k.e.l.s.e.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.....1.0.3. .=. .I.n.d.s.t.i.l.l.i.n.g.e.r.....1.0.4. .=. .A.f.i.n.s.t.a.l.l.e.r.i.n.g.....1.0.5. .=. .V...r.k.t...j.....1.0.6. .=. .J.a.g.t.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.f.i.n.s.t.a.l.l.e.r.....1.1.1. .=. .F.j.e.r.n. .e.m.n.e.....1.1.2. .=. .O.p.d.a.t.e.r.....1.1.3. .=. .E.r. .d.u. .s.i.k.k.e.r. .p... .d.u. .v.i.l. .f.j.e.r.n.e. .d.e.t. .v.a.l.g.t.e. .e.m.n.e.?.....1.1.4. .=. .E.r. .d.u. .s.i.k.k.e.r. .p... .d.u. .v.i.l. .a.f.i.n.s.t.a.l.l.e.r.e. .d.e.t. .v.a.l.g.t.e. .p.r.o.g.r.a.m.?.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (510), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):96592
                                                Entropy (8bit):3.7127262787086552
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:32082A6864E2BA727DBAAE26C494F281
                                                SHA1:8B4B50E7E3A95A93E456656DB0118497C71CE7E1
                                                SHA-256:634933FD82DFA32FE6258CC77D3A68EB115F6B8A648FA6AB459D96FB71F69716
                                                SHA-512:F195F1B479C47EE9D42425F5BF74441275106CCBAA18DFF4AD384AAAD151D266FE899CA211D939444ED9758D2FEA17274A7BFABF1A7EBFA68E857C0BEC209999
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n...i.n.a./.S.l.o.v.a.k.....W.e.b.L.a.n.g.=.S.K.....T.r.a.n.s.l.a.t.o.r.=.L.u.m.i.r. .-. .l.u.m.i.r.@.s.t.o.n.l.i.n.e...s.k.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .Z.o.b.r.a.z.e.n.i.e.....1.0.3. .=. .N.a.s.t.a.v.e.n.i.a.....1.0.4. .=. .O.d.i.n.a.t.a.l...t.o.r.....1.0.5. .=. .N...s.t.r.o.j.e.....1.0.6. .=. .R.e.~.i.m. .l.o.v.c.a.....1.0.7. .=. .Z.o.z.n.a.m.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .P.o.d.r.o.b.n.o.s.t.i.....1.1.0. .=. .O.d.i.n.a.t.a.l.o.v.a.e.....1.1.1. .=. .O.d.s.t.r...n.i.e.....1.1.2. .=. .O.b.n.o.v.i.e.....1.1.3. .=. .U.r...i.t.e. .c.h.c.e.t.e. .o.d.s.t.r...n.i.e. .v.y.b.r.a.t... .p.o.l.o.~.k.u.?.....1.1.4. .=. .U.r...i.t.e. .c.h.c.e.t.e. .o.d.i.n.a.t.a.l.o.v.a.e. .v.y.b.r.a.t... .p.r.o.g.r.a.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (562), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):110836
                                                Entropy (8bit):3.815923101679016
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2952EBFB627A4E0ECA6AE36179FB77E8
                                                SHA1:44E1DC938E9D4760EB3BC7B7A57BAFFA93ECF124
                                                SHA-256:104F10070994CA92176913A71726590DF2487BA756512CE6B3ABAA50CED8679B
                                                SHA-512:EA8F916977CEDBB7A6436FEFF19A2377266396799B11775FB00225854AFC5775018E2D8F0AC8CEF9E0D56CDC331C24825336A295AEE0A2E7314BF39FB91A7B84
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e. .=. .A.z.Y.r.b.a.y.c.a.n./.A.z.e.r.b.a.i.j.a.n.i.....W.e.b.L.a.n.g. .=. .A.Z.....T.r.a.n.s.l.a.t.o.r. .=. .M.a.h.i.r. .H.u.s.e.y.n.o.v. .(.u.r.o.b.o.r.o.s.1.3.0.8.7.5.@.g.m.a.i.l...c.o.m.). .....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E. .....V.e.r.s.i.o.n. .=. .2...0...6.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .G...r...n.t.......1.0.3. .=. .T.Y.n.z.i.m.l.Y.m.Y.l.Y.r.....1.0.4. .=. .P.r.o.q.r.a.m. .s.i.l.Y.n.....1.0.5. .=. .A.l.Y.t.l.Y.r.....1.0.6. .=. .O.v...u. .r.e.j.i.m.i.....1.0.7. .=. .S.i.y.a.h.1.....1.0.8. .=. .N.i._.a.n.l.a.r.....1.0.9. .=. .T.Y.f.Y.r.r...a.t.1. .i.l.Y.....1.1.0. .=. .S.i.l.m.Y.k.....1.1.1. .=. .Y.a.z.1.n.1. .s.i.l.m.Y.k. .....1.1.2. .=. .Y.e.n.i.l.Y.m.Y.k.....1.1.3. .=. .S.i.z. . .s.e...i.l.m.i._. .e.l.e.m.e.n.t.i. .s.i.l.m.Y.k. .i.s.t.Y.d.i.y.i.n.i.z.Y. .Y.m.i.n.s.i.n.i.z.m.i.?.....1.1.4. .=. .S.i.z. . .s.e...i.l.m.i._. .p.r.o.q.r.a.m.1. .s.i.l.m.Y.k. .i.s.t.Y.d.i.y.i.n.i.z.Y. .Y.m.i.n.s.i.n.i.z.m.i.?.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (768), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):116520
                                                Entropy (8bit):3.4502833810812774
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B941E859828CEFEDB42DF1A4781AAB8B
                                                SHA1:B8B9CB614DBAD6606B28149BE31627A158E01DEF
                                                SHA-256:B9DDCD9D489025435DCD58EFA188BB2D2AD8E283F64150B72FFB3AEB606C25D7
                                                SHA-512:9C07E5965BDC88E4B90E25AA37AC590130DC06BDD3E4288400037D2792C86F7A94264F6CD5C0B58D82D450036C52CF059032DFAB4462FD779379B7D3927FEC6C
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h. .....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .P.o.r.t.u.g.u.e.s.e./.P.o.r.t.u.g.a.l.....W.e.b.L.a.n.g.=.P.T.G.....T.r.a.n.s.l.a.t.o.r.=.L.u.i.s. .N.e.v.e.s. .(.l.u.i.s...a...n.e.v.e.s.@.s.a.p.o...p.t.). . .....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.r.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .C.a...a.d.o.r. .....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r. .....1.1.1. .=. .R.e.m.o.v.e.r. .e.n.t.r.a.d.a. .....1.1.2. .=. .A.c.t.u.a.l.i.z.a.r. .....1.1.3. .=. .T.e.m. .a. .c.e.r.t.e.z.a. .q.u.e. .d.e.s.e.j.a. .r.e.m.o.v.e.r. .a. .e.n.t.r.a.d.a. .s.e.l.e.c.c.i.o.n.a.d.a.?.....1.1.4. .=. .T.e.m. .a. .c.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (671), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):110176
                                                Entropy (8bit):3.6180166649155177
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:4D5EB6E082CD530F5594D290BBEFDBF9
                                                SHA1:410F8909B513C5890DD64525098DFA72363480FF
                                                SHA-256:B621D425E8ADA922FF2E75C03385A26D412BF0956B6DCEFD8C769EDD4F44A44D
                                                SHA-512:E4A8D85B5CB48C41CBCE1F36BC7D424EFE6B7CD0E19BFB06CAE85709559FA6E68D17215BC8D5A3024ACE18482CBF42317AFA0C67136A4A004064C4AF8A9EC22E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.M.a.g.y.a.r./.H.u.n.g.a.r.i.a.n.....W.e.b.L.a.n.g.=.H.U.N.....T.r.a.n.s.l.a.t.o.r.=.D...b.r...n.t.e.i. .S...n.d.o.r. .-. .s.a.n.d.o.r...d.o.b.r.o.n.t.e.i.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .N...z.e.t.....1.0.3. .=. .B.e...l.l...t...s.o.k.....1.0.4. .=. .E.l.t...v.o.l...t.......1.0.5. .=. .E.s.z.k...z...k.....1.0.6. .=. .K.e.r.e.s.Q. .m...d.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.o.k.....1.0.9. .=. .R...s.z.l.e.t.e.k.....1.1.0. .=. .E.l.t...v.o.l...t...s.....1.1.1. .=. .B.e.j.e.g.y.z...s. .t...r.l...s.e.....1.1.2. .=. .F.r.i.s.s...t...s.....1.1.3. .=. .B.i.z.t.o.s. .b.e.n.n.e.,. .h.o.g.y. .t...r.l.i. .a. .k.i.j.e.l...l.t. .b.e.j.e.g.y.z...s.t.?.....1.1.4. .=. .B.i.z.t.o.s. .b.e.n.n.e.,. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (896), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):123344
                                                Entropy (8bit):3.4859684858696127
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:00155578B98E07FC6288870E2AECCA68
                                                SHA1:FD934E59DA0813D7AB2E763BFCBA30DBB67D7721
                                                SHA-256:8CEF19D9D89BE0528643C45647085A85B136DF74987F7D25483732D431C70D12
                                                SHA-512:CDE580409DA144A7E9B0485EDB2610FCA23631712AB87A6FE727F3E5673357B315AB01B28C870815A985DA156251E68B2E20DEF1E7A0F919AA942EA0986BE446
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.D.e.u.t.s.c.h./.G.e.r.m.a.n.....W.e.b.L.a.n.g.=.G.E.R.....T.r.a.n.s.l.a.t.o.r.=.D.i.r.k. .P.a.u.l.s.e.n. . ..% .A.n.d.y. .K.l.e.i.n.e.r.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .A.n.s.i.c.h.t.....1.0.3. .=. .E.i.n.s.t.e.l.l.u.n.g.e.n.....1.0.4. .=. .A.n.w.e.n.d.u.n.g.e.n.\.n. .d.e.i.n.s.t.a.l.l.i.e.r.e.n.& ....1.0.5. .=. .E.x.t.r.a.s.....1.0.6. .=. .J.a.g.d.-.\.n.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.n.a.n.s.i.c.h.t.....1.0.8. .=. .S.y.m.b.o.l.a.n.s.i.c.h.t.....1.0.9. .=. .D.e.t.a.i.l.a.n.s.i.c.h.t.....1.1.0. .=. .A.n.w.e.n.d.u.n.g.\.n. .d.e.i.n.s.t.a.l.l.i.e.r.e.n.....1.1.1. .=. .E.l.e.m.e.n.t. .l...s.c.h.e.n.....1.1.2. .=. .A.k.t.u.a.l.i.s.i.e.r.e.n.....1.1.3. .=. .M...c.h.t.e.n. .S.i.e. .d.a.s. .a.u.s.g.e.w...h.l.t.e. .E.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (400), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):62482
                                                Entropy (8bit):4.078858907312597
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9D97E4DA88F7417381E9271B2A5FACC0
                                                SHA1:5B7019C9992ABF72147792DA5E264A3DD92DFCFD
                                                SHA-256:6AFA576FEADAF7AABE5FC735155523ED724ABC7871A899FBCA7A3F5AA1CFB8A8
                                                SHA-512:46BAB97CF5B825939A8CD0B8463DA22FF7626E06E0F7602A7D82AED8211608D8C94EBDB62C491A0C0CA7FB29AF025C2E837D7FE012B2FCCAAD8DD371D591643B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.........../.H.e.b.r.e.w.....W.e.b.L.a.n.g.=.H.E.B.....T.r.a.n.s.l.a.t.o.r.=.A.r.i.e.l. .N.e.m.t.z.o.v. ........... ...............C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...............1.0.3. .=. .....................1.0.4. .=. ......... ...................1.0.5. .=. .............1.0.6. .=. ."....... .".............1.0.7. .=. ...............1.0.8. .=. .....................1.0.9. .=. ...............1.1.0. .=. ...........1.1.1. .=. ....... ...........1.1.2. .=. .............1.1.3. .=.?. ....... ...../... ........./... ............... ........... ..... ......... ...............1.1.4. .=.?. ....... ...../... ........./... ............... ........... ..... ............. .................1.1.5. .=........... ...................1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (662), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):104660
                                                Entropy (8bit):3.466993833631326
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:5F57E969CB8F3AD0BBD859207A283BD5
                                                SHA1:5A232B0EED2D7437513010C7A0AF05CC4DE3D90F
                                                SHA-256:F2E8F9E5CF4F057E3399FF66485A485CBA419881AEEAC997049941396BDF63D8
                                                SHA-512:C48EC65D7DC7F1EF77BC708CDB6F49106651FB6D715450168F4D5FA8105C24DFB43D7378D8B0CEBA567942FD73FC95F7D41FD75C0824E619609981710B504CD0
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.n.g.l.i.s.h.....W.e.b.L.a.n.g.=.E.N.G.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.e.w.....1.0.3. .=. .O.p.t.i.o.n.s.....1.0.4. .=. .U.n.i.n.s.t.a.l.l.e.r.....1.0.5. .=. .T.o.o.l.s.....1.0.6. .=. .H.u.n.t.e.r. .M.o.d.e.....1.0.7. .=. .L.i.s.t.....1.0.8. .=. .I.c.o.n.s.....1.0.9. .=. .D.e.t.a.i.l.s.....1.1.0. .=. .U.n.i.n.s.t.a.l.l.....1.1.1. .=. .R.e.m.o.v.e. .E.n.t.r.y.....1.1.2. .=. .R.e.f.r.e.s.h.....1.1.3. .=. .A.r.e. .y.o.u. .s.u.r.e. .t.h.a.t. .y.o.u. .w.a.n.t. .t.o. .r.e.m.o.v.e. .t.h.e. .s.e.l.e.c.t.e.d. .e.n.t.r.y.?.....1.1.4. .=. .A.r.e. .y.o.u. .s.u.r.e. .t.h.a.t. .y.o.u. .w.a.n.t. .t.o. .u.n.i.n.s.t.a.l.l. .t.h.e. .s.e.l.e.c.t.e.d. .p.r.o.g.r.a.m.?.....1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (868), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):125884
                                                Entropy (8bit):4.129623998067867
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2750A46C066CE37250BE338D2D4B2C28
                                                SHA1:70A26F9D3E3E418DBC6B16C785B25B6E0EDE57B0
                                                SHA-256:1FBFEE3E9FB3D7E4BAC9AB89C49B25B1D93D65389A1DB3D9276C0B8C1A9C363B
                                                SHA-512:0856E4F4D81F1BF731B56C3A24E6A6D48726B89869012D8A63499D003B55303E9B0287291C11ACF6F2A940229204BB5FA7B694698E87D8997A703D531538CEFF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=................./.G.r.e.e.k.(.H.e.l.l.e.n.i.c.).....W.e.b.L.a.n.g.=.G.R.....T.r.a.n.s.l.a.t.o.r.=.V.S. .R.e.v.o. .G.r.o.u.p.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...................1.0.3. .=. .....................1.0.4. .=. .................................1.0.5. .=. .....................1.0.6. .=. ..................... .........................1.0.7. .=. .......................1.0.8. .=. .......................1.0.9. .=. .............................1.1.0. .=. ...............................1.1.1. .=. ................. ...........................1.1.2. .=. .....................1.1.3. .=. ........... ............... ....... ............. ..... ..................... ....... ..................... .....................;...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (713), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):106234
                                                Entropy (8bit):3.459364543901963
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:07982EC44C81B46E79709AA7C9D6D75D
                                                SHA1:606484E5E506AAC6C15EC740FA2F3A6651D0F912
                                                SHA-256:FA2ED7FB86F4D52206212A861BF306F3F34F0B2849C4C1AEC0F4E68ABC6D3FF1
                                                SHA-512:17CE8CD3E6A235EEFAA75A3D1C96B639FCC5D832E68398AA2E61AEFCA6DC9C63038F8887AA9C475A7AF6EE40DC07557CE0E1DE7174AF43936353E0AEDBDF31A5
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.B.a.h.a.s.a. .I.n.d.o.n.e.s.i.a./.I.n.d.o.n.e.s.i.a.n.....W.e.b.L.a.n.g.=.I.N.D.....T.r.a.n.s.l.a.t.o.r.=.P.u.r.w.o. .A.d.i. .N.u.g.r.o.h.o.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .L.i.h.a.t.....1.0.3. .=. .P.i.l.i.h.a.n.....1.0.4. .=. .P.e.n.g.h.a.p.u.s.....1.0.5. .=. .P.e.r.a.l.a.t.a.n.....1.0.6. .=. .M.o.d.e. .P.e.m.b.u.r.u.....1.0.7. .=. .D.a.f.t.a.r.....1.0.8. .=. .I.k.o.n.....1.0.9. .=. .R.i.n.c.i.a.n.....1.1.0. .=. .H.a.p.u.s.....1.1.1. .=. .H.a.p.u.s. .C.a.t.a.t.a.n.....1.1.2. .=. .S.e.g.a.r.k.a.n.....1.1.3. .=. .A.p.a.k.a.h. .a.n.d.a. .y.a.k.i.n. .i.n.g.i.n. .m.e.n.g.h.a.p.u.s. .c.a.t.a.t.a.n. .t.e.r.p.i.l.i.h.?.....1.1.4. .=. .A.p.a.k.a.h. .a.n.d.a. .y.a.k.i.n. .i.n.g.i.n. .m.e.n.g.h.a.p.u.s. .p.r.o.g.r.a.m. .t.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):48662
                                                Entropy (8bit):5.766695417079262
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:1741F9B110AF33284F55AB79B1C021CC
                                                SHA1:2F45A68B3DC13EED523DC5C657F0ACC35FB1F609
                                                SHA-256:75F2E61840EC81E7B7478D9981F5140974A84AB175D189B3BD8C42B27CE91C4E
                                                SHA-512:A692A9A4F794A378174EB648492B70F916791453CAE5E0F9B32950D93A8EDF2C2722209153B320133EA96C83B6CFAF74B4ACADA73C0752887E75A5D79E822E62
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .A~.-N.e ./. .T.r.a.d.i.t.i.o.n.a.l. .C.h.i.n.e.s.e.....W.e.b.L.a.n.g.=. .T.C.H.....T.r.a.n.s.l.a.t.o.r.=. .....C.o.d.e.p.a.g.e.=. .U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=. .2...4...5..... .........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ..j......1.0.3. .=. .x.......1.0.4. .=. ..yd..{.t.T....1.0.5. .=. .vQ.[.]wQ....1.0.6. .=. .us.N!j._....1.0.7. .=. ..n.U....1.0.8. .=. ..W:y....1.0.9. .=. .s.0}..e....1.1.0. .=. ..yd..[.....1.1.1. .=. ..yd....v....1.1.2. .=. ...ete.t....1.1.3. .=. ..`/f&T.x.....yd.x..S.v...v?.....1.1.4. .=. ..`/f&T.x.....yd..[.x..S.v.z._?.....1.1.5. .=. ...R.f.e....1.1.6. .=. ....f....1.1.7. .=. ..vMR.]wQ...f..........1.1.8. .=. ..}.z..........1.1.9. .=. ...e..........1.2.0. .=. ..`&N^..|q}.{.t.T!.....1.2.1. .=. ..`.x.....yd..[.x..S.v.|q}CQ.N.U?.\.n..`._.....[.`....#jZP!.....1.2.2.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (531), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):69166
                                                Entropy (8bit):3.5803296126896873
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:01B3ACB4EE074BDF8994CC6AD6E3D052
                                                SHA1:3C1BCA426E4A8328F5C0C75FE333BA806DF1E01B
                                                SHA-256:9B0C3A8D0BAB19D6FA3AAD207FCA13776AF59DE6580BFD49ACB0AFAF3B79BC5B
                                                SHA-512:8CBD95E0C318E0BF72E81247EB9A94A9D69EDE91CAF4167CD21D597C21286AFBB8D5F94EB2334156CF05325C24235A6882ED8F0CFA358E07E2CBD8F0CD39F280
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.../.K.u.r.d.i.s.h.....W.e.b.L.a.n.g.=.K.U.R.....T.r.a.n.s.l.a.t.o.r.=.O.c.c.o. .M.a.h.a.b.a.d. .-. .o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .D...m.e.n.....1.0.3. .=. .E.y.a.r.....1.0.4. .=. .U.n.i.n.s.t.a.l.l.e.r./.R.a.k.e.r.....1.0.5. .=. .A.m...r.....1.0.6. .=. .M.o.d.a. .N.......r.v.a.n.....1.0.7. .=. .L...s.t.e.....1.0.8. .=. .S...m.g.e.....1.0.9. .=. .D.e.t.a.y.....1.1.0. .=. .R.a.k.e.....1.1.1. .=. .Q.e.y.d... .R.a.k.e.....1.1.2. .=. .N... .B.i.k.e.....1.1.3. .=. .Q.e.y.d.a. .h.i.l.b.i.j.a.r.t... .w.e.r.e. .r.a.k.i.r.i.n.?.....1.1.4. .=. .B.e.r.n.a.m.e.y.a. .h.i.l.b.i.j.a.r.t... .w.e.r.e. .r.a.k.i.r.i.n.?.....1.1.5. .=. .R.o.j.a.n.e. .B.i.k.e.....1.1.6. .=. .A.l...k.a.r...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (437), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):82490
                                                Entropy (8bit):3.974625711084401
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C75676D808ED8D88ADD598CC51F79769
                                                SHA1:418CC54489003C093D391B5DA26105BCD0F13870
                                                SHA-256:D8D0C60EAD40825B14D3218AD5A17870F51D602653A397F2162F31B0150E6915
                                                SHA-512:E598EBDC0CEA722BA3811C1B1A13E256C940002CA5386FC6374CFFD8EE0CD414FAC300B638F0FA78EBD724720EC1FD865460CD3AB59923D62F1DBA050453B8C6
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .9.1.(.J./.A.r.a.b.i.c.....W.e.b.L.a.n.g.=.A.R.A.....T.r.a.n.s.l.a.t.o.r.=.'.D.#.3.*.'.0. .9.H.6. .".D.-.9.'.&.6. .'.D.:.'.E./.J.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=.9.1.6.....1.0.3. .=...J.'.1.'.*.....1.0.4. .=.%.D.:.'.!. .'.D.*.+.(.J.*.....1.0.5. .=.#./.H.'.*.....1.0.6. .=.F.E.7. .'.D.5.J.'./.....1.0.7. .=.B.'.&.E.).....1.0.8. .=.1.E.H.2.....1.0.9. .=.*.A.'.5.J.D.....1.1.0. .=.%.D.:.'.!. .'.D.*.+.(.J.*.....1.1.1. .=.%.2.'.D.). .'.D.E./...D.).....1.1.2. .=.*.-./.J.+.....1.1.3. .=.G.D. .*.1.J./. .A.9.D.'. .-.0.A. .'.D.E./...D.'.*. .'.D.E.-././.). .......1.1.4. .=.G.D. .*.1.J./. .A.9.D.'. .%.2.'.D.). .'.D.(.1.F.'.E.,. .'.D.E.-././. .......1.1.5. .=.*.-./.J.+. .*.D.B.'.&.J.....1.1.6. .=.*.9.D.J.E.'.*.....1.1.7. .=.*.9.D.J.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (657), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):107222
                                                Entropy (8bit):4.005861848520517
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:83D527FE61A3CEC460137D696AF7465F
                                                SHA1:C6C2F9D8323EC851D3A973060FA0DCF8BA82D313
                                                SHA-256:D5B886DD759CD7442705A044CB12D174621E199BCEA5E8728E63BCF6896F6BCA
                                                SHA-512:C1CF615536667825F2DEA8A8CB763B0440CA23D3160F95BC2E960C1010BBE545B3A2832905EA927615A31810321268BF718F74AF2D03DFB9A9E121A919E1F8E1
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .#.:.@.0.W.=.A.L.:.0./.U.k.r.a.i.n.i.a.n.....W.e.b.L.a.n.g.=.U.K.R.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.x.e.y. .L.u.g.i.n. .-. .a.l.e.x.@.u.k.r.l.o.c.a.l...i.n.f.o.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...8.3.;.O.4. .....1.0.3. .=. ...0.;.0.H.B.C.2.0.=.=.O. .....1.0.4. .=. ...5.V.=.A.B.0.;.O.B.>.@. .....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.8. .....1.0.6. .=. . .5.6.8.<.\.n.?.>.;.N.2.0.=.=.O. .....1.0.7. .=. .!.?.8.A.>.:. .....1.0.8. .=. ...V.:.B.>.3.@.0.<.8. .....1.0.9. .=. ...5.B.0.;.V. .....1.1.0. .=. ...5.V.=.A.B.0.;.O.F.V.O. .....1.1.1. .=. ...8.4.0.;.8.B.8. .5.;.5.<.5.=.B. .....1.1.2. .=. ...=.>.2.8.B.8. .....1.1.3. .=. ...8.4.0.;.8.B.8. .2.8.1.@.0.=.8.9. .5.;.5.<.5.=.B.?. .....1.1.4. .=. ...5.V.=.A.B.0.;.N.2.0.B.8. .2.8.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:data
                                                Category:dropped
                                                Size (bytes):48242
                                                Entropy (8bit):5.709563455127656
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:E28499F183FE96F8E42D383630D3ECAF
                                                SHA1:8C02586B6120180E6CC7BD79FAE983AEE666BCBE
                                                SHA-256:C324CFCDA981FDEB77D4CB936ECE749A29071E9C5C90D10B096D7A14C6A94DA2
                                                SHA-512:08E34431F8A666D5DCFC16D7BB6E712ADA56291AEA78BE87B0545675A18207C23DA29E12D64170756728D600207A45ECA4D86D042395BF335ED3E3A05562D826
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=..{SO-N.e ./. .S.i.m.p.l.i.f.i.e.d.C.h.i.n.e.s.e.....W.e.b.L.a.n.g.=.S.C.H.....T.r.a.n.s.l.a.t.o.r.=.P.e.p.c.h.i.d. .(.m.e.@.p.e.p.c.h.i.d...c.o.m.).....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...V....1.0.3. .=. ...y.....1.0.4. .=. .xS}.hV....1.0.5. .=. ..]wQ....1.0.6. .=. ..s.N!j._....1.0.7. .=. ..Rh.....1.0.8. .=. ..V.h....1.0.9. .=. ..~......1.1.0. .=. .xS}.....1.1.1. .=. . Rd.ag.v....1.1.2. .=. .7R.e....1.1.3. .=. ..`nx.[.. Rd.@b..ag.v.T?.....1.1.4. .=. ..`nx.[.. Rd.@b...z.^.T?.....1.1.5. .=. ..R.f.e....1.1.6. .=. ..^.R....1.1.7. .=. .S_MR.]wQ.^.R..........1.1.8. .=. .;Nu...........1.1.9. .=. .sQ.N..........1.2.0. .=. ..`.N/f.|.~.{.tXT!.....1.2.1. .=. ..`nx.[.. Rd.@b...|.~.~.N.T?.\.n...\P.N,. .d.^..`...Ynx.[.`ck(WZP.NHN
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (512), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):100596
                                                Entropy (8bit):3.692222328330995
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3A9FE274B3EA866821486DB9B5540682
                                                SHA1:90C32315371DB0EBF44EDCF8BC4D871009BFAD40
                                                SHA-256:BF3E83C343A5A221422CBA73B97451E7ED3DB0C8B429D636F0FAF524CFD9A652
                                                SHA-512:94FA091924A1CC0A63865CCC17865BBE31B0E9DC4D3AD0ADDAC5ADB4B22007CD205B217BE7FF90687E18CAA1CDA8FFFDA67B5FC16A7C8FEEDCFAA5935B166F5B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.l.s.k.i./.P.o.l.i.s.h.....W.e.b.L.a.n.g.=.P.L.....T.r.a.n.s.l.a.t.o.r.=.h.i.r.y.u.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .W.i.d.o.k.....1.0.3. .=. .O.p.c.j.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.a.t.o.r.....1.0.5. .=. .N.a.r.z...d.z.i.a.....1.0.6. .=. .T.r.y.b. .B.o.w.c.y.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .D.e.t.a.l.e.....1.1.0. .=. .O.d.i.n.s.t.a.l.u.j.....1.1.1. .=. .U.s.u.D. .w.p.i.s.....1.1.2. .=. .O.d.[.w.i.e.|.....1.1.3. .=. .C.z.y. .n.a. .p.e.w.n.o. .u.s.u.n..... .z.a.z.n.a.c.z.o.n.y. .o.b.i.e.k.t.?.....1.1.4. .=. .C.z.y. .n.a. .p.e.w.n.o. .o.d.i.n.s.t.a.l.o.w.a... .z.a.z.n.a.c.z.o.n.y. .p.r.o.g.r.a.m.?.....1.1.5. .=. .A.k.t.u.a.l.i.z.u.j.....1.1.6. .=. .P.o.m.o.c.....1.1.7. .=. .P.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (601), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):107310
                                                Entropy (8bit):3.485215413973629
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:CD86D5DF4564A5D91934B3383A2B342E
                                                SHA1:D278404BF4412D00E07839911CFF8A9F0C3AFC2A
                                                SHA-256:09FE4F2A0D1D54C5D374DB235F07F06642404A630F8B981461B0F7998B7C753B
                                                SHA-512:7FC876B6637897CE0AA46D947764DA63616978F0F5BBC71B0BF1E6B7B1FC8680FF0A5E1B691737B4D0F75920B1C854CEC150DFD27E599C326FBFD5277609ECA1
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.D.o.k.u.m.e.n.t.i. .i. .g.j.u.h.e.s. .i. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....;.T.r.a.n.s.l.a.t.e.d. .b.y. .K.l.a.u.s. .V.e.l.i.u.....;.C.o.n.t.a.c.t. .k.l.a.u.s.v.e.l.i.u.@.h.o.t.m.a.i.l...c.o.m.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .S.h.q.i.p./.A.l.b.a.n.i.a.n.....W.e.b.L.a.n.g.=.A.L.....T.r.a.n.s.l.a.t.o.r.=.K.l.a.u.s. .V.e.l.i.u. .e.-.m.a.i.l.:. .k.l.a.u.s.v.e.l.i.u.@.h.o.t.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[...i.n.s.t.a.l.u.e.s.i. .T.o.o.l.b.a.r.].....1.0.2. .=. .P.a.m.j.a.....1.0.3. .=. .O.p.s.i.o.n.e.t.....1.0.4. .=. ...i.n.s.t.a.l.u.e.s.i.....1.0.5. .=. .M.j.e.t.e.t.....1.0.6. .=. .M.e.n.y.r.a. .e. .g.j.u.e.t.a.r.i.t.....1.0.7. .=. .M.e. .l.i.s.t.i.m.....1.0.8. .=. .M.e. .i.n.k.o.n.a.....1.0.9. .=. .M.e. .d.e.t.a.j.e.....1.1.0. .=. ...i.n.s.t.a.l.o.....1.1.1. .=. .H.i.q. .s.h.e.n.i.m.i.n.....1.1.2. .=. .R.i.f.r.e.s.k.o.....1.1.3. .=. .J.e.n.i. .t.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (668), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):100750
                                                Entropy (8bit):3.739375961948482
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:EDF65AA9E3901E57E6290C53D9B18F19
                                                SHA1:C22A962518F577F96D187831C4009D807F5F8B6D
                                                SHA-256:AA6B1D30A2ADC755A44122ACA13C7CA56C740C6E69F9B799EA6FD5CA7109DC4E
                                                SHA-512:0BE4B66E464CCC6108DF33156EEF18E473424E8EBE832060321DEA50BE93E2A8E1AA81801AB44D545E24654CB112ABF302D983345936DC2E8A73B0ABBD4A9505
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. ...e.a.t.i.n.a./.C.z.e.c.h.....W.e.b.L.a.n.g.=.C.Z.....T.r.a.n.s.l.a.t.o.r.=. .=.M.r...=.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .Z.o.b.r.a.z.e.n.......1.0.3. .=. .N.a.s.t.a.v.e.n.......1.0.4. .=. .O.d.i.n.s.t.a.l...t.o.r.....1.0.5. .=. .N...s.t.r.o.j.e.....1.0.6. .=. .R.e.~.i.m. .L.o.v.e.c.....1.0.7. .=. .S.e.z.n.a.m.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .D.e.t.a.i.l.y.....1.1.0. .=. .O.d.i.n.s.t.a.l.o.v.a.t.....1.1.1. .=. .O.d.s.t.r.a.n.i.t. .z...z.n.a.m.....1.1.2. .=. .O.b.n.o.v.i.t.....1.1.3. .=. .O.p.r.a.v.d.u. .m...m. .o.z.n.a...e.n... .z...z.n.a.m. .o.d.s.t.r.a.n.i.t.?.....1.1.4. .=. .O.p.r.a.v.d.u. .m...m. .t.e.n.t.o. .p.r.o.g.r.a.m. .o.d.i.n.s.t.a.l.o.v.a.t.?.....1.1.5. .=. .A.u.t.o.a.k.t.u.a.l.i.z.a.c.e.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (787), with CRLF, CR line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B1130B82AF1277725D411840C0173265
                                                SHA1:05760EBC0248D176BE83E99744B498C290955F51
                                                SHA-256:6B5A5D57E054CC867DDC276CEA4861FE43656269C18C8FBAEA739C16944E5B47
                                                SHA-512:2553FAE3BF7611FE0C3A73BA4F4E0156D76CFD005490BBE6D057D01949B44143E5EF8081F0E4C6A181E1263C1D5FDCE45131D0987F38A5834703015C3FE75745
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.........................................................................[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.I.t.a.l.i.a.n.o./.I.t.a.l.i.a.n.....W.e.b.L.a.n.g.=.I.T.A.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.s.s.a.n.d.r.o. .V.i.s.e.n.t.i.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.................................................................................[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.d.i.....1.0.3. .=. .O.p.z.i.o.n.i.....1.0.4. .=. .D.i.s.i.n.s.t.a.l.l.a.t.o.r.e.....1.0.5. .=. .S.t.r.u.m.e.n.t.i.....1.0.6. .=. .M.o.d.o. .M.i.r.i.n.o.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.c.o.n.e.....1.0.9. .=. .D.e.t.t.a.g.l.i.....1.1.0. .=. .D.i.s.i.n.s.t.a.l.l.a.....1.1.1. .=. .R.i.m.u.o.v.i. .v.o.c.e.....1.1.2. .=. .A.g.g.i.o.r.n.a.....1.1.3. .=. .S.i.c.u.r.i. .d.i. .v.o.l.e.r. .r.i.m.u.o.v.e.r.e. .l.a. .v.o.c.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (397), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C4744120A026563103B7CFF0BB71BD6B
                                                SHA1:8D2DEDE8F14EB8797FBABF7773650F4D0081F8F3
                                                SHA-256:0279CA9EAE7FB271D195ECC5072A48D629FD560B1560BC5C88DD238E992FC436
                                                SHA-512:08E1DB3F5669E3CB53A3560F86B48582C53ACB1F1A18E34A1EB9C8FA6310976CF518BA7447F510FA3321C3A60A3FFC5357D61FD9751D24C624F85B74950EEB79
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=..e,g../.J.a.p.a.n.e.s.e.....W.e.b.L.a.n.g.=.J.P.N.....T.r.a.n.s.l.a.t.o.r.=.T.i.l.t.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .h.:y-..[....1.0.3. .=. ..0.0.0.0.0....1.0.4. .=. ..0.0.0.0.0.0.0.0....1.0.5. .=. ..0.0.0....1.0.6. .=. ..0.0.0.0.0.0.0....1.0.7. .=. ..N......1.0.8. .=. ..0.0.0.0....1.0.9. .=. .s.0}....1.1.0. .=. ..0.0.0.0.0.0.0.0....1.1.1. .=. ..0.0.0.0.0d..S....1.1.2. .=. ..f.e....1.1.3. .=. .x..bU0.0_0.0.0.0.0.0,gS_k0JRd.W0~0Y0K0?.....1.1.4. .=. .x..bU0.0_0.0.0.0.0.0.0,gS_k0.0.0.0.0.0.0.0.0W0~0Y0K0?.....1.1.5. .=. ..0.0.0.0.0.0....1.1.6. .=. ..0.0.0....1.1.7. .=. ..0.0.0.0.0.0..........1.1.8. .=. ..0.0.0.0.0.0..........1.1.9. .=. ..0.0.0.0.0.`1X..........1.2.0. .=. ..{.t..)jP.g0.0.0.0.0W0f0O0`0U0D0!.....1.2.1. .=.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (400), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F94E17A85FB506876093C080337ABBD8
                                                SHA1:AEF30BB2D35C29751F169DC4CD69543A1158B78D
                                                SHA-256:A45749730A58A5A8911A98738C7FBD21DA0609A16E8E9FC3F8018BBD19B83C9A
                                                SHA-512:F55B53D24B3AC16BB2A544CF0E7898D8DC85E206101FB0DE738B4D81ADE38E476F4F30DFDEB67589B5E54732C737E314E05B83C0F8A491454E0FFEFD067694DE
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.\.m... ./. .K.o.r.e.a.n.....W.e.b.L.a.n.g.=.K.O.R.....T.r.a.n.s.l.a.t.o.r.=.J.a.e.H.y.u.n.g. .L.e.e. ./. .k.o.l.a.n.p.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...0.....1.0.3. .=. .5.X.....1.0.4. .=. ...p.0.....1.0.5. .=. ..l.....1.0.6. .=. ...0.......1.0.7. .=. .........1.0.8. .=. .D.t.X.....1.0.9. .=. ...8.......1.1.0. .=. ...\..... ...p.....1.1.1. .=. . ... .m.. ...p.....1.1.2. .=. .... ........1.1.3. .=. ....\. . ...\. .m..D. ...p.X.......L.?.....1.1.4. .=. ....\. . ...\. ...\.....D. ...p.X.......L.?.....1.1.5. .=. ...p.t......1.1.6. .=. .........1.1.7. .=. .... ..l. ...............1.1.8. .=. .H..t.............1.1.9. .=. .... ...............1.2.0. .=. ...X.. ......... .D...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (531), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:01B3ACB4EE074BDF8994CC6AD6E3D052
                                                SHA1:3C1BCA426E4A8328F5C0C75FE333BA806DF1E01B
                                                SHA-256:9B0C3A8D0BAB19D6FA3AAD207FCA13776AF59DE6580BFD49ACB0AFAF3B79BC5B
                                                SHA-512:8CBD95E0C318E0BF72E81247EB9A94A9D69EDE91CAF4167CD21D597C21286AFBB8D5F94EB2334156CF05325C24235A6882ED8F0CFA358E07E2CBD8F0CD39F280
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.K.u.r.d.../.K.u.r.d.i.s.h.....W.e.b.L.a.n.g.=.K.U.R.....T.r.a.n.s.l.a.t.o.r.=.O.c.c.o. .M.a.h.a.b.a.d. .-. .o.c.c.o.7.4.@.h.o.t.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...0...6.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .D...m.e.n.....1.0.3. .=. .E.y.a.r.....1.0.4. .=. .U.n.i.n.s.t.a.l.l.e.r./.R.a.k.e.r.....1.0.5. .=. .A.m...r.....1.0.6. .=. .M.o.d.a. .N.......r.v.a.n.....1.0.7. .=. .L...s.t.e.....1.0.8. .=. .S...m.g.e.....1.0.9. .=. .D.e.t.a.y.....1.1.0. .=. .R.a.k.e.....1.1.1. .=. .Q.e.y.d... .R.a.k.e.....1.1.2. .=. .N... .B.i.k.e.....1.1.3. .=. .Q.e.y.d.a. .h.i.l.b.i.j.a.r.t... .w.e.r.e. .r.a.k.i.r.i.n.?.....1.1.4. .=. .B.e.r.n.a.m.e.y.a. .h.i.l.b.i.j.a.r.t... .w.e.r.e. .r.a.k.i.r.i.n.?.....1.1.5. .=. .R.o.j.a.n.e. .B.i.k.e.....1.1.6. .=. .A.l...k.a.r...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (480), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:0D49FD507C10E50977B85B4E16E5642A
                                                SHA1:687EE839A15C758B0505A05D7EF7798D7C926EDB
                                                SHA-256:3D97D5206A5997FE80886E6B9782C8A9C0E3BAC5EB1CCB6B68A882E43832B12E
                                                SHA-512:366CE1933EB0946E151BD90DABE9C875AB9191A07E06936899B821F1F2CE29E6628B3F5F960A47ED74E7BDC47C45842C304F849D8CE73A42AF4E7F2E95DCEA31
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=...0.:.5.4.>.=.A.:.8./.M.a.c.e.d.o.n.i.a.n.....W.e.b.L.a.n.g.=.M.K.D.....T.r.a.n.s.l.a.t.o.r.=.0.1. .V.l.a.t.c.e.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...?.F.8.8.....1.0.4. .=. ...5.8.=.A.B.0.;.5.@.....1.0.5. .=. ...;.0.B.:.8.....1.0.6. .=. ...>.4. .=.0. .1.0.@.0.Z.5.....1.0.7. .=. ...8.A.B.0.....1.0.8. .=. ...:.>.=.8.....1.0.9. .=. ...5.B.0.;.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.X.....1.1.1. .=. ...B.A.B.@.0.=.8. .3.>. .2.=.5.A.>.B.....1.1.2. .=. ...A.2.5.6.8.....1.1.3. .=. ...0.;.8. .A.B.5. .A.8.3.C.@.=.8. .4.5.:.0. .A.0.:.0.B.5. .4.0. .3.>. .B.@.3.=.5.B.5. .A.5.;.5.:.B.8.@.0.=.8.>.B. .2.=.5.A.?.....1.1.4. .=. ...0.;.8. .A.B.5. .A.8.3.C.@.=.8. .4.5.:.0. .A.0.:.0.B.5. .4.0. .3.>. .4.5.8.=.A.B.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (435), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3E633737F96D30604CAC348F7C0CA5D3
                                                SHA1:BEFC528C9476A3CABA53128F3EEF58E511F0EF6D
                                                SHA-256:C4DBDE88DFFDA3E9EB139D91E2FF49E736D76D52B46331D10DDE4147911D0428
                                                SHA-512:1667A7CF77FA92E334AE886F8C07E02494C67C38441A73BCA233093EDC91AE66B3D63B3699DD1CC3BE3534F5C0844113838BDE8D969A80A9CB416225C9201ABF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .N.o.r.s.k./.N.o.r.w.e.g.i.a.n.....W.e.b.L.a.n.g.=.N.O.R.....T.r.a.n.s.l.a.t.o.r.=.P.a.a.l. .R.o.n.n.i.n.g.e.n.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.....1.0.3. .=. .A.l.t.e.r.n.a.t.i.v.....1.0.4. .=. .A.v.i.n.s.t.a.l.l.e.r.e.r.....1.0.5. .=. .V.e.r.k.t...y.....1.0.6. .=. .J.a.k.t.m.o.d.u.s.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.v.i.n.s.t.a.l.l.e.r.e.....1.1.1. .=. .T.a. .b.o.r.t. .p.o.s.t.....1.1.2. .=. .O.p.p.d.a.t.e.r.e. .p.r.o.g.r.a.m.l.i.s.t.e.n.....1.1.3. .=. .V.i.l. .d.u. .v.i.r.k.e.l.i.g. .t.a. .b.o.r.t. .V.a.l.g.t. .p.o.s.t.?.....1.1.4. .=. .V.i.l. .d.u. .v.i.r.k.e.l.i.g. .t.a. .b.o.r.t. .V.a.l.g.t. .p.r.o.g.r.a.m.?.....1.1.5. .=. .O.p.p.d.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (1970), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2624EBD91EC84714395D1C1BB989A14B
                                                SHA1:E4A93AE374A2BA4F9BEAE19D937160535EDA7C20
                                                SHA-256:2B26C5DFACA7A8A89B50026F5C659A7CF8793E96EA70948E8799D58C8E0B92E1
                                                SHA-512:452648B7AE74C3BE3D054703BBA19FB22DD4969BF28A0AF87ACFAB7E00539BF827849FE055202A22C02D39D9CA15ADAE440E358CC1556E8E13419A8F7FE8AC8E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.e.r.s.i.a.n./.A.'.1.3.J.....W.e.b.L.a.n.g.=.F.A.R.....T.r.a.n.s.l.a.t.o.r.=.E.G.F./.3. .9.(./.'.D.1.6.'. .4.A.'.J.J.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .....V.e.r.s.i.o.n.=.2...1...7. .........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2.=.F.E.'.J.4.....1.0.3.=.*.F.8.J.E.'.*.....1.0.4.=.-.0.A. ...F.F./.G.....1.0.5.=.'.(.2.'.1.G.'.....1.0.6.=.-.'.D.*.\.n. .4...'.1...J.....1.0.7.=.A.G.1.3.*.....1.0.8.=.4.E.'.J.D.....1.0.9.=.,.2.&.J.'.*.....1.1.0.=.9.@.2. .D. .(.1.F.'.E.G.....1.1.1.=.-.0.A. .H.1.H./.J. .....1.1.2.=.*.'.2.G. .3.'.2.J.....1.1.3.=.".J.'. .E.7.E.&.F. .(.G. .-.0.A. .H.1.H./.J. .'.F.*...'.(. .4./.G. .G.3.*.J./. .......1.1.4.=.".J.'. .E.7.E.&.F. .(.G. ...1.H.,. .(.1.F.'.E.G. .(.1...2.J./.G. .'.2. .F.5.(. .G.3.*.J./. .......1.1.5.=.(.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (512), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3A9FE274B3EA866821486DB9B5540682
                                                SHA1:90C32315371DB0EBF44EDCF8BC4D871009BFAD40
                                                SHA-256:BF3E83C343A5A221422CBA73B97451E7ED3DB0C8B429D636F0FAF524CFD9A652
                                                SHA-512:94FA091924A1CC0A63865CCC17865BBE31B0E9DC4D3AD0ADDAC5ADB4B22007CD205B217BE7FF90687E18CAA1CDA8FFFDA67B5FC16A7C8FEEDCFAA5935B166F5B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.l.s.k.i./.P.o.l.i.s.h.....W.e.b.L.a.n.g.=.P.L.....T.r.a.n.s.l.a.t.o.r.=.h.i.r.y.u.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .W.i.d.o.k.....1.0.3. .=. .O.p.c.j.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.a.t.o.r.....1.0.5. .=. .N.a.r.z...d.z.i.a.....1.0.6. .=. .T.r.y.b. .B.o.w.c.y.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .D.e.t.a.l.e.....1.1.0. .=. .O.d.i.n.s.t.a.l.u.j.....1.1.1. .=. .U.s.u.D. .w.p.i.s.....1.1.2. .=. .O.d.[.w.i.e.|.....1.1.3. .=. .C.z.y. .n.a. .p.e.w.n.o. .u.s.u.n..... .z.a.z.n.a.c.z.o.n.y. .o.b.i.e.k.t.?.....1.1.4. .=. .C.z.y. .n.a. .p.e.w.n.o. .o.d.i.n.s.t.a.l.o.w.a... .z.a.z.n.a.c.z.o.n.y. .p.r.o.g.r.a.m.?.....1.1.5. .=. .A.k.t.u.a.l.i.z.u.j.....1.1.6. .=. .P.o.m.o.c.....1.1.7. .=. .P.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (768), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B941E859828CEFEDB42DF1A4781AAB8B
                                                SHA1:B8B9CB614DBAD6606B28149BE31627A158E01DEF
                                                SHA-256:B9DDCD9D489025435DCD58EFA188BB2D2AD8E283F64150B72FFB3AEB606C25D7
                                                SHA-512:9C07E5965BDC88E4B90E25AA37AC590130DC06BDD3E4288400037D2792C86F7A94264F6CD5C0B58D82D450036C52CF059032DFAB4462FD779379B7D3927FEC6C
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h. .....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .P.o.r.t.u.g.u.e.s.e./.P.o.r.t.u.g.a.l.....W.e.b.L.a.n.g.=.P.T.G.....T.r.a.n.s.l.a.t.o.r.=.L.u.i.s. .N.e.v.e.s. .(.l.u.i.s...a...n.e.v.e.s.@.s.a.p.o...p.t.). . .....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.r.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .C.a...a.d.o.r. .....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r. .....1.1.1. .=. .R.e.m.o.v.e.r. .e.n.t.r.a.d.a. .....1.1.2. .=. .A.c.t.u.a.l.i.z.a.r. .....1.1.3. .=. .T.e.m. .a. .c.e.r.t.e.z.a. .q.u.e. .d.e.s.e.j.a. .r.e.m.o.v.e.r. .a. .e.n.t.r.a.d.a. .s.e.l.e.c.c.i.o.n.a.d.a.?.....1.1.4. .=. .T.e.m. .a. .c.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (768), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2BE6DFDA140D556C60980C83958DA5C2
                                                SHA1:139CCE83C93AB264A67F0F53D3BA27AD52C9F370
                                                SHA-256:202DACEEFB06DAFC459FAD9E194643AEEA9D8FB441F898326FC26F27B73FE535
                                                SHA-512:155E4D47089E69C9BB13DA754AAE3AFCD3204C1A241263F8947BEB378F8EA930D7FDEA20E3462B816D1587E98EC6588E417E72A0B5D504F047EF2DB22974387D
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h. .....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .P.o.r.t.u.g.u...s./.P.o.r.t.u.g.u.e.s.e.....W.e.b.L.a.n.g.=.P.T.G.S.T.D.....T.r.a.n.s.l.a.t.o.r.=.L.u.i.s. .N.e.v.e.s. .-. .l.u.i.s...a...n.e.v.e.s.@.s.a.p.o...p.t. ./. .M.a.n.u.e.l.a. .S.i.l.v.a.-.A.l.f.r.e.d.o. .S.i.l.v.a. .(.T.r.a.n.s.l.a.t.i.o.n./.P.r.o.o.f.-.r.e.a.d.e.r.). .-. .2.0.1.5.1.1.1.7.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.u.a.l.i.z.a.....o.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .d.e. .P.e.s.q.u.i.s.a. .....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r. .....1.1.1. .=. .R.e.m.o.v.e.r. .E.n.t.r.a.d.a. .....1.1.2. .=. .A.t.u.a.l.i.z.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (707), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A7E3ACA49F123CA55F3C16D3471B097F
                                                SHA1:CFF36DAFC9DA080C47ABE80D26F63F04B426526B
                                                SHA-256:8AE5848453F428219588D16614FDC145E4E5B2ED9A436524FBB38BFC642F1CD3
                                                SHA-512:3C9DEDE08D83A30F9E03EE903CDE94C3F136B67FC0052B99DCA14C791D7FEBA8F47DDD1F2764C72A1B8084B78B3AF993CC28C2A9396EDD30203A40CB6B292622
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.A.r.q.u.i.v.o. .d.e. .i.d.i.o.m.a. .d.o. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.E.s.t.a. .s.e.....o. .d.e.v.e. .u.s.a.r. .P.o.r.t.u.g.u...s. .B.r.a.s.i.l.e.i.r.o.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.P.o.r.t.u.g.u...s. .B.r.a.s.i.l.e.i.r.o.....W.e.b.L.a.n.g.=.P.T.-.B.R.....T.r.a.n.s.l.a.t.o.r.=.M.a.r.c.u.s. .V.i.n...c.i.u.s. .R.o.c.h.a. .d.a. .S.i.l.v.a.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .E.x.i.b.i.r.....1.0.3. .=. .O.p.....e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .F.e.r.r.a.m.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .d.e. .C.a...a.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. ...c.o.n.e.s.....1.0.9. .=. .D.e.t.a.l.h.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r.....1.1.1. .=. .R.e.m.o.v.e.r. .e.n.t.r.a.d.a.....1.1.2. .=. .A.t.u.a.l.i.z.a.r.....1.1.3. .=. .T.e.m. .c.e.r.t.e.z.a. .q.u.e. .d.e.s.e.j.a. .r.e.m.o.v.e.r. .a. .e.n.t.r.a.d.a. .s.e.l.e.c.i.o.n.a.d.a.?.....1.1.4. .=. .T.e.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (742), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9F0EC5C7DC7D8E14DD0ED2E590E8326A
                                                SHA1:D9D55B5FEC39CAB7D8373DDAD7EB33BD305EE94A
                                                SHA-256:0BB8B7EB790CBB31605A11EE23B9B4F03ED60E076FABE5A9D82D1B915A3B1B27
                                                SHA-512:D04C74AAA239C4B7E9A022EF34246EB1FCC42B819DD9DAABEA57FACD5DD9B008137E340311EB11E7497F81D1B57E753E0865B6D7130DBEE18A9D44290D3F215D
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.R.o.m...n... ./. .R.o.m.a.n.i.a.n.....W.e.b.L.a.n.g.=.R.O.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.x.a.n.d.r.u. .B.o.g.d.a.n. .M.u.n.t.e.a.n.u.,. .M.a.r.i.n.e.l. .C.i.p.u.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.d.e.r.e.....1.0.3. .=. .O.p...i.u.n.i.....1.0.4. .=. .D.e.z.i.n.s.t.a.l.a.t.o.r.....1.0.5. .=. .U.n.e.l.t.e.....1.0.6. .=. .V...n...t.o.r.....1.0.7. .=. .L.i.s.t.......1.0.8. .=. .I.c.o.a.n.e.....1.0.9. .=. .D.e.t.a.l.i.i.....1.1.0. .=. .D.e.z.i.n.s.t.a.l.e.a.z.......1.1.1. .=. ...n.l...t.u.r.......1.1.2. .=. ...m.p.r.o.s.p...t.e.a.z.......1.1.3. .=. .S.i.g.u.r. .v.r.e.i. .s... ...n.l...t.u.r.i. .i.n.t.r.a.r.e.a. .s.e.l.e.c.t.a.t...?.....1.1.4. .=. .S.i.g.u.r. .v.r.e.i. .s... .d.e.z.i.n.s.t.a.l.e.z.i. .p.r.o.g.r.a.m.u.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (488), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BDA9820021C13CB5F7653D3CF5567A63
                                                SHA1:2F9C9598A669D3F39B1E6EDE5ABFCCA221AA0A4B
                                                SHA-256:8A93EF905E3CB63105E98CA4D4EE0FAAAD7286D8C347AD975830A1F57A816F66
                                                SHA-512:27AB0C40CA4FF6D7B6C50D2CFAD372F2FA9520D631DB043DDF88A6C6C8674EFD65DCEA4B259169A743FEDBF19D617140F14C0F71F80B58117200F8EED6AEFC69
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..[.I.n.f.o.].....L.a.n.g.u.a.g.e. .=. . .C.A.A.:.8.9./.R.u.s.s.i.a.n.....W.e.b.L.a.n.g. .=. .R.U.S.....T.r.a.n.s.l.a.t.o.r. .=. .K.p.o.J.I.u.K.,. .G.o.d.c.a.t. .(.g.o.d.c.a.t.@.b.k...r.u.).,. .S.e.T.V.e.l.....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E. .....V.e.r.s.i.o.n. .=. .2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...8.4.....1.0.3. .=. ...0.A.B.@.>.9.:.8.....1.0.4. .=. ...5.8.=.A.B.0.;.;.O.B.>.@.....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.K.....1.0.6. .=. . .5.6.8.<. .>.E.>.B.=.8.:.0.....1.0.7. .=. .!.?.8.A.>.:.....1.0.8. .=. ...=.0.G.:.8.....1.0.9. .=. ...>.4.@.>.1.=.>.....1.1.0. .=. .#.4.0.;.8.B.L.....1.1.1. .=. .#.4.0.;.8.B.L. .7.0.?.8.A.L.....1.1.2. .=. ...1.=.>.2.8.B.L.....1.1.3. .=. ...K. .C.2.5.@.5.=.K.,. .G.B.>. .E.>.B.8.B.5. .C.4.0.;.8.B.L. .2.K.1.@.0.=.=.K.9. .M.;.5.<.5.=.B.?.....1.1.4. .=. ...K. .C.2.5.@.5.=.K.,. .G.B.>. .E.>.B.8.B.5. .4.5.8.=.A.B.0.;.;.8.@.>.2.0.B.L. .2.K.1.@.0.=.=.C.N. .?.@.>.3.@.0.<.<.C.?.....1.1.5. .=. ...2.B.>.<.0.B.8.G.5.A.:.>.5.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (436), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:604CE883FD5E8100F69303F172790F5D
                                                SHA1:6DC166AD68251174A39F22BC955B63A7D9326338
                                                SHA-256:663FEF249682C9DE0819F193EF2B6E2625E2054F093EBA37EF852181CFB61AE0
                                                SHA-512:065D233F4407DCBA1319A515FE05FD6D2C2A1F66C25E1B0F15A7606E833C14CFA41701474C258EE74638E8291D41C2204BAFFF3B8FB107F53E9E2CF5C5E9D334
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.!.@.?.A.:.8./.S.e.r.b.i.a.n. .....W.e.b.L.a.n.g.=.S.R.B.L.T.....T.r.a.n.s.l.a.t.o.r.=.D.r.a.g.a.n. .B.j.e.d.o.v. .d.r.a.g.a.n.b.j.e.d.o.v.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...0...6.............[.D.e.i.n.s.t.a.l.e.r. .L.i.n.i.j.a. .s.a. .a.l.a.t.k.a.m.a.].....1.0.2. .=. ...7.3.;.5.4.....1.0.3. .=. ...>.A.B.0.2.:.5.....1.0.4. .=. ...5.8.=.A.B.0.;.5.@.....1.0.5. .=. ...;.0.B.8.....1.0.6. .=. ...@.5.A.@.5.B.0.Z.5.....1.0.7. .=. ...8.A.B.0.....1.0.8. .=. ...:.>.=.5.....1.0.9. .=. ...5.B.0.Y.8.....1.1.0. .=. ...5.8.=.A.B.0.;.8.@.0.X.....1.1.1. .=. .#.:.;.>.=.8. .C.=.>.A.....1.1.2. .=. ...A.2.5.6.8.....1.1.3. .=. .#.:.;.>.=.8.B.8. .>.7.=.0.G.5.=.8. .C.=.>.A.?.....1.1.4. .=. ...5.8.=.A.B.0.;.8.@.0.B.8. .>.7.=.0.G.5.=.8. .?.@.>.3.@.0.<.?.....1.1.5. .=. ...>.3.@.0.4.Z.0.....1.1.6. .=.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (446), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:0370A43B65F652B883EF7FB20BFBB017
                                                SHA1:BA904238476AEF10DB916E1F478FED478E24B2EA
                                                SHA-256:EADC85C8748F3B86297B0F69A04964F5C72A2AF6A39CE3AE62224572750E7C0F
                                                SHA-512:9C9A44FCE1817C4F5D4984E2B3C5AFE5A893B46D87EFC1E100B90DD5E592A9E0D8D6D5F2F2B57B75B97B0D251C6EAB05DB0AD4DD6FE4EC0494AB7D64DEC4CBAA
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.r.p.s.k.i./.S.e.r.b.i.a.n. .....W.e.b.L.a.n.g.=.S.R.B.L.T.....T.r.a.n.s.l.a.t.o.r.=.D.r.a.g.a.n. .B.j.e.d.o.v. .d.r.a.g.a.n.b.j.e.d.o.v.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...0...6.............[.D.e.i.n.s.t.a.l.e.r. .L.i.n.i.j.a. .s.a. .a.l.a.t.k.a.m.a.].....1.0.2. .=. .I.z.g.l.e.d.....1.0.3. .=. .P.o.s.t.a.v.k.e.....1.0.4. .=. .D.e.i.n.s.t.a.l.e.r.....1.0.5. .=. .A.l.a.t.i.....1.0.6. .=. .P.r.e.s.r.e.t.a.n.j.e.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .D.e.t.a.l.j.i.....1.1.0. .=. .D.e.i.n.s.t.a.l.i.r.a.j.....1.1.1. .=. .U.k.l.o.n.i. .u.n.o.s.....1.1.2. .=. .O.s.v.e.~.i.....1.1.3. .=. .U.k.l.o.n.i.t.i. .o.z.n.a...e.n.i. .u.n.o.s.?.....1.1.4. .=. .D.e.i.n.s.t.a.l.i.r.a.t.i. .o.z.n.a...e.n.i. .p.r.o.g.r.a.m.?.....1.1.5. .=. .D.o.g.r.a.d.n.j.a.....1.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:data
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:E28499F183FE96F8E42D383630D3ECAF
                                                SHA1:8C02586B6120180E6CC7BD79FAE983AEE666BCBE
                                                SHA-256:C324CFCDA981FDEB77D4CB936ECE749A29071E9C5C90D10B096D7A14C6A94DA2
                                                SHA-512:08E34431F8A666D5DCFC16D7BB6E712ADA56291AEA78BE87B0545675A18207C23DA29E12D64170756728D600207A45ECA4D86D042395BF335ED3E3A05562D826
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=..{SO-N.e ./. .S.i.m.p.l.i.f.i.e.d.C.h.i.n.e.s.e.....W.e.b.L.a.n.g.=.S.C.H.....T.r.a.n.s.l.a.t.o.r.=.P.e.p.c.h.i.d. .(.m.e.@.p.e.p.c.h.i.d...c.o.m.).....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...V....1.0.3. .=. ...y.....1.0.4. .=. .xS}.hV....1.0.5. .=. ..]wQ....1.0.6. .=. ..s.N!j._....1.0.7. .=. ..Rh.....1.0.8. .=. ..V.h....1.0.9. .=. ..~......1.1.0. .=. .xS}.....1.1.1. .=. . Rd.ag.v....1.1.2. .=. .7R.e....1.1.3. .=. ..`nx.[.. Rd.@b..ag.v.T?.....1.1.4. .=. ..`nx.[.. Rd.@b...z.^.T?.....1.1.5. .=. ..R.f.e....1.1.6. .=. ..^.R....1.1.7. .=. .S_MR.]wQ.^.R..........1.1.8. .=. .;Nu...........1.1.9. .=. .sQ.N..........1.2.0. .=. ..`.N/f.|.~.{.tXT!.....1.2.1. .=. ..`nx.[.. Rd.@b...|.~.~.N.T?.\.n...\P.N,. .d.^..`...Ynx.[.`ck(WZP.NHN
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (510), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:32082A6864E2BA727DBAAE26C494F281
                                                SHA1:8B4B50E7E3A95A93E456656DB0118497C71CE7E1
                                                SHA-256:634933FD82DFA32FE6258CC77D3A68EB115F6B8A648FA6AB459D96FB71F69716
                                                SHA-512:F195F1B479C47EE9D42425F5BF74441275106CCBAA18DFF4AD384AAAD151D266FE899CA211D939444ED9758D2FEA17274A7BFABF1A7EBFA68E857C0BEC209999
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n...i.n.a./.S.l.o.v.a.k.....W.e.b.L.a.n.g.=.S.K.....T.r.a.n.s.l.a.t.o.r.=.L.u.m.i.r. .-. .l.u.m.i.r.@.s.t.o.n.l.i.n.e...s.k.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .Z.o.b.r.a.z.e.n.i.e.....1.0.3. .=. .N.a.s.t.a.v.e.n.i.a.....1.0.4. .=. .O.d.i.n.a.t.a.l...t.o.r.....1.0.5. .=. .N...s.t.r.o.j.e.....1.0.6. .=. .R.e.~.i.m. .l.o.v.c.a.....1.0.7. .=. .Z.o.z.n.a.m.....1.0.8. .=. .I.k.o.n.y.....1.0.9. .=. .P.o.d.r.o.b.n.o.s.t.i.....1.1.0. .=. .O.d.i.n.a.t.a.l.o.v.a.e.....1.1.1. .=. .O.d.s.t.r...n.i.e.....1.1.2. .=. .O.b.n.o.v.i.e.....1.1.3. .=. .U.r...i.t.e. .c.h.c.e.t.e. .o.d.s.t.r...n.i.e. .v.y.b.r.a.t... .p.o.l.o.~.k.u.?.....1.1.4. .=. .U.r...i.t.e. .c.h.c.e.t.e. .o.d.i.n.a.t.a.l.o.v.a.e. .v.y.b.r.a.t... .p.r.o.g.r.a.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (675), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F66C35E147B4BA36B84828F558724FC7
                                                SHA1:BF143C467AE0E394978F5F48CF13067D6ABF5A35
                                                SHA-256:7AC22AE651ED90C1ADFA83945322734D51807814598709ACC0F91804087DA511
                                                SHA-512:AB4CB440E44040CFCA2698740D67B5EA159EB6172DB7CF9B55E577A856C6510459E687D48BFE6BBFFEC1834522654756BB1A87A363294330D0E6C76583AFE456
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.S.l.o.v.e.n.a...i.n.a./.S.l.o.v.e.n.i.a.n.....W.e.b.L.a.n.g.=.S.I.....T.r.a.n.s.l.a.t.o.r.=.V.i.n.k.o. .K.a.s.t.e.l.i.c.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .P.o.g.l.e.d.....1.0.3. .=. .N.a.s.t.a.v.i.t.v.e.....1.0.4. .=. .O.d.s.t.r.a.n.j.e.v.a.l.n.i.k.....1.0.5. .=. .O.r.o.d.j.a.....1.0.6. .=. .L.o.v.e.c. .....1.0.7. .=. .S.e.z.n.a.m.....1.0.8. .=. .I.k.o.n.e.....1.0.9. .=. .P.o.d.r.o.b.n.o.s.t.i.....1.1.0. .=. .O.d.s.t.r.a.n.i. .\.n.p.r.o.g.r.a.m.....1.1.1. .=. .O.d.s.t.r.a.n.i. .v.n.o.s.....1.1.2. .=. .O.s.v.e.~.i.....1.1.3. .=. .S.t.e. .p.r.e.p.r.i...a.n.i.,. .d.a. .~.e.l.i.t.e. .o.d.s.t.r.a.n.i.t.i. .i.z.b.r.a.n.i. .v.n.o.s.?.....1.1.4. .=. .S.t.e. .p.r.e.p.r.i...a.n.i.,. .d.a. .~.e.l.i.t.e. .o.d.s.t.r.a.n.i.t.i. .i.z.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (628), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:77FC775F98A986CABAA1EF592DF4681E
                                                SHA1:D327461322D20A1BBCEA86BDD27FBC5E2058F043
                                                SHA-256:07CE496FAE3B0F26EF06F20BFE03A8E60FD96BCED6EF61C471CD7AC3BC3C500E
                                                SHA-512:63A93055C1082669D2217F5CE4FEBF0AA82D3A59738C3139916892BED929550BD14B9F5A6DA21480B4753ED5EF6BF5C811AF0A7078AE3EC05A740B7084C0D6BF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.E.s.p.a...o.l./.S.p.a.n.i.s.h.....W.e.b.L.a.n.g.=.E.S.P.....T.r.a.n.s.l.a.t.o.r.=.F.e.r.n.a.n.d.o. .G.r.e.g.o.i.r.e.,. .J.o.s.e. .V.i.l.l.a.l.b.a. .S.a.n.c.h.e.z.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...1...7.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.e.r.....1.0.3. .=. .O.p.c.i.o.n.e.s.....1.0.4. .=. .D.e.s.i.n.s.t.a.l.a.d.o.r.....1.0.5. .=. .H.e.r.r.a.m.i.e.n.t.a.s.....1.0.6. .=. .M.o.d.o. .C.a.z.a.d.o.r.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.c.o.n.o.s.....1.0.9. .=. .D.e.t.a.l.l.e.s.....1.1.0. .=. .D.e.s.i.n.s.t.a.l.a.r.....1.1.1. .=. .Q.u.i.t.a.r. .E.n.t.r.a.d.a.....1.1.2. .=. .R.e.f.r.e.s.c.a.r.....1.1.3. .=. ...E.s.t... .s.e.g.u.r.o. .d.e. .q.u.e. .d.e.s.e.a. .q.u.i.t.a.r. .l.a. .e.n.t.r.a.d.a. .s.e.l.e.c.c.i.o.n.a.d.a.?.....1.1.4. .=. ...E.s.t... .s.e.g.u.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (774), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9D4D0F41350759F705360E889C0EF5E1
                                                SHA1:8A1878835F20A525301556D09E2847942EC960EA
                                                SHA-256:0BA87F5E19BB9DCD8DB42D1051AB232D985EE0713492D59D37ABAF1FF1D9FA72
                                                SHA-512:546DD34D57DAB9D3784A8F17AFE2CBCE1022E07B295BAE4CA663C4E53BD2161B5DA8C5CE84B2A3CFD354C9E1DB7E717BA525F54A13D1753EAE7258DAEC9BBE78
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .S.v.e.n.s.k.a./.S.w.e.d.i.s.h.....W.e.b.L.a.n.g.=.S.W.E.....T.r.a.n.s.l.a.t.o.r.=.S.t.e.f.a.n. .L.j.u.n.g.w.a.l.l. .-. .l.j.u.n.g.w.a.l.l.@.g.m.a.i.l...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .V.i.s.a.....1.0.3. .=. .A.l.t.e.r.n.a.t.i.v.....1.0.4. .=. .A.v.i.n.s.t.a.l.l.e.r.a.r.e.....1.0.5. .=. .V.e.r.k.t.y.g.....1.0.6. .=. .J.a.k.t.l...g.e.....1.0.7. .=. .L.i.s.t.a.....1.0.8. .=. .I.k.o.n.e.r.....1.0.9. .=. .D.e.t.a.l.j.e.r.....1.1.0. .=. .A.v.i.n.s.t.a.l.l.e.r.a.....1.1.1. .=. .T.a. .b.o.r.t. .p.o.s.t.....1.1.2. .=. .U.p.p.d.a.t.e.r.a. .p.r.o.g.r.a.m.l.i.s.t.a.n.....1.1.3. .=. .V.i.l.l. .d.u. .v.e.r.k.l.i.g.e.n. .t.a. .b.o.r.t. .m.a.r.k.e.r.a.d. .p.o.s.t.?.....1.1.4. .=. .V.i.l.l. .d.u. .v.e.r.k.l.i.g.e.n. .t.a.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (579), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7262C82A010789707FCDDAD58EEA61BB
                                                SHA1:054873004D9CD2BD4F60117F8C74F5AA73A94FBA
                                                SHA-256:7F4519B478F322286096DC796529DF25BAB8AABCEB64218908F78DC7507C9A29
                                                SHA-512:FA0F1D78DA928252E7A744469994FF72660E79C3DABE975E725EF654608AD6ED6236A660BC44E5FAABF12F9C1DCAEA2DACDDDAD8166B49BD2171A324627AD5C9
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .2.).2.D..."./.T.h.a.i.....W.e.b.L.a.n.g. .=. .T.H.A.I.....T.r.a.n.s.l.a.t.o.r. .=. .P.o.r.n.c.h.a.i. .P.e.t.t.h.a.v.e.e.p.o.r.n.d.e.j.....C.o.d.e.p.a.g.e. .=. .U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...9.....1.0.3. .=. ...1.'.@.%.7.-.......1.0.4. .=. .B...#.A...#.!...-.....2.#...4.....1.I.......1.0.5. .=. .@...#.7.H.-...!.7.-.....1.0.6. .=. .B.+.!.....1...@...-.#.L.....1.0.7. .=. .#.2."...2.#.....1.0.8. .=. .D.-...-.......1.0.9. .=. .#.2.".%.0.@.-.5.".......1.1.0. .=. ...-.....2.#...4.....1.I.......1.1.1. .=. .%...#.2."...2.#.....1.1.2. .=. .#.5.@...#.......1.1.3. .=. ...8...A...H.C...+.#.7.-.D.!.H.'.H.2...8.....I.-.....2.#.%...#.2."...2.#...5.H.@.%.7.-...?.....1.1.4. .=. ...8...A...H.C...+.#.7.-.D.!.H.'.H.2...I.-.....2.#...-.....2.#...4.....
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:1741F9B110AF33284F55AB79B1C021CC
                                                SHA1:2F45A68B3DC13EED523DC5C657F0ACC35FB1F609
                                                SHA-256:75F2E61840EC81E7B7478D9981F5140974A84AB175D189B3BD8C42B27CE91C4E
                                                SHA-512:A692A9A4F794A378174EB648492B70F916791453CAE5E0F9B32950D93A8EDF2C2722209153B320133EA96C83B6CFAF74B4ACADA73C0752887E75A5D79E822E62
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .e.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .A~.-N.e ./. .T.r.a.d.i.t.i.o.n.a.l. .C.h.i.n.e.s.e.....W.e.b.L.a.n.g.=. .T.C.H.....T.r.a.n.s.l.a.t.o.r.=. .....C.o.d.e.p.a.g.e.=. .U.N.I.C.O.D.E.....V.e.r.s.i.o.n.=. .2...4...5..... .........[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ..j......1.0.3. .=. .x.......1.0.4. .=. ..yd..{.t.T....1.0.5. .=. .vQ.[.]wQ....1.0.6. .=. .us.N!j._....1.0.7. .=. ..n.U....1.0.8. .=. ..W:y....1.0.9. .=. .s.0}..e....1.1.0. .=. ..yd..[.....1.1.1. .=. ..yd....v....1.1.2. .=. ...ete.t....1.1.3. .=. ..`/f&T.x.....yd.x..S.v...v?.....1.1.4. .=. ..`/f&T.x.....yd..[.x..S.v.z._?.....1.1.5. .=. ...R.f.e....1.1.6. .=. ....f....1.1.7. .=. ..vMR.]wQ...f..........1.1.8. .=. ..}.z..........1.1.9. .=. ...e..........1.2.0. .=. ..`&N^..|q}.{.t.T!.....1.2.1. .=. ..`.x.....yd..[.x..S.v.|q}CQ.N.U?.\.n..`._.....[.`....#jZP!.....1.2.2.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (550), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BB7C613587724040DB123308D4A62FDF
                                                SHA1:190C1738F14952F9AAA5B0900B93E85C00700DE3
                                                SHA-256:5F9E53ABAE5E8F438C1CB01D4DE4C1EB459B340066EF8D19B9F677DD8C8BBDBD
                                                SHA-512:FE0EDFB942BCD54534B20D662B295E6D46D70730E4F865639B34BE8CE86FFCB8FE444615699DA78477A180B19B2165D563831289062E0AE321A714A438099E1E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T...r.k...e./.T.u.r.k.i.s.h.....W.e.b.L.a.n.g.=.T.R.....T.r.a.n.s.l.a.t.o.r.=.G.N.C.,. .s.e.c.r.e.t. .+.+.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...2...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .G...r...n...m.....1.0.3. .=. .S.e...e.n.e.k.l.e.r.....1.0.4. .=. .P.r.o.g.r.a.m. .K.a.l.d.1.r.1.c.1.....1.0.5. .=. .A.r.a...l.a.r.....1.0.6. .=. .A.v.c.1. .M.o.d.u.....1.0.7. .=. .L.i.s.t.e.....1.0.8. .=. .S.i.m.g.e.l.e.r.....1.0.9. .=. .A.y.r.1.n.t.1.l.a.r.....1.1.0. .=. .K.a.l.d.1.r. .(.S.i.l.).....1.1.1. .=. .K.a.y.d.1. .S.i.l.....1.1.2. .=. .Y.e.n.i.l.e.....1.1.3. .=. .S.e...i.l.e.n. .k.a.y.d.1. .k.a.l.d.1.r.m.a.k. .i.s.t.e.d.i.g.i.n.i.z.d.e.n. .e.m.i.n. .m.i.s.i.n.i.z.?.....1.1.4. .=. .S.e...i.l.e.n. .p.r.o.g.r.a.m.1. .k.a.l.d.1.r.m.a.k. .i.s.t.e.d.i.g.i.n.i.z.d.e.n. .e.m.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (657), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:83D527FE61A3CEC460137D696AF7465F
                                                SHA1:C6C2F9D8323EC851D3A973060FA0DCF8BA82D313
                                                SHA-256:D5B886DD759CD7442705A044CB12D174621E199BCEA5E8728E63BCF6896F6BCA
                                                SHA-512:C1CF615536667825F2DEA8A8CB763B0440CA23D3160F95BC2E960C1010BBE545B3A2832905EA927615A31810321268BF718F74AF2D03DFB9A9E121A919E1F8E1
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=. .#.:.@.0.W.=.A.L.:.0./.U.k.r.a.i.n.i.a.n.....W.e.b.L.a.n.g.=.U.K.R.....T.r.a.n.s.l.a.t.o.r.=.A.l.e.x.e.y. .L.u.g.i.n. .-. .a.l.e.x.@.u.k.r.l.o.c.a.l...i.n.f.o.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...4...5.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. ...8.3.;.O.4. .....1.0.3. .=. ...0.;.0.H.B.C.2.0.=.=.O. .....1.0.4. .=. ...5.V.=.A.B.0.;.O.B.>.@. .....1.0.5. .=. ...=.A.B.@.C.<.5.=.B.8. .....1.0.6. .=. . .5.6.8.<.\.n.?.>.;.N.2.0.=.=.O. .....1.0.7. .=. .!.?.8.A.>.:. .....1.0.8. .=. ...V.:.B.>.3.@.0.<.8. .....1.0.9. .=. ...5.B.0.;.V. .....1.1.0. .=. ...5.V.=.A.B.0.;.O.F.V.O. .....1.1.1. .=. ...8.4.0.;.8.B.8. .5.;.5.<.5.=.B. .....1.1.2. .=. ...=.>.2.8.B.8. .....1.1.3. .=. ...8.4.0.;.8.B.8. .2.8.1.@.0.=.8.9. .5.;.5.<.5.=.B.?. .....1.1.4. .=. ...5.V.=.A.B.0.;.N.2.0.B.8. .2.8.1.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-16, little-endian text, with very long lines (722), with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):0
                                                Entropy (8bit):0.0
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7B07AB2945C9171164A749833BEEEA7B
                                                SHA1:8EB3A4EBDDE4ADBA3CACA09B9C6E121E7B38FB26
                                                SHA-256:D79151B253E89F789C5BFDC5BABFDC167F6CAB830216F7D833106D27F14FDD24
                                                SHA-512:4C5E5BBFFB7D8F6926BC46D6F2D3BEFBED14A6CCFCC0F79F1193A26290B64014295047F21A1CF7450276A41919D52465C9E09441765FB8CA5F282499A77EE0AF
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:..;.L.a.n.g.u.a.g.e. .f.i.l.e. .o.f. .R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....;.T.h.i.s. .s.e.c.t.i.o.n. .m.u.s.t. .u.s.e. .E.n.g.l.i.s.h.....[.I.n.f.o.].....L.a.n.g.u.a.g.e.=.T.i...n.g. .V.i...t./.V.i.e.t.n.a.m.e.s.e.....W.e.b.L.a.n.g.=.V.N.....T.r.a.n.s.l.a.t.o.r.=.P.h.a.#.m. .T.u.....n. .K.h.a.n.h. .-. .p.t.k.9.1.1.@.y.a.h.o.o...c.o.m...v.n.,. .l.e.a.n.h.0.3.@.y.a.h.o.o...c.o.m.....C.o.d.e.p.a.g.e.=.U.N.I.C.O.D.E. .....V.e.r.s.i.o.n.=.2...3...9.............[.U.n.i.n.s.t.a.l.l.e.r. .T.o.o.l.b.a.r.].....1.0.2. .=. .H.i...n. .t.h.......1.0.3. .=. .C...i. .....t.....1.0.4. .=. .G... .b.......1.0.5. .=. .C...n.g. .c.......1.0.6. .=. .S...n. .t...m.....1.0.7. .=. .D.a.n.h. .s...c.h.....1.0.8. .=. .B.i...u. .t.....n.g.....1.0.9. .=. .C.h.i. .t.i...t.....1.1.0. .=. .G... .b.......1.1.1. .=. .X.o...a. .t.r.o.n.g. .r.e.g.i.s.t.r.y.....1.1.2. .=. .L...m. .m...i.....1.1.3. .=. .C... .p.h...i. .b...n. .m.u...n. .x.o...a. .r.e.g.i.s.t.r.y. .m.u.#.c. ..... .c.h...n. .?.....1.1.4. .=. .C... .p.h...i. .
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:InnoSetup Log 64-bit Revo Uninstaller {A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}, version 0x418, 17121 bytes, 701188\37\user\37, C:\Program Files\VS Revo Group\Revo Uninst
                                                Category:dropped
                                                Size (bytes):17121
                                                Entropy (8bit):3.7184542656682025
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:4FA9AA8585F0DDB2C5B9A7F834298CF1
                                                SHA1:2A657B3CD0833C3632B5466F9FDB5E264F82FE6E
                                                SHA-256:1C95886FF402DA374778ED1905F95643E237CEF6D0095981FDF0ABED909B22C7
                                                SHA-512:36EB47219EB5495352DE3D8CDDCB1577B50CE45D6D903E70C01C4F11F9AEC8D0504EA41774D7DB6BB2A558032D4991155898A57B8948CF0ED47E630D12B0B82A
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:Inno Setup Uninstall Log (b) 64-bit.............................{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}..........................................................................................Revo Uninstaller....................................................................................................................J....B..%..................................................................................................................`.........nM................7.0.1.1.8.8......t.o.r.r.e.s......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r....................... ..............IFPS.... ...............................................................................................................................................................BOOLEAN..............TEXECWAIT.........TSETUPSTEP.............TARRAYOFSTRING.................!MAIN....-1.....<.......GETCUSTOMSETUPEXITCODE....11..WIZARDSILENT.......SHELLEXEC.............%...
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:InnoSetup messages, version 5.5.3, 221 messages (UTF-16), &About Setup...
                                                Category:dropped
                                                Size (bytes):22709
                                                Entropy (8bit):3.2704486925356004
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:79173DA528082489A43F39CF200A7647
                                                SHA1:AA253B477CE2BF9D886D07694CD5DDB7C7FE9EEC
                                                SHA-256:4F36E6BE09CD12E825C2A12AB33544744E7256C9094D7149258EA926705E8FFD
                                                SHA-512:C46EB9DD3D03A993FDC4F65AE2751ECFDCB1FB6E1FB69A119105FD40290CE5EC4427B04F813EED47415390689943D05B5432D4571B1ACA0CE37EE52391790D18
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:Inno Setup Messages (5.5.3) (u).....................................hX..........&.A.b.o.u.t. .S.e.t.u.p.........%.1. .v.e.r.s.i.o.n. .%.2.....%.3.........%.1. .h.o.m.e. .p.a.g.e.:.....%.4.....A.b.o.u.t. .S.e.t.u.p...Y.o.u. .m.u.s.t. .b.e. .l.o.g.g.e.d. .i.n. .a.s. .a.n. .a.d.m.i.n.i.s.t.r.a.t.o.r. .w.h.e.n. .i.n.s.t.a.l.l.i.n.g. .t.h.i.s. .p.r.o.g.r.a.m.....T.h.e. .f.o.l.l.o.w.i.n.g. .a.p.p.l.i.c.a.t.i.o.n.s. .a.r.e. .u.s.i.n.g. .f.i.l.e.s. .t.h.a.t. .n.e.e.d. .t.o. .b.e. .u.p.d.a.t.e.d. .b.y. .S.e.t.u.p... .I.t. .i.s. .r.e.c.o.m.m.e.n.d.e.d. .t.h.a.t. .y.o.u. .a.l.l.o.w. .S.e.t.u.p. .t.o. .a.u.t.o.m.a.t.i.c.a.l.l.y. .c.l.o.s.e. .t.h.e.s.e. .a.p.p.l.i.c.a.t.i.o.n.s.....T.h.e. .f.o.l.l.o.w.i.n.g. .a.p.p.l.i.c.a.t.i.o.n.s. .a.r.e. .u.s.i.n.g. .f.i.l.e.s. .t.h.a.t. .n.e.e.d. .t.o. .b.e. .u.p.d.a.t.e.d. .b.y. .S.e.t.u.p... .I.t. .i.s. .r.e.c.o.m.m.e.n.d.e.d. .t.h.a.t. .y.o.u. .a.l.l.o.w. .S.e.t.u.p. .t.o. .a.u.t.o.m.a.t.i.c.a.l.l.y. .c.l.o.s.e. .t.h.e.s.e. .a.p.p.l.i.c.a.t.i.o.n.s... .A.f.
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Apr 26 12:03:28 2024, mtime=Fri Apr 26 12:03:29 2024, atime=Tue Dec 6 08:12:10 2022, length=1467128, window=hide
                                                Category:dropped
                                                Size (bytes):1162
                                                Entropy (8bit):4.492039445352422
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:05D95FA14EC0C098DF2093062E47AE8B
                                                SHA1:512C323C6B6392726EEA5B61434C117C08A5A6B3
                                                SHA-256:DC15AB1B0E509D5AA405CF1960E46E6F82328AE8867168E0AFE0656D5C5012F0
                                                SHA-512:F88761F1E8B68C796A05AFA64E3D18E8BFDF19931BFB6DE31806ABDB9B61A1EDDC9933C652D3089EB926ACF5716F408FB9C85C41AB2632192D339D3622D7EE89
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.... ...H6.!....q#"....Q..R....b...........................P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....d.1......Xnh..VSREVO~1..L......Xnh.Xoh..............................V.S. .R.e.v.o. .G.r.o.u.p.....j.1......Xoh..REVOUN~1..R......Xnh.Xoh..........................CCn.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.......2..b...U.I .REVOUN~1.PDF..d......Xoh.Xoh....I.........................R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .H.e.l.p...p.d.f.......x...............-.......w...........~.Q......C:\Program Files\VS Revo Group\Revo Uninstaller\Revo Uninstaller Help.pdf..X.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r. .H.e.l.p...p.d.f./.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.`......
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:MS Windows 95 Internet shortcut text (URL=<https://www.revouninstaller.com/>), ASCII text, with CRLF line terminators
                                                Category:dropped
                                                Size (bytes):58
                                                Entropy (8bit):4.583564668215613
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:8E02440366A76E3DCEED1E12C0CE25E2
                                                SHA1:CC3CE2A9230FCE87BE3621043417BAF82CA6427A
                                                SHA-256:DD1FD179E29F6E68371C78A2C2E1C4DA61C00BE358D54B92C868B8F85D509BD7
                                                SHA-512:837B0FBAD3CB8EC83BF5AFF2A275260A285D84CFC2E4BCBA40F102CC233E09D5BB9CA4F378ADCCCA194EC5C38171D8E7FA32DDEC4D90615D86C8A8CF37621141
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:[InternetShortcut]..URL=https://www.revouninstaller.com/..
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Apr 26 12:03:28 2024, mtime=Fri Apr 26 12:03:28 2024, atime=Tue Jun 6 06:34:02 2023, length=15111408, window=hide
                                                Category:dropped
                                                Size (bytes):1097
                                                Entropy (8bit):4.512484705004548
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F93435E57409819DFD750ACB3022AF7F
                                                SHA1:569AC6ED3329A445B51C4968ADFDDFAF84B16CDB
                                                SHA-256:6DD917506E6D9EE7691537F3291CDFE0A1ADC3FD4658CBFB1F7852644D8475E9
                                                SHA-512:F65E13D88D4BC2C5B08142274AF79939ECDE57231C73BA96EDED8758FD90990C9F12658B83D3FA295370548F3B8B7F14CF7381293B238CB4D98F64162A61A462
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.... ......!...V..!....Q.CI...............................P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XXh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....d.1......Xnh..VSREVO~1..L......Xnh.Xnh..............................V.S. .R.e.v.o. .G.r.o.u.p.....j.1......Xoh..REVOUN~1..R......Xnh.Xoh..........................CCn.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....f.2.....VA< .RevoUnin.exe..J......Xoh.Xoh..............................R.e.v.o.U.n.i.n...e.x.e.......k...............-.......j...........~.Q......C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe..K.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.\.R.e.v.o.U.n.i.n...e.x.e./.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.`.......X.......701188...........hT..CrF.f4... ....F...../....%..hT..CrF
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Apr 26 12:03:27 2024, mtime=Fri Apr 26 12:03:27 2024, atime=Fri Apr 26 12:03:09 2024, length=1348392, window=hide
                                                Category:dropped
                                                Size (bytes):1097
                                                Entropy (8bit):4.507476374114704
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:2DA8E49DB6FCEB6F4A7C5958CD6BC979
                                                SHA1:07BB199289E8F1DAA84B05EC1D2CB970B61BED3D
                                                SHA-256:D064DD0E3BA12F0B4BBFB15EAF0DD7C7221E1A17372E5670318621010AB623D9
                                                SHA-512:B27765E52BA3576DABFA10DA95238E8C67B6CFFAECF8DB6515E8E9E0FDAF439B47AD534F70052641FA1285ACAE34DAA3168D7E066F212FC8B44E41A26692CCC6
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.... ...... ...2..!...Q......(............................P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....d.1......Xnh..VSREVO~1..L......Xnh.Xoh..............................V.S. .R.e.v.o. .G.r.o.u.p.....j.1......Xoh..REVOUN~1..R......Xnh.Xoh..........................CCn.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....f.2.(....Xeh .unins000.exe..J......Xnh.Xnh....G.........................u.n.i.n.s.0.0.0...e.x.e.......k...............-.......j...........~.Q......C:\Program Files\VS Revo Group\Revo Uninstaller\unins000.exe..K.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.\.u.n.i.n.s.0.0.0...e.x.e./.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.`.......X.......701188...........hT..CrF.f4... ....F...../....%..hT..CrF
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Fri Apr 26 12:03:28 2024, mtime=Fri Apr 26 12:03:29 2024, atime=Tue Jun 6 06:34:02 2023, length=15111408, window=hide
                                                Category:dropped
                                                Size (bytes):1079
                                                Entropy (8bit):4.5112041503489495
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:608B506D03E3B787B0C02A9373A47576
                                                SHA1:95886BF946C808D08C98C9C65AC174DDD0358163
                                                SHA-256:178BD274079AFC19134AD2BD7E796EB0984CEB40DB78CC5A01DB4EC630C2BEF7
                                                SHA-512:796EBEA22B73EF129E43BF3067D73EE93A29F2F7A907D7A43450C03AA08EDE0EDC7ABE16519A2E6DD292F0F8719E97DB0D0BEAD2487C3C68106581BDA999A4D9
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.... ......!...V./"....Q.CI...............................P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....d.1......Xnh..VSREVO~1..L......Xnh.Xoh..............................V.S. .R.e.v.o. .G.r.o.u.p.....j.1......Xoh..REVOUN~1..R......Xnh.Xoh..........................CCn.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.....f.2.....VA< .RevoUnin.exe..J......Xoh.Xoh..............................R.e.v.o.U.n.i.n...e.x.e.......k...............-.......j...........~.Q......C:\Program Files\VS Revo Group\Revo Uninstaller\RevoUnin.exe..B.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.\.R.e.v.o.U.n.i.n...e.x.e./.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.S. .R.e.v.o. .G.r.o.u.p.\.R.e.v.o. .U.n.i.n.s.t.a.l.l.e.r.`.......X.......701188...........hT..CrF.f4... ....F...../....%..hT..CrF.f4... ....F...../
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                Category:modified
                                                Size (bytes):22103
                                                Entropy (8bit):5.02883367598602
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:953D5E9A4211CEBCA23D6FD30DF1ACE0
                                                SHA1:919E0957170338A41A0106D83C98554498FC4919
                                                SHA-256:251E7BF06C8627F63BC08EF3608E9BE85AFBB37C5DD37BCEC9839357EDA74886
                                                SHA-512:931A29C062D6156A8310EEDC9D3DE6D6B360427364025CBEFCB5E51CA08DDC389C8EBD3917D6E1B02B832B1FE1FD85B47E6C43723C03A00D5B766297EDBB7781
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.2024-04-26 15:03:10.138 Log opened. (Time zone: UTC+02:00)..2024-04-26 15:03:10.138 Setup version: Inno Setup version 5.6.1 (u)..2024-04-26 15:03:10.138 Original Setup EXE: C:\Users\user\Desktop\revosetup.exe..2024-04-26 15:03:10.138 Setup command line: /SL5="$202EE,6355320,266240,C:\Users\user\Desktop\revosetup.exe" ..2024-04-26 15:03:10.138 Windows version: 10.0.19045 (NT platform: Yes)..2024-04-26 15:03:10.138 64-bit Windows: Yes..2024-04-26 15:03:10.138 Processor architecture: x64..2024-04-26 15:03:10.138 User privileges: Administrative..2024-04-26 15:03:10.553 64-bit install mode: Yes..2024-04-26 15:03:17.675 Created temporary directory: C:\Users\user\AppData\Local\Temp\is-APUB4.tmp..2024-04-26 15:03:27.142 Starting the installation process...2024-04-26 15:03:27.158 Creating directory: C:\Program Files\VS Revo Group..2024-04-26 15:03:27.158 Creating directory: C:\Program Files\VS Revo Group\Revo Uninstaller..2024-04-26 15:03:27.158 Creating di
                                                Process:C:\Users\user\AppData\Local\Temp\is-QDQK0.tmp\revosetup.tmp
                                                File Type:PE32+ executable (console) x86-64, for MS Windows
                                                Category:modified
                                                Size (bytes):6144
                                                Entropy (8bit):4.720366600008286
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                Malicious:false
                                                Antivirus:
                                                • Antivirus: ReversingLabs, Detection: 0%
                                                • Antivirus: Virustotal, Detection: 0%, Browse
                                                Reputation:unknown
                                                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                Process:C:\Users\user\Desktop\revosetup.exe
                                                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                Category:dropped
                                                Size (bytes):1348392
                                                Entropy (8bit):6.530593804695602
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7B77E7C3EBD213D95C4D909716F10030
                                                SHA1:1C00EB97B4F154E209162BEE83A84A6F1D1EF034
                                                SHA-256:A1BAB1631135A982DFEC6024B1EF8EB1EA2BCE519CD832D9151E95E8DEF916D2
                                                SHA-512:FB6F95D42A936911B66861280CDEEE77E2125C6B30141EB66DAFF402453D635A87A7F8EC9435CEB7AD4FDDB473D6347A787BEDB5649AA3ABB234ACEEEAAF8DCD
                                                Malicious:false
                                                Antivirus:
                                                • Antivirus: ReversingLabs, Detection: 3%
                                                • Antivirus: Virustotal, Detection: 0%, Browse
                                                Reputation:unknown
                                                Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...Rm"[.....................8.......%.......0....@..................................m....@......@..............................@8...@...............R..(A...................................0.......................................................text............................... ..`.itext.............................. ..`.data....0...0...2..................@....bss.....a...p.......L...................idata..@8.......:...L..............@....tls....<.... ...........................rdata.......0......................@..@.rsrc........@......................@..@....................................@..@........................................................................................................................................
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:03:35 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2677
                                                Entropy (8bit):3.985883681835673
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:085164EA22696AFE7CF079D9E21761B2
                                                SHA1:4026D829DB34A41C7BD1DCF6C53B1A69EA1D6AFC
                                                SHA-256:5FD099A64C5E6FCFD80055813EDBEB007C96CD0D37FC3A3F090F669923A0D6E4
                                                SHA-512:429AB0720285DEA25547454BE87A347768B67C3F930EF69532A80A63F4D33CCDBDDDF44C292410F348A240C620880431E329AED45CDA7869600EB154D28CAF2E
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,.....".%.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Xrh...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:03:35 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2679
                                                Entropy (8bit):3.9963098394258227
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:8D161389AA3A6B010182E6D07CE618B9
                                                SHA1:4B764C751C42595D1A79A2877397B5AEDA287471
                                                SHA-256:4CE4314056B1CEE02781FEA79E199FB73DAEBA22257BC925FF57B1A590AC5D07
                                                SHA-512:9F7A9CE12582F4BF5836BF9D74B9354D9B42E8034D3DE88E84C1C633D42006F7812DC8B3BE39EF0E3ABE7DF74F6A9E97C882D39F7A959DEB50235536E97F171F
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,.......%.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Xrh...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2693
                                                Entropy (8bit):4.009092058701919
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:98A69211D5411F507426E42411869EAD
                                                SHA1:CF5D6735B558E3C36AD3A16D1B8D3418FAB8D833
                                                SHA-256:8C807FC16873AF5D9913A69CA44FA4B828C92CCE18454752E2872A0EE3A0EA9C
                                                SHA-512:A9B7A89BEF76BFD529F24C875CEAAC79195A5FFBD9E4FE1F7440DCDD091BE5DC55093B1EBE56BACC64CDB429C7CE336CC76D9FF4DECE8C91497A270D278E4738
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:03:35 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2681
                                                Entropy (8bit):3.997393040963818
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7DFE774C4CE3818FDA0743B809932732
                                                SHA1:A236A9746E4E923D2476DF0754C01B9F58B3CD53
                                                SHA-256:C499FA037B93E2F018C0C02509B94B7685C48E10DC976B063FA379B144AA4B33
                                                SHA-512:1D9C9D197F022561C2051BA6670CA8414E16A7FE07F07F9E90C40D4A567D57FCAF7817D8917603C5E646B4001B620C597B999E6E5ED070E0D2571FBC552FF7AC
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,.....?.%.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Xrh...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:03:35 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2681
                                                Entropy (8bit):3.9866738656213685
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A2B0EFB3818ADDFE4D5D93BC4EB38CEC
                                                SHA1:A42E91D218967858B43E3B773EF1580EFB91177F
                                                SHA-256:BC30C2E73CB09870EF2625410783A6412836F2FCC5E2D6056DF98A6D3CCD0934
                                                SHA-512:A51FE11FD7318AD1AF0650CB4B3DDBC64AD061914EAF23589E21137EA72892029110BF23559E9EC5BCB88B093C01048B2B2EE75E0C6FE903A97AC9B04A5E0A96
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,.......%.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Xrh...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:03:35 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                Category:dropped
                                                Size (bytes):2683
                                                Entropy (8bit):3.998759595763276
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:663E87F227B6FCD5DD2180FC48F840F6
                                                SHA1:85BF3018CDE620ACEA22FE4545B5271AEFF21C03
                                                SHA-256:5A88D17E03A47EDA8942DD52175F71C7C0227266079B1B84F92A4C25DF2F9592
                                                SHA-512:0F1BD17096990DC1054DC9EE6BDCBE1866C77150CC7879C4F2864BE78B1B57189D18358E8B067692CE595BE946120B2CDFA85101D8DCFD3065E60A059117D282
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:L..................F.@.. ...$+.,....4..%.......y... w......................1....P.O. .:i.....+00.../C:\.....................1......Xnh..PROGRA~1..t......O.I.Xoh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Xqh....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.Xqh....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.Xqh...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.Xrh...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........~.Q......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 19128, version 1.0
                                                Category:downloaded
                                                Size (bytes):19128
                                                Entropy (8bit):7.9868431514866085
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:885D32CF40294B2D69B2F58BB27468B7
                                                SHA1:C1C9DB162121048BF585AA8915AD88C2820D17C4
                                                SHA-256:C8545021FFD4B062EA76DF6AB092F50A7C0DE35D61132769DC7B43AFCDB0FC75
                                                SHA-512:EE625ED97724A5E4861EF595A962D42E2E9AB935DB201FD7A320AC0DFFCEC82FF11FFD20BDACE74A7EAF6D61E1DA01A7A9481A0D1CBBD7168D011CE0F9D9EF18
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/kanit/v15/nKKU-Go6G5tXcr4-ORWnVaE.woff2
                                                Preview:wOF2......J........t..JV.........................F..P....`.....,........@.....h..6.$..L. ..d.."..V.+.5...Aw..b.zp..8.."...=.0......$'26Pa.w5..1.M2.0.2...5.+*:N.....W....,:V.+..&...!|x....&L}..(~.";2...../.3..p...P..5`%.^.'1.X.}........0.0y................7....Pz1.W...h...t.E........mv`b.*...}T.........].".k._...s..H..w....L.k....j..*.@.O ...oJ.k.o...|...5Y)...L.|?..f.R.^...yA......~....t....`[7DK...CS.o....hN[._!..P.-j.~Fwz.@%. ,.....M.{.}..e..b.....j..P..d......\{.1....O.X.Y.]...4.....]...:W..2..8.f3....,..- ..r].p.....q.o).0.....L-..i.R..G..}...6.)%p!P..l...s...2...)f..M..-.W..5.....&^ ..)l.....?..m.*.1.........u. -.w.=.(W..'9.$g.C*...v...........@.....T..'............n....X8-.......X..G.Y[.............`....}.}.7..).q...[.f!.T Q@=.VK..3H..{.........:""C..1d.%....."....Zj%.w...c8.%M........I...is.)r. ..!ji..Q..8..R...b..P..0.\.........K..~I.n.O...D$.!;..hv.)7.`..._.........n..-@...c.....E.u...o....."..b...:..5.kJ.^.F..Xe.k3.`.1...6..-......y.S..Ie
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 24984, version 1.0
                                                Category:downloaded
                                                Size (bytes):24984
                                                Entropy (8bit):7.992209564589015
                                                Encrypted:true
                                                SSDEEP:
                                                MD5:303A79D404D97CCBB3D803088FC387D8
                                                SHA1:66E3525B79A1A58A63FE0934F31676DD40C7F033
                                                SHA-256:7E510E61C497D334DA21ECCDA06DF5D3A428C9EA94D6903B6138E7C7255ABA0F
                                                SHA-512:5751D97634F0FD270E36044A1EF077C0EC1D9B146BD8E5D28207A083CB350FA467E083433C2F81CFF896AC7E3756B7014A408FEB203F2D175FDEBA0A37F3614E
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTUGmu1aB.woff2
                                                Preview:wOF2......a...........a...............................j?HVAR.V.`?STAT.$'....+...|.../V....`.D..j.0..T.6.$..>. ..~.......'...6.Yw.....=W.y.DL.4.a.&)....N.!C.n..R.....".".P..=.#.L........62....2...e.z.V..U...r.H.Y.T.ZdkK...#ux3*,..&.I..dcb.[.>.....)g9up..f4.p..D.l...V..iEl.A..e....z.S..v.......c?.<..w...{V.9..C.=0MsF..o9......[.3...K..'...`....HA....b5..ms.l+.t....a...^......m.[..*.8.....A.DR@.3P..F0. ...s..XT}T. .......MzK(.FX..3<m..o.!..z....."..]3.e$ .X...Y.f].n7.([....{....@......sxC....8...9q........XJ........&m..e...M.. . A.B..!!x..AK}.i;Q.[.........N;..u.A...w9qA..4...I..q..e...o.....C.UVW.}.rn.x.W.8.kP.C<..{.3o.G&U.......25..3.../..k..uK..BB......(D....?....xgf...8...U)..Y%j.p.2....^....Q..!...".......a...P.../m.w&<.....R.1..FZ]H.8):.3...\...wV.P........K..@.j..C.:..jE..L...R.Z..@.<....y-_hsj.+J`....i. ..Ba.S..4...|o@.R.R..8.!..t.3y!U!J..X.....*...i..+..P.X..M...K5..fgF+.F..V.! .....X.B.......*..i.]..m.......*..`[>.q..m..w.......fC<
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:JSON data
                                                Category:dropped
                                                Size (bytes):593
                                                Entropy (8bit):5.194873040696454
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9492E14933680EF28B60770DAF7D8C96
                                                SHA1:0A419597517C16D0C90E21A58610DDFEC6428379
                                                SHA-256:EB8995EE04CEEFC8D79D5D0834390C6F34915AC5E9C5F4F1297FDBCE6D43EFD3
                                                SHA-512:ADF12A12A54C649BB538FA1E0E3F85622FA63779C1804DD33A1629A65D9A4BD04BDC45C0D89199D7324F25C582C0C70241E53BAD3274CA2B6207B628DA10AA7D
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:{"brand":"VS Revo Group Ltd","brandCount":1,"color":"#78A300","embeds":{"chat":{"embed":"chat","props":{"color":"#78A300","zopimId":"393O9gB158xzzs9O82F04ypD5NUqTehW","standalone":true,"badge":{"color":"#1a3958","enabled":true,"imagePath":"https://v2assets.zopim.io/393O9gB158xzzs9O82F04ypD5NUqTehW-banner?1654172833774","layout":"image_right","text":"Chat with us"},"forms":{"offlineEnabled":true,"preChatEnabled":true},"mediatorHost":"widget-mediator.zopim.com"}},"launcher":{"embed":"launcher","props":{"color":"#78A300"}}},"features":{"prechatFormVisibleDepartments":true,"fastLoad":true}}
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                Category:dropped
                                                Size (bytes):17708
                                                Entropy (8bit):7.961995178306922
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:E8F01FC47E082B951FE241FD1A291696
                                                SHA1:C0F4360BC45556C7DCEC18EBD590278DE10B07B1
                                                SHA-256:936CB6D96F115D51E7A2AC5AA09BB2C247A7DAA04951FF4B82DD14518FF2E6AF
                                                SHA-512:3CA6EF7944784E82445F1D33E3FED828D5790D3B6BBB7078B4E57AC4B29526440EE5F9F214AF03CF41F4358393FFF1527FB07FFC1F37CC0C6C522A47B984439B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR..............>a.....tEXtSoftware.Adobe ImageReadyq.e<...&iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c145 79.163499, 2018/08/13-16:40:22 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2019 (Windows)" xmpMM:InstanceID="xmp.iid:0F6802E988E311ECA41C8B17AD6825A0" xmpMM:DocumentID="xmp.did:0F6802EA88E311ECA41C8B17AD6825A0"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:0F6802E788E311ECA41C8B17AD6825A0" stRef:documentID="xmp.did:0F6802E888E311ECA41C8B17AD6825A0"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>A@p...A.IDATx..}..\iu...^{....$.F..3630f....98...`.....'...$89.$6..x!6'..x#`.`..........VK..]{...?........I..f.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (7789)
                                                Category:downloaded
                                                Size (bytes):8949
                                                Entropy (8bit):5.3609544985257305
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:66D3845E457BB829A08E82514C2929D3
                                                SHA1:5D7BE81EC42FB204EC3BB4E1318A951F6F252255
                                                SHA-256:42C1C119FFD369CB0603C073AAA1AD9C4BC67F01CB3BAA30A498D7243A0F6622
                                                SHA-512:24CF8DE1BFECE0AE94A5EC63E296DB8B0E8A828FD7D18D02AEB995A7A1D1D0A38DB125EE40C4AC7B2EDD9EEC851F0AFDBF92EFEE9D0FF9F72F390F40AFD47F2A
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.hotjar.com/c/hotjar-2449252.js?sv=7
                                                Preview:window.hjSiteSettings = window.hjSiteSettings || {"site_id":2449252,"r":0.45377386160714284,"rec_value":0.0,"state_change_listen_mode":"automatic","record":true,"continuous_capture_enabled":true,"recording_capture_keystrokes":true,"session_capture_console_consent":false,"anonymize_digits":true,"anonymize_emails":true,"suppress_all":false,"suppress_all_on_specific_pages":[],"suppress_text":false,"suppress_location":false,"user_attributes_enabled":false,"legal_name":null,"privacy_policy_url":null,"deferred_page_contents":[],"record_targeting_rules":[],"feedback_widgets":[],"heatmaps":[],"polls":[],"integrations":{"optimizely":{"tag_recordings":false},"abtasty":{"tag_recordings":false},"mixpanel":{"send_events":false},"unbounce":{"tag_recordings":false},"google_optimize":{"tag_recordings":false},"hubspot":{"enabled":false,"send_recordings":false,"send_surveys":false}},"features":["feedback.widgetV2","survey.embeddable_widget","error_reporting","ask.popover_redesign","survey.screenshots","
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 7281
                                                Category:downloaded
                                                Size (bytes):2030
                                                Entropy (8bit):7.910893877165037
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:0BED8F219278D79878D48AF3082F466E
                                                SHA1:B26B7FD8D8397B68AE6F1510034E0671883556D5
                                                SHA-256:1AE19D1393877A59253B33B2FE2D410E7113B252F003B9E1189110F6A27DD55A
                                                SHA-512:A6807B3CB82CEADF5A5D19B9BBED37F7265A7F120C27216D5F2421B7AC656C5056C2E6F22AA8CB01A2A0EAB304D396B5E97EA0C3B6F269DD71DD6D48E137E051
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://widget.trustpilot.com/trustboxes/5419b6a8b0d04a076446a9ad/index.html?templateId=5419b6a8b0d04a076446a9ad&businessunitId=600037798b18380001bcf594
                                                Preview:...........Y_o.6...O.zQ ...;..........{(p.S@....E*$..5..;..X.e'...fE..g~...3......_....(........-3F....r+....4..BY.=.T...i....W.9........&.....2%...V..f.b%-. *.....];.....]c.W..DbR..Y..O,..'.4.l..+.]...gs....GB.O.....a.I.iLb..:.R...Oq.A&V.a.....,.<O1..?F.?a....lr".6V.G..J......Z.".G....,.1.u.S.......3A.=8Q:.D`Q..I.-... ..Jb.m..,....j.`K1.. J..n.\...-....Q0...h.4.."@.4.K..`.,.$+.J[...2Zc..u3L..D......#&%......DJ..p.H .!.........Y8.N.]...K.*..\.0Z1.......0"......f5...K:.....rS...}.l.+7.J.1.f6.m}@.f...P*.......!#.#..c.K".....j...p2Y4C....a.+!HaX...5..>.^.V......u8....s.D.a%.........."M` 2.....e...[i}..r7.n/l.<....... S...BD<<...D......4(aOk.....F8........VDDRt..&..8.kbl.......@.....O[f....n....hR.b....ZG.(..S.vy.c_(...J..H...,qn.vQ(.].$2J..-.*<....{..~$.eg.00r..o.7..N.. ...*E.d.....g.x........}. RZ.w/N.f..|Z...k..!FM.M...U.s..I.......I)....8.#.;..%.......0...vAm.,...xA.lN.{z.~..1..R.iK.7....2.&.%.....-....87%E8.......U..u.....&.W[..u.V..l..n.=c.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (65324)
                                                Category:downloaded
                                                Size (bytes):159515
                                                Entropy (8bit):5.07932870649894
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7CC40C199D128AF6B01E74A28C5900B0
                                                SHA1:D305110FB79113A961394B433D851A3410342B8C
                                                SHA-256:2FF5B959FA9F6B4B1D04D20A37D706E90039176AB1E2A202994D9580BAEEBFD6
                                                SHA-512:CE79937F81CDA05F54EA67C1E8A96101285B46F6EDE02BC2687A0D574832B2C7D3A0D43FF40D1E35D51BBEC4B038852825D323146DA7752BEBD0BA37669B13A9
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/css/bootstrap.min.css?ver=4.4.1
                                                Preview:/*!. * Bootstrap v4.4.1 (https://getbootstrap.com/). * Copyright 2011-2019 The Bootstrap Authors. * Copyright 2011-2019 Twitter, Inc.. * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */:root{--blue:#007bff;--indigo:#6610f2;--purple:#6f42c1;--pink:#e83e8c;--red:#dc3545;--orange:#fd7e14;--yellow:#ffc107;--green:#28a745;--teal:#20c997;--cyan:#17a2b8;--white:#fff;--gray:#6c757d;--gray-dark:#343a40;--primary:#007bff;--secondary:#6c757d;--success:#28a745;--info:#17a2b8;--warning:#ffc107;--danger:#dc3545;--light:#f8f9fa;--dark:#343a40;--breakpoint-xs:0;--breakpoint-sm:576px;--breakpoint-md:768px;--breakpoint-lg:992px;--breakpoint-xl:1200px;--font-family-sans-serif:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,"Noto Sans",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";--font-family-monospace:SFMono-Regular,Menlo,Monaco,Consolas,"Liberation Mono","Courier New",monospace}*,::after,::before{box-sizing:
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with no line terminators
                                                Category:downloaded
                                                Size (bytes):16
                                                Entropy (8bit):3.75
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A2EF88E7A0848BC7D9A148E39372E7AE
                                                SHA1:8B2A9649ED6BF2B6C46030F43CE09A5D616EC231
                                                SHA-256:B3CEBF486137DBBBED4646E526A3C7B6BEAACFE717B0B9EF701AB291F24A429F
                                                SHA-512:C003DDAE7492ACFDB023030AFFF8E03D7D0D0238C4BD55D37B22AA89598C548BB77E6567A8820E3EB67BF5F03C4E0402D2840370DEA8C3CCB09FDB4AB407F73A
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAnhpvaNIW-d-xIFDc9OUJg=?alt=proto
                                                Preview:CgkKBw3PTlCYGgA=
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 1600 x 842, 8-bit colormap, non-interlaced
                                                Category:dropped
                                                Size (bytes):117465
                                                Entropy (8bit):7.974632553069143
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C906D9048E7FD55333ED12D888B634E2
                                                SHA1:E56F1996B4723BAB72EB430CBCECB373198F88B7
                                                SHA-256:568849A9B53202C322377A9061B5F918FD01FFFE5E76783AFE5D323A1D6400A6
                                                SHA-512:7D84FAA42EBC3341F6EF7825C5C1D8319D48187E34A756067D96B81B93AD699EC86A444E9EF61B920255A6479716A06046931B7A1D57B279EC6BF5FCBBBCB9B0
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR...@...J......qrT....PLTE.......x....................................................................................................V`.........x.................................................cl..v......~....FF..............gl~......os.klr....y......s........@FY.............}..A@K".$........trxNHL..._br...{|..............2)+..][`.....A9;JPeVSWx..gccSXn.|z/1@|.......P8....tljo{..........oi......]D;..........z.....o....6.S.../7WaRK,.....lVU.86.......wd[........e......yo.G}..............5j....Ey...............'Y.t..Dcv...]w.............Nc.5Ve...K$.9Lt....*L.NQRs.......+..`...jS.....&HWE=f.....zu.zTB.st..e.................d.W...U..lB.5..)u....*.F..i...'/.....3}..:6...Y...mm.Z...8.}%.J.a....~s9.$U.g@..*.....Y......_.[.....eb.9:...T.c...C.....IDATx...m.@.D37V..r.-'.s.........B.P...A....0d.#..a..x@s.].$`!?..!...x..|.`B.!V...n9.:@..b.l.?..|my.H.$I+.@.7.}.....@ I.$.@#...{[.x..^B$I..]fhX##..|...!.x|..c.a..;@ _..K.*3W3_..<..
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:JSON data
                                                Category:dropped
                                                Size (bytes):940
                                                Entropy (8bit):5.269772715826349
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BC27E0C5393378FE585D1CA15C5C8CD7
                                                SHA1:535F16131AE1CD59E15A6CB52B223117BC158E84
                                                SHA-256:D26045DEE3D6F7AE5BF7D887EF7FC7D29BD3179311BF5B90808FE62F3AD77136
                                                SHA-512:B8CE2CE97DDA8768934F9E128F0AC62F125DF51A7B9E255DDD7548F839AA267366682F7EF9D75E2C8B5989BEF569D9F1F1D33DDD94494399FA0BA0852EB7D1F3
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:{"products":[{"name":"web_widget","id":"vsrevogroup.zendesk.com","bootstrap":{"config":{"features":{"prechatFormVisibleDepartments":true,"fastLoad":true},"color":"#78A300","brand":"VS Revo Group Ltd","embeds":{"chat":{"embed":"chat","props":{"standalone":true,"badge":{"layout":"image_right","text":"Chat with us","color":"#1a3958","enabled":true,"imagePath":"https://v2assets.zopim.io/393O9gB158xzzs9O82F04ypD5NUqTehW-banner?1654172833774"},"color":"#78A300","mediatorHost":"widget-mediator.zopim.com","forms":{"preChatEnabled":true,"offlineEnabled":true},"zopimId":"393O9gB158xzzs9O82F04ypD5NUqTehW"}},"launcher":{"embed":"launcher","props":{"color":"#78A300"}}},"brandCount":1.0}},"features":["chat"],"url":"https://ekr.zendesk.com/compose_product/web_widget/7bc1c0f290501106fa41dc515076261e2325fb83?features%5B%5D=chat","assets":{"scripts":[{"src":"https://static.zdassets.com/web_widget/classic/latest/web-widget-main-7bc1c0f.js"}]}}]}
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (21084)
                                                Category:downloaded
                                                Size (bytes):21257
                                                Entropy (8bit):5.218656398361519
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:84415B7368FD6FC764CBE86039CE0626
                                                SHA1:62F238E73348C77EB9E865426A7D1B7DE23CBB2D
                                                SHA-256:C776195AD46333C6C9A9FE3C74502FFEA9A02FAF122388EA3567922CC65A3060
                                                SHA-512:8423F7A626064813EA9D7CA974AC4A3D23B304717BE6853CC10F356BA3A21971C531E2ACF7FF0285B81897BA54BF02265C96F4DCDE1BB35A350F399BA2479E17
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://cdn.jsdelivr.net/npm/popper.js@1.16.0/dist/umd/popper.min.js?ver=1.16.0
                                                Preview:/*. Copyright (C) Federico Zivolo 2019. Distributed under the MIT License (license terms are at http://opensource.org/licenses/MIT).. */(function(e,t){'object'==typeof exports&&'undefined'!=typeof module?module.exports=t():'function'==typeof define&&define.amd?define(t):e.Popper=t()})(this,function(){'use strict';function e(e){return e&&'[object Function]'==={}.toString.call(e)}function t(e,t){if(1!==e.nodeType)return[];var o=e.ownerDocument.defaultView,n=o.getComputedStyle(e,null);return t?n[t]:n}function o(e){return'HTML'===e.nodeName?e:e.parentNode||e.host}function n(e){if(!e)return document.body;switch(e.nodeName){case'HTML':case'BODY':return e.ownerDocument.body;case'#document':return e.body;}var i=t(e),r=i.overflow,p=i.overflowX,s=i.overflowY;return /(auto|scroll|overlay)/.test(r+s+p)?e:n(o(e))}function i(e){return e&&e.referenceNode?e.referenceNode:e}function r(e){return 11===e?re:10===e?pe:re||pe}function p(e){if(!e)return document.documentElement;for(var o=r(10)?document.body:
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:MS Windows icon resource - 1 icon, 24x24, 32 bits/pixel
                                                Category:dropped
                                                Size (bytes):2462
                                                Entropy (8bit):6.549803730530185
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:780F9DC38A92057E7290FC69D765D73D
                                                SHA1:FFE4D4BD2EA337C926DC71AFBE309DAA24352B41
                                                SHA-256:91E8F868EEF6967DCFCA5EEB8E428184A0F4DCD017246C78138E71E158A78DB7
                                                SHA-512:D03786070CA50868AE449E31E3CEC7A488196DC1D5EAB344E7DEC1D8F081BF7B376C8C42266B7171C6A46CBA972321BBB954586FDB7FAC978826B5586644AE92
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:............ .........(.......0..... ........................................................................*...(..........................................................................%...{....................v...+..................................................J.......w`.pY2.hL..gH..gI..iN..s^:...o...................................................~...v_.gI..iE..nH..pK..rL..rL..qK..nI..iE..iN....t........D..y................................q[7.iF..sL..xP..}S...T...V...V...V...T..|R..wN..kH..}kN........S.....................j....qZ5.pJ..{Q..~Q...U...V...[..._...\...X...X...U...W...U..tL...nQ........0...............0....rX.rK...U...V...kF.......n..^...e...]....i......vW..Z...]...Y..wO....x.......................sP...V...\...]...qE..........h&..n...k............t..h...i...a...Z..yY"........O...........zY..i...j...i...h...m/...........E...................u..}.......z...o...\....y...........K....d*..n...s...u...v...p............f..~....&...........k..x...z...w
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (1572)
                                                Category:downloaded
                                                Size (bytes):31114
                                                Entropy (8bit):5.431685131102474
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C2F7505C83268914435C433E5B91E41F
                                                SHA1:C96275DE583596EA5869EB7D79A048C50B7B2F18
                                                SHA-256:24145BD4277F4115911C6451A096121DBEED93BE1231A93D5F164000EF3303EC
                                                SHA-512:DB764F513623BB2E331A784BBFF6B461F6171F186C8F63918B4C9683D9365179B7E6A796D6F0EA1735BA306A984D4179FB713F84924E1E36984CAED9B6A360EC
                                                Malicious:false
                                                Reputation:unknown
                                                URL:"https://fonts.googleapis.com/css?family=Varela+Round%7COpen+Sans:300,400,700%7CKanit:300,400,600,700%7CPoppins:400,600%7CCalistoga%7CMontserrat:400,600&display=swap"
                                                Preview:/* vietnamese */.@font-face {. font-family: 'Calistoga';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/calistoga/v15/6NUU8F2OJg6MeR7l4e0fvMwB8dQ.woff2) format('woff2');. unicode-range: U+0102-0103, U+0110-0111, U+0128-0129, U+0168-0169, U+01A0-01A1, U+01AF-01B0, U+0300-0301, U+0303-0304, U+0308-0309, U+0323, U+0329, U+1EA0-1EF9, U+20AB;.}./* latin-ext */.@font-face {. font-family: 'Calistoga';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/calistoga/v15/6NUU8F2OJg6MeR7l4e0fvcwB8dQ.woff2) format('woff2');. unicode-range: U+0100-02AF, U+0304, U+0308, U+0329, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Calistoga';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/calistoga/v15/6NUU8F2OJg6MeR7l4e0fs8wB.woff2) format('woff2');. uni
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (5140)
                                                Category:downloaded
                                                Size (bytes):67035
                                                Entropy (8bit):5.332649069169522
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:4AABDDDF209E33AD0FD87CA9F895A929
                                                SHA1:C3AA8CE9653023F855B448F46A78B35409EF00CB
                                                SHA-256:EB6C5EC010E321ED80961757E075B2AADCD56FD96EC5526678BCBE124102FF91
                                                SHA-512:C00CE79780869CC2332B457D680437BCBB4B8D1EC8FD7DEBF5D210346442D928F01BE0E21A526BDDA5F84AF6D77D956DF0AB283461E74799B0D8E4D5550C9BB6
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://connect.facebook.net/signals/config/502397613272382?v=2.9.154&r=stable&domain=www.revouninstaller.com&hme=c3a545c63044e8e9102d4f32d84a1137594d024f28e801d670bc76dc5c075575&ex_m=67%2C112%2C99%2C103%2C58%2C3%2C93%2C66%2C15%2C91%2C84%2C49%2C51%2C158%2C161%2C172%2C168%2C169%2C171%2C28%2C94%2C50%2C73%2C170%2C153%2C156%2C165%2C166%2C173%2C121%2C14%2C48%2C178%2C177%2C123%2C17%2C33%2C38%2C1%2C41%2C62%2C63%2C64%2C68%2C88%2C16%2C13%2C90%2C87%2C86%2C100%2C102%2C37%2C101%2C29%2C25%2C154%2C157%2C130%2C27%2C10%2C11%2C12%2C5%2C6%2C24%2C21%2C22%2C54%2C59%2C61%2C71%2C95%2C26%2C72%2C8%2C7%2C76%2C46%2C20%2C97%2C96%2C9%2C19%2C18%2C81%2C53%2C79%2C32%2C70%2C0%2C89%2C31%2C78%2C83%2C45%2C44%2C82%2C36%2C4%2C85%2C77%2C42%2C39%2C34%2C80%2C2%2C35%2C60%2C40%2C98%2C43%2C75%2C65%2C104%2C57%2C56%2C30%2C92%2C55%2C52%2C47%2C74%2C69%2C23%2C105
                                                Preview:/**.* Copyright (c) 2017-present, Facebook, Inc. All rights reserved..*.* You are hereby granted a non-exclusive, worldwide, royalty-free license to use,.* copy, modify, and distribute this software in source code or binary form for use.* in connection with the web services and APIs provided by Facebook..*.* As with any software that integrates with the Facebook platform, your use of.* this software is subject to the Facebook Platform Policy.* [http://developers.facebook.com/policy/]. This copyright notice shall be.* included in all copies or substantial portions of the software..*.* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN.* CONNECTION WI
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (32492)
                                                Category:downloaded
                                                Size (bytes):339219
                                                Entropy (8bit):5.564912866430228
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:D7F7A688F56BE29C4146652FD6C2F1DE
                                                SHA1:AA4AFC8C20C401C29293D6B7F1569C1920D2DAA0
                                                SHA-256:2CEDDE903BFFBA30D1BBD0A6E62085232B1E724D8ABAAA9942E48B3FF5AF152D
                                                SHA-512:B970B3912B365E87FC80C731D18E12DB4197236D0C607DBF02B3D7882F5BD54F2471D1DBECDEB13A902E8894F0EF4BECAAB381D519CDE098C7973FD8DC1460AF
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://www.googletagmanager.com/gtm.js?id=GTM-T6G2J7
                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"63",. . "macros":[{"function":"__e"},{"function":"__e"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"fsc-url"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__r"},{"function":"__u","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__aev","vtp_varType":"TEXT"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"fsc-order-total"},{"function":"__v","vtp_dataLayerVersion":2,"vtp_setDefaultValue":false,"vtp_name":"fsc-order-id"},{"function":"__gas","vtp_cookieDomain":"auto","vtp_doubleClick":false,"vtp_setTrackerName":false,"vtp_useDebugVersion":false,"vtp_useHashAutoLink":false,"vtp_decorateFormsA
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 790 x 521, 8-bit colormap, non-interlaced
                                                Category:downloaded
                                                Size (bytes):45535
                                                Entropy (8bit):7.983732035182996
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:D8C7804B94FF102892E567488B3C5607
                                                SHA1:929C16EC2CC3960EEB665091BF4AC32FC734EF4B
                                                SHA-256:6BB1455C84F2E77D8FEF44E02368071910A667B8EDB24367C3F3CA9C4D2ECA42
                                                SHA-512:E43151FC82F8D8B4114DDE6C6F00DFA882D903175148F662D48ACA8A1E4934A0C1742E0EBC11C00C9E5CF5F3F2BDC4E05A61B8290ADD529E086B31F0BCEE9113
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com/site/screens-5/quick-multiple-uninstall.png
                                                Preview:.PNG........IHDR...............[o....PLTE................................................................................................................................................FF.....................................................%""..............IED....."..tts....................././...ab`...:=?...}|......l..2..nifRPO.........]XVa..V........G..........4.....z..egq...............FG-+D............9( .mB71........QXe.|........#.../...O..g.......s\Q............}...xl;6V#..@KT....4..h\........2.+...MPW).M.0...l{.........q*.........{LDaSB0.....cK@.....<.....VkzWMt|.7.....h.{.k.8..S|!..Z..;....w.....\..J..v...\a.Q......).-.k"..J......w}..F...\. ....l..>.u...pg...QsN._Y.>s.sxK. ...~..Z...8..#....f.T.>..%..Cce9..~.T'{.s_...9`.`y.c.7+.....IDATx..n.0.......(.EC...(..U...%{...2u.....?B.z..).P ..A.w.Q...N..(.%.~..M....9..z..r...HeGh.2..~suy..N.#.9#...U~t....2:....(:.....?>T...%.lj....U......u6$V.ipN.@..J.?.#.[.M
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (65307)
                                                Category:downloaded
                                                Size (bytes):206903
                                                Entropy (8bit):5.378855086321751
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B8284A4B45E40625C2B90A641EBE4A68
                                                SHA1:8285EA200E6679B92B07818033EE54199CCC13D5
                                                SHA-256:965CBA95C928E95003CE37271090406EAA7D5C2D955230A785B2B3BE8A9A17F5
                                                SHA-512:BA9BEFB2DCCDEF7FC088C927DD8C123BFA70989618552B644D229420B3F97F665FCBC16B0DEC39E2A1191A99ACF0C265BA9CA7E83AB2B22C128BD5BE4FE34E7B
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.zdassets.com/web_widget/classic/latest/web-widget-chat-sdk-7bc1c0f.js
                                                Preview:/*! Our embeddable contains third-party, open source software and/or libraries. To view them and their license terms, go to https://developer.zendesk.com/documentation/classic-web-widget-sdks/web-widget/getting-started/legal/ */.(globalThis.webpackChunk_zendesk_web_widget_classic=globalThis.webpackChunk_zendesk_web_widget_classic||[]).push([[8876],{65532:e=>{var t;window,t=function(){return function(e){var t={};function r(o){if(t[o])return t[o].exports;var n=t[o]={i:o,l:!1,exports:{}};return e[o].call(n.exports,n,n.exports,r),n.l=!0,n.exports}return r.m=e,r.c=t,r.d=function(e,t,o){r.o(e,t)||Object.defineProperty(e,t,{enumerable:!0,get:o})},r.r=function(e){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},r.t=function(e,t){if(1&t&&(e=r(e)),8&t)return e;if(4&t&&"object"==typeof e&&e&&e.__esModule)return e;var o=Object.create(null);if(r.r(o),Object.defineProperty(o,"default",{enume
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (57671), with no line terminators
                                                Category:downloaded
                                                Size (bytes):57671
                                                Entropy (8bit):5.406436595808325
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:BBBCF811D8437A575D796A4C1E5D4FAD
                                                SHA1:CCE821AAE4F2B8982D9C08B308FB5306945EA68E
                                                SHA-256:4D15FF2317E16CCD8CA1D3248FEA7D91130E022369BB032824A84AD9967064DF
                                                SHA-512:6D0E3E9079DB4C175F0E8EC0279E9A89DF786D226685C0764AB20179D69E19CA269E8CC40646A97D31F95597654EC869472358BB72071011DF3410FC32E501C0
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.ads-twitter.com/uwt.js
                                                Preview:!function(){var t={6173:function(t,e,n){var r;t.exports=(r=r||function(t,e){var r;if("undefined"!=typeof window&&window.crypto&&(r=window.crypto),"undefined"!=typeof self&&self.crypto&&(r=self.crypto),"undefined"!=typeof globalThis&&globalThis.crypto&&(r=globalThis.crypto),!r&&"undefined"!=typeof window&&window.msCrypto&&(r=window.msCrypto),!r&&void 0!==n.g&&n.g.crypto&&(r=n.g.crypto),!r)try{r=n(2480)}catch(t){}var i=function(){if(r){if("function"==typeof r.getRandomValues)try{return r.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof r.randomBytes)try{return r.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")},o=Object.create||function(){function t(){}return function(e){var n;return t.prototype=e,n=new t,t.prototype=null,n}}(),a={},c=a.lib={},u=c.Base={extend:function(t){var e=o(this);return t&&e.mixIn(t),e.hasOwnProperty("init")&&this.init!==e.init||(e.init=function(){e.$super.init.apply
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Unicode text, UTF-8 text, with very long lines (25709), with no line terminators
                                                Category:downloaded
                                                Size (bytes):25711
                                                Entropy (8bit):4.76122248133975
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:6EB45E96A7CBB4B8CA10897F3CF09981
                                                SHA1:2A12B20D1CA65377448DCE30519C629AA4273346
                                                SHA-256:A48FD35C61908D912B5AC9E1FACE12E0962A0D9ECC8679E87DB4031697CEC54E
                                                SHA-512:71C0B51DA71EAD8652A3858B0A42AEE0A6E4CD1B1FE2752458716951110D57FE1DCFE9C9C5EE535400E3D01487E8D3E194BDDE9CC9A998C9649AC3B2253ADA19
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.zdassets.com/web_widget/classic/latest/web-widget-locales/classic/en-us-json-7bc1c0f.js
                                                Preview:"use strict";(globalThis.webpackChunk_zendesk_web_widget_classic=globalThis.webpackChunk_zendesk_web_widget_classic||[]).push([[6950],{43255:e=>{e.exports=JSON.parse('{"locale":{"locale":"en-us","rtl":false,"translations":{"embeddable_framework.answerBot.article.feedback.no.need_help":"No, I need help","embeddable_framework.answerBot.article.feedback.no.reason.related":"It\'s related, but it didn\'t answer my question","embeddable_framework.answerBot.article.feedback.no.reason.title":"Please tell us why.","embeddable_framework.answerBot.article.feedback.no.reason.unrelated":"It\'s not related to my question","embeddable_framework.answerBot.article.feedback.title":"Does this article answer your question?","embeddable_framework.answerBot.article.feedback.yes":"Yes","embeddable_framework.answerBot.bot.name":"Answer Bot","embeddable_framework.answerBot.button.get_in_touch":"Get in touch","embeddable_framework.answerBot.contextualResults.intro.many_articles":"Here are some top suggestions f
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (10187), with no line terminators
                                                Category:downloaded
                                                Size (bytes):10187
                                                Entropy (8bit):5.17908949611252
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C0053B411B753138AF468DB1BD3B19F3
                                                SHA1:7C3A187AA58F2B9E5446EDB761B3D4D2BA506FE7
                                                SHA-256:CE337EC7DDA4B3A741363A2673C7EDCE5C736F1660E2AA908131ECFD9DD1343F
                                                SHA-512:E0EAF480CC88817BCE216614F9813C10D7FC3930A8899F4C7C68B442E90846AABE0B5A536D9B273570671B7E8DDE614B347891839BD6699EDA355EC8B5FB1852
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.zdassets.com/ekr/snippet.js?key=4c200800-b795-45ba-8671-5fe06189f891
                                                Preview:(()=>{var e,t,r={271:e=>{function t(e){const t=document.createElement("a");return t.href=e,t.search.split("?")[1]||""}e.exports={getQueryParamsString:t,parseUrlParams:function(e){const r=t(e);return""===r?{}:r.split("&").reduce((function(e,t){const r=t.split("=");return e[r[0]]=decodeURIComponent(r[1]),e}),{})},loadScript:function(e,t=(()=>{})){const r=document.createElement("script");r.type="text/javascript",r.onerror=function(){t(new Error("Script failed to load"))},r.readyState?r.onreadystatechange=function(){"loaded"!==r.readyState&&"complete"!==r.readyState||(r.onreadystatechange=null,t())}:r.onload=function(){t()},r.src=e,document.getElementsByTagName("head")[0].appendChild(r)}}}},n={};function s(e){var t=n[e];if(void 0!==t)return t.exports;var o=n[e]={id:e,loaded:!1,exports:{}};return r[e](o,o.exports,s),o.loaded=!0,o.exports}s.m=r,s.d=(e,t)=>{for(var r in t)s.o(t,r)&&!s.o(e,r)&&Object.defineProperty(e,r,{enumerable:!0,get:t[r]})},s.f={},s.e=e=>Promise.all(Object.keys(s.f).reduc
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
                                                Category:downloaded
                                                Size (bytes):48236
                                                Entropy (8bit):7.994912604882335
                                                Encrypted:true
                                                SSDEEP:
                                                MD5:015C126A3520C9A8F6A27979D0266E96
                                                SHA1:2ACF956561D44434A6D84204670CF849D3215D5F
                                                SHA-256:3C4D6A1421C7DDB7E404521FE8C4CD5BE5AF446D7689CD880BE26612EAAD3CFA
                                                SHA-512:02A20F2788BB1C3B2C7D3142C664CDEC306B6BA5366E57E33C008EDB3EB78638B98DC03CDF932A9DC440DED7827956F99117E7A3A4D55ACADD29B006032D9C5C
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2
                                                Preview:wOF2.......l......D...............................O..B..h?HVAR.x.`?STAT.$'...0+...|.../V........+..2.0..6.6.$..`. ..~......[B4q.....t..P.M_.z...1..R.S*...u.#..R....fR.1.N.v.N.P...;.2........!Z......Qs...5f.G.K.an2&....2...*......C.H.t..N!.....nh.<(.vN.....j.._.L.P.t..Ai.%.............._I.i,..o,C.].H.X9.....a.=N....k.....n.L..k.f.u..{...:.}^\[..~5...Z`...........`!...%4..,...K0..&.a/....P....S....m.Z......u...D.j.F...f.0`I.`.`.h#..)(FQ.F!o$........S.).MV8%Rh...r...x...T]$.=......Y...!.3.&U..."....Q....{.l/0..d..4iJ/..}...3....i[Z..NG.WD...>.[U..Q.h..@m.=..S...1C2...d...<..v.?.q.f..n...OUz.....&Z......Z."..N.....n...9.B..C..W....}...W..6Zs.i.+Z........jB.n..x.8M.....q..@I....-.%..,C,..K..#.2...4)/.v_..x.<....t.....%[.4?.=j.V..jj''..W.u..q....I.L.=......E...\.M.7{.>......W........C.`...,9$......\..o........y...4A..m.P.,X..=?.:................wF`..+.P..........M!.4.......l.>M..t.ff5r..^..Z.g...!fA,hIIQ...e.R>B.AH.VuX..>..\.=.ky...1>C....>C.c.;...6D.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (65450)
                                                Category:downloaded
                                                Size (bytes):225866
                                                Entropy (8bit):5.379271278866028
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:B89693E18ED17F9B649DDAF638E17A57
                                                SHA1:3C51EF5B0AB1367A91F3FC50F2AC7D31C264CB88
                                                SHA-256:BCCE269FE4E329E6AAC07BDA59F9F10948F0FF09A492146306F16BFC24A99E35
                                                SHA-512:0C24B146510FE8CF5F1697041A4FB22B9AC0A4DEBBD97D028BD1AFF0439BCAA167205B4D4FEE5D54976A80D93950DEEC9112BD2584CE2A20FE5C841A7467CE22
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://script.hotjar.com/modules.25f289cf2c430c5f1dfb.js
                                                Preview:/*! For license information please see modules.25f289cf2c430c5f1dfb.js.LICENSE.txt */.!function(){var e={4788:function(e,t,n){"use strict";n.d(t,{s:function(){return r}});const r=Object.freeze({IDENTIFY_USER:"identify_user",AUTOTAG_RECORDING:"autotag_recording",TAG_RECORDING:"tag_recording",HEATMAP_HELO:"heatmap_helo",RECORDING_HELO:"recording_helo",REPORT_USER_ID:"report_user_id",MUTATION:"mutation",MOUSE_CLICK:"mouse_click",INPUT_CHOICE_CHANGE:"input_choice_change",KEY_PRESS:"key_press",MOUSE_MOVE:"mouse_move",RELATIVE_MOUSE_MOVE:"relative_mouse_move",CLIPBOARD:"clipboard",PAGE_VISIBILITY:"page_visibility",SCROLL_REACH:"scroll_reach",SCROLL:"scroll",SELECT_CHANGE:"select_change",VIEWPORT_RESIZE:"viewport_resize",SCRIPT_PERFORMANCE:"script_performance",REPORT_CONTENT:"report_content",INSERTED_RULE:"inserted_rule",DELETED_RULE:"deleted_rule"})},6939:function(e,t,n){"use strict";n.d(t,{f:function(){return f},W:function(){return g}});const r=Object.freeze({LIVE:"LIVE",REVIEW_WEBAPP:"REVI
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with no line terminators
                                                Category:downloaded
                                                Size (bytes):236
                                                Entropy (8bit):5.288571114461417
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:77BB07CA171E3FF2B72A7DAFA7822BC8
                                                SHA1:2FBD32C0E434F7F2C355A92CE29C35F29EFA9A9F
                                                SHA-256:A29E4AF6AA6A95982D1092A20F0068173B9A9D5DF0A89BC99DA556AEBEC3CE54
                                                SHA-512:C86D851298EAD9DA81837465F1BA608DB05F00F0E2282C58FCC24F32CBC78116C1E9380C31DCA1B6F6C731B3227ACA463586D4C75BE595EBE4B74B1E8CECDAC9
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.zdassets.com/web_widget/classic/latest/web-widget-chat-incoming-message-notification-7bc1c0f.js
                                                Preview:"use strict";(globalThis.webpackChunk_zendesk_web_widget_classic=globalThis.webpackChunk_zendesk_web_widget_classic||[]).push([[5376],{62677:(e,s,d)=>{d.r(s),d.d(s,{default:()=>c});const c=d.p+"fda6cd35495c75f83508d9d2e77ee33d.mp3"}}]);
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (65307)
                                                Category:downloaded
                                                Size (bytes):992059
                                                Entropy (8bit):5.51512413886698
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3784CF5E1DDD3A68E335F3BB4A5E2FCD
                                                SHA1:617BEBEE8C2ACFFF41763B25AA8E2B65BDEBC1D3
                                                SHA-256:7F4AC95D1AB40C0D78D98ACF1DA862B901CE896B43F738C7B1731C986A612BF4
                                                SHA-512:A53D86A35C099EC66735015D479ABA8865D1AB318AF49E88636CF608CEE12677781EE38CCD09CC890F70EDEEABA545591377D7318225196CD9A20DAD3FE0E3DA
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://static.zdassets.com/web_widget/classic/latest/web-widget-main-7bc1c0f.js
                                                Preview:/*! Our embeddable contains third-party, open source software and/or libraries. To view them and their license terms, go to https://developer.zendesk.com/documentation/classic-web-widget-sdks/web-widget/getting-started/legal/ */.(()=>{var e,t,n,r,o={20916:(e,t,n)=>{"use strict";n.r(t),n.d(t,{default:()=>i});var r,o=n(15826);function a(){return a=Object.assign?Object.assign.bind():function(e){for(var t=1;t<arguments.length;t++){var n=arguments[t];for(var r in n)Object.prototype.hasOwnProperty.call(n,r)&&(e[r]=n[r])}return e},a.apply(this,arguments)}const i=e=>{let{title:t,titleId:n,...i}=e;return o.createElement("svg",a({xmlns:"http://www.w3.org/2000/svg",width:12,height:12,focusable:"false",viewBox:"0 0 12 12","aria-labelledby":n},i),t?o.createElement("title",{id:n},t):null,r||(r=o.createElement("path",{fill:"none",stroke:"currentColor",strokeLinecap:"round",strokeLinejoin:"round",strokeWidth:1.25,d:"M3 6l2 2 4-4"})))}},18266:(e,t,n)=>{"use strict";n.r(t),n.d(t,{default:()=>i});var r,o
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 1600 x 814, 8-bit colormap, non-interlaced
                                                Category:dropped
                                                Size (bytes):183810
                                                Entropy (8bit):7.970270382360372
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:3AC70E8793ADDE124FB90B65694FF1D9
                                                SHA1:727064B422CAB2E7E467A72BC24482037C2BDB7B
                                                SHA-256:63CACEFE7F2DA164F756FD92658D8285F28E44E245C1632B4F675131E751BBD6
                                                SHA-512:C7DFB87CE2856F42097E7C8741C84289B49D686A0898E338C66EFF175F54B65DF363359F7EE0E081A97AFEF072A4390BBE8FB7FCD6BA07186069B6AF19C3208F
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR...@.........v.?.....PLTE................w......................................................................................................................w......>=>...............x...............u.............]ZZ.......DHcch.t....-07iktFDNrswz{~JPY...T\e.....#o.rmi......VPN......-v.......ep.......{..J60...&"%..........NEA....v....qr..vo...:)#...3BK...@@[..{.................r.......ld[...................,/J...........[^v..............u.....z....)...............7.....J...j|........e..~....{:..x...vl..jTNBSg...!.....*..l..Wmtp... b.......`G>........a{..nZ....B}E...W........GQR..k....n...........3...r.D..RJn-Hb.$3Pl.A\y...^......~\^...1..........h...R./.......8.hX.........z.HZ.e' a8.v`=.qv.bl*A.mp..=v.I.F...}....q<.4a.2.G.2..n....IDATx...m.0.E.+/...K..x.N..|...{.oP1.H.F.@.!..# S.D1..o..|....p...........T.2J..........T..Q~.....!y.Y.Q...........wZ..{.& .@...x.......m.1l...].a.mM0..D]BJy........'.Q...J..'.2..
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 19572, version 1.0
                                                Category:downloaded
                                                Size (bytes):19572
                                                Entropy (8bit):7.990105841735588
                                                Encrypted:true
                                                SSDEEP:
                                                MD5:24AD3FEA714CB5E100AA16F832531BF3
                                                SHA1:A5475CD37AFB39FC2472EF8391A4A3FD900122EB
                                                SHA-256:7196C3002F08704F9F99DE95B6357969A512EAA9A766EEE693921DCE72927CEA
                                                SHA-512:C6ED21A6CA08630DC71071B56C5F6AE0C6CE4AA5084E9E395B9DDDDC68BAB48944443AC37BA3642E9AD0FCF95F0899A4047F11536D93A1CA14490D15DECD04A3
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/kanit/v15/nKKU-Go6G5tXcr5KPxWnVaE.woff2
                                                Preview:wOF2......Lt.......8..L..........................F..z....`.....,........D..6..h..6.$..L. ..v.."..V...5..#n..1..#*i%g.... 2...?-..aIY....1..()].HV.{...........;.Ku.DA|j.!Z.,n..*h.`s(..........^5.K2.....<`..).(,V..<.g......u~...gQ......{rJ9.H.wtC.Ws.P..V....W :.Na........e.d...j.|.w..a...K&!.<.T....VQq.n..>...I...8.#..3>.-.......{....+[[.N.gl.0z....(\.v\.......u...x...v..3@5...N..m;%..w.(......W.snz...s....B..TqTaA....r(9p......v............L6.&.x....l.y_U...............Z.FC7X.!'aGv9Sf'.....v..-R...7d..Y..?.6.....J_.+..WC...+.....Z \Dn.[J+...a@.....(`];.......)._....9...qL.cbF.<.uJ2..........=Ir..e..dh......3.Y.........P.4E)T...s..)..@.A.!.:E%..gm@A.!.......iU.....^g........F..^(.3...14 ..@....C`.?.hU..?.fK...R<N...'y.%.*,.i..-..t..rP..EH.._:...VIF..PG.......c.'.m^l..}U.TAB*.X....L.XHn7..*..Ep.9.?.N......?.....q=y5.e\.lcY.%.9..D...'.nl..?S....q".....A.&z..(.-.2q..7..!.6~...CD.E.R...J.io....@.YOP.>...V.h..|..E.W........BH(.../.......(U..[.,.....W.U.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (5945)
                                                Category:downloaded
                                                Size (bytes):323941
                                                Entropy (8bit):5.599173798300496
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:4A90E9106E1187E7E6191E649780D6B5
                                                SHA1:247CD366E77E56EF3B85403FF5E9FC3CBD6D5955
                                                SHA-256:777B041EAB04EA0705E08287A483774D9EFBC7037D219DFC1D0D79F366E40D7D
                                                SHA-512:D9D964F8356FF3048657D45553888F93785A6D78CA483F36AB4495940C6FF0E5A3AF9B611C2F8B7A30EF445203BFDB03FEDE28DA238FF1270BAAAA1D0D9389FF
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://www.googletagmanager.com/gtag/js?id=G-P73P80145H&l=dataLayer&cx=c
                                                Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"8",. . "macros":[{"function":"__e"},{"vtp_signal":1,"function":"__c","vtp_value":1},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0},{"function":"__c","vtp_value":false},{"vtp_signal":1,"function":"__c","vtp_value":1},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_cross_domain","priority":26,"vtp_rules":["list","store\\.revouninstaller\\.com","tracking\\.avangate\\.net","secure\\.2checkout\\.com"],"tag_id":115},{"function":"__ogt_ip_mark","priority":16,"vtp_instanceOrder":0,"vtp_paramValue":"internal","vtp_ruleResult":["macro",4],"vtp_enableIpRegex":true,"tag_id":113},{"function":"__ogt_cps","priority":16,"vtp_cpsMode":"ALL","tag_id":116},{"function":"__ogt_1p_data_v2","priority":16,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_ci
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 19388, version 1.0
                                                Category:downloaded
                                                Size (bytes):19388
                                                Entropy (8bit):7.989728083266218
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F816F16F297C801AAF01FF43C9FCD563
                                                SHA1:2E9E2C80BC5AA5F01F75CD486BAA1769F53DEA5E
                                                SHA-256:AE7B918EFE7CD287651E014ED269C923E1A925C8EEE1A474AD11184F04659D3E
                                                SHA-512:C5A77C8A204C81A3BE9AE0555D2889A345E3DC2B428B10EFAC85FD0BC97FE35177F90CDC0B3CA77498C4CD4FDB5AB831368D9A5DA04763D2B0C028C6F4AE1994
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/kanit/v15/nKKZ-Go6G5tXcraVGwA.woff2
                                                Preview:wOF2......K...........KZ.........................F..P....`.....,........L..B..h..6.$..L. ..z.."..V....d^K.....B.U...........6....E.....R........M...J....f..6.b.bT...:V..9p..z.B.s..t...r.t_.V-w.|.V....e....j.s..G.P.=A5.'?vg4~.A{q@"..;....e.2...E`.2F.r..<....}....(..@.XGg.....)......;@...0...)...P@..J...Q1...h...E...m.......O{.>p.=I#.Mc@}....P.P...< .U..R.S4.R.U.+..g..O.?|{..w..-,..".X....L...f...[.@.<.o..dg*T.....`.c..2.~...PKA..JYg.z.Z]..s.0......DJ..v.%. ....%.._.C..r...e.11..8s&.t.x...oi......@.J...H.....9...d ......].wg.....t.X.TVs....3..w..k'.cH....2y.+?^g6#.yV..!.....:"...CZ.z...A.]..7 ..@.Y.:.......^..M..o...#.(.M..f.[.J.C.R....o......H..H..6ER2..f.|....@R>P<t8{..).L..0..Do........ve.B,.f.....\.U=.S.4M.'h.3...e..b.. A..O.Iq....4...}...{$....3_./I.$...3cA..z.$dm.Z_w.....^6e.*=.......`"..G.......AD....[.......E...@..h.....m@.iwk=.s..]......r.Hs=...u` .y..@....0....P. ...g.......oS.Q....NJN,..I.r3...........jC6..Er."xQ..&."..z.I.....3..H.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:HTML document, ASCII text, with no line terminators
                                                Category:downloaded
                                                Size (bytes):13
                                                Entropy (8bit):2.7773627950641693
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:C83301425B2AD1D496473A5FF3D9ECCA
                                                SHA1:941EFB7368E46B27B937D34B07FC4D41DA01B002
                                                SHA-256:B633A587C652D02386C4F16F8C6F6AAB7352D97F16367C3C40576214372DD628
                                                SHA-512:83BAFE4C888008AFDD1B72C028C7F50DEE651CA9E7D8E1B332E0BF3AA1315884155A1458A304F6E5C5627E714BF5A855A8B8D7DB3F4EB2BB2789FE2F8F6A1D83
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://td.doubleclick.net/td/ga/rul?tid=G-P73P80145H&gacid=1413362299.1714136623&gtm=45je44o0v869118035z871855269za200&dma=0&gcd=13l3l3l3l1&npa=0&pscdl=noapi&aip=1&fledge=1&z=820655299
                                                Preview:<html></html>
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 170 x 126, 8-bit colormap, non-interlaced
                                                Category:downloaded
                                                Size (bytes):7999
                                                Entropy (8bit):7.952135194287251
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9BB15490A0D123CD6DB268591E49D6DA
                                                SHA1:26318F17E01447AA98376EBCBA4E3C1F1DEA4C89
                                                SHA-256:92623AA7803E3F90705BC625C7D1C4AB288FB636B5C326B47EA1B6E03291C24C
                                                SHA-512:90F951ACB7F84FB5DE07F661E8DA64BBF67E60D8BC22A65704917F29FD2FBEA11F4918BCF3BEAEA8E1341C9BCA14E48B6C953F562C7C7FAFA6D0E7248CDF9ED5
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com/site/popup/product-logos.png
                                                Preview:.PNG........IHDR.......~.......z.....PLTE........................./9......FGG..........8F.......0<................#+.Oi.Ng.Oi.....!.......Oi."&.Ng.........!"!......BDE_o.........................~..GNRd~.......fnq[^_.............................X\]..........Oi..............9.................f.....................<P..........................4...............m.....w.............................X.........OPP.............Si......Hm.....w....'........^_a......b..Q{ehj........X............opr~.!.....xy{/Te........%...../_...............+...+<.............X[[...uL...FLc..Qq..r..........V.....@..C..>v...ieG_..%_..W....N.B!..g...7J.....ud[.<y..1..v....{.>R.....JZe9mV.........O[.(....BW.4......BW.iS777...)........w3,..A.....lyxZ..L..m..t..je`C....q.........2..%...Y...HtRNS...............2.. ...g.@....\U.w\%4..........KV.......p......y..At......IDATx....a....)...."z.....m.?.n>.cF..#..)......A..[L...{....v.K.e.A........zg.X.....C...3.g.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 286 x 35, 8-bit colormap, non-interlaced
                                                Category:dropped
                                                Size (bytes):1847
                                                Entropy (8bit):7.709830380580177
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:56792CE856FD50036D6DF977E97AA0E4
                                                SHA1:84D81689A05A06D5B1ECA2774720DAFF748947BB
                                                SHA-256:4A43F37A56077705CD95FB9D3B20C5A660B3A2FFBAB855F8730DCECB8432E496
                                                SHA-512:8BD57C327FEEC591F7A5FA47EFC50C1B5FCD975ADEAB46922F194380CC91F8921C35F9DBB32AA37B135E0B8795690424CBAE1604EA2C0FBC178FB9C351AAF26C
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR.......#.....u..#....PLTE................................................................................................................................................:..o.../tRNS......Z..i..y...=. .4.J.m...C..N^.c}.Sq..(u.......'IDATh....r.@..........mH.DI.9..v#.*U1)*...+n....s..X...u,F.B...5...p..RV;h..51B....U.......t...J..U.1e.=...gO....:..K..{...=.o..'iY%.K,+.d.Vc.........:y..L.^.xlCr...........0..>.e..'.xE... ..>.G...~.X.....WAsX.s}..c....DdT..#.`...F...t...0..Y.f3#.B..+.....r0...P..].L.....A......(.|.D..(.B.?.gKn.H..m9....qp....,.....d"<./.,"....(k..<c....bv.;1...Z.I.n.6........(...$...(...i.....:r......z........l...$........f.N.QNL.!..s..GV........g..P.3.@.<.6..N{..3.(.=.C.lA.i..a.?0..8{..Z<....a.ax6.....>r.b.Y........z..g {.k.5......W...g.Y..e..&c.b0#~~.F..\.....8......5..Z.o..<....j.j0...V......n.....`.I.}..q.v.){E.Ds........`.|...H..L..8.\...v:.e...k..1.ib%..$...*..R....;O5...%.....l)I..VH<.x.........../..,.3..r.p...
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 1650 x 875, 8-bit colormap, non-interlaced
                                                Category:downloaded
                                                Size (bytes):70602
                                                Entropy (8bit):7.96163019714407
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:A5C572CE44FD3A42F00CC6BED12ED986
                                                SHA1:15BCFB19B3CDCF45B5149370531DB86C497A626D
                                                SHA-256:6625BC05FE0B30643675381684B69B0A7795863CAC0CD88BC3967C9B23483BA2
                                                SHA-512:6E3BA6DDBEC755F1623F8B6EA1E3BBECFA98EA3DB06D02D9B52A69FC30A8A0114BA6020A392C18A2863955A817BDD1D93F6BB8E0097CBB35A669948356A76245
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com/site/screens-5/real-time-installation-monitor.png
                                                Preview:.PNG........IHDR...r...k.....E.......PLTE...........................................................f.:...J`..........ddd...........9..55.........f......e..s...f.......:.........f...7.....f..f.f..a......9.e.HH......9.....:......[..8.T...r..:9.........Q.[r.3mml8.8..../......d..q..(v....S..`A....h!z^.4.u4^..Kft.....Q...{..............N..........011...3...a.|..ltu|tDb3.....Rq..B..........`...KKV.Z.ff:.eg9f..Y..T........6(.....`......Z.......<[e..........`.0.[..8....EEE`::...r..........mm.G`n[......~2.....YU.2...|..:9:0..:f...Zq~t..]|.i..n..l..f:.Dx./\.......f.8c..........}......`..ii2Eb_A.....~.....}NF.y.T..........8.`.4.....jk..r..c?.f(U~T..P....[....BC.Z.Y...{.....\.42[.s.Z.@.}^.{.c;....}'....5..x...6.Q...3f.g......M...=........\..AH.@....b..w|2....IDATx..1k.1...J.3.kB..n0N.y..%....e).t(G.@....C6....n..v.....E.b........'wzz.....7.. ......A..A..... ....L9!......q..<..hhhhh.7.Yr}...`...(".P....3.....A..A:O.#.)@.o.bd....".V9....
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (65451)
                                                Category:downloaded
                                                Size (bytes):89476
                                                Entropy (8bit):5.2896589255084425
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:DC5E7F18C8D36AC1D3D4753A87C98D0A
                                                SHA1:C8E1C8B386DC5B7A9184C763C88D19A346EB3342
                                                SHA-256:F7F6A5894F1D19DDAD6FA392B2ECE2C5E578CBF7DA4EA805B6885EB6985B6E3D
                                                SHA-512:6CB4F4426F559C06190DF97229C05A436820D21498350AC9F118A5625758435171418A022ED523BAE46E668F9F8EA871FEAB6AFF58AD2740B67A30F196D65516
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js?ver=3.5.1
                                                Preview:/*! jQuery v3.5.1 | (c) JS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}function w(e){return null==e?e+"":"o
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 790 x 538, 8-bit colormap, non-interlaced
                                                Category:dropped
                                                Size (bytes):44153
                                                Entropy (8bit):7.983622187498285
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:7F4BFFFFBC2452A85F200682A155CE89
                                                SHA1:A23B7816308036B57EC172BDBC0C1EFDD0BDF2CE
                                                SHA-256:4302EAC6F74FB5F3FF2229402DDB0BEF9A518F8188319428D157159768FA2366
                                                SHA-512:CA34CCEC97991526B377AD36B2016F893F5A01B698D7B6FB0FA157BD119F822781DD8EA288D866E0C03319F8CD7D0B285FB3E153821610B3A579B960C38554B0
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR...............+Z....PLTE..........................................................................................................................................FF........................................................! 6,..G=9ZUR...jlp...yz}.....+&B....wqp..e]YMHJOSW.........or}.....egd.....\cq[]`......-(+...............9$.?0*................. 559...=<E...|~.n~.....bm|...uib.............BGQ.....{...EG......UPD...|t............................qi.;K`.....VSgoXMj`l..............j....IZl:6Y..0.........v.-7P........................O5-......XB7...ICh.......IJ................cKC....SO}.vd......nd............j].U..YE[.............d|.h........dT#..~s...........TX.{t.........s{...z..Ui..UZ......N.....|s..#~.s....B.......`..........p...4IDATx.._.LQ......G.q.[+.MKR.v.......}...}PWS..K..$..'B.xp.B"j..Va..M.0..Ly..;..{.?...9s.w.9......3s.J.....X.n.L0.Y.. ...=h........L...../F...m2!8H..>.-,....p.........|....
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (59729)
                                                Category:downloaded
                                                Size (bytes):60010
                                                Entropy (8bit):5.251561930322096
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:61F338F870FCD0FF46362EF109D28533
                                                SHA1:B3C116C65E6F053AAAB45E5619A78EC00271A50F
                                                SHA-256:5AA53525ABC5C5200C70B3F6588388F86076CD699284C23CDA64E92C372A1548
                                                SHA-512:8C2694D03A7721B303959E9FE9D4844129CEAD2B2E806E85E988A04569DA822EC7A0E2EC845D64C312D3E3EC42651810B1336AA542A3E969963B1B2EF65DD444
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js?ver=4.4.1
                                                Preview:/*!. * Bootstrap v4.4.1 (https://getbootstrap.com/). * Copyright 2011-2019 The Bootstrap Authors (https://github.com/twbs/bootstrap/graphs/contributors). * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */.!function(t,e){"object"==typeof exports&&"undefined"!=typeof module?e(exports,require("jquery"),require("popper.js")):"function"==typeof define&&define.amd?define(["exports","jquery","popper.js"],e):e((t=t||self).bootstrap={},t.jQuery,t.Popper)}(this,function(t,g,u){"use strict";function i(t,e){for(var n=0;n<e.length;n++){var i=e[n];i.enumerable=i.enumerable||!1,i.configurable=!0,"value"in i&&(i.writable=!0),Object.defineProperty(t,i.key,i)}}function s(t,e,n){return e&&i(t.prototype,e),n&&i(t,n),t}function e(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);t&&(i=i.filter(function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable})),n.push.apply(n,i)}return n}function l(o){for(var t=1;t<arguments.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (64347)
                                                Category:downloaded
                                                Size (bytes):223683
                                                Entropy (8bit):5.454805360153245
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:85F41014BE15CC3E54A4123C00C5021E
                                                SHA1:1E5468F507A8B0216114A8D8F63309BE8CBCAB9F
                                                SHA-256:01E9582655224C83E6C075F44B7EECB135E108B6AD2150BF6F78A0A77C4AD5E0
                                                SHA-512:78F6D6CD922AA42FD340CF215D7D91DDFABEF5EC393DFA5EB578436B9B668F839747218A4DE980AEC2395194667B1E0215623EC902EAAF8CE592536172414FCD
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://connect.facebook.net/en_US/fbevents.js
                                                Preview:/**.* Copyright (c) 2017-present, Facebook, Inc. All rights reserved..*.* You are hereby granted a non-exclusive, worldwide, royalty-free license to use,.* copy, modify, and distribute this software in source code or binary form for use.* in connection with the web services and APIs provided by Facebook..*.* As with any software that integrates with the Facebook platform, your use of.* this software is subject to the Facebook Platform Policy.* [http://developers.facebook.com/policy/]. This copyright notice shall be.* included in all copies or substantial portions of the software..*.* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.* FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.* COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.* IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN.* CONNECTION WI
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:PNG image data, 1903 x 380, 8-bit colormap, non-interlaced
                                                Category:dropped
                                                Size (bytes):59829
                                                Entropy (8bit):7.976263691894518
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:24AECC1A53DC19E47069D721E8E80B0C
                                                SHA1:889E013666044B2AB303B0FA97B55F643D7A77B3
                                                SHA-256:B7450CA7ECB39CD62204F5BC7EB5E882E685EF0A658D8F4AB69C9B5B2A9F3AAE
                                                SHA-512:F2DED0F7DE0CFE33DA321E452321DF51C49DB835E5DF169B442718F3B2E3C73C7F609EC88002D6C81511CFDEBE5A97C4D33802663630F7C69E13138AEB7B9B12
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:.PNG........IHDR...o...|........P....PLTE|....................................... .!%%'............y|.//1...**,.........................................325............tv.....779..........................................................wz...................qs....................................,.X.....................fi.=<?np......vx..............FH.IIL...34fPPT.........VW[......CCE........]]`......'(O.......cf.............km.....KM.......:<s...iik...................AC..........ccf......!"C.....Y].nmp.....ac.]`.............LS....SX....ik..........zz}..................gh......ssv.......{....vt.nr......nl.................\....y....{.....&.........._\~...?@[...Dv....v..~....Zkf.....?..}g...$.........r.....R..gj....0G.Y..p.j"..\.8-.......pIDATx...?..`...#..n.3ttK.! ........q.......I.,.:.wPWE........P..w.O.+wW../..^..............................7..O.ht....g..<..^_..Bx..8..}..P.......{..J..Kx....p...t.\...n..
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:Web Open Font Format (Version 2), TrueType, length 19336, version 1.0
                                                Category:downloaded
                                                Size (bytes):19336
                                                Entropy (8bit):7.987443056045714
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:463FF07D80F3F3EA8828C03844BC54F0
                                                SHA1:FCEE9670095EAC94263C6996102997CBDAAF2F25
                                                SHA-256:DCC14901EB1CB3BDCE862861295FB44BD29B1A1DD5F375B4D488C020E22023D1
                                                SHA-512:4E029D68CC42178D82B228C046D36387750F49C00B9DC6300ABE2BFEC6A9AD00F03D057C6645FDC667B53223CEEC648B24C114873683D4EF550E36A3FAB3EC55
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://fonts.gstatic.com/s/kanit/v15/nKKU-Go6G5tXcr4uPhWnVaE.woff2
                                                Preview:wOF2......K...........K$.........................F..~....`.....,........h.....h..6.$..L. ..b.."..V..5.%n."D.^(.`.....BZ6H{...I.J...c/.)U..&\f:.P.N.}t.f...Z..=.Pakw..2|.1..S.8.W .q]L..2T...w.z......>....y&..X..I....v..............2..X.F.....>....I^.......[...J..^]o*..h4..K.....*\...w...Q*&." R*.%e#U.....0........t.+.......#j....{...{R.............R..h#......;.v.....\*(69...6..-.rE../ADO1..........v....'No..f.{..2.g .@t........5b...]M....+X.$..4..lru.f\.2.2.P(3.......z...s.x...*.i. ...-=.......O.]#...RP:2bQoW=mh.2..3......ncAe3.........f.o...K@v...{.......6.a......Ss.-e..`K .,WL!$X..T_.._.......T....."\................a..T....IH...V.=..w.S\o.Az.5~u..j4.....B..hN.C.cPh...R.....y..g)R..:c"g.........Fgl.f.Q..k..,_....0(.w".{4....n.@.rQ$\t...E(d....cm...A..m.."..;3.9]....u.0..B.a.....C.t(....9+..g..c..X.......`.H.............L.V ........u........K.W......!.....-B=*z.#.5.$.(......;..k......'.,#(`...$....g..z,..H..p.%.{..t.xM;...!..kh..=..2..|.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 700x500, components 3
                                                Category:downloaded
                                                Size (bytes):12455
                                                Entropy (8bit):7.834304187486952
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:F8669288AD3F39110248F57EBF19D4BD
                                                SHA1:91E289AE2162D202807600C1E122A3CCECE81A6B
                                                SHA-256:EB77891B9EC81C7AE5E4B3CC90B548D23745DFFBE62AAD19CA2F6A507466C175
                                                SHA-512:8DB49DB3A4AAAA50E971AD3F9F5EF1FC5788FE3FAA1381880561C5AC2C2C420336B36DFD9BE7458BA19AFAC5932958A984AEC82E1016A72ACD6CC68EA0F5FD30
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://f057a20f961f56a72089-b74530d2d26278124f446233f95622ef.ssl.cf1.rackcdn.com/site/popup/revo-bg.jpg
                                                Preview:......JFIF.............C.............................! ....#'2*#%/%..+;,/35888!*=A<6A2785...C...........5$.$55555555555555555555555555555555555555555555555555..........................................................................................I...@...E....@((.HQ.....((-....QB..RYDP...(......O.^.(.....(.A@......*.j.....*H..R..(..`..A@.........H.....()..P...R.......%...E .@.Kl..:.).VE.......(.<MzE....(...(......(A@.(A@)l......ud.!D....@(.J.(..&.4....U....,...(,..T..(...H-..*.$..T@..@...-.(.@.u..P..Z.....((@((.P*..(.!@(JZ..)..(.Z..PH.....(..!......-....@(*....QB..(...*...B.I....P.P..%..,.h..<;............!AAK....A@..h.PP.U......J.*.T...,.)hAHx..((-.........@)AdP.%...........5fK......A@..5fe....R.,.....X.T.....PP.AD........ P.P..P..*..3(..x..(.(..J.(...((,.....-B..(...@...(.%.....D..@..$R.O....).P*.P. P.....@)P Z...PP.PPT.......P,.bR....B..d...............P..@JP.@*...R.dh.R.........&..e.R..P..d.X.........PPY.(*P.)HT....H.(.P T..(....-.3-.....)..........PP......%...%!M..P..P..
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:JSON data
                                                Category:dropped
                                                Size (bytes):1314
                                                Entropy (8bit):5.0004625529284485
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:48503492E38E0814836F0FF8E7E25FDD
                                                SHA1:77790F61217B63C78D4E5C5CD03A6F0F6CCBA3D7
                                                SHA-256:6F6AE0D9218DC0C92BCCA4F25100B9F90AEE750B301CFD11918651AC36F89FAB
                                                SHA-512:CD7A093BCB10CB6F0C9174C6BECC24BD0963D90755F7D0681BF58B62CEDDBD15F8AD9904B383C67DB2861E8892C17B80B12B61C318383C619BD4920BC754151B
                                                Malicious:false
                                                Reputation:unknown
                                                Preview:{"businessUnit":{"stars":5.0,"trustScore":4.8,"displayName":"Revo Uninstaller","numberOfReviews":{"total":150,"oneStar":3,"twoStars":1,"threeStars":2,"fourStars":6,"fiveStars":138},"websiteUrl":"http://www.revouninstaller.com"},"businessEntity":{"stars":5.0,"trustScore":4.8,"displayName":"Revo Uninstaller","numberOfReviews":{"total":150,"oneStar":3,"twoStars":1,"threeStars":2,"fourStars":6,"fiveStars":138},"websiteUrl":"http://www.revouninstaller.com"},"reviews":null,"links":{"profileUrl":"https://www.trustpilot.com/review/www.revouninstaller.com","evaluateUrl":"https://www.trustpilot.com/evaluate/www.revouninstaller.com","evaluateEmbedUrl":"https://www.trustpilot.com/evaluate/embed/www.revouninstaller.com","consumerWebPageUrl":null},"starsString":"Excellent","translations":{"main":"<span class='text'>[SEEOUR] <strong>[NOREVIEWS]</strong></span> <span class='text'>[REVIEWSON]</span>","seeour":"See our","reviewson":"reviews on","firstreviewer":"Be the first to review us on","firstreview
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 21980
                                                Category:downloaded
                                                Size (bytes):6759
                                                Entropy (8bit):7.970766444142892
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:15864CE88FA79A3E954417D0C3396798
                                                SHA1:FB9C3441942954B8EF8D637CDB307CBBAE25DA56
                                                SHA-256:97FDE46829E88416162D1CF2BA9C0BDC0A5C45D826ECF44095782AFD7417C500
                                                SHA-512:AC2B648224C8DD20F4BF5DAE9A4347C57B9902AE554E84FD3506F8B3B1E7759B33CB937B04D509E1DF06E4CBBF133C09D98A06E6FE8D30F639E4B8619E778697
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js
                                                Preview:...........\.R.H..?Oa4.niI.....L.EO.Q.....,A.V.d...H.h.'...H..{N..%.zf"f#.....'..;'..?.....y>.....$E..%./...l.o.7.V=q..%):,.LS/....q......v..a.}......".0.t..`yf.2]&.....8........&y.Eg..3..<...M..}..A8.).....?~8..xy}.....{..Y.K.........%....n.Q.e>.u.1..a.zA./..oo.........CN....5.d*.cX5R'{.u..{....3.O...nn.._....,e./..M.H"......R.l$.....:.aJ.L.S.g...>#...-/$.<.g..i..[....O.............^..?.6...........g.u...............w8.w..v.=...........qog.w@..n.....%Y,o....r....%5Q......\..%Y1......!..SZ$....yyz....%...\.o.'I.1......`B.........>.<X......E......#..^..eP.....,`...E...H.4..G.v.T.A.J.Y...,....x.......!.B&.6...~0.....9.*|....4.HB.K .......,..J....!.\5+p.......94O...Ar....?..+K...>L7R..s...&.v.=+.{I..M.....D..Q..\T..%..H.....Qt..P.X...L#.g.H......O.xlu<X.........pD.lJ......(..!...V..E%.4N...z.J-...o.".~...BC....T.Qf.@..p...fS.../.R.....;3.a2.e.~>.2`Z.A..R$.X.......KZ|..y.ei.GrI..d..P...e..d......(..(gF>k.P.>.H~.Wt...dP.KY.*".....{C515... .v.
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with no line terminators
                                                Category:downloaded
                                                Size (bytes):56
                                                Entropy (8bit):4.8095995116839045
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:1D4931C1A7D08B7ED9F6C6F22559192D
                                                SHA1:357B7E1D710041DCBEA6B02464DD42AA3DD79CB4
                                                SHA-256:33111B6CE1155AFEF442FBCA32D044CAA0547382DF422BE7EA34E2D95B5DB422
                                                SHA-512:37C8AF439BEB0A6CC9CEB4007E7DB1839AE4FB747C4B5915A4804E08A86BA04FB35E55694A11683F430B702328484A6CDA5E59CC96E97775411330395E571298
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSFwnpGtWnGXJQDRIFDc9OUJgSBQ1FaQxEEhAJ4ab2jSFvnfsSBQ3PTlCYEhAJh2EMu8OtwvkSBQ1FaQxE?alt=proto
                                                Preview:ChIKBw3PTlCYGgAKBw1FaQxEGgAKCQoHDc9OUJgaAAoJCgcNRWkMRBoA
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:ASCII text, with very long lines (2343)
                                                Category:downloaded
                                                Size (bytes):52916
                                                Entropy (8bit):5.51283890397623
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:575B5480531DA4D14E7453E2016FE0BC
                                                SHA1:E5C5F3134FE29E60B591C87EA85951F0AEA36EE1
                                                SHA-256:DE36E50194320A7D3EF1ACE9BD34A875A8BD458B253C061979DD628E9BF49AFD
                                                SHA-512:174E48F4FB2A7E7A0BE1E16564F9ED2D0BBCC8B4AF18CB89AD49CF42B1C3894C8F8E29CE673BC5D9BC8552F88D1D47294EE0E216402566A3F446F04ACA24857A
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://www.google-analytics.com/analytics.js
                                                Preview:(function(){/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var n=this||self,p=function(a,b){a=a.split(".");var c=n;a[0]in c||"undefined"==typeof c.execScript||c.execScript("var "+a[0]);for(var d;a.length&&(d=a.shift());)a.length||void 0===b?c=c[d]&&c[d]!==Object.prototype[d]?c[d]:c[d]={}:c[d]=b};function q(){for(var a=r,b={},c=0;c<a.length;++c)b[a[c]]=c;return b}function u(){var a="ABCDEFGHIJKLMNOPQRSTUVWXYZ";a+=a.toLowerCase()+"0123456789-_";return a+"."}var r,v;.function aa(a){function b(k){for(;d<a.length;){var m=a.charAt(d++),l=v[m];if(null!=l)return l;if(!/^[\s\xa0]*$/.test(m))throw Error("Unknown base64 encoding at char: "+m);}return k}r=r||u();v=v||q();for(var c="",d=0;;){var e=b(-1),f=b(0),h=b(64),g=b(64);if(64===g&&-1===e)return c;c+=String.fromCharCode(e<<2|f>>4);64!=h&&(c+=String.fromCharCode(f<<4&240|h>>2),64!=g&&(c+=String.fromCharCode(h<<6&192|g)))}};var w={},y=function(a){w.TAGGING=w.TAGGING||[];w.TAGGING[a]=!0};var ba=Array.isArray,c
                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 56424
                                                Category:downloaded
                                                Size (bytes):17380
                                                Entropy (8bit):7.985676241300046
                                                Encrypted:false
                                                SSDEEP:
                                                MD5:9708742D2D4498168C0FC01551F7C6F2
                                                SHA1:F6EA6F060FA1DA24FA0F807D0A4E9998030A5221
                                                SHA-256:99360E28070F230FA4457C21B6119C0066337EC9E7577A5009E6FFC322C29662
                                                SHA-512:A94F5C363268056354FD3E1A9A57D79404E7D50652C9542F37E840EFEB6768E8F785B090A824371A21AB410BD9BA9A2AE29F1B8418CEC6B2555FDF7A31F711E3
                                                Malicious:false
                                                Reputation:unknown
                                                URL:https://widget.trustpilot.com/trustboxes/5419b6a8b0d04a076446a9ad/main.js
                                                Preview:............v.F....<E..GJ.. ..lY%...%y,...,.....(g.l.I.&s.. .&.c.e^`^a..#..L...U..J.m&......wl .....~p...uV.r\....7MK5..T........D.*..UR...j.Y}}..g.2..uV.........s.L.u..r....}.....(...|...G..(...$.zt...X....W.i.4]7..".i/_...g.^.~...?...f.|F .n...EYW... ...s.,.......1.*.....>9NOnoS}c.F.@i.Lmdo.I...j...c.c.3. }...4?./..=..'.U?P.l.7......\...U:..2.....W....u....lY.....0Ye....*}_..h.Q..qW....*..2..x...k...o0g~...yZ?.^..-...X.J.s..?.WY..i..kLS....X....L..L.b.....R..a.I}|..j...1..J7_..........mN.;.......~_..iY_.sC{...^2...QZ....k...:H.]..bdI...........*..g.A.8)..4.+.S5xJ.Q..`..z.......eQ...ER.~.+...X....8?...O#.)dk.E...'e.\.Y.....v..o.W.....L.$(........9>.*.X..md.Guy.!1.Yz.5..X?x0.g.dV.y...C{,.<......'&.B7....D....dqF.i3O..... ..Y..e......A..ae..._c..e.:.Q.Q..7.<..F.....R.....V..u...Gu1Z.`.......'..S..,..$.... #e`..~.. ..r..j..'.Dj.Ha.e..,.T.g.e....BPdHA.fu.......,[...E.L.\7W......yd.....wt..P.N.m..b..EJ....^<%.r.....T?i.....
                                                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                Entropy (8bit):7.9898740485713216
                                                TrID:
                                                • Win32 Executable (generic) a (10002005/4) 99.94%
                                                • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                • Generic Win/DOS Executable (2004/3) 0.02%
                                                • DOS Executable Generic (2002/1) 0.02%
                                                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                File name:revosetup.exe
                                                File size:6'970'144 bytes
                                                MD5:63150c4846bfbcf27fa70ccaa8a01943
                                                SHA1:bfe32dcc00b041e0007a883af1588f354bb9f032
                                                SHA256:a05acc9172e98ec6a6a7f923f5c648cc7a7c4e02bbcaaa5a6d9663229e662c24
                                                SHA512:7c0c8065c83529ffe9cf092a7ffb19f59252015d643bded9cf5459e6e6a4c582962ab6e36b330275a79649fa6e8d3da01cb95352870a52fa159bb278b967cd90
                                                SSDEEP:98304:MPyYn2kIIR7ABl27MwarecfhZzwStzDtAVl3gaSZmg4MPyDv0bSpkmmf6osFQaiS:q7Vty27MJzw6z8X4mgJSyNyos6ac4l
                                                TLSH:64663346B35B10B3E8292D31CD9A84065E3ABDB13EE085183D74F31E56B8FD39E72649
                                                File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                Icon Hash:3f7b3cbc6465716d
                                                Entrypoint:0x41181c
                                                Entrypoint Section:.itext
                                                Digitally signed:true
                                                Imagebase:0x400000
                                                Subsystem:windows gui
                                                Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                Time Stamp:0x5B226D52 [Thu Jun 14 13:27:46 2018 UTC]
                                                TLS Callbacks:
                                                CLR (.Net) Version:
                                                OS Version Major:5
                                                OS Version Minor:0
                                                File Version Major:5
                                                File Version Minor:0
                                                Subsystem Version Major:5
                                                Subsystem Version Minor:0
                                                Import Hash:20dd26497880c05caed9305b3c8b9109
                                                Signature Valid:true
                                                Signature Issuer:CN=DigiCert Global G3 Code Signing ECC SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                                Signature Validation Error:The operation completed successfully
                                                Error Number:0
                                                Not Before, Not After
                                                • 27/07/2021 02:00:00 07/08/2024 01:59:59
                                                Subject Chain
                                                • CN=VS Revo Group Ltd., O=VS Revo Group Ltd., L=Ruse, C=BG, SERIALNUMBER=200204019, OID.1.3.6.1.4.1.311.60.2.1.3=BG, OID.2.5.4.15=Private Organization
                                                Version:3
                                                Thumbprint MD5:1884464E49C1DFC765B837961EA25568
                                                Thumbprint SHA-1:68A7EC9C14F45C97E8A743552672971C2DCB0A29
                                                Thumbprint SHA-256:8DBF178B186FD778052FF6AF8D168C71912553561FD9B8B8A643F97C9EC4607B
                                                Serial:07ED134B1ECF561A9EB5B05388BFF047
                                                Instruction
                                                push ebp
                                                mov ebp, esp
                                                add esp, FFFFFFA4h
                                                push ebx
                                                push esi
                                                push edi
                                                xor eax, eax
                                                mov dword ptr [ebp-3Ch], eax
                                                mov dword ptr [ebp-40h], eax
                                                mov dword ptr [ebp-5Ch], eax
                                                mov dword ptr [ebp-30h], eax
                                                mov dword ptr [ebp-38h], eax
                                                mov dword ptr [ebp-34h], eax
                                                mov dword ptr [ebp-2Ch], eax
                                                mov dword ptr [ebp-28h], eax
                                                mov dword ptr [ebp-14h], eax
                                                mov eax, 0041015Ch
                                                call 00007F84ACF2259Dh
                                                xor eax, eax
                                                push ebp
                                                push 00411EFEh
                                                push dword ptr fs:[eax]
                                                mov dword ptr fs:[eax], esp
                                                xor edx, edx
                                                push ebp
                                                push 00411EBAh
                                                push dword ptr fs:[edx]
                                                mov dword ptr fs:[edx], esp
                                                mov eax, dword ptr [00415B48h]
                                                call 00007F84ACF2ACFBh
                                                call 00007F84ACF2A84Ah
                                                cmp byte ptr [00412AE0h], 00000000h
                                                je 00007F84ACF2D81Eh
                                                call 00007F84ACF2AE10h
                                                xor eax, eax
                                                call 00007F84ACF20635h
                                                lea edx, dword ptr [ebp-14h]
                                                xor eax, eax
                                                call 00007F84ACF2787Bh
                                                mov edx, dword ptr [ebp-14h]
                                                mov eax, 00418658h
                                                call 00007F84ACF20C0Ah
                                                push 00000002h
                                                push 00000000h
                                                push 00000001h
                                                mov ecx, dword ptr [00418658h]
                                                mov dl, 01h
                                                mov eax, dword ptr [0040C04Ch]
                                                call 00007F84ACF28192h
                                                mov dword ptr [0041865Ch], eax
                                                xor edx, edx
                                                push ebp
                                                push 00411E66h
                                                push dword ptr fs:[edx]
                                                mov dword ptr fs:[edx], esp
                                                call 00007F84ACF2AD6Eh
                                                mov dword ptr [00418664h], eax
                                                mov eax, dword ptr [00418664h]
                                                cmp dword ptr [eax+0Ch], 01h
                                                jne 00007F84ACF2D85Ah
                                                NameVirtual AddressVirtual Size Is in Section
                                                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                IMAGE_DIRECTORY_ENTRY_IMPORT0x190000xe04.idata
                                                IMAGE_DIRECTORY_ENTRY_RESOURCE0x1c0000x2e6e4.rsrc
                                                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                IMAGE_DIRECTORY_ENTRY_SECURITY0x6a19f00x4130
                                                IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                IMAGE_DIRECTORY_ENTRY_TLS0x1b0000x18.rdata
                                                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                IMAGE_DIRECTORY_ENTRY_IAT0x193040x214.idata
                                                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                .text0x10000xf25c0xf4000da5d73ffbc41792fa65a09058a91476False0.5482197745901639data6.375879013420213IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                .itext0x110000xfa40x10002eb275566563c3f1d0099a0da7345b74False0.563720703125data5.778765357049134IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                .data0x120000xc8c0xe0073b859e23f5fd17e00c08db2e0e73dfeFalse0.25362723214285715data2.3028287433175367IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                .bss0x130000x56bc0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                .idata0x190000xe040x1000e9b9c0328fd9628ad4d6ab8283dcb20eFalse0.321533203125data4.597812557707959IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                .tls0x1a0000x80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                .rdata0x1b0000x180x2003dffc444ccc131c9dcee18db49ee6403False0.05078125data0.2044881574398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                .rsrc0x1c0000x2e6e40x2e800451e566b9d13b35598cd40ce2ba20326False0.5272334929435484data6.5036107166389385IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                NameRVASizeTypeLanguageCountryZLIB Complexity
                                                RT_ICON0x1c47c0xc301PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9996995252498948
                                                RT_ICON0x287800x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584EnglishUnited States0.38365077487282623
                                                RT_ICON0x38fa80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.5286372224846481
                                                RT_ICON0x3d1d00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.5776970954356846
                                                RT_ICON0x3f7780x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.7035647279549718
                                                RT_ICON0x408200x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.8430851063829787
                                                RT_STRING0x40c880x68data0.6538461538461539
                                                RT_STRING0x40cf00xd4data0.5283018867924528
                                                RT_STRING0x40dc40xa4data0.6524390243902439
                                                RT_STRING0x40e680x2acdata0.45614035087719296
                                                RT_STRING0x411140x34cdata0.4218009478672986
                                                RT_STRING0x414600x294data0.4106060606060606
                                                RT_RCDATA0x416f40x82e8dataEnglishUnited States0.11261637622344235
                                                RT_RCDATA0x499dc0x10data1.5
                                                RT_RCDATA0x499ec0x150data0.8392857142857143
                                                RT_RCDATA0x49b3c0x2cdata1.2045454545454546
                                                RT_GROUP_ICON0x49b680x5adataEnglishUnited States0.7666666666666667
                                                RT_VERSION0x49bc40x4f4dataEnglishUnited States0.2807570977917981
                                                RT_MANIFEST0x4a0b80x62cXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4240506329113924
                                                DLLImport
                                                oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                                                advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey
                                                user32.dllGetKeyboardType, LoadStringW, MessageBoxA, CharNextW
                                                kernel32.dllGetACP, Sleep, VirtualFree, VirtualAlloc, GetSystemInfo, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, lstrcpynW, LoadLibraryExW, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetCommandLineW, FreeLibrary, FindFirstFileW, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, CloseHandle
                                                kernel32.dllTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleW
                                                user32.dllCreateWindowExW, TranslateMessage, SetWindowLongW, PeekMessageW, MsgWaitForMultipleObjects, MessageBoxW, LoadStringW, GetSystemMetrics, ExitWindowsEx, DispatchMessageW, DestroyWindow, CharUpperBuffW, CallWindowProcW
                                                kernel32.dllWriteFile, WideCharToMultiByte, WaitForSingleObject, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, SizeofResource, SignalObjectAndWait, SetLastError, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, RemoveDirectoryW, ReadFile, MultiByteToWideChar, LockResource, LoadResource, LoadLibraryW, GetWindowsDirectoryW, GetVersionExW, GetVersion, GetUserDefaultLangID, GetThreadLocale, GetSystemInfo, GetSystemDirectoryW, GetStdHandle, GetProcAddress, GetModuleHandleW, GetModuleFileNameW, GetLocaleInfoW, GetLastError, GetFullPathNameW, GetFileSize, GetFileAttributesW, GetExitCodeProcess, GetEnvironmentVariableW, GetDiskFreeSpaceW, GetCurrentProcess, GetCommandLineW, GetCPInfo, InterlockedExchange, InterlockedCompareExchange, FreeLibrary, FormatMessageW, FindResourceW, EnumCalendarInfoW, DeleteFileW, CreateProcessW, CreateFileW, CreateEventW, CreateDirectoryW, CloseHandle
                                                advapi32.dllRegQueryValueExW, RegOpenKeyExW, RegCloseKey, OpenProcessToken, LookupPrivilegeValueW
                                                comctl32.dllInitCommonControls
                                                kernel32.dllSleep
                                                advapi32.dllAdjustTokenPrivileges
                                                Language of compilation systemCountry where language is spokenMap
                                                EnglishUnited States