Loading ...

Play interactive tourEdit tour

Analysis Report http://www.videosoftdev.com/services/download.aspx?ProductID=1

Overview

General Information

Sample URL:http://www.videosoftdev.com/services/download.aspx?ProductID=1
Analysis ID:326343

Most interesting Screenshot:

Detection

Score:19
Range:0 - 100
Whitelisted:false
Confidence:0%

Signatures

Contains capabilities to detect virtual machines
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to detect sandboxes (mouse cursor move detection)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to record screenshots
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain checking for process token information
Found potential string decryption / allocating functions
Is looking for software installed on the system
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file contains strange resources
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Tries to load missing DLLs
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample has functionality to log and monitor keystrokes, analyze it with the 'Simulates keyboard and window changes' cookbook
Sample may be VM or Sandbox-aware, try analysis on a native machine
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
Sample monitors window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook
Sample searches for specific file, try point organization specific fake files to the analysis machine
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior



Startup

  • System is w10x64
  • cmd.exe (PID: 6652 cmdline: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1' > cmdline.out 2>&1 MD5: F3BDBE3BB6F734E357235F4D5898582D)
    • conhost.exe (PID: 6660 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • wget.exe (PID: 6692 cmdline: wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1' MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
  • video_editor_x64.exe (PID: 496 cmdline: 'C:\Users\user\Desktop\download\video_editor_x64.exe' MD5: 10B5CDAB87CF1825DF1134F16DFF7062)
    • video_editor_x64.tmp (PID: 4276 cmdline: 'C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp' /SL5='$1F0056,89355248,121344,C:\Users\user\Desktop\download\video_editor_x64.exe' MD5: B2EAFA8C7E4EAEB302AA4AB062B17EBA)
      • vcredist_x64.exe (PID: 6120 cmdline: 'C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' /install /passive /norestart MD5: 1E7BD6790391B5B710C6372AB2042351)
        • vcredist_x64.exe (PID: 5088 cmdline: 'C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe' -burn.clean.room='C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' -burn.filehandle.attached=580 -burn.filehandle.self=564 /install /passive /norestart MD5: 1D7599C4A31B82E70308C022E9494011)
          • VC_redist.x64.exe (PID: 4796 cmdline: 'C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe' -q -burn.elevated BurnPipe.{AEC565AB-0FED-47E7-88D9-B941D20CF512} {87809E35-81C0-47B4-86E7-066B690A99EC} 5088 MD5: 1D7599C4A31B82E70308C022E9494011)
  • VC_redist.x64.exe (PID: 4572 cmdline: 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /burn.runonce MD5: 1D7599C4A31B82E70308C022E9494011)
    • VC_redist.x64.exe (PID: 3016 cmdline: 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install MD5: 1D7599C4A31B82E70308C022E9494011)
      • VC_redist.x64.exe (PID: 5636 cmdline: 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install MD5: 1D7599C4A31B82E70308C022E9494011)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C99EB7 DecryptFileW,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBF961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C99C99 DecryptFileW,DecryptFileW,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F39EB7 DecryptFileW,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5F961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F39C99 DecryptFileW,DecryptFileW,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018F961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00169C99 DecryptFileW,DecryptFileW,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00169EB7 DecryptFileW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00405BEC GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004AD294 FindFirstFileW,GetLastError,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00408174 GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004C0BC0 SetErrorMode,FindFirstFileW,FindNextFileW,FindClose,SetErrorMode,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004C107C SetErrorMode,FindFirstFileW,FindNextFileW,FindClose,SetErrorMode,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C83BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CC4315 FindFirstFileW,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C9993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB7A87 FindFirstFileExW,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F3993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F23BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F64315 FindFirstFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00194315 FindFirstFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0016993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00153BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00187A87 FindFirstFileExW,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cab
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\NULL
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\NULL
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\NULL
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmpString found in binary or memory: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.674987522.0000000005F2E000.00000004.00000001.sdmpString found in binary or memory: . Por ejemplo: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.674313336.0000000005DD5000.00000004.00000001.sdmpString found in binary or memory: : http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: is-GK5DP.tmp.22.drString found in binary or memory: InformationAhttps://www.youtube.com/watch?v= equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.673428705.00000000059DF000.00000004.00000001.sdmpString found in binary or memory: Sfoglia..."Lettori e dispositivi multimedialiKInserisci qui l'URL. Ad esempio: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.673989945.0000000005C7B000.00000004.00000001.sdmpString found in binary or memory: diaMInserir seu URL aqui. Por exemplo: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.670684399.0000000005728000.00000004.00000001.sdmpString found in binary or memory: riquesMCollez votre URL ici. Par exemple: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: video_editor_x64.tmp, 00000016.00000002.671162818.0000000005886000.00000004.00000001.sdmpString found in binary or memory: tenQLegen Sie Ihre URL hier. Zum Beispiel: http://www.youtube.com/watch?v=jaA2361wq50 equals www.youtube.com (Youtube)
Source: vcredist_x64.exe, VC_redist.x64.exeString found in binary or memory: http://appsyndication.org/2006/appsyn
Source: vcredist_x64.exe, 0000001B.00000000.544275902.0000000000CCB000.00000002.00020000.sdmp, vcredist_x64.exe, 0000001D.00000000.545735742.0000000000F6B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000020.00000002.589217485.000000000019B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000025.00000000.583222248.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000026.00000000.584723229.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000027.00000002.610680528.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe.32.drString found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: video_editor_x64.tmp, 00000016.00000002.668331619.0000000004E60000.00000004.00000001.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: video_editor_x64.tmp, 00000016.00000002.668331619.0000000004E60000.00000004.00000001.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://crl.globalsign.net/root-r3.crl0
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://crl.trustwave.com/CSCA2_L1.crl0q
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://crl.trustwave.com/STCA.crl0=
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpString found in binary or memory: http://downloads.videosoftdev.com/video_tools/video_editor_x64.exe
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpString found in binary or memory: http://downloads.videosoftdev.com/video_tools/video_editor_x64.exe3
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpString found in binary or memory: http://downloads.videosoftdev.com/video_tools/video_editor_x64.exetates3
Source: video_editor_x64.tmp, 00000016.00000002.668331619.0000000004E60000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.comodoca.com0
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.sectigo.com0
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://ocsp.sectigo.com0#
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.thawte.com0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.trustwave.com/09
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.trustwave.com05
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ssl.trustwave.com/issuers/CSCA2_L1.crt0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ssl.trustwave.com/issuers/STCA.crt0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: VC_redist.x64.exe, 00000027.00000003.608972858.00000000032BA000.00000004.00000001.sdmp, VC_redist.x64.exe, 00000027.00000003.609712314.0000000001060000.00000004.00000040.sdmpString found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: http://www.codejock.com
Source: video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpString found in binary or memory: http://www.conduit.com/legal/searchprotectdescription
Source: video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpString found in binary or memory: http://www.delta-search.com/eula.html
Source: video_editor_x64.exe, 00000014.00000003.386914432.00000000024B0000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.653698216.000000000250A000.00000004.00000001.sdmpString found in binary or memory: http://www.dk-soft.org/
Source: video_editor_x64.exe, 00000014.00000003.387425971.000000007FD80000.00000004.00000001.sdmp, video_editor_x64.tmp, video_editor_x64.tmp, 00000016.00000000.388602269.0000000000401000.00000020.00020000.sdmpString found in binary or memory: http://www.innosetup.com/
Source: video_editor_x64.exeString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
Source: video_editor_x64.exe, 00000014.00000000.386663597.0000000000401000.00000020.00020000.sdmpString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: is-SR4CK.tmp.22.drString found in binary or memory: http://www.realnetworks.com
Source: is-64E3N.tmp.22.drString found in binary or memory: http://www.realnetworks.com0=1
Source: video_editor_x64.exe, 00000014.00000003.387425971.000000007FD80000.00000004.00000001.sdmp, video_editor_x64.tmpString found in binary or memory: http://www.remobjects.com/ps
Source: video_editor_x64.tmp, 00000016.00000002.652002104.0000000000835000.00000004.00000020.sdmpString found in binary or memory: http://www.videosoftdev.co
Source: video_editor_x64.tmp, 00000016.00000002.653698216.000000000250A000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com
Source: wget.exe, 00000002.00000002.340414107.00000000009F0000.00000004.00000020.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=1
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=1.
Source: wget.exe, 00000002.00000002.340511863.0000000001100000.00000004.00000040.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=19
Source: wget.exe, 00000002.00000002.340511863.0000000001100000.00000004.00000040.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=1?
Source: video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=x32_1
Source: video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com/services/download.aspx?ProductID=xp_1
Source: video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com/services/install.aspx?ProductID=1
Source: video_editor_x64.tmp, 00000016.00000002.658287088.0000000003688000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000003.389180628.0000000003390000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com/services/purchase.aspx?ProductID=1a
Source: video_editor_x64.exe, 00000014.00000003.386914432.00000000024B0000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000003.389180628.0000000003390000.00000004.00000001.sdmpString found in binary or memory: http://www.videosoftdev.com6http://www.videosoftdev.com6http://www.videosoftdev.com
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.671162818.0000000005886000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.674313336.0000000005DD5000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673428705.00000000059DF000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673989945.0000000005C7B000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.674987522.0000000005F2E000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.670684399.0000000005728000.00000004.00000001.sdmpString found in binary or memory: http://www.youtube.com/watch?v=jaA2361wq50
Source: is-GK5DP.tmp.22.drString found in binary or memory: https://accounts.google.com/o/oauth2/approval
Source: is-GK5DP.tmp.22.drString found in binary or memory: https://myaccount.google.com
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: https://sectigo.com/CPS0C
Source: wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpString found in binary or memory: https://sectigo.com/CPS0D
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: https://ssl.trustwave.com/CA06
Source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpString found in binary or memory: https://ssl.trustwave.com/CA0l
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: https://www.globalsign.com/repository/0
Source: video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drString found in binary or memory: https://www.globalsign.com/repository/06
Source: is-GK5DP.tmp.22.drString found in binary or memory: https://www.youtube.com/watch?v=
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00434448 GetObjectW,GetDC,CreateCompatibleDC,CreateBitmap,CreateCompatibleBitmap,GetDeviceCaps,GetDeviceCaps,SelectObject,GetDIBColorTable,GetDIBits,SelectObject,CreateDIBSection,GetDIBits,SelectObject,SelectPalette,RealizePalette,FillRect,SetTextColor,SetBkColor,SetDIBColorTable,PatBlt,CreateCompatibleDC,SelectObject,SelectPalette,RealizePalette,SetTextColor,SetBkColor,BitBlt,SelectPalette,SelectObject,DeleteDC,SelectPalette,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0045C584 GetKeyboardState,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004808CC: CreateFileW,DeviceIoControl,GetLastError,CloseHandle,SetLastError,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040E538 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004B00AC GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\is-JBMK9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeFile deleted: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeJump to behavior
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00402260
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040D33C
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0041259C
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004E2284
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00488C40
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004E2D99
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004736F8
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004AC17C
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0049E118
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004EA1FC
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00402474
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0044A72C
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004FCA0C
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004C6BD4
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAC0FA
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C86184
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB022D
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBA3B0
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB0662
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C8A7EF
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBA85E
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C969CC
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAF919
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB0A97
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB2B21
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBED4C
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB2D50
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAFE15
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F369CC
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F4C0FA
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5A85E
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F26184
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F4F919
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5A3B0
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F52B21
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F52D50
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5ED4C
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F2A7EF
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017C0FA
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00156184
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018022D
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018A3B0
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00180662
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0015A7EF
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018A85E
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017F919
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_001669CC
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00180A97
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00182B21
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00182D50
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018ED4C
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017FE15
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: String function: 0019012F appears 678 times
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: String function: 0019061A appears 34 times
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: String function: 00151F20 appears 54 times
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: String function: 001931C7 appears 83 times
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: String function: 001537D3 appears 496 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 00487C88 appears 39 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 00409620 appears 139 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 00406914 appears 39 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 00406438 appears 41 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 0040C24C appears 32 times
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: String function: 004B2BC8 appears 36 times
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: String function: 00CC31C7 appears 83 times
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: String function: 00CC061A appears 34 times
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: String function: 00CC012F appears 677 times
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: String function: 00C837D3 appears 496 times
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: String function: 00C81F20 appears 54 times
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: String function: 00404C88 appears 36 times
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: String function: 00F631C7 appears 83 times
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: String function: 00F6012F appears 640 times
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: String function: 00F21F20 appears 53 times
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: String function: 00F6061A appears 34 times
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: String function: 00F237D3 appears 474 times
Source: video_editor_x64.tmp.20.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: video_editor_x64.tmp.20.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-9I76T.tmp.22.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-9I76T.tmp.22.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: video_editor_x64.exe.2.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: video_editor_x64.exe.2.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: video_editor_x64.tmp.20.drStatic PE information: Resource name: RT_BITMAP type: GLS_BINARY_LSB_FIRST
Source: video_editor_x64.tmp.20.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: video_editor_x64.tmp.20.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: is-9I76T.tmp.22.drStatic PE information: Resource name: RT_BITMAP type: GLS_BINARY_LSB_FIRST
Source: is-9I76T.tmp.22.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: is-9I76T.tmp.22.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeSection loaded: tsappcmp.dll
Source: classification engineClassification label: clean19.evad.win@19/873@0/2
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004328A4 GetLastError,FormatMessageW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040E538 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004B00AC GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C844E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F244E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_001544E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040805C GetDiskFreeSpaceW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004CC238 GetVersion,CoCreateInstance,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040EE14 FindResourceW,SizeofResource,LoadResource,LockResource,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CA6945 ChangeServiceConfigW,GetLastError,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegroJump to behavior
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\cmdline.outJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6660:120:WilError_01
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpMutant created: \Sessions\1\BaseNamedObjects\{E1AE6C64-631C-4B2F-853C-45C1BD634C03}
Source: C:\Users\user\Desktop\download\video_editor_x64.exeFile created: C:\Users\user\AppData\Local\Temp\is-M4I27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: )L
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: cabinet.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: msi.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: version.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: wininet.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: comres.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: clbcatq.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: msasn1.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: crypt32.dll
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCommand line argument: feclient.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: cabinet.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: msi.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: version.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: wininet.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: comres.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: clbcatq.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: msasn1.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: crypt32.dll
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCommand line argument: feclient.dll
Source: C:\Users\user\Desktop\download\video_editor_x64.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile read: C:\Program Files\FlashIntegro\VideoEditor\Localizations\crashrpt_lang_CS.iniJump to behavior
Source: C:\Windows\SysWOW64\wget.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Windows\SysWOW64\wget.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\SysWOW64\wget.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: video_editor_x64.exeString found in binary or memory: rting applications. /LOADINF="filename" Instructs Setup to load the settings from the specified file after having checked the co
Source: vcredist_x64.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: vcredist_x64.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: VC_redist.x64.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1' > cmdline.out 2>&1
Source: unknownProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1'
Source: unknownProcess created: C:\Users\user\Desktop\download\video_editor_x64.exe 'C:\Users\user\Desktop\download\video_editor_x64.exe'
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp 'C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp' /SL5='$1F0056,89355248,121344,C:\Users\user\Desktop\download\video_editor_x64.exe'
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe 'C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' /install /passive /norestart
Source: unknownProcess created: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe 'C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe' -burn.clean.room='C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' -burn.filehandle.attached=580 -burn.filehandle.self=564 /install /passive /norestart
Source: unknownProcess created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe 'C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe' -q -burn.elevated BurnPipe.{AEC565AB-0FED-47E7-88D9-B941D20CF512} {87809E35-81C0-47B4-86E7-066B690A99EC} 5088
Source: unknownProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /burn.runonce
Source: unknownProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: unknownProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1'
Source: C:\Users\user\Desktop\download\video_editor_x64.exeProcess created: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp 'C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp' /SL5='$1F0056,89355248,121344,C:\Users\user\Desktop\download\video_editor_x64.exe'
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe 'C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' /install /passive /norestart
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeProcess created: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe 'C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe' -burn.clean.room='C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' -burn.filehandle.attached=580 -burn.filehandle.self=564 /install /passive /norestart
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeProcess created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe 'C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe' -q -burn.elevated BurnPipe.{AEC565AB-0FED-47E7-88D9-B941D20CF512} {87809E35-81C0-47B4-86E7-066B690A99EC} 5088
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeProcess created: unknown unknown
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: C:\Windows\SysWOW64\wget.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpWindow found: window name: TSelectLanguageForm
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpAutomated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeWindow detected: Number of UI elements: 23
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeWindow detected: Number of UI elements: 23
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegroJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\unins000.datJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\is-9I76T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditorJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-CSG4M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegroJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-51BGK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-P6BPJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-VKA8L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\LocalizationsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-BCRV8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-OOR8C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-RB1FB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-TMPGC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-GBMCS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-VM6FH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-UGT21.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-J2KOS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-2QLEA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-VQJ9Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-6PL4E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-9B4VS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-LFTOB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Localizations\is-S1GUV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\ToolsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\LocalizationsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-LEDT9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-TSN75.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-638JN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-N2LQP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-M9F7B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-QDAKE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-609T5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-4CTD0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-HSQHC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-5TUHG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-TDM5E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-UA69A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-Q60U2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-PT0C2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-2P8H9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-0SG7I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-EUP48.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-EPPLT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-7P8PE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-H3Q3E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-VQLEK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-ROU4O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-5IHAM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-VSVSM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P1PRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-CPPIC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PJL5P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-09ON3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-GOHUV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-QSTSG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBinJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\is-CL5VE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiencesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GHKQD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-I46UE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-PRH4T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-5EQ0E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-TBRIB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-BSLL4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-MVRHA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GHI5G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-F29EL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-FR4HO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-CELBG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-EMVVC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-NTE34.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-OLPN3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-KHL16.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-3LBIS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-39A7G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-JOGRT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GIT45.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-68POL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-D3DNG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-KAHAS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-UPAA4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-S1HTH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-H1LIS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-TH42R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-2M1CS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-H7428.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-929TD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-OV9MG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-BITA4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-70ERH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-QKRUR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-N2GCJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-CHT3L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-PH5I5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-QC42T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-US9VT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-1DHV6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-6RM2R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-L8VPB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QP1V5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-4AD6F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-8OEUB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NEFLU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NJJD4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-V9E7A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QI59E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-FELGD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\pluginsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-JLV0H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-DBGJC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-CMQSS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-M0I4H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-37145.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-6LQ0G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\toolsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-FE45C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9F3I2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-NL7MN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-R788B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-64E3N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-KH2SN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VE8B0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7EV8O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-SR4CK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VQ2C8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-RJM7O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-MJN3C.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1DN8R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-LKBCE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-GSO7L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-DS9U1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9S1L5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7JSD1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1KUPI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-4922F.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P9F2A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DI71O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-67Q05.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-IE7UD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T11L1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T3E2B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-19FI6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DVG3K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-3EO63.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-1K3AJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LCGQE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-BS97R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LTK27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-405Q8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9KGNK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DDA4R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7AVA5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PIVL1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-ILPSH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-32VOB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-GUIIM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-Q042M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-TI4FS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P4R44.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-UNR4I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-35DF0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-22CCE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-91VDT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-R5R9N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9T70V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-JIFVF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-0HCB9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7DG6H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-2APG5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-EPU6H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\SkinsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\Skins\is-B3CLK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\IconsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\Common Files\FlashIntegro\Icons\is-OEFT9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-LLEGR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-RQNKS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\is-LBTK9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I6T9L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I7CDN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VAK07.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-05DK1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VVOBD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-C5B5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-0O32B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-MA3LK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-BKS6A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FMAB2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-RGQOV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-GK5DP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-NLT24.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-18751.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LP55S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LIT59.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-3G6AI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H1IE7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4EEP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-U4VOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9HOFC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FG6LB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9UITF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H7IP7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-EL74B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4TT6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-TMCVL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-FAIB7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-26N17.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-GC7SG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-0P374.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-FPN7G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-MHS1N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Tools\Localizations\is-VJVTV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\TemplatesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVisJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\is-AEM9J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\dataJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-PASQS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-18N5J.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-EE30E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-D7F0R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-71763.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-QJKGK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-205MJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-MACAJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-JL8TS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presetsJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\AderrasiJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-RQ9AI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-HGA76.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-EKH8K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-CI9B0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-3LHV4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-QUMD0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-OPJ0L.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-LOAA6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-GQFU2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-4S9MO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-FL6SE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-GJEC6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-9E7R5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-2EJ77.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-GTG9P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-UNULP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-FIVE4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-NG7L4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-76EQB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Aderrasi\is-2JGVN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.SJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-9TRIO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-1UNB8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-F6C3V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-73DMN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-G5U8P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-M548A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-RBA0A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-VVLRI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-IS4JU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-3JNV3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-1HGD7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-SB92V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-TS4RV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-VKPMB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-6ARCB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-CPBLM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-T6CCL.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-RE48O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-1793G.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-6NCGG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-JITLO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-IVS55.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-TE7SE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-MCB45.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-QDEAV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-AG5E8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-2P44S.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-OSTLC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-AA542.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-NJPQP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-PUMEJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-04MSU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-K3NSQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-S3ULH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-7VHFA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-9KC7I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-PI9KV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-VGQT7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-43G0Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-Q4RM0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-TB8G8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-T1D4K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-JO30Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-NFHT1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Eo.S\is-9QBMD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiNJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-3G1IF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-VVVH3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-1RG5D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-M3HJ7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-CK81H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-03CNC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-MFIBR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-OTTME.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-P9A0I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-SHHTE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-CPL14.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-0NMJO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-820I8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-M34H0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-7QR9V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-GJ430.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-3PADE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-4DM3R.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-T8KV4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\fiShbRaiN\is-9CCVS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexiJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-FG1SQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-7O2BM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-RJ4DC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-EOLA4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-T7IV4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-GVT2A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-104LF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-VDS5H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-59H75.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-C005E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-SBFC4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-03PPR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-RCDRK.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-V7PMR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-PS2Q4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-0TTIP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-75DNA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-SJPS8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-4U7S6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-CEC03.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-DMV8U.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-6N0VE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-GIO32.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-O1SLI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-1CGJ9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-M5DE4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-033JI.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-L4OAU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-LJ5D3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-IF9Q3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-HAN6B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-AGMRU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-RVD12.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-PTQP2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-I5287.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-5JT8A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-OFOE1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-S0D4Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-IGSPU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-R0RJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-1SG6M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-HR3R2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-CODG7.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-LNB69.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-C4AHP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-865TJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-5EFJR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-SMCBB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-261A3.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-MECI4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-CGP1H.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-U74IP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-SN7UB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-66H2D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-GV0A1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-OGSGC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-B81HA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-MPQS8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-0N2I4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-V5TRR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-D3MPN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-GFDHA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-M69II.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-4PHGV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-VUC2B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-2EMNE.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-SVHO2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\flexi\is-OETFG.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\GeissJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-GVN9T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-FKS89.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-V6G3D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-EH2R5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-6QM36.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-LBA1M.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-KVO9A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-K3RRM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-123KU.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-VF05A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-NM2IH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-KTPSS.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-JAEPR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-5P0OV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-24HRR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-2R3EF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-98G0O.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-LNU6D.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-FLPM0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-MPI46.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-8SVCB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-KA8RB.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-J845N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-ADGLP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Geiss\is-GTAJC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\GoodyJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-B9T9I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-86O3P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-HVOV1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-O9B0K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-TOI6P.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-67UST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-64HVM.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-STRIQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-6T6CP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-A0AHR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-KRDRF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-MKESN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-F2EP9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-BQRNC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-P87Q4.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-C0552.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-A64E2.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-667M8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Goody\is-1L27E.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\HexcollieJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Hexcollie\is-EN26K.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Hexcollie\is-R9IGR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Hexcollie\is-L6UB6.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Hexcollie\is-JD4J5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Hexcollie\is-CP3G5.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\MartinJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-0J4BD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-0UG6V.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-40PGV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-C3M4B.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-JGJBF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-BNKEA.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-72CON.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-E2CQ1.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-GAL2Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-67EPV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-OC963.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-0CLRT.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-0P975.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-IJLMN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-HVMOR.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-90H8N.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-D97I9.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-8DO5A.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-5COKO.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-2A6J8.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-02E1T.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-IJ3QF.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-NJB1I.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-58R27.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-DVENQ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-92AUV.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-7D1B0.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-707GD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-05TPN.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-FLAFH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-DG40Q.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-N7ECH.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-2FVHD.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-BGFST.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-DREMP.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-L4HPC.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-1MMCJ.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDirectory created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\presets\Martin\is-8MVBT.tmpJump to behavior
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: vcredist_x64.exe, 0000001B.00000000.544275902.0000000000CCB000.00000002.00020000.sdmp, vcredist_x64.exe, 0000001D.00000000.545735742.0000000000F6B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000020.00000002.589217485.000000000019B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000025.00000000.583222248.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000026.00000000.584723229.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000027.00000002.610680528.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe.32.dr
Source: Binary string: e:\src\datatype_rn\lsd\codec\ralf.pdb source: is-QI59E.tmp.22.dr
Source: Binary string: d:\agent\_work\2\s\\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: is-CPPIC.tmp.22.dr
Source: Binary string: e:\src\producersdk\plugins\transform\audioresampler\audioresampler.pdb source: is-64E3N.tmp.22.dr
Source: Binary string: w:\Work2\ActiveX5_Edited\VStudia\mslanimationfile5\x64\Release\mslanimationfile5.pdb6 source: is-DDA4R.tmp.22.dr
Source: Binary string: w:\Tools\Codejock Software\MFC\Xtreme ToolkitPro v19.2.0\Source\Styles\Office2016\Release\vc160\Office2016vc160.pdb source: video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmp
Source: Binary string: e:\src\producersdk\plugins\transform\eventpack\eventpack.pdb source: is-SR4CK.tmp.22.dr
Source: Binary string: w:\Work2\ActiveX5_Edited\VStudia\mslanimationfile5\x64\Release\mslanimationfile5.pdb source: is-DDA4R.tmp.22.dr
Source: Binary string: w:\Work2\Projects_VideoSoftDev\video_tools\YouTubeUploader\obj\Release\YouTubeUploader.pdb source: is-GK5DP.tmp.22.dr
Source: Binary string: w:\Work2\Projects_VideoSoftDev\video_tools\YouTubeUploader\obj\Release\YouTubeUploader.pdbh source: is-GK5DP.tmp.22.dr
Source: Binary string: W:\Work2\Projects_VideoSoftDev\common\ExecuteHelper\x64\Release\ExecuteHelper.pdb source: video_editor_x64.tmp, 00000016.00000002.668331619.0000000004E60000.00000004.00000001.sdmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004A1A3C LoadLibraryExW,LoadLibraryW,GetProcAddress,
Source: is-9I76T.tmp.22.drStatic PE information: real checksum: 0x12d125 should be: 0x12adc8
Source: video_editor_x64.exe.2.drStatic PE information: real checksum: 0x55c3daa should be:
Source: itdownload.dll.22.drStatic PE information: real checksum: 0x0 should be: 0x3c807
Source: vcredist_x64.exe.22.drStatic PE information: real checksum: 0xe56dd3 should be:
Source: vcredist_x64.exe.27.drStatic PE information: real checksum: 0xe56dd3 should be: 0xa5b19
Source: _iscrypt.dll.22.drStatic PE information: real checksum: 0x0 should be: 0x89d2
Source: vcredist_x64.exe.22.drStatic PE information: section name: .wixburn
Source: vcredist_x64.exe.27.drStatic PE information: section name: .wixburn
Source: VC_redist.x64.exe.32.drStatic PE information: section name: .wixburn
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040D034 push ecx; mov dword ptr [esp], eax
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040E0D0 push 0040E118h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_004100D8 push 00410140h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00406944 push 00406986h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040B104 push 0040B2B0h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00406A50 push 00406A88h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040E250 push 0040E27Ch; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00406A92 push 00406AC0h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00406A94 push 00406AC0h; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_004064A6 push 0040650Dh; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_004064A8 push 0040650Dh; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_004034A8 push eax; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0041157C push 004115FAh; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_0040DD38 push 0040DD7Bh; ret
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00411618 push 00411645h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004FA044 push ecx; mov dword ptr [esp], ecx
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0046E0B0 push ecx; mov dword ptr [esp], edx
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00482158 push 0048219Bh; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004AC17C push ecx; mov dword ptr [esp], eax
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0044C1F4 push 0044C220h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0042E1B4 push 0042E1E0h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0047E234 push 0047E28Eh; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0045C2C4 push ecx; mov dword ptr [esp], ecx
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0040A2C4 push 0040A306h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004542FC push 00454367h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0049C374 push ecx; mov dword ptr [esp], ecx
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0040A3D0 push 0040A408h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0046E404 push ecx; mov dword ptr [esp], edx
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0040A412 push 0040A440h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0040A414 push 0040A440h; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004204B0 push 004204FDh; ret
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P4R44.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-RGQOV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-P6BPJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-0HCB9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-19FI6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-GOHUV.tmpJump to dropped file
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\wixstdba.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\Icons\is-OEFT9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-8OEUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-MA3LK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\is-9I76T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NEFLU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I6T9L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-0QH9Q.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-RQNKS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-LBTK9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H1IE7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9UITF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-37145.tmpJump to dropped file
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9HOFC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-8FNTV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-EUP48.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-2APG5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-OHJAD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-VSVSM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-MJN3C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-64E3N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-2P8H9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-UNR4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-205MJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-QSTSG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1DN8R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H7IP7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LIT59.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9KGNK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-3G6AI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-R788B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-67Q05.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-1K3AJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-GUIIM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-BS97R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7AVA5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DI71O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-C5B5H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-JNA69.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\_isetup\_setup64.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NJJD4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-35DF0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-L00SG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9T70V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-4922F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-3EO63.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T3E2B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7EV8O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P9F2A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PIVL1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PJL5P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-09ON3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\_isetup\_iscrypt.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-ROU4O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VE8B0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VVOBD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-RBT22.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-6LQ0G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7DG6H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-GSO7L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-4AD6F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LCGQE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QI59E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-M0I4H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-JIFVF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-22CCE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-GK5DP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-6RM2R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-EPPLT.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-R5R9N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-CPPIC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-5IHAM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-91VDT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-DBGJC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-IE7UD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-G6P95.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-EL74B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-V9E7A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-QUAMI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-AGCOG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-MFS8H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-TI4FS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-SR4CK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LP55S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-Q042M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QP1V5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-EPU6H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VAK07.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-0SG7I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DVG3K.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-NL7MN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-JLV0H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-FE45C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VQ2C8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-LKBCE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-G038I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-405Q8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-C5KCH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P1PRU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-BKS6A.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-U4VOR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-L8VPB.tmpJump to dropped file
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-ILPSH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-05DK1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-PL5GF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9F3I2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-0O32B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4TT6.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-VKA8L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\Skins\is-B3CLK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-CSG4M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-H3Q3E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1KUPI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4EEP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-95VKA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-51BGK.tmpJump to dropped file
Source: C:\Windows\SysWOW64\wget.exeFile created: C:\Users\user\Desktop\download\video_editor_x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FG6LB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeFile created: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-CMQSS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T11L1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7JSD1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-VQLEK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-VHK7U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FMAB2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-1DHV6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-UR5C0.tmp
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\wixstdba.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9S1L5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-7P8PE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LTK27.tmpJump to dropped file
Source: C:\Users\user\Desktop\download\video_editor_x64.exeFile created: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-32VOB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-RJM7O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-DS9U1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\is-CL5VE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\is-LLEGR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DDA4R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\itdownload.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-CFMS7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-FELGD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I7CDN.tmp
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-G6P95.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-VHK7U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-8FNTV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-RBT22.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-OHJAD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-JNA69.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-QUAMI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-UR5C0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-AGCOG.tmp
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\wixstdba.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-PL5GF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-MFS8H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-G038I.tmp
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\wixstdba.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-L00SG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-C5KCH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-CFMS7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-95VKA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpFile created: C:\Windows\System32\is-0QH9Q.tmp
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeFile created: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1028\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1029\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1031\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1036\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1040\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1041\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1042\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1045\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1046\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1049\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\1055\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\2052\license.rtfJump to behavior
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\3082\license.rtfJump to behavior
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeFile created: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\3082\license.rtf
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00470AAC GetWindowLongW,IsIconic,IsWindowVisible,ShowWindow,SetWindowLongW,SetWindowLongW,ShowWindow,ShowWindow,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004736F8 IsIconic,SetFocus,GetParent,SaveDC,RestoreDC,GetWindowDC,SaveDC,RestoreDC,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004629EC IsIconic,GetCapture,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00470A2C IsIconic,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeRegistry key monitored for changes: HKEY_CURRENT_USER_Classes
Source: C:\Users\user\Desktop\download\video_editor_x64.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetCurrentThreadId,GetCursorPos,WaitForSingleObject,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P4R44.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-RGQOV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-P6BPJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-0HCB9.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-19FI6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-GOHUV.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\Icons\is-OEFT9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-MA3LK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-8OEUB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\is-9I76T.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I6T9L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NEFLU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-RQNKS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-0QH9Q.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-LBTK9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9UITF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H1IE7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-37145.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-9HOFC.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-8FNTV.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-EUP48.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-2APG5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-OHJAD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-VSVSM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-UNR4I.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-MJN3C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-2P8H9.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-64E3N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Templates\AudioVis\data\is-205MJ.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-QSTSG.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1DN8R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-H7IP7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LIT59.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9KGNK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-3G6AI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-R788B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-1K3AJ.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-GUIIM.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-67Q05.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-BS97R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7AVA5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DI71O.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-C5B5H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-JNA69.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\_isetup\_setup64.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-35DF0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NJJD4.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-L00SG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9T70V.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-3EO63.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-4922F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T3E2B.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P9F2A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7EV8O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PIVL1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PJL5P.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-09ON3.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-ROU4O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VE8B0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VVOBD.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-RBT22.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-6LQ0G.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7DG6H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-GSO7L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-4AD6F.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LCGQE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QI59E.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-M0I4H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-JIFVF.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-GK5DP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-22CCE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-6RM2R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-EPPLT.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-R5R9N.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-CPPIC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-5IHAM.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-91VDT.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-DBGJC.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-IE7UD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-G6P95.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-EL74B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-V9E7A.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-QUAMI.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-AGCOG.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-MFS8H.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-TI4FS.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-SR4CK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-LP55S.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\is-Q042M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-EPU6H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QP1V5.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-VAK07.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-0SG7I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DVG3K.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-NL7MN.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-JLV0H.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-VQ2C8.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-FE45C.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-LKBCE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-G038I.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-405Q8.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-C5KCH.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P1PRU.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-BKS6A.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-U4VOR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-L8VPB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-ILPSH.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-05DK1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-PL5GF.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9F3I2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-0O32B.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4TT6.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-VKA8L.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\Skins\is-B3CLK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-CSG4M.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-H3Q3E.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1KUPI.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-O4EEP.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-95VKA.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-51BGK.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FG6LB.tmp
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeDropped PE file which has not been started: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T11L1.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-CMQSS.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-7JSD1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-VQLEK.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-VHK7U.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-FMAB2.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-1DHV6.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-UR5C0.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-9S1L5.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LTK27.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-7P8PE.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-32VOB.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-RJM7O.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-DS9U1.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\is-CL5VE.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\is-LLEGR.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DDA4R.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\itdownload.dll
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Windows\System32\is-CFMS7.tmp
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-FELGD.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpDropped PE file which has not been started: C:\Program Files\FlashIntegro\VideoEditor\Tools\is-I7CDN.tmp
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeEvaded block: after key decision
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeEvaded block: after key decision
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeEvaded block: after key decision
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeEvaded block: after key decision
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeEvaded block: after key decision
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeRegistry key enumerated: More than 150 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeRegistry key enumerated: More than 152 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeRegistry key enumerated: More than 151 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00CBFE5Dh
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CBFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00CBFE56h
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00F5FE5Dh
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F5FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00F5FE56h
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0018FE5Dh
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0018FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 0018FE56h
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00405BEC GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004AD294 FindFirstFileW,GetLastError,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00408174 GetModuleHandleW,GetProcAddress,lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004C0BC0 SetErrorMode,FindFirstFileW,FindNextFileW,FindClose,SetErrorMode,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004C107C SetErrorMode,FindFirstFileW,FindNextFileW,FindClose,SetErrorMode,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C83BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CC4315 FindFirstFileW,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C9993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB7A87 FindFirstFileExW,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F3993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F23BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F64315 FindFirstFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00194315 FindFirstFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0016993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00153BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00187A87 FindFirstFileExW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_00406458 GetSystemInfo,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cab
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\NULL
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\NULL
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\NULL
Source: video_editor_x64.exe, 00000014.00000002.651888982.00000000023C0000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.657074100.00000000029A0000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001B.00000002.599493680.0000000002F00000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001D.00000002.595145867.0000000002E00000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000020.00000002.590824327.0000000003550000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000025.00000002.589434841.0000000003470000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000026.00000002.616679838.00000000033C0000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000027.00000002.611705152.0000000002D70000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
Source: video_editor_x64.exe, 00000014.00000002.651888982.00000000023C0000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.657074100.00000000029A0000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001B.00000002.599493680.0000000002F00000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001D.00000002.595145867.0000000002E00000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000020.00000002.590824327.0000000003550000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000025.00000002.589434841.0000000003470000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000026.00000002.616679838.00000000033C0000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000027.00000002.611705152.0000000002D70000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
Source: video_editor_x64.exe, 00000014.00000002.651888982.00000000023C0000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.657074100.00000000029A0000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001B.00000002.599493680.0000000002F00000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001D.00000002.595145867.0000000002E00000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000020.00000002.590824327.0000000003550000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000025.00000002.589434841.0000000003470000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000026.00000002.616679838.00000000033C0000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000027.00000002.611705152.0000000002D70000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
Source: wget.exe, 00000002.00000002.340434297.00000000009F8000.00000004.00000020.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: video_editor_x64.exe, 00000014.00000002.651888982.00000000023C0000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.657074100.00000000029A0000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001B.00000002.599493680.0000000002F00000.00000002.00000001.sdmp, vcredist_x64.exe, 0000001D.00000002.595145867.0000000002E00000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000020.00000002.590824327.0000000003550000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000025.00000002.589434841.0000000003470000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000026.00000002.616679838.00000000033C0000.00000002.00000001.sdmp, VC_redist.x64.exe, 00000027.00000002.611705152.0000000002D70000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.
Source: C:\Users\user\Desktop\download\video_editor_x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeProcess information queried: ProcessInformation
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAE625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004A1A3C LoadLibraryExW,LoadLibraryW,GetProcAddress,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB4812 mov eax, dword ptr fs:[00000030h]
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F54812 mov eax, dword ptr fs:[00000030h]
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00184812 mov eax, dword ptr fs:[00000030h]
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C838D4 GetProcessHeap,RtlAllocateHeap,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAE773 SetUnhandledExceptionFilter,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAE188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAE625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CB3BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F4E188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeCode function: 29_2_00F53BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017E773 SetUnhandledExceptionFilter,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017E188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_0017E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeCode function: 32_2_00183BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004D8F68 ShellExecuteExW,GetLastError,MsgWaitForMultipleObjects,GetExitCodeProcess,CloseHandle,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeProcess created: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe 'C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe' -burn.clean.room='C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' -burn.filehandle.attached=580 -burn.filehandle.self=564 /install /passive /norestart
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeProcess created: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe 'C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe' -q -burn.elevated BurnPipe.{AEC565AB-0FED-47E7-88D9-B941D20CF512} {87809E35-81C0-47B4-86E7-066B690A99EC} 5088
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeProcess created: unknown unknown
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: unknownProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe 'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_00480E38 InitializeSecurityDescriptor,SetSecurityDescriptorDacl,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_0047FFEC AllocateAndInitializeSid,GetVersion,GetModuleHandleW,CheckTokenMembership,GetCurrentThread,OpenThreadToken,GetLastError,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,FreeSid,
Source: video_editor_x64.exe, 00000014.00000002.650376524.0000000000E70000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.652288287.0000000000FE0000.00000002.00000001.sdmpBinary or memory string: Program Manager
Source: video_editor_x64.exe, 00000014.00000002.650376524.0000000000E70000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.652288287.0000000000FE0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
Source: video_editor_x64.exe, 00000014.00000002.650376524.0000000000E70000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.652288287.0000000000FE0000.00000002.00000001.sdmpBinary or memory string: Progman
Source: video_editor_x64.exe, 00000014.00000002.650376524.0000000000E70000.00000002.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.652288287.0000000000FE0000.00000002.00000001.sdmpBinary or memory string: Progmanlock
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CAE9A7 cpuid
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: GetModuleFileNameW,RegOpenKeyExW,RegOpenKeyExW,RegOpenKeyExW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,lstrcpynW,GetThreadLocale,GetLocaleInfoW,lstrlenW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: GetLocaleInfoW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: GetLocaleInfoW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: GetLocaleInfoW,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: lstrcpynW,GetThreadLocale,GetLocaleInfoW,lstrlenW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetModuleFileNameW,RegOpenKeyExW,RegOpenKeyExW,RegOpenKeyExW,RegOpenKeyExW,RegQueryValueExW,RegQueryValueExW,RegCloseKey,lstrcpynW,GetThreadLocale,GetLocaleInfoW,lstrlenW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: lstrcpynW,GetThreadLocale,GetLocaleInfoW,lstrlenW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,lstrcpynW,LoadLibraryExW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetLocaleInfoW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetLocaleInfoW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetLocaleInfoW,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: GetLocaleInfoW,
Source: C:\Windows\SysWOW64\wget.exeQueries volume information: C:\Users\user\Desktop\download VolumeInformation
Source: C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exeQueries volume information: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\logo.png VolumeInformation
Source: C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exeQueries volume information: C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\logo.png VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C94CE8 ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree,
Source: C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmpCode function: 22_2_004B2868 GetSystemTimeAsFileTime,FileTimeToSystemTime,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00C860BA GetUserNameW,GetLastError,
Source: C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exeCode function: 27_2_00CC8733 GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime,
Source: C:\Users\user\Desktop\download\video_editor_x64.exeCode function: 20_2_004110C4 GetModuleHandleW,GetVersion,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,SetProcessDEPPolicy,
Source: C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsNative API3DLL Side-Loading1Exploitation for Privilege Escalation1Deobfuscate/Decode Files or Information1Input Capture11System Time Discovery12Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationSystem Shutdown/Reboot1
Default AccountsCommand and Scripting Interpreter13Windows Service1DLL Side-Loading1Obfuscated Files or Information2LSASS MemoryAccount Discovery1Remote Desktop ProtocolScreen Capture1Exfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsService Execution1Logon Script (Windows)Access Token Manipulation1DLL Side-Loading1Security Account ManagerFile and Directory Discovery3SMB/Windows Admin SharesInput Capture11Automated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Windows Service1File Deletion1NTDSSystem Information Discovery56Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptProcess Injection13Masquerading23LSA SecretsQuery Registry1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonVirtualization/Sandbox Evasion11Cached Domain CredentialsSecurity Software Discovery41VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup ItemsAccess Token Manipulation1DCSyncVirtualization/Sandbox Evasion11Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobProcess Injection13Proc FilesystemProcess Discovery12Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)Masquerading/etc/passwd and /etc/shadowApplication Window Discovery11Software Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)Invalid Code SignatureNetwork SniffingSystem Owner/User Discovery3Taint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
Compromise Software Dependencies and Development ToolsWindows Command ShellCronCronRight-to-Left OverrideInput CaptureRemote System Discovery1Replication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 326343 URL: http://www.videosoftdev.com... Startdate: 03/12/2020 Architecture: WINDOWS Score: 19 8 video_editor_x64.exe 2 2->8         started        11 cmd.exe 2 2->11         started        13 VC_redist.x64.exe 2->13         started        file3 40 C:\Users\user\...\video_editor_x64.tmp, PE32 8->40 dropped 15 video_editor_x64.tmp 58 508 8->15         started        17 wget.exe 2 11->17         started        21 conhost.exe 11->21         started        23 VC_redist.x64.exe 13->23         started        process4 dnsIp5 25 vcredist_x64.exe 3 15->25         started        50 198.251.66.75 ONEANDONE-ASBrauerstrasse48DE United States 17->50 52 8.8.8.8 GOOGLEUS United States 17->52 38 C:\Users\user\...\video_editor_x64.exe, PE32 17->38 dropped 28 VC_redist.x64.exe 23->28         started        file6 process7 file8 42 C:\Windows\Temp\...\vcredist_x64.exe, PE32 25->42 dropped 30 vcredist_x64.exe 71 25->30         started        44 C:\Windows\Temp\...\wixstdba.dll, PE32 28->44 dropped process9 file10 46 C:\Windows\Temp\...\VC_redist.x64.exe, PE32 30->46 dropped 48 C:\Windows\Temp\...\wixstdba.dll, PE32 30->48 dropped 33 VC_redist.x64.exe 30 18 30->33         started        process11 file12 36 C:\ProgramData\...\VC_redist.x64.exe, PE32 33->36 dropped

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
http://www.videosoftdev.com/services/download.aspx?ProductID=10%VirustotalBrowse
http://www.videosoftdev.com/services/download.aspx?ProductID=10%Avira URL Cloudsafe

Dropped Files

SourceDetectionScannerLabelLink
C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe0%MetadefenderBrowse
C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp3%MetadefenderBrowse
C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp2%ReversingLabs
C:\Users\user\Desktop\download\video_editor_x64.exe5%MetadefenderBrowse
C:\Users\user\Desktop\download\video_editor_x64.exe0%ReversingLabs
C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\wixstdba.dll0%MetadefenderBrowse
C:\Windows\Temp\{9BCC3480-CDF5-4D98-B3FD-8A6800206E32}\.ba\wixstdba.dll0%ReversingLabs
C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe2%ReversingLabs
C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\wixstdba.dll0%MetadefenderBrowse
C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.ba\wixstdba.dll0%ReversingLabs
C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe0%MetadefenderBrowse
C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe0%ReversingLabs

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
http://www.innosetup.com/0%URL Reputationsafe
http://www.innosetup.com/0%URL Reputationsafe
http://www.innosetup.com/0%URL Reputationsafe
http://www.innosetup.com/0%URL Reputationsafe
http://ocsp.sectigo.com00%URL Reputationsafe
http://ocsp.sectigo.com00%URL Reputationsafe
http://ocsp.sectigo.com00%URL Reputationsafe
http://ocsp.sectigo.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://www.videosoftdev.com6http://www.videosoftdev.com6http://www.videosoftdev.com0%Avira URL Cloudsafe
http://www.codejock.com0%Avira URL Cloudsafe
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor0%Avira URL Cloudsafe
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#0%URL Reputationsafe
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#0%URL Reputationsafe
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#0%URL Reputationsafe
http://ocsp.sectigo.com0#0%URL Reputationsafe
http://ocsp.sectigo.com0#0%URL Reputationsafe
http://ocsp.sectigo.com0#0%URL Reputationsafe
http://www.dk-soft.org/0%URL Reputationsafe
http://www.dk-soft.org/0%URL Reputationsafe
http://www.dk-soft.org/0%URL Reputationsafe
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t0%URL Reputationsafe
http://www.videosoftdev.co0%Avira URL Cloudsafe
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#0%URL Reputationsafe
https://sectigo.com/CPS0C0%URL Reputationsafe
https://sectigo.com/CPS0C0%URL Reputationsafe
https://sectigo.com/CPS0C0%URL Reputationsafe
https://sectigo.com/CPS0D0%URL Reputationsafe
https://sectigo.com/CPS0D0%URL Reputationsafe
https://sectigo.com/CPS0D0%URL Reputationsafe
http://www.remobjects.com/ps0%URL Reputationsafe
http://www.remobjects.com/ps0%URL Reputationsafe
http://www.remobjects.com/ps0%URL Reputationsafe
http://www.realnetworks.com0=10%Avira URL Cloudsafe
http://www.realnetworks.com0%Avira URL Cloudsafe
http://appsyndication.org/2006/appsyn0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://www.innosetup.com/video_editor_x64.exe, 00000014.00000003.387425971.000000007FD80000.00000004.00000001.sdmp, video_editor_x64.tmp, video_editor_x64.tmp, 00000016.00000000.388602269.0000000000401000.00000020.00020000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
  • URL Reputation: safe
  • URL Reputation: safe
unknown
http://www.videosoftdev.com/services/purchase.aspx?ProductID=1avideo_editor_x64.tmp, 00000016.00000002.658287088.0000000003688000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000003.389180628.0000000003390000.00000004.00000001.sdmpfalse
    high
    http://ocsp.sectigo.com0wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpfalse
    • URL Reputation: safe
    • URL Reputation: safe
    • URL Reputation: safe
    • URL Reputation: safe
    unknown
    http://www.videosoftdev.com/services/download.aspx?ProductID=x32_1video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpfalse
      high
      http://wixtoolset.org/schemas/thmutil/2010VC_redist.x64.exe, 00000027.00000003.608972858.00000000032BA000.00000004.00000001.sdmp, VC_redist.x64.exe, 00000027.00000003.609712314.0000000001060000.00000004.00000040.sdmpfalse
        high
        http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUvideo_editor_x64.exe, 00000014.00000000.386663597.0000000000401000.00000020.00020000.sdmpfalse
          high
          http://ocsp.thawte.com0video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpfalse
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          unknown
          http://downloads.videosoftdev.com/video_tools/video_editor_x64.exewget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpfalse
            high
            http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlinevideo_editor_x64.exefalse
              high
              http://www.videosoftdev.com6http://www.videosoftdev.com6http://www.videosoftdev.comvideo_editor_x64.exe, 00000014.00000003.386914432.00000000024B0000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000003.389180628.0000000003390000.00000004.00000001.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.codejock.comvideo_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0swget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drfalse
              • URL Reputation: safe
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              http://www.videosoftdev.com/services/download.aspx?ProductID=1.wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpfalse
                high
                http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgorvcredist_x64.exe, 0000001B.00000000.544275902.0000000000CCB000.00000002.00020000.sdmp, vcredist_x64.exe, 0000001D.00000000.545735742.0000000000F6B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000020.00000002.589217485.000000000019B000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000025.00000000.583222248.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000026.00000000.584723229.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe, 00000027.00000002.610680528.0000000000ADB000.00000002.00020000.sdmp, VC_redist.x64.exe.32.drfalse
                • Avira URL Cloud: safe
                unknown
                http://downloads.videosoftdev.com/video_tools/video_editor_x64.exe3wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpfalse
                  high
                  http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  http://ocsp.sectigo.com0#wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drfalse
                  • URL Reputation: safe
                  • URL Reputation: safe
                  • URL Reputation: safe
                  unknown
                  http://www.videosoftdev.comvideo_editor_x64.tmp, 00000016.00000002.653698216.000000000250A000.00000004.00000001.sdmpfalse
                    high
                    http://www.dk-soft.org/video_editor_x64.exe, 00000014.00000003.386914432.00000000024B0000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.653698216.000000000250A000.00000004.00000001.sdmpfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0twget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpfalse
                    • URL Reputation: safe
                    • URL Reputation: safe
                    • URL Reputation: safe
                    unknown
                    http://www.videosoftdev.com/services/download.aspx?ProductID=19wget.exe, 00000002.00000002.340511863.0000000001100000.00000004.00000040.sdmpfalse
                      high
                      http://www.videosoftdev.covideo_editor_x64.tmp, 00000016.00000002.652002104.0000000000835000.00000004.00000020.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.videosoftdev.com/services/download.aspx?ProductID=1wget.exe, 00000002.00000002.340414107.00000000009F0000.00000004.00000020.sdmpfalse
                        high
                        http://crl.thawte.com/ThawteTimestampingCA.crl0video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpfalse
                          high
                          http://www.videosoftdev.com/services/download.aspx?ProductID=1?wget.exe, 00000002.00000002.340511863.0000000001100000.00000004.00000040.sdmpfalse
                            high
                            http://www.conduit.com/legal/searchprotectdescriptionvideo_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpfalse
                              high
                              http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpfalse
                              • URL Reputation: safe
                              • URL Reputation: safe
                              • URL Reputation: safe
                              unknown
                              http://crl.trustwave.com/CSCA2_L1.crl0qvideo_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpfalse
                                high
                                https://sectigo.com/CPS0Cwget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, is-DDA4R.tmp.22.drfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                https://sectigo.com/CPS0Dwget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmp, video_editor_x64.exe, 00000014.00000003.387281147.0000000002706000.00000004.00000001.sdmpfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                http://www.videosoftdev.com/services/install.aspx?ProductID=1video_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpfalse
                                  high
                                  https://www.youtube.com/watch?v=is-GK5DP.tmp.22.drfalse
                                    high
                                    http://www.remobjects.com/psvideo_editor_x64.exe, 00000014.00000003.387425971.000000007FD80000.00000004.00000001.sdmp, video_editor_x64.tmpfalse
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    • URL Reputation: safe
                                    unknown
                                    http://downloads.videosoftdev.com/video_tools/video_editor_x64.exetates3wget.exe, 00000002.00000002.340520016.0000000001106000.00000004.00000040.sdmpfalse
                                      high
                                      http://crl.trustwave.com/STCA.crl0=video_editor_x64.tmp, 00000016.00000002.675326646.0000000006170000.00000004.00000001.sdmpfalse
                                        high
                                        http://www.youtube.com/watch?v=jaA2361wq50video_editor_x64.tmp, 00000016.00000002.673721113.0000000005B3E000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.671162818.0000000005886000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.674313336.0000000005DD5000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673428705.00000000059DF000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.673989945.0000000005C7B000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.674987522.0000000005F2E000.00000004.00000001.sdmp, video_editor_x64.tmp, 00000016.00000002.670684399.0000000005728000.00000004.00000001.sdmpfalse
                                          high
                                          http://www.delta-search.com/eula.htmlvideo_editor_x64.tmp, 00000016.00000002.682043750.0000000006F4B000.00000004.00000001.sdmpfalse
                                            high
                                            http://www.realnetworks.com0=1is-64E3N.tmp.22.drfalse
                                            • Avira URL Cloud: safe
                                            low
                                            http://www.realnetworks.comis-SR4CK.tmp.22.drfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://appsyndication.org/2006/appsynvcredist_x64.exe, VC_redist.x64.exefalse
                                            • Avira URL Cloud: safe
                                            unknown

                                            Contacted IPs

                                            • No. of IPs < 25%
                                            • 25% < No. of IPs < 50%
                                            • 50% < No. of IPs < 75%
                                            • 75% < No. of IPs

                                            Public

                                            IPDomainCountryFlagASNASN NameMalicious
                                            8.8.8.8
                                            unknownUnited States
                                            15169GOOGLEUSfalse
                                            198.251.66.75
                                            unknownUnited States
                                            8560ONEANDONE-ASBrauerstrasse48DEfalse

                                            General Information

                                            Joe Sandbox Version:31.0.0 Red Diamond
                                            Analysis ID:326343
                                            Start date:03.12.2020
                                            Start time:10:19:10
                                            Joe Sandbox Product:CloudBasic
                                            Overall analysis duration:0h 14m 35s
                                            Hypervisor based Inspection enabled:false
                                            Report type:light
                                            Cookbook file name:urldownload.jbs
                                            Sample URL:http://www.videosoftdev.com/services/download.aspx?ProductID=1
                                            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                            Number of analysed new started processes analysed:40
                                            Number of new started drivers analysed:0
                                            Number of existing processes analysed:0
                                            Number of existing drivers analysed:0
                                            Number of injected processes analysed:0
                                            Technologies:
                                            • HCA enabled
                                            • EGA enabled
                                            • HDC enabled
                                            • AMSI enabled
                                            Analysis Mode:default
                                            Analysis stop reason:Timeout
                                            Detection:CLEAN
                                            Classification:clean19.evad.win@19/873@0/2
                                            EGA Information:
                                            • Successful, ratio: 100%
                                            HDC Information:
                                            • Successful, ratio: 62.5% (good quality ratio 57.5%)
                                            • Quality average: 72%
                                            • Quality standard deviation: 30.9%
                                            HCA Information:
                                            • Successful, ratio: 52%
                                            • Number of executed functions: 0
                                            • Number of non-executed functions: 0
                                            Cookbook Comments:
                                            • Adjust boot time
                                            • Enable AMSI
                                            Warnings:
                                            Show All
                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, dllhost.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
                                            • Created / dropped Files have been reduced to 100
                                            • Report creation exceeded maximum time and may have missing disassembly code information.
                                            • Report size exceeded maximum capacity and may have missing behavior information.
                                            • Report size exceeded maximum capacity and may have missing disassembly code.
                                            • Report size getting too big, too many NtCreateFile calls found.
                                            • Report size getting too big, too many NtOpenFile calls found.
                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                            • Report size getting too big, too many NtQueryAttributesFile calls found.
                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                            • Report size getting too big, too many NtSetInformationFile calls found.
                                            • Report size getting too big, too many NtWriteFile calls found.

                                            Simulations

                                            Behavior and APIs

                                            TimeTypeDescription
                                            10:22:47AutostartRun: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce {40d3fee2-b257-46c2-bdc0-cb1088d97327} "C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe" /burn.runonce

                                            Joe Sandbox View / Context

                                            IPs

                                            No context

                                            Domains

                                            No context

                                            ASN

                                            No context

                                            JA3 Fingerprints

                                            No context

                                            Dropped Files

                                            No context

                                            Created / dropped Files

                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-09ON3.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):337696
                                            Entropy (8bit):6.010310833200254
                                            Encrypted:false
                                            SSDEEP:3072:uMCZbDoSbwlSCpYQfj+f1D0I/esAjznECGJGSuyuMiQdqyHGxRCcXYJ7q5g03Lbh:uCXSUYQeisA3EJnkgCbDmgpbPSNA
                                            MD5:9FF7C9FF349B13430FD4575556ED3A15
                                            SHA1:CED03401B3FFA7BF372B6E7B9CE3D6856D646373
                                            SHA-256:C04C348CF3CB28A550ADC72D40F7473D03F1EAC63F3B945A6A56C476265295A7
                                            SHA-512:CB656E556EC12CE5A8979C69C777ABC83B5E8023E90F7A0DC206FEF9DF8C04B96B70CCBCE4F563265392E313AE6E4C4DC2E5A2FDFACA32AB0E167E45C7581374
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^.M...#...#...#.....#..."...#...&...#...'...#... ...#......#...".l.#...*...#...#...#......#...!...#.Rich..#.........PE..d...T:.^.........." .........f......P~.......................................0......M.....`A.............................................>..d...,................ ...... A..........`...T...............................0............................................text...V........................... ..`.rdata...v.......x..................@..@.data...(.... ......................@....pdata... ......."..................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-0HCB9.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):142744
                                            Entropy (8bit):6.031469250611835
                                            Encrypted:false
                                            SSDEEP:3072:41RJVeUv5NFDOYn3nVsiMHl3UNFFlhyHXGbNXx8jsF0I:EDecFDp3Vk3UsiXxuI
                                            MD5:46F663A8E1F4887A9DEBDCCE330202CD
                                            SHA1:5F526BA3AC3A892030C1DCDC52B7F85F7BC1FD84
                                            SHA-256:A674C9D62FAC81468217212CB6974BCE4CF672C45C75FC180F65196F3A8DA25F
                                            SHA-512:FA2F49E2E6568320D4CC11E760E72E9286BB7889BE0075C9BDDAFDE0335AB5547E4FF8A1B53DCC061BBCE0FE28F5F1CE00CCF7F4165ED62F71FB8C560746741B
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........B.S#..S#..S#..Z[&._#...r.Q#...S..[#...S..W#...S..U#...S..w#...K..Q#...K..X#..S#...#...R..R#...R..\#...R..R#...RJ.R#..S#".R#...R..R#..RichS#..........................PE..d....'V_.........." .....:..........d=.......................................P...........`.........................................p.......4...........H&...................@..H...P{..T....................|..(....{..0............P...............................text....9.......:.................. ..`.rdata..:|...P...~...>..............@..@.data... ...........................@....pdata..............................@..@.rsrc...H&.......(..................@..@.reloc..H....@......................@..B........................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-19FI6.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):393624
                                            Entropy (8bit):6.429183076567012
                                            Encrypted:false
                                            SSDEEP:6144:iDRMKhK+1F9os+C3PwA+vA9JXvZ10Qaz+02wZIfQa4CCuM2ERx3sPy2bGnthi3qJ:MhK+aVA+uJXx10k0rZIfQHvS3bGf7J
                                            MD5:571375C5A4151AE1B789590506184E7C
                                            SHA1:C4061E47C19A91603D09A46F50EC8D7DF8FDBFB2
                                            SHA-256:0A56A159CE424B66FDB5BA5E89B9A1CB05F5A5CD5AAE07F8BE4D5A1E982210C5
                                            SHA-512:06DC983A1848A64177A3C36EBC011CB7DD214DB4457CA3D0D77BF2520D93E2FC52C6116C57886619596934928064175D40CF318C63B805AE53BC8BF388952223
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$...........el..el..el......el...i..el.P.h..el.P.o..el..el..el...e..el.P.m..el.P.i..el...h..el...m..el..em..el...h..el...i..el...l..el......el..e...el...n..el.Rich.el.........PE..d...r(V_.........." ................LS..............................................:.....`..........................................D.......E..h....p..H...............................T...................0...(.......0............... ............................text.............................. ..`.rdata..............................@..@.data........`..."...D..............@....pdata........... ...f..............@..@_RDATA...G... ...H..................@..@.rsrc...H....p......................@..@.reloc..............................@..B................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-1K3AJ.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):127896
                                            Entropy (8bit):5.989587287420056
                                            Encrypted:false
                                            SSDEEP:3072:SLXMntuPc06jtBvH8dtdBjU1fzT0rNKx2dmUq7tdjlByW0x:SL8M002H8dJY1fz4rE8Y7tdjlBYx
                                            MD5:7501500AC9B33397D97B5599740BA712
                                            SHA1:0D3B7FBDE65C333247E7D00AB336124380AC924C
                                            SHA-256:77546AB7DA770E574C66ED86A2CAD9ABB63C8C5153051DEB4FD6815D43BC46E9
                                            SHA-512:429C4DE88F49EC13BE66855EC1F4F9FBF3D43610023C82088E32D9BF687A04A64BC25FA1FF4C48B3BF244CC0EE4F71B33A4D6E69CFBD4AE366285FEFE83BF03F
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................0...........!..L.!This program cannot be run in DOS mode....$.......@....d..d..d...q..d.....d.....d.....d.n....d.R....d.....d._...d._...d..d.d....d....d....d.....d..du..d.....d.Rich.d.........................PE..d...A(V_.........." ......................................................... ............`.........................................@...................X"..........................pM..T....................O..(....M..0............0...............................text............................... ..`.rdata..:o...0...p..................@..@.data...h...........................@....pdata..............................@..@.rsrc...X".......$..................@..@.reloc..............................@..B................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-22CCE.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):64416
                                            Entropy (8bit):5.923907444798146
                                            Encrypted:false
                                            SSDEEP:768:aZIpjMNZbG70aS5Z35C7aKHdefchMdPusXvU0XeIDjzFuLp23+zjz:aZ4MNZK7uX35fUMpun0XeIDjME0z
                                            MD5:03A69FD66637E5FC97437A1551FE64EF
                                            SHA1:A943DB9CAFAA8422E0CBD18FF99DEB6DEADCFC40
                                            SHA-256:9CCA00520B8158949759B90306D5A123E8D06CD5D3402571DCAA0A9468A0C6D8
                                            SHA-512:C6F250698F75977FC8945AE2880724593ABC361EF8C7FF8745E4AA2CF50F49D8F885F85A3F021C4C0F4C05C65CEB1D0AEF8A4F01F7EA4F47E3E56FC26E99140D
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......J.H...&...&...&......&...'...&...#...&..."...&...%...&.U."...&.U.'...&...'.|.&...#...&.../...&...&...&......&.......&...$...&.Rich..&.........PE..d...z(V_.........." .....v...n.......x....................................... ......")....`.........................................0.......,...................................p...X...p..............................0............................................text...nt.......v.................. ..`.rdata..xI.......J...z..............@..@.data...p...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..p...........................@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-2APG5.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):129928
                                            Entropy (8bit):6.075089460502067
                                            Encrypted:false
                                            SSDEEP:3072:tEyGvYDfRkqVr6zvtkGIqcgDQEEfXC30K:tEyUikqUrtkImEEfXfK
                                            MD5:3C4F1AE406E2E7B350BE9EA3B08EEA1C
                                            SHA1:1DA91199EF7712FB629A98321A6B290D467683AC
                                            SHA-256:732B6EA199E8387D224BC0E3F96733F509EC0976D12337833BA0F466B4903589
                                            SHA-512:2838A12314D4D19316921D7FBC54DB05B15966DF57CD9AE3B57C55910BEDAFD31C2374F12C007AE78DB9924F8C7995304CF9372526EAD726E69F62ECE8865296
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........9...W...W...W......W.O.V...W.O.S...W.O.T...W.O.R...W..S...W..V...W...V.$.W...S...W...R...W...W...W.......W.......W...U...W.Rich..W.................PE..d....'V_.........." ..... ..........4........................................ ............`.................................................\...,........'......T....................K..T....................L..(...pK..0............0...............................text...\........ .................. ..`.rdata...k...0...l...$..............@..@.data...`...........................@....pdata..T...........................@..@.rsrc....'.......(..................@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-32VOB.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):159632
                                            Entropy (8bit):6.11742852575518
                                            Encrypted:false
                                            SSDEEP:3072:fOqGgCY2J5gk4cbiowLQop1rj3alGTgHW7Blh7r67O5sa08:LcbFwLQe3alcN7BDCO5S8
                                            MD5:8D05D11BDD2E2363C5C2457DF23DF257
                                            SHA1:0159AD1531547E250AF4BA34BE27C77E4AB55252
                                            SHA-256:40E3840E1AFFF305BB68ED0BBAACBB3436CAECD65451AE9BD8EBED802A909D5D
                                            SHA-512:CD8066549BF5E08782A24FA02B40BF7763ADCCB5FE73752295FAAC106CDA9C26A03E67A1FFCA8C0CE33910A1DF069B4981A3D683764CFF4BC51E8435CA34CBB8
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........^...0...0...0.....0...1...0.uk....0...4...0...3...0...5...0..4...0..1...0...1...0.\.4...0.\.5...0.\.0...0.\.....0......0.\.2...0.Rich..0.........PE..d....'V_.........." .....\...........[....................................................`.........................................@...........@....@...:...0.......T..................T.......................(...p...0............p...............................text....[.......\.................. ..`.rdata.......p.......`..............@..@.data...@...........................@....pdata.......0......................@..@.rsrc....:...@...<..................@..@.reloc...............N..............@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-3EO63.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):840088
                                            Entropy (8bit):6.680031671113697
                                            Encrypted:false
                                            SSDEEP:12288:qh0Qk74unPbwxRKMyrXXi4koHEM7heYt9OyKuHVWL5JsVVA:TpGKMybPZeYP7Kc0uA
                                            MD5:59699BD57E1DE91401EAD4A98C51B0B0
                                            SHA1:88B5A745D3AFD5FFF434F6CEAB6843F73E7B3F66
                                            SHA-256:71DFF1066E9E98B353A819EAD6AE93F2F35B72E0C014D7569AAEDE88B9DA3428
                                            SHA-512:52FE50FFFA7229BCF8BF2814C2010378DE41A72D42380255FD75CA31881A24B05F938E457ED813552380D02B20EC92DD545344C307D076E90EB48D647F9BE7D8
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........m....................Q.......Q.......Q.......Q.............................................................................Rich............................PE..d...5(V_.........." .........n......................................................e.....`.....................................................,............p...D.....................T...................`...(...0...0............0...............................text............................... ..`.rdata.......0......."..............@..@.data....3...0...Z..................@....pdata...D...p...F...n..............@..@_RDATA..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-405Q8.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):247704
                                            Entropy (8bit):6.162598223810973
                                            Encrypted:false
                                            SSDEEP:6144:1hJVhL6ufB1Nu+MwLheDgLHCvMEs2c0MwxkXfTXEYUNxxQs1R5BhP4aiSvhbDAI:NL6ufeNxCs1R5BDV
                                            MD5:B67380AB28CB607DFFDB45A7244C39B4
                                            SHA1:EC93BB8633E8A066E4842D6F3E56337C573E790E
                                            SHA-256:5EFBB2101A0D0EE3180B5A1EB316D9E4F4EB0166A96DEB731350AB88F80425F3
                                            SHA-512:51ECD3A8F6451ACA024651C6F373EC5B8E66548174EC138A136CEAAA956ED4D87C6CCFB4D85774950B70C38377B647EED6CF82C0C7CB2979F4F1B75A0991E284
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........E"(^$L{^$L{^$L{W\.{R$L{.TMzZ$L{.THzV$L{.TOzZ$L{.TIz@$L{.LHzZ$L{.LMzU$L{^$M{.$L{.UHz_$L{.UIzN$L{.ULz_$L{.U.{_$L{^$.{_$L{.UNz_$L{Rich^$L{................PE..d.....X_.........." .....@...p.......>..............................................b.....`..........................................................p...a...P..........................T.......................(...p...0............P...............................text...@>.......@.................. ..`.rdata.......P.......D..............@..@.data....1.......*..................@....pdata.......P... ... ..............@..@.rsrc....a...p...b...@..............@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-51BGK.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):218504
                                            Entropy (8bit):6.1736138518071355
                                            Encrypted:false
                                            SSDEEP:3072:SGYbeaxbDu8toYaO8+Bsfvj9sdkYhv1XVrwl7jm0I:ScOi2oYN8+gRKml7DI
                                            MD5:D201B13BAE6CA38ECD833FF55B5DB612
                                            SHA1:52137B4CD3E928006F47C0AA106D506FA7B6D01F
                                            SHA-256:96EE6583AD1D3A04A2D90CEF4879A2DB3677528C3A24311C9DF71100CDB76381
                                            SHA-512:1AEE1C14101C587E622B87AFBEADA162AEDAC5D917F65077FC0936DCB92EE3C12C8B157DA66C19D37BD487F73D979E59333220C7D95005CCB220F4F10510BD87
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......,z.`h.h3h.h3h.h3ac.3b.h3.ki2l.h3.km2|.h3.kl2`.h3.kk2k.h33si2m.h3h.i3..h3.jm2a.h3.jh2i.h3.j.3i.h3.jj2i.h3Richh.h3................PE..d.....E_.........." .........&...... .....................................................`......................................... ................`.......@.......:.......p......0...............................P...0............0...............................text...r........................... ..`.rdata..j....0......................@..@.data....4.......0..................@....pdata.......@......................@..@.rsrc........`.......2..............@..@.reloc.......p.......4..............@..B................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-5IHAM.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):317224
                                            Entropy (8bit):6.325476680883488
                                            Encrypted:false
                                            SSDEEP:6144:6lTcrTKDDPzfM0xmNcwwY2baM739NhNN40aBqnWzgPPz:6cKHzEc/Yzz
                                            MD5:165E673B081CF2C90A2E63A6834ACE1E
                                            SHA1:544014C03FB2E91454D4BAC4934B1C44F2ED8943
                                            SHA-256:8BF7EFB1FA4F86DB826B79EA1D3DAA6E18019790D7B5FF58B53BFB4CAD967974
                                            SHA-512:BB02ED42C4AFC2AE1AD5A01D974B41C511E04964962655CF387E07FB364075A1939CB9EEA0B72BBC73F6813BE9107D650543EE1ACC3583A3A59AA8B416AF9565
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........e............/.<....|@....ct............ct.....ct.....ct......ct.....ct,....ct.....Rich....................PE..d...M8.^.........." ................p.....................................................`A........................................0....M..<................p...6......(A......l....4..T...........................p4..0............................................text...<........................... ..`.rdata...2.......4..................@..@.data....?...0...8..................@....pdata...6...p...8...N..............@..@.rsrc...............................@..@.reloc..l...........................@..B........................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-67Q05.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):3824528
                                            Entropy (8bit):6.210077276469363
                                            Encrypted:false
                                            SSDEEP:49152:QUXb03HeN/6WtDZIUbLmxnPL1kw0c3uKZXbsE83lpKfA5CxoeReW88a4LO3+L9Tf:Jnd1IUbKhL1kw0c3uKZrLXWLlQ
                                            MD5:E4D307024EE5782D3E0C4B64D32D3474
                                            SHA1:0BEED949C93A87ED0BDBA0B213670F1972B5AA62
                                            SHA-256:4756739B346ED772BE88CD8A38C04FAE2AAD24105661D1F43788F829CF54ABFA
                                            SHA-512:0DACDB0D78EEC412B879BD41675F633A8A9AD48CD5844EF539D9A21F00CF9AF2FC45D0DA35D7A5A401FD2153EEA20C20E4FDEE504554917F9D26ED581EF8D471
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.........1.g_..g_..g_.....g_...[..g_...^..g_..g^..a_.F.^..g_. ...g_.F.\..g_.F.[..g_.F.Z..g_...[..g_...Z.vf_..._..g_......g_..g..g_...]..g_.Rich.g_.........................PE..d...'[__.........." .....n...........+........................................:.....Z;;...`......................................... .%.......%.......).. ....'......@:.......9.....H.!.T.....................!.(.....!.0................$...........................text....l.......n.................. ..`.rdata..............r..............@..@.data...8....0&..\....&.............@....pdata........'......x'.............@..@.rsrc.... ....).."...").............@..@.reloc........9......D9.............@..B........................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7AVA5.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):348560
                                            Entropy (8bit):6.323250206104049
                                            Encrypted:false
                                            SSDEEP:6144:0gvCyrREQiDDwRa09ihsXfIUVzTI3wb71Pt4zoUcV8n:jvLrREvD7Sz8uUco
                                            MD5:876AA9D9FC89D89D05531159A7E1ADAE
                                            SHA1:62A01EF7AFC9153697983F9B5F0C4A7633F5224E
                                            SHA-256:93ADCE830FE6A58F9BF7B8182042F2F7952A19FEF9F0749DD2D7967671824A83
                                            SHA-512:F3127DB8B133FBC9F5EFBE5ACB68B28BAA2313658F2BC026D275E7D8C1DD1AE28175B16D28FC6E4F991588B7A6A4B4335FF13DFA4878B597684A13241C56E551
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......6.i.rn..rn..rn..{...`n.....vn......~n.....zn.....vn.....Vn..)...qn..)....n..rn..n.......n......`n......sn......sn..rn..sn......sn..Richrn..................PE..d....'V_.........." .................Z.......................................p............`.........................................P...........h.... ..h;......$-...6.......`..t....&..T...................0(..(....'..0............................................text............................... ..`.rdata..............................@..@.data....6.......(..................@....pdata..$-..........................@..@.rsrc...h;... ...<..................@..@.reloc..t....`......................@..B................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-7DG6H.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):209800
                                            Entropy (8bit):6.301030379282958
                                            Encrypted:false
                                            SSDEEP:3072:7EH9rvXopCtbVvDFCfv0nEp/icXt2F73OElpc2P3aJMvuCqSwZmo0E:7M9efv0nEp/S7c2P3aivugw8E
                                            MD5:6F1E18451064B62F1636A944B8EA76E8
                                            SHA1:D814D893E8DFC0084F652A14BC990BC48E6BEEA7
                                            SHA-256:E1BF401D3311D3189CAC65F3F64FE0A3A9558DC9906D0B5C9DB004552DD16279
                                            SHA-512:89FEFAB321D764E49097652E926FD9EE5DB56F898BEDD8EE18F93FB137F291B14EAB5CB18CFAF0368D993AFACC29F0E136B113F7064A4903FCEA745040A6E3D4
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.............B...B...B..kB...Bx..C...B.$?B...Bx..C...Bx..C...Bx..C...B...C...B...C...B...B6..B7..C...B7..C...B7..C...B7..B...B..oB...B7..C...BRich...B........................PE..d....'V_.........." .....Z..........tZ.......................................P............`.........................................P...........@.... .......................@......@...T......................(.......0............p...............................text...PX.......Z.................. ..`.rdata..0m...p...n...^..............@..@.data...............................@....pdata........... ..................@..@.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-91VDT.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):150432
                                            Entropy (8bit):5.953850899956778
                                            Encrypted:false
                                            SSDEEP:3072:yU3X6XwzBAV3QWlFtZ3kOuiHXSfOXEDW8rj6G+0m:y2Pz23QWHBuw0W86Qm
                                            MD5:F26DBF2340866A81C230ABA182C3F2E9
                                            SHA1:D8E00910F9E4FAB19C31D2811CC4E6CEDF11113B
                                            SHA-256:B4EC17B4281AA3EA523973039AE64789BC0F5E40D68A55EB3D6D73F125F7C5BD
                                            SHA-512:B962F425CFF6FC1CD00DC1CA68FDA63E3C460DA8BEAD3AB6A377E335EA8C292BB517594AA9E9CAAF5301E61DE8A2C1D6C6633A8F2C34AD49B6C1AA2F4C6214C8
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......0Fk.t'.^t'.^t'.^}_.^|'.^.W._|'.^.W._p'.^.W._r'.^.W._j'.^/O._w'.^/O._e'.^t'.^.'.^.V._u'.^.V._}'.^.V._u'.^.V.^u'.^t'.^u'.^.V._u'.^Richt'.^........PE..d...N(V_.........." .....*..........P+.......................................p............`.........................................`.......$...@.......pM......@....0.......`.......i..T...................Pk..(... j..0............@.. ............................text....).......*.................. ..`.rdata..n....@......................@..@.data...H...........................@....pdata..@...........................@..@.rsrc...pM.......N..................@..@.reloc.......`.......*..............@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9KGNK.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):264592
                                            Entropy (8bit):6.116869023381677
                                            Encrypted:false
                                            SSDEEP:6144:OsNP137nbHnlYU5pzygydSJ0kicLbMj6sheG:OylHlYOpugydSg28
                                            MD5:9F582C1EAD5AAE1F484BDB1DFDEB890F
                                            SHA1:8B58B343014A6C45D1C923D25024181E2CCC379C
                                            SHA-256:C8BAAB1B74E73C032AB97AE20FFA9D0A9D4A736285D28D6CB27AED48480AA910
                                            SHA-512:D201E891AAD9FAFD3E17FD0971EEA417C969090BBBAA40B7E5232E026349FC98598A5F348ACD239B9F1E676671CA24A1D8153C2BCBF430C673C723894AF9E766
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.........S..=..=..=......=...9...=...>...=...<...=...8..=...9...=...<...=..<.W.=.F.9..=.F.8..=.F.=..=.F....=....=.F.?..=.Rich.=.........................PE..d...t'V_.........." .........F.............................................. ............`.........................................pi......,j..T........F......H...............L...`...T.......................(.......0...............8............................text............................... ..`.rdata..............................@..@.data................l..............@....pdata..H...........................@..@.rsrc....F.......H..................@..@.reloc..L...........................@..B................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-9T70V.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):23952
                                            Entropy (8bit):6.0627826013258295
                                            Encrypted:false
                                            SSDEEP:384:eF2KnSKkNESTk5MX/QjnPgKoxTmPg1Zdo99dJcKrF5GfZPmp23+r/jLzVD:e7SKwESMjPgKoxTmSTyjJcEFuPmp23+9
                                            MD5:23E013ED7B20C0BA7152C39AB70FB04D
                                            SHA1:FCE17600155FFD47B06DE154F1E51BD91CAFB890
                                            SHA-256:BA37399C1A84EF78B32B5FB26FF309BEA11C5E507F4028D3B943FFA43EFCE45A
                                            SHA-512:0BCD60C193082DCF80B4278805CCF28C4EE70B11DC1408F7F75F846FA3E5E11C71D4ACB020B13D2F0F4B5E03E86261C5479BA056E91F01E252D5AA6E5B0A702A
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......X..n...=...=...=..#=...=..<...=..<...=..<...=..<...=G..<...=...=[..=..<...=..<...=..O=...=..'=...=..<...=Rich...=................PE..d...((V_.........." .........*......d"....................................................`..........................................:......p;..x............`..`....B..........(....3..p...........................@4..0............0...............................text............................... ..`.rdata.......0....... ..............@..@.data........P.......2..............@....pdata..`....`.......4..............@..@.JET.........p.......8..............@....rsrc................:..............@..@.reloc..(............@..............@..B................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-BS97R.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):56728
                                            Entropy (8bit):5.8695812713418825
                                            Encrypted:false
                                            SSDEEP:768:gGC/LOx5aS6M/65p3+Bq2jCFeAFmxk3gJV8RidKmqb478wbHllivo6pFuwp23+z1:gGuOxTd65pQjZMmxrDKm378wbFYA5n0J
                                            MD5:714121339CC11B6039136DB63F2FAAD1
                                            SHA1:2EE60335D69583B753AA7E4132CBE2AD733D95EF
                                            SHA-256:3D4951A56BA73C9D2CC72CC59569365D49E9132C75A48B450B018CF45E137173
                                            SHA-512:A353EA6929727BEAF3121F42F75E7A806EC5D309974BF00E92778238DDBA1937B3F48D2C73B860266CFEA5A40EAB1CACB91A647D8BB7A958BC68EC331705A210
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........|G../G../G../N.1/A../....C../....O../....D../....R../...O../-../F../...D../...J../G../5../....E../....F../..]/F../G.5/F../....F../RichG../........PE..d....(V_.........." .....d...b......,g...............................................;....`.................................................L...................D...............8......p...........................`...0............................................text...,c.......d.................. ..`.rdata.."=.......>...h..............@..@.data...............................@....pdata..D...........................@..@.rsrc...............................@..@.reloc..8...........................@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-CPPIC.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):193832
                                            Entropy (8bit):6.592581384064209
                                            Encrypted:false
                                            SSDEEP:3072:V7vC/HAiCsJCzwneNPXU7tm1hTt8KBDal8zg/0LwhORfewlMi0JHV:VTGAtweN85m1f8KBI9wfpsJH
                                            MD5:937D6FF2B308A4594852B1FB3786E37F
                                            SHA1:5B1236B846E22DA39C7F312499731179D9EE6130
                                            SHA-256:261FBD00784BB828939B9B09C1931249A5C778FCEAD5B78C4B254D26CF2C201F
                                            SHA-512:9691509872FDB42A3C02566C10550A856D36EB0569763F309C9C4592CAF573FBB3F0B6DC9F24B32A872E2E4291E06256EAE5F2A0DEB554F9241403FD19246CAC
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........94..Wg..Wg..WgVt.g..Wg..g..Wg..Sf..Wg..Tf..Wg..Vg..Wg..Vf..Wg..Rf..Wg..Wf..Wg...g..Wg..Uf..WgRich..Wg........................PE..d...W8.^.........." ................p............................................... .....`A........................................ ..................................(A...........K..T........................... L..0...............P............................text............................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DDA4R.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):7587744
                                            Entropy (8bit):6.614711906923776
                                            Encrypted:false
                                            SSDEEP:98304:ahpuo7UAmTdBax91K8UoHh9eaxObGzB0/62bpT7MGOFUTrGczE3hmJn4:ahpvyT7MGUczEW4
                                            MD5:A32B3E74500A712E8E50D66898A558A0
                                            SHA1:417A1603D57F20C3529697B73798EDB27953C5C6
                                            SHA-256:B2E55C762F11F230BEA1146BE3A77882ECFE6148D91A60DA1F7F47655D7CD7F3
                                            SHA-512:6FE1BE9E3465E3F83973358DC099827DE423C063E2898E27066CC9DECCCA150FF00257A5A7FC16F644DB4487D8058C86447299C67C81B38AA66E051DFB8D8C10
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.........b.u...u...u.......u......u..x....u..x....u......u...u..L}..x....u..x....u.......u.......u...u...t..7...@u..7....u..7....u..7..u...u...u..7....u..Rich.u..........................PE..d...^'V_.........." ......_........../X.......................................t.......t...`...........................................n.. ..\.n......pt..B...Pq.<|....s.......t.H....j.T...................p.j.(...@.j.0.............`..............................text....6X......8X................. ..`.rodata......PX......<X............. ..`.rotext......`X......>X............. ..`IPPCODE.....pX......@X............. ..`.rdata........`......._.............@..@.data...HW....n..~....n.............@....pdata..<|...Pq..~...0p.............@..@IPPDATA.W.....s.......r.............@....rsrc....B...pt..D...Ls.............@..@.reloc..H.....t.......s.............@..B........................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DI71O.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):192920
                                            Entropy (8bit):6.119218949929854
                                            Encrypted:false
                                            SSDEEP:3072:4jFeS1k+GtXXaZzdpVwW+vS8g/sK0f0SWZ0wlmJmUR1+nl0Y:aZG9awW+vS8g/svf0N0wl8Y
                                            MD5:F3F04B8B5E1F60C8D37888BD29083BBC
                                            SHA1:EF8D7366A4A52B2A95D43861F5CF1DF0E65865A1
                                            SHA-256:106251ECAB152856B5281E6E4F275B4A8ADCC6A33A3BE0057BA6136B182B2E43
                                            SHA-512:B8D5B7E33FF78B3815E25CC099945DB666C461C74F97809778D88CA1C578EDC7B13D74ED88731D815CD514CC361916C2FB4683325B547D7B1411B47A4B6101B0
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........,..;M..;M..;M..25<.7M...=..?M...=..3M...=..?M...=...M..`%..=M..`%..0M..;M...M...<..:M...<..=M...<..:M...<P.:M..;M8.:M...<..:M..Rich;M..........................PE..d...z'V_.........." ......................................................... ......}.....`.........................................pK......0L...........`......x...............4...0...T.......................(.......0............................................text...0........................... ..`.rdata.. |.......~..................@..@.data........`.......D..............@....pdata..x............X..............@..@.rsrc....`.......b...n..............@..@.reloc..4...........................@..B................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-DVG3K.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):330040
                                            Entropy (8bit):6.657964399026725
                                            Encrypted:false
                                            SSDEEP:6144:Qgpy6Lp49Y/jdpL3KjsY0Cmj4KIza/9AOq8mQc:QH6Lp49Y/jjfYWjlIW1h
                                            MD5:437FD66D477FBAA501B396F7EC1F9BFA
                                            SHA1:C5D403D7C7AE60B8314A637AE47B2A292A35DB1D
                                            SHA-256:B79DA8B2239E6A521351830042EB6735E9994685C3F2DF0816AF18358BAC4E61
                                            SHA-512:83619771612865EEFFFE634EDD4B2A1A12E08FD51561DEAF45747817448960070F7313A2F3A7475D4E95796970C4C6C4C88D477857E33C70C0EF8C3FAB610F65
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Q............................&..........................7...................Rich............................PE..L...v"`B...........!...............................................................................................Px..N....p..<.......................8i.......%...................................R..H...............t............................text.............................. ..`.rdata..............................@..@.data...............................@....reloc.../.......0...p..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-EPU6H.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):886160
                                            Entropy (8bit):5.474561349963375
                                            Encrypted:false
                                            SSDEEP:6144:WUnYCf6zT01NjsNYbvc9ramrfKT7GpdaGtwTXn62hd6U8zaYKKkeyOZDC5U:WcbS01NjgYA9FrCHK4Gt2hJ8z0/eyOb
                                            MD5:8244E7C07CA0F81061F3EDE315A13379
                                            SHA1:112B6961805DDCD9EFF07195F57006E35E8E3F79
                                            SHA-256:966DB54339F7B2A3CC74EDD99079C111796E556E7A53241D63660FB839E90100
                                            SHA-512:E8E0640FA4B2B2B0439AFB6E00DAAFD8793A03501C4633B2FF3D6BAE370A2475C46D0C0872E295CC974EACCAF976A138D4C9D4CFC724E2BFB83F0B39356CB0DF
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9. .}.NS}.NS}.NSt..Sq.NS&.ORm.NS..JRw.NS..MR~.NS..KR].NS}.OSG.NS..ORt.NS.KR~.NS..S|.NS}..S|.NS.LR|.NSRich}.NS........................PE..d.....E_..........#......6...8......\1.........@....................................^..... .................................................0|..@....................j...............k......................@m..(....l..0............P...............................text...P4.......6.................. ..`.rdata...=...P...>...:..............@..@.data................x..............@....pdata...............|..............@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-GOHUV.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):101672
                                            Entropy (8bit):6.566355945650465
                                            Encrypted:false
                                            SSDEEP:1536:7y6+2mUD0uBFRXqYue/o+18iBH5T7heunxr98nZXR9xecbSQ2bIB0TO:7lXfRXqQw+PHLrCZh9xecbSt
                                            MD5:8697C106593E93C11ADC34FAA483C4A0
                                            SHA1:CD080C51A97AA288CE6394D6C029C06CCB783790
                                            SHA-256:FF43E813785EE948A937B642B03050BB4B1C6A5E23049646B891A66F65D4C833
                                            SHA-512:724BBED7CE6F7506E5D0B43399FB3861DDA6457A2AD2FAFE734F8921C9A4393B480CDD8A435DBDBD188B90236CB98583D5D005E24FA80B5A0622A6322E6F3987
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!/.NeNl.eNl.eNl....gNl.l6..nNl.eNm.INl..>o.hNl..>h.uNl..>i.zNl..>l.dNl..>..dNl..>n.dNl.RicheNl.................PE..d...M8.^.........." .........^...... .....................................................`A........................................`1..4....9.......p.......P.......L..(A..........H...T...............................0............................................text...b........................... ..`.rdata...?.......@..................@..@.data...0....@.......4..............@....pdata.......P.......8..............@..@_RDATA.......`.......D..............@..@.rsrc........p.......F..............@..@.reloc...............J..............@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-IE7UD.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):68096
                                            Entropy (8bit):5.602336138621584
                                            Encrypted:false
                                            SSDEEP:1536:pcl8iVFa2mbqXzr2TOUeQ7t9OiIKxTx8lnSJRu:oVIvbLSRckiIKxTx8eu
                                            MD5:704F6DEA488B843A194A51BE88F8E277
                                            SHA1:C2CC4071468941E58459DD5439EEF4105ECFE42D
                                            SHA-256:C04E9C85FE2E7E2BBDF81ACAFC9EE1BE51E7DB21BB492D854D614E49C825F678
                                            SHA-512:B742A32A4173B1D7755C9FF1E93036B2CD219364536E8B4E5B441AD59BE7DACA32F54876D76ED000C014ED889F9221610021DD9E18D7CA7CDD448B10AA608B70
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........#&..BH.BH.BH.:..BH.e2I.BH.e2L.BH.e2K.BH.e2M.BH..*L.BH..*I.BH.BI..BH.*3L.BH.*3M.BH.*3H.BH.*3..BH.B..BH.*3J.BH.Rich.BH.........................PE..d....'V_.........." .........|..............................................@............`.................................................P................................0...... ...T...............................0...............0............................text...<........................... ..`.rdata..BD.......F..................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc.......0......................@..B................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-ILPSH.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):208280
                                            Entropy (8bit):6.1177788632703125
                                            Encrypted:false
                                            SSDEEP:3072:dVHTNGEXkqi+BhCeGUFGShnJQtbQNyUwGMY7i0nm+Uz/BBNZjy0h:zTNPi+nCeGCkZYm3+m/Blh
                                            MD5:C2833403BD976615000CC84D4497985D
                                            SHA1:88A05955C1454D312BBB5623CCAF861456F8FAD0
                                            SHA-256:2BD3D2DF348EFEBDB942C3248D0F3EA0F2F8049153C87F2D3AC3C9B984760624
                                            SHA-512:69EEC85F88257C6BE655D4B591A791E0CF243C4A248E0654FE600DD3FB26C36FEE02B16846C738A1B7F61F2E4AC6416B99EE1A79F4B14B68554FA5B7D403E2CD
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$..........8..k..k..k..*k..kD.~k..k".j..k".j..k".j..k".j..k..j..k..j..k..kG..km.j..km.j..km.j..km.Fk..k..k..km.j..kRich..k........................PE..d....'V_.........." .........$...............................................P...........`.........................................p.......0............E...................@......p>..T....................@..(....>..0............................................text............................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc....E.......F..................@..@.reloc.......@......................@..B........................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-JIFVF.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):21107080
                                            Entropy (8bit):6.939471862296033
                                            Encrypted:false
                                            SSDEEP:196608:Aaej1L9Y05h2AdBrROQ8R9FYfGq7rgX3uW3fXC7nc+ILiAUfUX:oj1L9J5h2+ZUOgmc3LiAU4
                                            MD5:6114B8A9AC886500DA545DE36F92800F
                                            SHA1:981D0A666625149435C4BE86ECDA3334F54A8C77
                                            SHA-256:31024C8C869822E16418AED0A220DFED54F9D6A61824FC3D572C8A2E3017BE0F
                                            SHA-512:A39DC2655F19F99EAD916C0236DC121D9DE0C64BB767689840D2421BEC6DEA6A6447CB01F8723E781CE82B103E9D2B3E5A40FB22EF2A3908BCBDFD6FA61D1F48
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$.........E.Pp+.Pp+.Pp+.Y...Dp+....Tp+.../.Xp+...(.Tp+...*.Xp+.....q+.Pp+..a+.....qp+.../.Rp+...*.[p+.Pp*..q+.../.]p+.....Dq+...+.Qp+....Qp+.Pp..Qp+...).Qp+.RichPp+.........PE..d....(V_.........." ..........m.....T.........................................L.......B...`.........................................p.8.....,.8.......K.`.....F. .....A.......K..... .+.T.....................+.(.....+.0............................................text............................... ..`IPPCODE..<.......>.................. ..`.rdata....Y.......Y.................@..@.data.........8..T....8.............@....pdata.. .....F.......<.............@..@IPPDATA..9...pK..:....@.............@....rsrc...`.....K.......@.............@..@.reloc........K.......@.............@..B........................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LCGQE.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):654232
                                            Entropy (8bit):6.2330705632037855
                                            Encrypted:false
                                            SSDEEP:12288:ca5/AbMMJ6KqpTvADxi+GLS+bmZ05oyKeluLgRy/lxcVJS30OwA:cjCvii+4S+bmZ05fKeluLgRy/vcXS302
                                            MD5:C6F1078C805CD149B93FDBCAC10E3812
                                            SHA1:E40E40BE3B9D72C8E31674BA6F71222077EC9BC9
                                            SHA-256:8FA3AFA409C2C926ABA81AD683CDDF37E2265F9C86CB38F7427814F9AD20DFBA
                                            SHA-512:50A18354E0157DB290012C735EA736EA089127F735731B2528BE2706367289A94C734D7492BB328E0A31CB1D5D3B89D512CC06F54161F34C91E6AA18476C334E
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........Y,..8B..8B..8B..@..8B..HF..8B..HA..8B.'WF..8B..8B..8B..HC..8B..HG..8B..PF..8B..PC..8B..8C. 8B.VIF..8B.VIG..8B.VIB..8B.VI...8B..8..8B.VI@..8B.Rich.8B.................PE..d...M'V_.........." .....z..........l................................................F....`.........................................@...........T.......H....`...1......................T................... ...(......0............................................text...`........................... ..`.rodata..-.......................... ..`.rotext.Y........................... ..`.rdata...g.......h...~..............@..@.data....G..........................@....pdata...1...`...2..................@..@.rsrc...H...........................@..@.reloc..............................@..B........................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-LTK27.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):1981336
                                            Entropy (8bit):6.443356868350275
                                            Encrypted:false
                                            SSDEEP:24576:E71BtVxef4zyClu5harL4nzFuMTolNnAOvzrEBJyCgC+FDpJ98:G1TDzTlu51usoLPvgyJq
                                            MD5:F20AF387BC631232AC7E3230EAABB293
                                            SHA1:08570EE568E9C63384F954DA22C1A89B698E5C13
                                            SHA-256:977358BC096C149EC7B59FD90C2CB42C0271529838278324D19201DBB9C0DA65
                                            SHA-512:3A9E2CF59778D59B29C1550A6F5FD1604764CD955E31713DDFE32029F5B325096B1CF540CAFAD1EBEA4E0C14F3B30D778F2FBAA9BCFB36BB1307DBB54D3729FA
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$........1$?.PJl.PJl.PJl.(.l.PJlj Km.PJlj Nm.PJlj Im.PJl..l.PJl.('l.PJl.PJl.RJlT?Om.PJl.(1l.PJlj Om.PJl.8Nm.PJl.8Km.PJl.PKl2PJl%!Nm.PJl%!Om.PJl%!Jm.PJl%!.l.PJl.P.l.PJl%!Hm.PJlRich.PJl........PE..d....(V_.........." ......................................................................`..........................................z.......{..,....P..H.......Pv... .......p.........T...................P...(... ...0............................................text...l........................... ..`.rodata............................. ..`.rotext............................. ..`IPPCODE............................. ..`.rdata..d...........................@..@.data................n..............@....pdata..Pv.......x..................@..@IPPDATA......@......................@....rsrc...H....P......................@..@.reloc.......p......................@..B........................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P1PRU.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):31528
                                            Entropy (8bit):6.472533190412445
                                            Encrypted:false
                                            SSDEEP:384:R77JqjlI8icUYWhN5tWcS5gWZoMUekWi9pBj0HRN7RA5aWixHRN7osDhzlGs6N+E:R5D8icUlX5YYMLAWRAlypmPB
                                            MD5:7EE2B93A97485E6222C393BFA653926B
                                            SHA1:F4779CBFF235D21C386DA7276021F136CA233320
                                            SHA-256:BD57D8EEF0BC3A757C5CE5F486A547C79E12482AC8E694C47A6AB794AA745F1F
                                            SHA-512:4A4A3F56674B54683C88BD696AB5D02750E9A61F3089274FAA25E16A858805958E8BE1C391A257E73D889B1EEA30C173D0296509221D68A492A488D725C2B101
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........U..\4~.\4~.\4~...^4~.UL..X4~.Dz.[4~.D}.^4~.\4..v4~.D..Y4~.D{.O4~.D~.]4~.D..]4~.D|.]4~.Rich\4~.........PE..d...W8.^.........." .........$............................................................`A.........................................>..L....?..x....p.......`..4....:..(A......p...@3..T............................3..0............0..0............................text...(........................... ..`.rdata.......0......................@..@.data........P.......,..............@....pdata..4....`.......0..............@..@.rsrc........p.......4..............@..@.reloc..p............8..............@..B................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P4R44.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):130448
                                            Entropy (8bit):6.0053552859255666
                                            Encrypted:false
                                            SSDEEP:1536:79HgLe4nDaHKGSnATpw/Fqv+Z+vHJXfZDv496nkE4UgjLfaQ0YbrVCB3K0g:hA64eqGnu/Fqv6ypXxQ6nkEk/k60g
                                            MD5:57C6A4FCF72C08C13B94097AB20FAEAF
                                            SHA1:42A5F641E4297492A76DEE655E0E961CCC2986F6
                                            SHA-256:857706037C5DEC4AFF4C1932A41B96D4683E9CBBAE825C0BAE1ABDCAE9AF6DB6
                                            SHA-512:0736E79E6C7A37EDCE38DE5007B030C0E1E76242A554839C7D95B166FA4DFD6F635967B913F9A512A0ACEA5EA0FE91E6C5B53FA59F63D2BFA59895D0C1DFEF6C
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........y-...~...~...~..~...~ ......~ ......~ ......~ ......~.......~.......~...~...~o......~o......~o......~o..~...~..~...~o......~Rich...~................PE..d....'V_.........." ......................................................... ......U3....`.........................................0...................@B......................@....G..T....................H..(...`G..0............................................text...L........................... ..`.rdata..............................@..@.data...x............v..............@....pdata..............................@..@.rsrc...@B.......D..................@..@.reloc..@...........................@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-P9F2A.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):44304272
                                            Entropy (8bit):6.856413505722362
                                            Encrypted:false
                                            SSDEEP:393216:nXxHhTxcSFyhSi1p7OowbvQCf+RmgS1f8TFpYYGjmS:XxbfmOowBKJ6
                                            MD5:25BF073CA67157C08B582D27B9E53826
                                            SHA1:186EF5EE7179B3A994FD6BF700A0E1BCC50BA90B
                                            SHA-256:CCCE53C5BF322E7735B18585E97D4916559E2A498658781050AE1197FF29D49B
                                            SHA-512:EDE6C50612D0C46F28C09A9485993EB47533D7217DA73F9DFFF88EE5268C00D0DA6F762842D7403F1ED5798EE202C98CD6492569A5A35E28A4C1F26FD8F8EE70
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.......... ..gs..gs..gs...s..gs...s..gsab.s..gs..cr..gs..dr..gsH.or..gsI.cr..gs..gsv.gs..fr..gs..br..gs..cr..gs..fr..gs..fse.gsH.cr..gsH.br4.gsH.gr..gsH..s..gs...s..gsH.er..gsRich..gs........PE..d...g'V_.........." ......0..(......8+/......................................P7.....\)....`.................................................l.........4..4....,..\...........5.8b......T...................P...(... ...0.............0..............................text....Q/......R/................. ..`.rodata......p/......X/............. ..`.rotext..$..../..&...Z/............. ..`IPPCODE..=..../..>..../............. ..`.rdata..Z.b...0...b...0.............@..@.data...........$..................@....pdata...\....,..^..................@..@.rodata.P....p4......>..............@..@_RDATA..0.....4......L..............@..@IPPDATA.......4......N..............@....rsrc....4....4..6...R..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PIVL1.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):211856
                                            Entropy (8bit):6.081276068949082
                                            Encrypted:false
                                            SSDEEP:6144:F9HyLHw/Xh9AjRr4hhPmQK0ZlJyhpxYS0wW:FlyLHqXnAjRQM0WE
                                            MD5:1A7BC39270FB2944FD7B31DA6A449DBA
                                            SHA1:80E34BE2CE5FB59D698B551ED83D5F31FD5AF985
                                            SHA-256:CE21D8415E36CE9F15F3D06FF7097999B869B643327232785C00AC30FA782493
                                            SHA-512:A18C065131982336C711DDFD7115E1663568FD7318805BECB41FBBD82B227EFE550FCFE32CA1B34760CFD0DE0736F2F9A28ED9AD94CA0C6849B48E94D3E32BC2
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...................."....Y......Y......Y......Y.......................2..........................N.....&...........Rich............PE..d....'V_.........." .........0......4........................................`.......p....`.............................................................H........... .......P......XK..T....................L..(....K..0............................................text............................... ..`.rdata.............................@..@.data...............................@....pdata..............................@..@.rsrc....H.......J..................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-PJL5P.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):27936
                                            Entropy (8bit):6.577459666532623
                                            Encrypted:false
                                            SSDEEP:384:nGpHh29k7lAv1WioEWQ53tWi9pBj0HRN7evpPOWixHRN76MauOMlVt:nCHc4MqPAWevp3y6MgI
                                            MD5:1B8D2F7700EB84B832E9750880CDCBD5
                                            SHA1:3AE22588F9420414182F78A994E1E2D9153E48E2
                                            SHA-256:13DC526343225AD933612A6BBCEC4F9A3A9A94B00B2F24B7DA8F851E9DE00992
                                            SHA-512:6DB667391D842511867EED010055E9E3A09897004F77912E055FE794870EFD59CDE822D9AE819963595EB53A17477B24C981A334EBFB3869D71C3FE6A8274F14
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........T...:N..:N..:N9(.N..:N..N..:N..;N..:Nu.;O..:Nu.>O..:Nu.9O..:Nu.?O..:Nu.:O..:Nu..N..:Nu.8O..:NRich..:N........PE..d...W8.^.........." ................ ........................................p...........`A........................................p'..0....(..P....P..0....@.......,.. A...`.. ....!..T............................!..0............ ...............................text...X........................... ..`.rdata..0.... ......................@..@.data........0....... ..............@....pdata.......@......."..............@..@.rsrc...0....P.......$..............@..@.reloc.. ....`.......*..............@..B................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-QSTSG.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):44328
                                            Entropy (8bit):6.631745572973897
                                            Encrypted:false
                                            SSDEEP:768:uJnUUV7xPg4RdPvv1DHkhhFAWN6srByiYzC:uaY7XN7Ih4CIiYzC
                                            MD5:21AE0D0CFE9AB13F266AD7CD683296BE
                                            SHA1:F13878738F2932C56E07AA3C6325E4E19D64AE9F
                                            SHA-256:7B8F70DD3BDAE110E61823D1CA6FD8955A5617119F5405CDD6B14CAD3656DFC7
                                            SHA-512:6B2C7CE0FE32FAFFB68510BF8AE1B61AF79B2D8A2D1B633CEBA3A8E6A668A4F5179BB836C550ECAC495B0FC413DF5FE706CD6F42E93EB082A6C68E770339A77C
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........h..j...j...j....l.h....y..h...cq..a...j...[....y..o....y..m....y..p....y..k....y|.k....y..k...Richj...................PE..d...Q8.^.........." .....:...4......pA....................................................`A........................................Pk.......k..x....................l..(A......8...(b..T............................b..0............P..X............................text....9.......:.................. ..`.rdata... ...P..."...>..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..8............j..............@..B........................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-R5R9N.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):250768
                                            Entropy (8bit):6.1373382300932855
                                            Encrypted:false
                                            SSDEEP:3072:7KzvZoDlAz//7Jbl2oUbMwcOVQxQFPkjOg7YMskOB/uMsTnLPJEwSerle9ejdPIk:7/DM7JbooUbMw00EGZuFn+ejdVZwt9sl
                                            MD5:C6749BFCC78511374306FC6F22D5C23F
                                            SHA1:6759A3F2A535911C29C3E177E4A1677EA2B3AAA7
                                            SHA-256:898D50D5464DB102572D455AF693A649CD89208E266A3D6F9252F0A5CF58F230
                                            SHA-512:0F0CB00E19D001316B9EDD2167BFF9C20DEF5983ECAD34CB6E3A9F1CC8AA542875D02B0BD5C43B77E1852C31A04E3EAFDBBE69593221474007C92B8150F37F0E
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......QK=n.*S=.*S=.*S=.R.=.*S=.ZW<.*S=.ZP<.*S=.ZR<.*S=.ZV<.*S=NBW<.*S=NBR<.*S=.*R=.*S=.[W<.*S=.[V<.*S=.[S<.*S=.[.=.*S=.*.=.*S=.[Q<.*S=Rich.*S=........PE..d....'V_.........." .....t...H......,`..............................................P.....`......................................... O.......O..h...............d................... ...T.......................(.......0...............(............................text...Hr.......t.................. ..`.rdata...............x..............@..@.data....8...p...0...L..............@....pdata..d............|..............@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T11L1.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):86944
                                            Entropy (8bit):5.9624570687102745
                                            Encrypted:false
                                            SSDEEP:1536:IBFTSLtywceYf2kv4pP1V7ufwNgF6PV36hGfKCX7kRf9Kr9j+0RE:bLrk94R1V7E+e6N6kfKCXgQ9C02
                                            MD5:8F33B0B07D5CA3139A45BB6B402B9FB7
                                            SHA1:9D94C74952A74A36DFE487660B3387F54EB51246
                                            SHA-256:00BF1A5E5BBB6675F84D336D608780BBDA0999132A9C688A92D3220B58B1B892
                                            SHA-512:676123E52FA1AE2C26A2DD5AD1A749D2D93D73A0505200E7BDB90BBF9F1334356FF9CAB4A71E21595B51EDB496FD9A000FBEAC8A1267B262D0DD82D1855C369C
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......iF..-'..-'..-'..$_b.+'...W..)'...W..%'...W..)'...W..7'..vO...'..vO..&'..-'..N'..V..,'..V..)'..V..,'..V..,'..-'f.,'..V..,'..Rich-'..........PE..d....'V_.........." ........................................................p.......9....`..........................................................0...(... .......8.......`..D.......T...............................0...............0............................text.............................. ..`.rdata...E.......F..................@..@.data...............................@....pdata....... ......................@..@.rsrc....(...0...*..................@..@.reloc..D....`.......4..............@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-T3E2B.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):4659104
                                            Entropy (8bit):6.333935702932292
                                            Encrypted:false
                                            SSDEEP:49152:chofA+qyml656pmOdUqbW7j9BWl3Sm0TI4c1nT5:wNyml65kdUqYWu4
                                            MD5:EDDC407A59FFDC57589241B6022CD7A5
                                            SHA1:9EEF17B610835CCA590C2EB3C51BBDF2895A1CEC
                                            SHA-256:76551E87993CF9E0F9764B5539047AB7D1B9F9DDCECC42ACA6A5493ED6CE3B58
                                            SHA-512:CA11F012CE3179C83C2D6CB9FDC40074C19677D4093B7C8E1E00C67D26721CE8FBCED23443E22E31C176A0D6241880EC373F9FD4939DA631FC3B2AE40F255731
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$............t...t...t.......t..9....t..9....t...t...w....Z..t..9....t..9....t.......t.......t...t..Wt..v....t..v....t..v....t..v.h..t...t...t..v....t..Rich.t..................PE..d.....Y_.........." ......%..\!..............................................PG.....<@G...`...........................................E.....d.E.......F.8R....F.`.....F......0G......ED.T...................pGD.(...@FD.0.............%..............................text............................... ..`IPPCODE.....0...................... ..`.rdata..".....%.......%.............@..@.data....E....E..<....E.............@....pdata..`.....F.......E.............@..@IPPDATA.......F.......F.............@....rsrc...8R....F..T....F.............@..@.reloc.......0G.. ....F.............@..B........................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-UNR4I.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):137624
                                            Entropy (8bit):5.909722238073581
                                            Encrypted:false
                                            SSDEEP:3072:rOHSL/+jkiG2dRTZQILKrcGbjjW9+D95zi+0M:SLjkiZdRTZQILKrPjjzD95z4M
                                            MD5:C274F551A84006AF1F7222410EDA8C1E
                                            SHA1:890DC8153FABEE82015990D2D2E5A6C6EB1E7512
                                            SHA-256:CCC1BDA842699E94AA1B426EA6D3FA3A4F5866912D1511F61621531F482B8F86
                                            SHA-512:4D980ECB3BAC8A3D0C95AAB1E4D8436B801C167BB2DCED5CC8768C0DC7E793C7F53B97760587BB89CC7D14E42C7F60EE89471AB254047C77A66E75AA5AE0474E
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Xs...............j.......b.......b.......b.......b......Gz......Gz..........l....c.......c.......c.......cm..............c......Rich....................PE..d....'V_.........." .........................................................@......w}....`.........................................0....................F...................0..0....H..T....................J..(....H..0............ ...............................text...`........................... ..`.rdata...|... ...~..................@..@.data...............................@....pdata..............................@..@.rsrc....F.......H..................@..@.reloc..0....0......................@..B........................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\is-VSVSM.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):590632
                                            Entropy (8bit):6.463330275333709
                                            Encrypted:false
                                            SSDEEP:12288:Mt8MRN4gE4x4iTqwTQa6IUqXF7XyxpypsdUDqNSfbQEKZm+jWodEEV3Ho/:MCMm9pyp35bQEKZm+jWodEExg
                                            MD5:E74CAF5D94AA08D046A44ED6ED84A3C5
                                            SHA1:ED9F696FA0902A7C16B257DA9B22FB605B72B12E
                                            SHA-256:3DEDEF76C87DB736C005D06A8E0D084204B836AF361A6BD2EE4651D9C45675E8
                                            SHA-512:D3128587BC8D62E4D53F8B5F95EB687BC117A6D5678C08DC6B59B72EA9178A7FD6AE8FAA9094D21977C406739D6C38A440134C1C1F6F9A44809E80D162723254
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......n...*...*...*.....w.(...#...<...*......./.....".................+.....g.+.....+...Rich*...................PE..d...R8.^.........." .....>..........p"....................................................`A........................................ m..h....G..,...............(;......(A......4.......T...............................0............P......Ti..@....................text....=.......>.................. ..`.rdata.......P.......B..............@..@.data....:...`..."...P..............@....pdata..(;.......<...r..............@..@.didat..h...........................@....rsrc...............................@..@.reloc..4...........................@..B................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-2M1CS.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2771
                                            Entropy (8bit):4.891825004332733
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAA8XGhQXmbt6CVrwQdi+SEQAQdikSESSAQdiGSbQAQdiISbSSE:fJXGhQXmZFrwQdi+SEQAQdikSErAQdi0
                                            MD5:EB5AE1A2971541214DBFB0F9A62C09D3
                                            SHA1:CC8BC9251B7F016C38D8004983458A92E6BD2F86
                                            SHA-256:EE4604416BDC01B355F7E420DD865B2238FD2A624B1DF80CA87528AE049F2246
                                            SHA-512:36211EC09C4CABCE6246623E50F5BABB558E981A13C0E1BB7F19F1FEFDAA687CF0572720F54D7699C7AA40C03E657E1C0A7D7A923773F28A2E5103D0CD92B40E
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">50000</avgBitrate>.. <maxBitrate type="uint">100000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">35</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>.
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-39A7G.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.901729136243566
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAy9GhQXmxfZCVrwQdiTSSEQAQdiTSSESSAQdiCSbQAQdiCSbSSE:fy9GhQXmxkrwQdi+SEQAQdi+SErAQdiC
                                            MD5:1B8A5FAC7AFDAF1D1065544D28FA8032
                                            SHA1:6ECBF75BBBCCAC4D1E489092EC1AE6CA04933A87
                                            SHA-256:65FABDFBD8EC6FCD83E98773617549F3A429743CC6353A07BE47E8FB3D596E73
                                            SHA-512:65FF373816011F1651642B1874842457DF57837FB99613AE34F43161EDDEB2CC77F88ED7BDEB683535DCEF2091ACC37A581D2EF325E45881C6C5CD1A562971E6
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">350000</avgBitrate>.. <maxBitrate type="uint">700000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">60</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-3LBIS.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.897602688600901
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAy9GhQXmxfZCVrwQdiESEQAQdiESESSAQdiqtSbQAQdi5SbSSE:fy9GhQXmxkrwQdiESEQAQdiESErAQdiz
                                            MD5:41F4DBF923105EC11F65BA2144A4AA1C
                                            SHA1:08944B39295DA9DCB2C9552621B18F2675D72A28
                                            SHA-256:A1B83BDBF455584BD9CB52F4046DD11F2C0C344BDD9AAF3A9C86026CD5A19539
                                            SHA-512:152E8B1F6FC5BCD4E8F552E777B97470D551A00ADC99328EAF35ECD4489EA4E5F784DB8DFC118CA96E9F2A264F9FC79533BE2D94AE07C38A804FE383378697F8
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">350000</avgBitrate>.. <maxBitrate type="uint">700000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">60</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-5EQ0E.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2774
                                            Entropy (8bit):4.898279100458865
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA7ExGhQXmbfZCVrwQdiGSEQAQdi2SESSAQdiOSbQAQdiCSbSSE:f7ExGhQXmbkrwQdiGSEQAQdi2SErAQd1
                                            MD5:74D3A101D199809C2D5162F09AE1FDCB
                                            SHA1:B54E08E6BE8E4F8F61EF1819CDCF5366BFA6195E
                                            SHA-256:0CE611955AAD8AF165042230B7F4AF5D9668E3A5E1C157554E0E8CD93611BA67
                                            SHA-512:12428D43FB4630139F017377B9DD3CB776061E76A78E1514C775B8328E97BD91858B05C87A72FEE8ED190C762DF3CAA20AA554D8CCF6FCC8DC2DFEC1B89E528E
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">150000</avgBitrate>.. <maxBitrate type="uint">300000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">60</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-68POL.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.898446871040008
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA7vGhQXmxaZCVrwQdiESEQAQdiESESSAQdiqtSbQAQdi5SbSSE:f7vGhQXmskrwQdiESEQAQdiESErAQdiz
                                            MD5:C4516399B1272FB46728BC44D0F8AF75
                                            SHA1:90F1632637FDD6F712CD729517BADD1BD76242E3
                                            SHA-256:2AACFEDF24629B3CFF4056521D4C140F98B98E9FE779E4CA1700AAA4CE8B8EE0
                                            SHA-512:C8B0526E1FFDAD76C570131B1A9B73640B6FAABF5E92C5E7905D89597BDACAA2769360F1C2A8205682A01F335DF66DD38EE4E14A12ABECE9560D8523CCB23F82
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">450000</avgBitrate>.. <maxBitrate type="uint">900000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">70</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-70ERH.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2776
                                            Entropy (8bit):4.9012380435446525
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUALbGhQXmbJZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:fLbGhQXm9krwQdiOSEQAQdiCSErAQdiC
                                            MD5:59704A98B21B5D7977FE72173FEA8AED
                                            SHA1:B365E8A0476B57955C77C12923B08EAA5BBCBE42
                                            SHA-256:7BD5781745DFB8FF0D92E803C8D55FC3E3524CBC3D4E415826881F5CA3201648
                                            SHA-512:D476E393BFF6F4156EE6AFCF069FB881061F1AA45BB031ABFAC85B2728B502CBAEBEC8772AB66A114590C222227F479235685A7B2A3F66DC093081D4B612F505
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">700000</avgBitrate>.. <maxBitrate type="uint">1400000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">88</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-929TD.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2783
                                            Entropy (8bit):4.901505287509225
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAW7aGhQXmxRZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:fW7aGhQXm/krwQdiOSEQAQdiCSErAQdx
                                            MD5:A58F9D142858D86DE5744B13508A1277
                                            SHA1:DD54CE0714F09B54D22E3B6D2F84F19CE1549D5F
                                            SHA-256:68D2CF05EDFC6361FAEC27FBE85C915E9D5339375956EE9289EEB80BFAAD4AEC
                                            SHA-512:9937AAD9A78398D8F77271D4F41C740470BFD613F7BC0BD71486181141FAA84A5CA255C7D272084CAFDD97F15C956411365DDBB90BC4A31FBA8B5EE703B377AD
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">750000</avgBitrate>.. <maxBitrate type="uint">1500000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">80</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plu
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-BITA4.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2783
                                            Entropy (8bit):4.900953331049162
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUALbGhQXmxRZCVrwQdir4SEQAQdiFSESSAQdiCSbQAQdiCSbSSE:fLbGhQXm/krwQdir4SEQAQdiFSErAQdx
                                            MD5:C307D31594EDC65F24723B9CEB54CB53
                                            SHA1:20A092A476CADE15C29259F08D8488D12C0AC441
                                            SHA-256:230435126A87E06C08E04D1DD51D7218CAED36CF5859592D9E9F52DC2A710884
                                            SHA-512:D4BA746C291CFD9E94FD3547B36B29D627ADA184EB2BE67013EBC2DA1F52FB359DDDD9375C630D6E1EB7A3EEAD8952E0F134AC6B25D7658EDF5A408ACA7DDECE
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">700000</avgBitrate>.. <maxBitrate type="uint">1400000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">80</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plu
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-BSLL4.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.899820695443051
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAlCGhQXmxMZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:flCGhQXm6krwQdiOSEQAQdiCSErAQdiC
                                            MD5:3D7059100F8CF93797B50707E579F404
                                            SHA1:C0EB19A6D7A6346645B9D4C88923C69F47C3368F
                                            SHA-256:F7CAFA941211364CFF275EEE988066071D26BE2A22A3066E7AC77B5EC008FAD2
                                            SHA-512:9BCE2F2491ADF41CD9DAAE3941CD09CA66317632E10ADA425748A51066B02074E33E9CFE41CB8F34EB0D610CFDCC05E31E2F08868D2130328E657DD96DC36328
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">1000000</avgBitrate>.. <maxBitrate type="uint">2000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">90</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-CELBG.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2769
                                            Entropy (8bit):4.884427653572266
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAy4GhQXmbm6CVrwQdiFSEQAQdi7SESSAQdiwSbQAQdiSSbSSE:fy4GhQXmaFrwQdiFSEQAQdi7SErAQdiY
                                            MD5:D00A40C77A68E94D1C5E8B228A8699A6
                                            SHA1:702DB15DB02B370632CDFB0625F55794C6B223DD
                                            SHA-256:622C669B93980B8CA46416BF683B1AD9554B1E984970FF3FE06B379122CBD640
                                            SHA-512:B3C5182FEA25DE82507C40D2253EE9E583C820ECBD37D4982B81F7A1C7DABEA07D07DCAA88C3E2E3B868B083193EDB052AF3505C06F991CA7FE57CB77F3A7C8C
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">20000</avgBitrate>.. <maxBitrate type="uint">40000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">30</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-CHT3L.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2800
                                            Entropy (8bit):4.8498080202398155
                                            Encrypted:false
                                            SSDEEP:48:cF880UA0KGrDorWbYs43kQX7iVQdXDSCkpK73QdXDQkpKCRVQdXDSCnpKXVQdXDg:L0KGrcrWsuQX7iVQdXDtkpK73QdXDQk9
                                            MD5:9BDB0DE024E3113C93493CC856B74273
                                            SHA1:B58E715BD23CBDFBEC96CE9812104EBA5F6442E0
                                            SHA-256:51B7EAAD90181FF7D3585632A14CF6964B449241D4CD194AC84A6D27E45AABD4
                                            SHA-512:AC73D4F01C7A15FE5C100CFB412446DB6E93332FB7EBE874E5140F86DD15CA6A2E6E12CBEA571D9177567072ECD36554187D52B5474163A1CE6B3C52EDEFB3D5
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0".. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance".. xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">80000</avgBitrate>.. <maxBitrate type="uint">112000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <codecName type="string">rv8</codecName>.. <enableLossProtection type="bool">false</enableLossProtection>.. <encodingType type="string">cbr</encodingType>.. <maxFrameRate type="double">7.500000</maxFrameRate>.. <maxKeyFrameInterval type="double">10.000000</maxKeyFrameInterval>.. <maxStartupLatency type="double">4.000000</maxStartupLatency>.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <quality type="uint">40</quality>.. </stream>.. <stream xsi:type="audioStream">.. <codecFlavor type="uint">2</codecFlavor>.. <codecN
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-D3DNG.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.901010228982603
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA7vGhQXmxaZCVrwQdiTSSEQAQdiTSSESSAQdiCSbQAQdiCSbSSE:f7vGhQXmskrwQdi+SEQAQdi+SErAQdiC
                                            MD5:51469FA9523E74A5D541E564E1B0F9D2
                                            SHA1:A68F5A8B71367728FFA6228D663BC266DCBFE7EC
                                            SHA-256:28395B9FC5DFE974EA4F395DC31DB91ED23D89A2AEC9F5BB6CB7650BDC851BEE
                                            SHA-512:A93A199C127A4F9A49B62D5DEF541A678F2F943AC77655DD50DFF0180A61531B667A25A5E1585B2474E70355EC22CFBB93403AD8351CDB5B2D93B3D2834A9DF1
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">450000</avgBitrate>.. <maxBitrate type="uint">900000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">70</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-EMVVC.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.902211089463482
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAqAGhQXmxDZCVrwQdiOSEQAQdir4SESSAQdiCSbQAQdiCSbSSE:fqAGhQXm5krwQdiOSEQAQdir4SErAQdx
                                            MD5:81DE0C06D6497EC2A7CB7B8658986EC9
                                            SHA1:159F250531109C135FFB44DB8F297A74E647FB27
                                            SHA-256:987ED4FBF8403E67A70B17F62D20321F6A4B1A253846FFDB09915F7492814CEF
                                            SHA-512:5C8A243DD003BECBAAAF104E13A6E50BB5855CC5A68EA638C99AC6925EE8165256900D0FE920A81C1F62C37A9DEFDB30F072A323332DBADDFF50D1070582BE7C
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">2000000</avgBitrate>.. <maxBitrate type="uint">4000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">95</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-F29EL.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2774
                                            Entropy (8bit):4.899204992683194
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAZtGhQXmbaZCVrwQdiGSEQAQdiISESSAQdiOSbQAQdiCSbSSE:fZtGhQXmmkrwQdiGSEQAQdiISErAQdiO
                                            MD5:D86218B5C90A79AD4722E00C637B2C37
                                            SHA1:9B8441BC9FB364B25E99842E2B91F102C8A90AF8
                                            SHA-256:136742FE009FE8E2E3C579B20E363B10F3DB4D78D7A7D6BF488B9BC76D0AC26D
                                            SHA-512:7B6739B8B55E8CFCE79DD0206809D43389D37013C5A7144851399BEEF0617CCA9C478DD4D8FE85B96CA967F40EC7E4AD1FDBF5623D3B5E1F45F33D9FB4F25ACF
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">225000</avgBitrate>.. <maxBitrate type="uint">450000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">70</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-FR4HO.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2769
                                            Entropy (8bit):4.887012888493202
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAQdGhQXmbm6CVrwQdiFSEQAQdi7SESSAQdiwSbQAQdiSSbSSE:fQdGhQXmaFrwQdiFSEQAQdi7SErAQdiY
                                            MD5:7B08034A769601CA7423A8E5CB3BA023
                                            SHA1:27D77173000FC265F784ACB1F9441A79DCE1B92C
                                            SHA-256:B2814E8A44302ECD53A035F65A3ED0359A7C31076B32EE64DADA09D52D0CD901
                                            SHA-512:4DB8FD610A0AFD1DA24C35CB0F32873A45E07984191FE6BC9B2D71A10DC5BB5B559344640C017C27C879C2C773B06BA725DC5C4933BBE0C9C67299C6662D824D
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">26000</avgBitrate>.. <maxBitrate type="uint">52000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">30</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GHI5G.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.900208739789838
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAlCGhQXmxMZCVrwQdir4SEQAQdiCSESSAQdiCSbQAQdiCSbSSE:flCGhQXm6krwQdir4SEQAQdiCSErAQdx
                                            MD5:C553F56300A54DBF9B3293F0265BE113
                                            SHA1:D411084A1B93C2DD778F4D118F5413CD787F8A0A
                                            SHA-256:462A635F1EC39F3FEA18D555D09BC2A6C0BC51BB71FBFF7DD56F20B09D203CE7
                                            SHA-512:7246F0D1130512876769DEB1155A8CC73E2D86669A012C38E5E09629991DE2F582AEDA52096DE55D45346D40052FAB1F1BB1E73B60EC68607E627960F6DF23FE
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">1000000</avgBitrate>.. <maxBitrate type="uint">2000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">90</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GHKQD.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2786
                                            Entropy (8bit):4.900760319907551
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAAEXGhQXmxGZCVrwQdiOSEQAQdiFSESSAQdiCSbQAQdiCSbSSE:fpXGhQXmQkrwQdiOSEQAQdiFSErAQdiC
                                            MD5:5D7B439263EB75B6227E51BD37B79AE2
                                            SHA1:2D785F343437ADC2F78DD06280B6FC3F2227FD95
                                            SHA-256:F23D3EA032819EDF9575FD7284DD78C2CF63DE57E8532EBC2F3DB534F54CDE7A
                                            SHA-512:56CA3A349F836B11990D2C077C980380170EE899B240A3747922BCA312F9CB871C27D240D357BE74F907A7BD6582579A1FDCC4950EFF76DA75767570CBF12772
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">5000000</avgBitrate>.. <maxBitrate type="uint">10000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">100</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-GIT45.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.900959291006299
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA7vGhQXmxaZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:f7vGhQXmskrwQdiOSEQAQdiCSErAQdiC
                                            MD5:8EC1E3994954979297D6451177C609B1
                                            SHA1:0BB6EA34A8D18245C6D8E296E6F21FE9FB7B342D
                                            SHA-256:9488DFD2A418D2039AB92616FC0C4D641B1ADB8BE57B683C05FF640B76D73651
                                            SHA-512:6B8418FB1E39FCDFE4C814B1D72EFA935A700895DBC00B82D9EAE5A4B625DD721FC7C81DE484A7104FA047B785CDC6B58F4E1EBCD09BF90CE80E3BFE2A1C54B0
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">450000</avgBitrate>.. <maxBitrate type="uint">900000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">70</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-H1LIS.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2786
                                            Entropy (8bit):4.8982790656137905
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAAEXGhQXmxGZCVrwQdi5SEQAQdi5SESSAQdi5SbQAQdi5SbSSE:fpXGhQXmQkrwQdi5SEQAQdi5SErAQdiQ
                                            MD5:258A87EC71859D3E7A0B92D82792C48E
                                            SHA1:10EB812873308C393A85A0BA95D552F3ED137D97
                                            SHA-256:3C020749A6B145A812323332E5C2EEA48A14025091B25B5CD3B8EE3E19AAEB94
                                            SHA-512:0C0C2088B8CE3C8B1E12B717656B17497B364F9B0BEE886959DE58F7DB30518ACA0E421750EB78F780EE142266DED80663BF4CBCE3D3C25467A17DBA6139F6D3
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">5000000</avgBitrate>.. <maxBitrate type="uint">10000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">100</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-H7428.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2783
                                            Entropy (8bit):4.900947577390879
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUALbGhQXmxaZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:fLbGhQXmskrwQdiOSEQAQdiCSErAQdiC
                                            MD5:5307E2EFBE96D3E1AFE609C6A6C0E591
                                            SHA1:3FF1A198ED0F16E77BEDC71FA7888C95039B2F69
                                            SHA-256:D8C7CABD3C82CC58BB255229C3A77091C631767A437C1C58AC3085BB1069473E
                                            SHA-512:E03982089972F26A590D2CDC3E29085EA955AE06DF1CB4CF509DE19339EAD43A2879127C579E30C6182AEAC41AD0B22CAB6E05ED432451513BEC6EDF75C2BDB9
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">700000</avgBitrate>.. <maxBitrate type="uint">1400000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">70</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plu
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-I46UE.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2773
                                            Entropy (8bit):4.892963874866102
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA90GhQXmbd6CVrwQdiwSEQAQdiSSESSAQdiOSbQAQdiCSbSSE:f90GhQXmZFrwQdiwSEQAQdiSSErAQdiO
                                            MD5:D93D7D90A09D5C70EB4DA26291313D06
                                            SHA1:9C554F9FE121A93EF7FF9DC36D7606D0328E5E64
                                            SHA-256:7E5D4FBBDE6766DF96575F1BE3F376FCAF973EF9457E4D80820609E2BB2D9441
                                            SHA-512:D815A9CAFD8B5AA29419D97D703C039AEA14D9E6C1A40B5196E58812C09561397F94679A897C0275D760C24F3DA063C696425E27F8771B665F81622BFECBFC30
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">100000</avgBitrate>.. <maxBitrate type="uint">200000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">40</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-JOGRT.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2775
                                            Entropy (8bit):4.9006782402039955
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAy9GhQXmbPZCVrwQdiOSEQAQdiJSESSAQdiCSbQAQdiCSbSSE:fy9GhQXmzkrwQdiOSEQAQdiJSErAQdiC
                                            MD5:369D6681BBB69CA6BB29A106D4F3C3FA
                                            SHA1:7D392F609C16AC010857180CE09802EA11D0C4FA
                                            SHA-256:DEB1CC555647073A4E0410054FABFDD8303E53F1F50B16EB126E559F49E445BD
                                            SHA-512:E05A64636DBB75D8BEFD95049FEB054E9BFBFEBCE144E97B53DD49A09B386A7E820309C0AF089BBB77A56089FE7BADCAF690F3D3304A37868ED389505AC7AB61
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">350000</avgBitrate>.. <maxBitrate type="uint">700000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">77</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-KAHAS.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2775
                                            Entropy (8bit):4.900324924891799
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUA7vGhQXmbNZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:f7vGhQXm5krwQdiOSEQAQdiCSErAQdiC
                                            MD5:C955F947CDC39D2466CCC1CC522EAD5D
                                            SHA1:85D9EA0E5A7B1635C53FE6DF44D30B90B8445C4C
                                            SHA-256:AC597B9207A05CA0DD7CE8D1609169A3A6536FA798C06F923DD0B1C6FA2AB087
                                            SHA-512:72F4F0AB335FB21FDC739AF31E367EAEA864518BFE674BCD7410DCFB5BC2C1EF97009C1D00D57D21EB6584021BE832680270B8054E89BBE316D27F2316865939
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">450000</avgBitrate>.. <maxBitrate type="uint">900000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">84</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-KHL16.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2782
                                            Entropy (8bit):4.901135504160747
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAy9GhQXmxfZCVrwQdiOSEQAQdiJSESSAQdiCSbQAQdiCSbSSE:fy9GhQXmxkrwQdiOSEQAQdiJSErAQdiC
                                            MD5:0F1839E97AF9EAC1C407E4EDBE43FFB4
                                            SHA1:647EEFA3A0B2C04F626B1D519B64E240472CF9A0
                                            SHA-256:C1E4D129BEC794F4966C6D895ACA2B91E9D0A7A05CF0D5B3A4E774EC420CE29D
                                            SHA-512:BA9901A0E2950410AE046D6DD14A580F50C9495B81F5CD604ECA5E3CCEAB40D5C5A15C3F77C9C9142C1DE9A6B39BEDEA8451551B30E3078CC789D2E8C305A56F
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">350000</avgBitrate>.. <maxBitrate type="uint">700000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">60</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plug
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-MVRHA.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.897203254179472
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAlCGhQXmxMZCVrwQdiqtSEQAQdiqtSESSAQdi5SbQAQdi5SbSSE:flCGhQXm6krwQdiqtSEQAQdiqtSErAQR
                                            MD5:A2BED710F1CF410F3FD33970D3D267AE
                                            SHA1:D3B1C227E851B43596AF7DD8B3FB25A97A516BC7
                                            SHA-256:1BEF17720FF6C88365AA7E7DF0C3DD490205786A7DEE5B45932D30FDE56264DF
                                            SHA-512:E7FEFA43DDAEC6C233F77DE670E3BD8F88FDF73A5EE04AD807576E31296E29C93D749FA2489C224FBA068F9AD71A9C28677E8409C3F4486083A65EB707E38CC6
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">1000000</avgBitrate>.. <maxBitrate type="uint">2000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">90</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-N2GCJ.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.90111726170542
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAqAGhQXmxMZCVrwQdiOSEQAQdir4SESSAQdiCSbQAQdiCSbSSE:fqAGhQXm6krwQdiOSEQAQdir4SErAQdx
                                            MD5:F328E233516EA0EBA47CB6067880E4EA
                                            SHA1:E6CC429F94C0CB93FB4B47F4C016AFD71BDBC8BC
                                            SHA-256:E21A0F10C91D6D6D06CABE5E3AE3A3ED96CDFF821DBEFDCDF1C887358FC1F175
                                            SHA-512:A967F72A2656EB9F48B3B2917BA241D7FE17E2FE2C6A7520221D2D2528F3991D5125F6881C09E81938362A467F437DE21D697D4350E09AE6A744078292042CF9
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">2000000</avgBitrate>.. <maxBitrate type="uint">4000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">90</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-NTE34.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.899310933601001
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAqAGhQXmxDZCVrwQdi5SEQAQdi5SESSAQdi5SbQAQdi5SbSSE:fqAGhQXm5krwQdi5SEQAQdi5SErAQdiQ
                                            MD5:90EE424A1EFEE8B9115B06DCB311C814
                                            SHA1:EB9F2DB4E3CE695AAE9DB7AB4AEF57F15F2D8239
                                            SHA-256:0B691ACE022931A7E8CF60E8B45AC8A39537216B5F219BC631385F6A70D618FA
                                            SHA-512:F6546DED7442D49E243F6AE1BD195D7345C49724343F18449937C71223292BC4FDF08DE4918F88B2D7979AA546D498A12DD2F734B03A86659E9DE3108CA65508
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">2000000</avgBitrate>.. <maxBitrate type="uint">4000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">95</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-OLPN3.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.900855328863332
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAqAGhQXmxDZCVrwQdiFSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:fqAGhQXm5krwQdiFSEQAQdiCSErAQdiC
                                            MD5:38E965EA1276ED6B62C6EF060D978E9E
                                            SHA1:4080BA407618A8B684446A950FA8204D48BB33B9
                                            SHA-256:9C92417E9AC0F855358A2983BA74F32B80A0955E2AFEB975FB75532A98125593
                                            SHA-512:F8BFF9C4D3AD036EA5C7C775E7865EA0B8B115C875D7070E9E2AD26E910F8B897B3A06C892937D0A22064EB2C919685E820D09F296B0C0002EAF7EC296638C54
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">2000000</avgBitrate>.. <maxBitrate type="uint">4000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">95</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-OV9MG.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2783
                                            Entropy (8bit):4.898526134677562
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUALbGhQXmxRZCVrwQdibSEQAQdibSESSAQdi5SbQAQdi5SbSSE:fLbGhQXm/krwQdibSEQAQdibSErAQdiQ
                                            MD5:F6BCCFD4B20A2A381D3618422E56D9C5
                                            SHA1:E55E7D62C8D97611CA4BC069D260A883FF67C55B
                                            SHA-256:6D6DAC09AB8E5DF5C46F455061116039CD8AD124411C439B5437B56E96647D12
                                            SHA-512:5F31ED103D227EB67E3E92B6B5C0EA86A9CBEDFA0A2E476F2381687DEFA4B6AF38D8E4975F1E3003B988A806699033261489B5BFF5B27CDBBC13108B9FBC2A62
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">700000</avgBitrate>.. <maxBitrate type="uint">1400000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">80</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</plu
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-PH5I5.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2798
                                            Entropy (8bit):4.839744521077124
                                            Encrypted:false
                                            SSDEEP:48:cF880UAyCGrDorWbYZ43kQXiwVQdXDSCkpKw3QdXDQkpKiVQdXDSCnpK73QdXDQH:LyCGrcrWs1QXiwVQdXDtkpKw3QdXDQk5
                                            MD5:3931BA0423004139D1FCB58DCC4434B9
                                            SHA1:E5C4E12B0DDCF2570C9B32E7FFB9495022C0B8E5
                                            SHA-256:F1ADB2B4B1F1A6598AED0BD70761E869599A3D503ECE5E980EA1551A075492F8
                                            SHA-512:EA242F5147E4A57475D9BBAA7B8AFDCF0A514DD18A3904EE281D784920C8A4F2158586007B9C776BC0649194F00C41AE3F4B865630B21E47D43CC85E9637AAD5
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0".. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance".. xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">20000</avgBitrate>.. <maxBitrate type="uint">28000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <codecName type="string">rv8</codecName>.. <enableLossProtection type="bool">false</enableLossProtection>.. <encodingType type="string">cbr</encodingType>.. <maxFrameRate type="double">5.000000</maxFrameRate>.. <maxKeyFrameInterval type="double">10.000000</maxKeyFrameInterval>.. <maxStartupLatency type="double">4.000000</maxStartupLatency>.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <quality type="uint">30</quality>.. </stream>.. <stream xsi:type="audioStream">.. <codecFlavor type="uint">0</codecFlavor>.. <codecNa
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-PRH4T.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2769
                                            Entropy (8bit):4.886617018932608
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAn2GhQXmbm6CVrwQdiXSEQAQdijSESSAQdi+SbQAQdikSbSSE:fn2GhQXmaFrwQdiXSEQAQdijSErAQdio
                                            MD5:CBEDCAB30E616A115973115340B36146
                                            SHA1:A5B9C5A1A2F9E37A6CCF2F5E578C1A9C55D3B68C
                                            SHA-256:00442F4CD2C183505B0B5DF3796CA8FFCBCE6BE02BFCEE9E666A12EE7C3AE882
                                            SHA-512:8E28EF41EB89E5E5741CC837AFC02A7C49EC7A6C9D8DAD78CB44FBE5BBDBFD972A550A1F66915DAB3F2CD3E813A84942984F9B22DD433BE4F20982E0CACD0E9D
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">12000</avgBitrate>.. <maxBitrate type="uint">24000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">30</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-QC42T.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2777
                                            Entropy (8bit):4.89018673094656
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAqAGhQXmxGZCVrwQ5iISEQAQ5iISESSAQ5iISbQAQ5iISbSSE:fqAGhQXmQkrwQ5iISEQAQ5iISErAQ5iw
                                            MD5:A8A1F53B88491643AF854DA1BFED49C5
                                            SHA1:9E193975DEF484AEA1C449571E0B12C6A73C3A44
                                            SHA-256:B221266E1EBC54F4007A815918DA4ACF867A9CFEEB2DBDB5CFEE8C0ECECF9390
                                            SHA-512:6E8FD5CA8E4C6DDE545CDA73468AB734212B814C08DA4A684B6905D7E3A55AC0210A486EBDC4E7104A9C582DACF5EA2C799068FC0E7EF86576E10E8A6DF93B5A
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">2000000</avgBitrate>.. <maxBitrate type="uint">4000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">100</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-lossless</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-QKRUR.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2784
                                            Entropy (8bit):4.899102304638453
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAlCGhQXmxRZCVrwQdiOSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:flCGhQXm/krwQdiOSEQAQdiCSErAQdiC
                                            MD5:A615E0394F584B4A2F062F453DAE6E80
                                            SHA1:57C818FDBE9D55C0DA232CCBD3D38233A3D2CE07
                                            SHA-256:0A2D12393DC0029DB5B16022C1EAEC6B57A0944623B92153B95178ADF9847240
                                            SHA-512:4BE1D760825071B36A18B7020E5E2E2CD3E1D9A925F940CC823BFF0B294839F29A2D12A42925681FB9817C69C4702ECB1E50E61BD70DEBC37CFD664E8792762D
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">1000000</avgBitrate>.. <maxBitrate type="uint">2000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">80</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pl
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-S1HTH.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2786
                                            Entropy (8bit):4.900760319907551
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAAEXGhQXmxGZCVrwQdiOSEQAQdiFSESSAQdiCSbQAQdiCSbSSE:fpXGhQXmQkrwQdiOSEQAQdiFSErAQdiC
                                            MD5:5D7B439263EB75B6227E51BD37B79AE2
                                            SHA1:2D785F343437ADC2F78DD06280B6FC3F2227FD95
                                            SHA-256:F23D3EA032819EDF9575FD7284DD78C2CF63DE57E8532EBC2F3DB534F54CDE7A
                                            SHA-512:56CA3A349F836B11990D2C077C980380170EE899B240A3747922BCA312F9CB871C27D240D357BE74F907A7BD6582579A1FDCC4950EFF76DA75767570CBF12772
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">5000000</avgBitrate>.. <maxBitrate type="uint">10000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">100</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-TBRIB.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2769
                                            Entropy (8bit):4.888076695342852
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUADzGhQXmbm6CVrwQdiXSEQAQdijSESSAQdiwSbQAQdiZSbSSE:fDzGhQXmaFrwQdiXSEQAQdijSErAQdix
                                            MD5:01BA77EC69B97759673494289721A7A1
                                            SHA1:EE5F2EAD3DCBD460D3B3785CBA05B9E5FF7ADAD4
                                            SHA-256:5456F4CD1A39B7AB2524340C8E56FC0F9E3D5F4EAB8A460B3877D582B68AE08A
                                            SHA-512:2474E8F5E578BA2110ACFB6B0D5A2C6471F724968400AE7EB2A420F27E50608321F8CFACC241ADB10F4B49223C6FDF9D3F292973500CB33173095857E7C6C88D
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">16000</avgBitrate>.. <maxBitrate type="uint">32000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">30</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-TH42R.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2786
                                            Entropy (8bit):4.900152461503551
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAAEXGhQXmxGZCVrwQdiFSEQAQdiCSESSAQdiCSbQAQdiCSbSSE:fpXGhQXmQkrwQdiFSEQAQdiCSErAQdiC
                                            MD5:152840C49C7B27E86872A003EC913575
                                            SHA1:49C460DFAFF5238A6C0C0D73BE97F742D1AA9A07
                                            SHA-256:AEFAC4EE115419A8BF432D18D2B3D60FA59AC199D7402F83382917994EE16EC8
                                            SHA-512:AEDEE1D44A6FE9B25F3CD020820F178D2C2701FD95AE60CD471F4A0BA6EF34F10CB1CFAE7F9F6F8E76C11D84C0D38BD74DF8CF29DE3D9DD0D4FBBDC3F7008D0F
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">5000000</avgBitrate>.. <maxBitrate type="uint">10000000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">vbrBitrate</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">100</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">30</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-UPAA4.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2770
                                            Entropy (8bit):4.89211739812396
                                            Encrypted:false
                                            SSDEEP:48:cFx8DUAfmGhQXmbm6CVrwQdiFSEQAQdi7SESSAQdiGSbQAQdi2SbSSE:ffmGhQXmaFrwQdiFSEQAQdi7SErAQdi6
                                            MD5:C8859FEBE57ACD0411A0963530D90430
                                            SHA1:ED75101906B45656BCFEEA1038B70A6C8B4ADF79
                                            SHA-256:FEA8E082BB13EA02C2F60B91837664637F4325E1DCC26F50183C996FE9FB7761
                                            SHA-512:4D30E7D56828EB87B2C95A2142160114A4E0B09F530292CD56B57258BA1EDD436F3C32118D964148C0186305F116A74F7AA84BD19903FF330F3E35307206BE57
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">34000</avgBitrate>.. <maxBitrate type="uint">68000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <encodingType type="string">cbr</encodingType>.. <encodingComplexity type="string">high</encodingComplexity>.. <quality type="uint">30</quality>.. <maxStartupLatency type="double">4</maxStartupLatency>.. <maxFrameRate type="double">15</maxFrameRate>.. <maxKeyFrameInterval type="double">10</maxKeyFrameInterval>.. <enableLossProtection type="bool">false</enableLossProtection>....</stream>.. <stream xsi:type="audioStream">.. <pluginName type="string">rn-audiocodec-realaudio</pluginName>..
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\audiences\is-US9VT.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):2803
                                            Entropy (8bit):4.8551933948648225
                                            Encrypted:false
                                            SSDEEP:48:cF880UA8hGrDorWbYs43kQXGdVQdXDSCkpKXVQdXDQkpKhVQdXDSCnpKXVQdXDQH:L8hGrcrWsuQXGdVQdXDtkpKXVQdXDQke
                                            MD5:341F17366A7ED4FB2FA3CC4B1FEB6B07
                                            SHA1:BB6FABB2F9D4B3E97C4662C3545F8FD3B38ACEE3
                                            SHA-256:1595698CB16144131F0669CE166EDE6FCA0E0B942CB34FCF9D9B095660750D9A
                                            SHA-512:EFB0271C11681C6C1C3293979D357B6A2C666F5DE7F9A48EDD03F8912292835D16B4BA8F500F01A0CCA0DACBFD7F86203CF40FF1DF18EC1F9FBED7F7B2F9698B
                                            Malicious:false
                                            Reputation:low
                                            Preview: <?xml version="1.0" encoding="UTF-8"?>..<audience xmlns="http://ns.real.com/tools/audience.2.0".. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance".. xsi:schemaLocation="http://ns.real.com/tools/audience.2.0 http://ns.real.com/tools/audience.2.0.xsd">.. <avgBitrate type="uint">200000</avgBitrate>.. <maxBitrate type="uint">256000</maxBitrate>.. <streams>.. <stream xsi:type="videoStream">.. <codecName type="string">rv8</codecName>.. <enableLossProtection type="bool">false</enableLossProtection>.. <encodingType type="string">cbr</encodingType>.. <maxFrameRate type="double">15.000000</maxFrameRate>.. <maxKeyFrameInterval type="double">10.000000</maxKeyFrameInterval>.. <maxStartupLatency type="double">4.000000</maxStartupLatency>.. <pluginName type="string">rn-videocodec-realvideo</pluginName>.. <quality type="uint">70</quality>.. </stream>.. <stream xsi:type="audioStream">.. <codecFlavor type="uint">16</codecFlavor>.. <cod
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-1DHV6.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):73793
                                            Entropy (8bit):5.5605243298434965
                                            Encrypted:false
                                            SSDEEP:768:z84NgbRXrRdn8hHNp57RoeTX79c9sI4gA5Ii/hQVCVL8jDOeIJunlkonm+SQYq4W:zIXrRMp57zsD4GiZO+8+onGUdSQT4DS
                                            MD5:107A64D31CB2DAD1746B060886440F60
                                            SHA1:BC89B6AFD11FDDE240DAE5DE8C43C567B96C8240
                                            SHA-256:11D85AED01DA3581D659B18B406F5C188C95EDB7C574B9A4881E0DC0229D849B
                                            SHA-512:F9DEF5B32D0141395AACF5E852A74841584DDD042B439172FDE8C017EC7B26C3374FC486C549CEE05649CC99B83D7A386C2CC26631DA990F3EC9ADD18363C6CD
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........d............!.............................................e...............].......Rich............................PE..L...M$.>...........!..............................U`.........................`..................................................(....@..h....................P......P...................................................D............................text...D........................... ..`.rdata........... ..................@..@.data...<]....... ..................@....rsrc...h....@......................@..@.reloc..@....P......................@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-4AD6F.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):176195
                                            Entropy (8bit):6.0377378471977226
                                            Encrypted:false
                                            SSDEEP:3072:61Exx64kgPNRE0/WFOBC/Wgf11y1rgEedRjlbDDDDDDDkYzbDd:3NRE/gBC/Wgf11y1rgEeXlbDDDDDDDk0
                                            MD5:C1237664CC679ECDEBB955981DC8786A
                                            SHA1:2BBFF876F29F23CFFA55780B28C98504A5BAB6ED
                                            SHA-256:1E902223D3E4EC7BAA4580AF3B28A15B866340301434090B2F11AF29A021501B
                                            SHA-512:85AADC138EAD2925D26D164A536D6D39CC893EB412D7B8EE4251022D1B5F6C39FE25D7DC0C24330701001127AF21070947644267346CDCD1E8FECB87DC6E8789
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........C............................b...............".......................Rich....................PE..L....;.@...........!................`U.............a................................w...............................0W..p....U..P...................................@...................................................@............................text....F.......P.................. ..`IACODE2. 4...`...@...`.............. ..`IACODE1.......... .................. ..`MMXCODE1.;.......@.................. ..`.rdata...X.......`..................@..@.data....*...`.......`..............@...MMXDATA1......... ...p..............@....rsrc...............................@..@.reloc..............................@..B....g..E@...p$#C..8..3...u...8.d.34..78....)n.9..\p.2..g.7.O._x.. T.B...8..%......tc.>1.aD0X.N.".@f..,.o.........X..Vz.S{2.r.......................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-6RM2R.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):548919
                                            Entropy (8bit):6.4777190361374535
                                            Encrypted:false
                                            SSDEEP:12288:5LfLv74Iq4S1K2hTxlSLR8QegKXHLEU+RONk76RyP0oBrfdtW:NnMuR8JxXHLEU+RONk76RyP0oBrfPW
                                            MD5:FEE174FA75745239446F0D1F1D365C28
                                            SHA1:D86A90F33A507FBD8278CC58B1D0C2CE6FB809A2
                                            SHA-256:219A8E99B8002E72E48732D502E3A6BB194B4554104F9E58D4A28D443A1EBDBE
                                            SHA-512:159456DCD6351C443F1379FD44DE3A79ED624CDDD1BBB91E778A9865EAF6557F52189096AC54D4C5D9B0B73147AE7705A3E2ACA2E6510D36644757D273475AFA
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........2x..S...S...S..@O...S...L...S...L...S...S...S...L...S...U...S...p...S...p...S...S...S..<s...S..Rich.S..........................PE..L...}Vr@...........!..............................U`.........................`.................................................<................................f..0...................................................$............................text.............................. ..`.rdata..............................@..@.data...t........ ..................@....rsrc...............................@..@.reloc...i.......p..................@..B........................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-8OEUB.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):327749
                                            Entropy (8bit):6.6610539163254865
                                            Encrypted:false
                                            SSDEEP:6144:H62Ol7Ss4LQZp0Suz1QfJyKEGfWoQaioeygljEzi:dOr0SuzaDEGfWo5glYzi
                                            MD5:079525F2434437FA1624285657B617BD
                                            SHA1:E9EB76039AC262F6731C38FCE133C6C99D12A20B
                                            SHA-256:52D8322E5285EC81044E49CDA3C429ECD275FF168368271239224742C3B4CCE4
                                            SHA-512:C667A14DF291DFA9E701D0B5DE17F7D2D5724462B5624924D29CDCA29CCFB2FA4AE56D4B6ED38B262542B86B9C3686D0487DAA803E1575623F7D1768DA005C7E
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........^......................b..........................."....................Rich...................PE..L...)<.@...........!.........P.....................a......................... ......................................0.......(...P...............................\....................................................................................text...*........................... ..`.rdata..............................@..@.data...P...........................@....data1..............................@....rsrc...............................@..@.reloc........... ..................@..B....\..Y`....-.o..`u.k.R.R...9.r|.y.r..nq....!...t.*.(...TO1...~...Yi. .....X..vZ.z.*...5.....g.{.m........aU...6...4\.....#pbved. .Intel(R) C++ Compiler for 32-bit applications, Version 5.0.1 Build 010922Z : D:\Intel\rv2001\enc\x86\winterp4.cpp : -Qvc6 -Qlocatio
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-FELGD.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):102465
                                            Entropy (8bit):6.701185053572777
                                            Encrypted:false
                                            SSDEEP:1536:q0JYC+dEQ8OMBhyGfnVI7ZWTsrfrI7ZWTsWm:q0iELlMOVI7ZWTErI7ZWTZm
                                            MD5:A781F8AB9720EFA9C4F198BD79866E11
                                            SHA1:0111066B577B2CA6098CD77EED2473590E288719
                                            SHA-256:7961CEAC07ACE2628967D015F78B9E64B71D280CEC641CB9D58926785E47F64B
                                            SHA-512:CE89D98E3241142F7C0F655D7A479EBA407060464FCC868A0D692C81F3F4713454CE8FFB0418D52FDBDE3EE8B694FE6004C478B4B6E01DBE18EF344507577655
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}O..9.y.9.y.9.y..2w.;.y.V1s.=.y.9.x.).y.V1}.:.y.?.s.8.y..(..8.y.?.r.i.y...}.8.y.Rich9.y.................PE..L....Vr@...........!................G.............s`....................................................................(...T...(....p..@.......................@...P...................................................D............................text............................... ..`.rdata..............................@..@.data....~..........................@....rsrc...@....p.......p..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-L8VPB.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):65602
                                            Entropy (8bit):5.507533722705891
                                            Encrypted:false
                                            SSDEEP:768:tBrGeYp8LkLF7JlJa6Cvu+iZK4nGlo7dCYtVykJK+t6tj6tVDWBE3Ghv+XbG:tS8LkzNCvViZNnyYdRK+t6t1F
                                            MD5:FEC421F11F3E143665387A26B05B696E
                                            SHA1:881DF4F3E97FCB2E671F4DC54BA6B5D56F0EFF54
                                            SHA-256:A51BFF72ECE803500283517AC3D35E25D17295B094CB453687B75D159353BAFA
                                            SHA-512:F30AE4FF177C625DAAABAFD497E191E98571A0A35DE096BBD54A406CD56F85998269D9F720B6BEEB192BAFD1A6EF5A0E747EF313BD0C450F747E199E6380C1F6
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........?K.^%..^%..^%..B+..^%..A/..^%..A!..^%..^$..^%..}/..^%.JX#..^%..}...^%.r~!..^%.Rich.^%.................PE..L....Vr@...........!.....p...........{............q`.........................P......................................`...(...|...(.... ..`....................@..<...0...................................................,............................text....k.......p.................. ..`.rdata...,.......0..................@..@.data....j....... ..................@....rsrc...`.... ... ..................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NEFLU.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):266306
                                            Entropy (8bit):6.610971834095742
                                            Encrypted:false
                                            SSDEEP:6144:nwbEScIpZH6B7HZDQAfmLSieQu/tWOwFt5ZRsNZmljEz7:qE4aBTZDX7T/thwFt5Z+ZmlYz7
                                            MD5:C1C3701481221AB39365C2F300643A63
                                            SHA1:1983AA9BDA31856CC000E280AECD906F54B4E0FB
                                            SHA-256:91D5A17FF6FCFAB890D24D57C9C64F03F540979E949D4883433CC44B8CC32700
                                            SHA-512:C115C4599716CF43D0FD3A450AF14A7655A486C2B01DCB02CA4EA8413716C924F57E1B37195223D70B87414FD1B6F86E66EC4CA85EC69AA3B7FDE7978DCD2A95
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........E..$...$...$..98...$...;...$...;...$...$...$...;...$...$...$..F....$.......$..}"...$.......$..E....$..Rich.$..........PE..L....Wr@...........!................a..............`.........................P...................................... ...........P.... ..P....................0..l....................................................................................text............................... ..`MMXCODE1............................ ..`.rdata..'R.......`..................@..@.data........0.......0..............@....data1..............................@..._RDATA.. ...........................@....rsrc...P.... ......................@..@.reloc.......0... ..................@..BIntel(R) C++ Compiler for 32-bit applications Version 5.0 Beta 1 000517 Copyright (C) 1985-2000 Intel Corporation. All rights reserved. .Intel(R) C++ Compiler for 32-bit applications
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-NJJD4.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):479298
                                            Entropy (8bit):6.491323519270892
                                            Encrypted:false
                                            SSDEEP:6144:02yjLfQhD7QvWTM9HZ5kf7kqHda6aDKfFZSScAoyus7Vd/pojh1vczmDJ1u+BilC:eBHzaI/6ymF520j/pch1vcCDJA+8lYz7
                                            MD5:93B0942D1A70B8D7D59D90089E246C25
                                            SHA1:2170EADA30779AF102964EA05DD8A6F449876C97
                                            SHA-256:3B27565278CC6B3A499F3EB041161A8E1E002D7FBD7AD17BE79BFF79E0F5CBBB
                                            SHA-512:E01EFA89D17DE9658E7974DB3AE1EDB4849AA41D3CA966A064AE4DA68631F83F19450642C515188D13AC4988FE5A2016322C3242445243990CB2E8820D9E4127
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........>...P..P..P.3.^..P...Z..P...T..P..Q...P...C..P..P...P..Z..P.w.V..P..[..P.O.T..P.Rich..P.................PE..L...TWr@...........!.................v.............`............................................................................x....`..x....................p......0...................................................,............................text...jg.......p.................. ..`MMXCODE14........................... ..`.rdata...#.......0..................@..@.data...............................@....data1..p............P..............@....rsrc...x....`......................@..@.reloc...,...p...0... ..............@..B................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QI59E.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):155702
                                            Entropy (8bit):5.898078968562479
                                            Encrypted:false
                                            SSDEEP:3072:sHWOqg0q2eZa8tMS+4L2XKhQlR9k2AX4G2c78RUtq82OEk74n:gZD/Za8x+I2ahwDAXt2cgRUtV/LE
                                            MD5:408D468086D281F526A84836E0C49E71
                                            SHA1:2E339077D0C5BDD0E0A6DB892054289E24AD7682
                                            SHA-256:B07CC92E6CF0A2609BB20BEF9A4D469A77C6CCE6BC5A147F4125A456CDB429EC
                                            SHA-512:5A6689890BBC3F13925D73076018F8EBB75F314E732336A8163D563B2959C48D11C347BE997C1F9EE5459AFE52134500A11FFBAB94B8FB632C8597F1D375C096
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......7t..s...s...s.......q.......r.......v.......p...s...x.......r...u6..w...u6..u....5..r...Richs...................PE..L....Vr@...........!..........#...................w`.........................@$........................................u......<.....$.`.................... $.....0...................................................,............................text...d........................... ..`.rdata..U...........................@..@.data....U#.........................@....rsrc...`.....$......0..............@..@.reloc....... $.. ...@..............@..B........................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-QP1V5.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):102464
                                            Entropy (8bit):5.749974043070897
                                            Encrypted:false
                                            SSDEEP:1536:Hre+EuDd38Nd72KNClBpdHZZd9CBpdHZZd9gr4QcuMV+D8Kf5PL0QTsXcAPZF1:Ha1483FN6rC1mXTGcAPP1
                                            MD5:9AE31533C71CB4094B6681F0A7D055E8
                                            SHA1:DDC683257E4C75649FAD93C0543FE5F12CC846DE
                                            SHA-256:051B7C1F3BC06B34260C16AA4E8EF75018E2C142480027FC5C0D384A545041F9
                                            SHA-512:E1B8E3678017C0060BB8C047890DB2E4D76FE6E21CDD6CE1EB3893DE8C12B41DEA04CBB2EB3D766DC5384184304591568DD32D8C900C76BBA30D23DAE01F7C57
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........f..R.a.R.a.R.a.R.`.S.a.0.r.P.a.R.a.T.a...c.A.a...g.S.a.T$j.S.a.T$k._.a..'e.S.a.RichR.a.........PE..L....;.@...........!..... ..........P&.......0.....`................................h................................1..}....0..<...................................@0...............................................0..4............................text...@........ .................. ..`.rdata..=....0.......0..............@..@.data....o...@...0...@..............@....rsrc................p..............@..@.reloc..............................@..B.....#..z.IK...5&.~.....79X...@z#.`....V%..~...o.}&......4.(..Q.~.;........<?..v.5z8....Xij...(?.HkB.}(...M.........Z.G}.yxk.....................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\codecs\is-V9E7A.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):548940
                                            Entropy (8bit):6.292254057074961
                                            Encrypted:false
                                            SSDEEP:12288:qM7FGk3xrXrzfN3IBk0hLwPiHRE6sHjFr12d9TNcKKKKYYYYYHZ+dKixv65fxg0:qM7FGkB77N3IWqLwPixE6sHjFUdVNcKx
                                            MD5:284B66AA31D1B4117141BC4DB6B9210C
                                            SHA1:2A7B870F34B15643CBE98CC28224250ECDB0E2EF
                                            SHA-256:0EE3AE8F2FF1324BF4F153AE3BD4FE20505A2DD3049ABC5F23DC4F378D578C81
                                            SHA-512:EE01E967EF37D7B3358CB57632ED30388CD1A27F1933238AE9B42D2CFA632BB6DC4A9BC425D153370B5BD672ABE7074C2A0BB6E8FA1C0431F320CFC237C55EF2
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........C..C..C..!..A..,..@..8..B.....G..,..F..,..@..C..X..C../.....B..E..A..E..J.....B..RichC..........................PE..L....Vr@...........!.........@......c..............`............................................................................<....... ........................ ..p...................................................l............................text...*........................... ..`.text1.............................. ..`.rdata........... ..................@..@.data............ ..................@....data1...(.......0..................@....rsrc... ............ ..............@..@.reloc...(.......0...0..............@..B........................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\is-CL5VE.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):272896
                                            Entropy (8bit):6.523120738605816
                                            Encrypted:false
                                            SSDEEP:6144:P/pb95LIbfMWZskFONizSLLsCn3cEFMWiFtNF7R5Lgr1A09:PBHEML25BkA09
                                            MD5:78A2145443852E9297D38D70C88AEC06
                                            SHA1:AC0F6FC47DF474C17792F6EBE3C568EE15B52431
                                            SHA-256:A3061F0938B309D24524A03A4C7356C396B5DE48F3BB70A13DC5AE2221DFC7CA
                                            SHA-512:F07B3588AB555B8D4ED0C7566C70C48F2B9A110D206CB796C384C2196111016171A79001EFC6E829AC1C4E462D7CF2BB7C363BA4A698E6B2021E4208CF0186BD
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....X5...........!.....H..........0........`.....b.........................p......................................P....;... ..(....0.......................@..h&..................................................T"..,............................text.../F.......H.................. ..`.rdata../]...`...^...X..............@..@.data...@P.......8..................@....idata..R.... ......................@....rsrc........0......................@..@.reloc...(...@...*..................@..B................................................................................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-37145.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):61440
                                            Entropy (8bit):5.3597251485932915
                                            Encrypted:false
                                            SSDEEP:768:wTijBJRj+KSZhWJrFwW/Rwu177rwnfF0PunStYoA0I89xus+mx7y+:wTijBJRyNZhWJHRwkwf2WSrIIw
                                            MD5:52E1316205C14C5DE7F16DB53C18052D
                                            SHA1:3F2EF67E5BF18DCC7ACAD84C9A9AD8B5554F1BDD
                                            SHA-256:9D61A772F8FF721F4E6F03403CC3A9A1C97347E700364975B8D4D67DEBAEBC54
                                            SHA-512:142765AEB5A4259C00628833E58881D9B008AE548AC44F982533048563B950742772B9589E45D68EAF64FB10DCE08C07AC857E94C2641E462A95C3CBBCA74E9E
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c@..'!.W'!.W'!.W\=.W$!.W'!.W-!.WE>.W#!.W'!.W !.W.=.W.!.W.'.W&!.W!..W)!.W...W&!.WRich'!.W................PE..L...m.=...........!.........P....................8`....................................................................e.......P.......8............................................................................................................text...`........................... ..`.rdata........... ..................@..@.data...............................@....rsrc...8...........................@..@.reloc..T...........................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-6LQ0G.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):61493
                                            Entropy (8bit):5.5587880881632845
                                            Encrypted:false
                                            SSDEEP:768:qvmCzyQ2W+V028BTjy5U/Kx9nELA0RmI6RleZDG2tqZrBht0wx:aD3+V028BTjM9EsXbMGv/t0wx
                                            MD5:3F823B4A0072A63493D5520ABA54E667
                                            SHA1:F799505F167224B375D7CF46541E419BC336AEF0
                                            SHA-256:193618D489E76BEF9BBBCEA7369721170874AFE2D6722A156CE70914E49963C8
                                            SHA-512:4C545BD7567361B3B3A5D8E01CCA49BD21FB7E74082955E59C346728F47BB27AD710051CF3EE6FED629601E52DC17D91F9A61656F7C96B4DC057EB7E656BC73F
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........cu....V...V...V...V...V...V...V...V...V...V...V...V...V...V...V...V...V.!.V...VV..V...V.!.V...Vn".V...VRich...V........PE..L...YWr@...........!.........P.....................`................................................................`...{.......P...............................H...................................................................................text..."........................... ..`.rdata........... ..................@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-CMQSS.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):262204
                                            Entropy (8bit):6.472369609358146
                                            Encrypted:false
                                            SSDEEP:6144:hODHwsiXglutYxyv3wPwLjgG2V/hakgl7Tr23znV/ym2v/KGYg6oX3q/x20SvC2t:hODHwsiXglutYxyv3wPwLj92V/hakgll
                                            MD5:420ACE51F164B0951A993EE8C9A71DB9
                                            SHA1:2EFA3807A850332CDDF3B2F5D99CD50ADE195970
                                            SHA-256:3CD05F6A3DBD061BB90C50770F8B2F1C9DE73EEDEBC14BDACCF7AFCF3A70A0D9
                                            SHA-512:ADC3E476453228C706768E73DC17361A9B4DDA14DC2BCBE6BCCC9CE1C55B4BDF623AE769E34FF2023AF68524402FD270494AEB68B3500049D4E57C1A1EB7AAAC
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........\>D\=P.\=P.\=P.'!\.Q=P..!^.^=P.3"[.]=P.3"Z.Y=P.3"T.^=P.>"C.[=P.\=Q..=P.Z.Z.]=P..;V.]=P.Z.[..=P...T.]=P.Rich\=P.........PE..L....Vr@...........!.....P...........Q.......`.....`....................................................................O......P....................................a...............................................`...............................text...eC.......P.................. ..`.rdata...D...`...P...`..............@..@.data...h........ ..................@....rsrc...............................@..@.reloc.. ........ ..................@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-DBGJC.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):40960
                                            Entropy (8bit):4.516940717479657
                                            Encrypted:false
                                            SSDEEP:384:QcI3vT+ceoy8tbnSEJK+NSmLedj96qrr0m6akPVKdo:kr+Ky8tbn3JK+NSIed5Drrfq6
                                            MD5:CC63DC6E942B646B6052E02C1C7142FB
                                            SHA1:D5FEB9C48B68BCE7B58EA86EC00C7238B8128C48
                                            SHA-256:B98685C985B325CAA4208263D7DFEA2E66C76951BAB313C87CF5F0AD2C17D063
                                            SHA-512:402D8F12206997FCF1285CE409CD2EB2DACAB7C10B9BAB8D57E443E4A074A79E051DAA12B7872608AD774CB6D5C779444F933C180A87EEE4A75B1147AAFAFF39
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........#.vp.vp.vp..zp.vp.wp.vp..ep.vp.vp.vpT.tp.vp..pp.vp.}p.vp,.rp.vpRich.vp................PE..L.....=...........!.....@...P......pM.......P....;`................................................................0a..g...X_..<.......x............................................................................P..X............................text....>.......@.................. ..`.rdata.......P... ...P..............@..@.data........p.......p..............@....rsrc...x...........................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-JLV0H.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):49152
                                            Entropy (8bit):4.6602334406323
                                            Encrypted:false
                                            SSDEEP:768:6m6CjTBuCjDr0M6L32+cSsnbInD1tmSOlX/UxbV:zzVuCjDrLy31vGbIpqCb
                                            MD5:791A9D804A7430D1170D39C0BCDAD904
                                            SHA1:2A0D7AACDD0C6D0580736E01642C478D239255CB
                                            SHA-256:57ABD3EE33952EA698AD82029F0397796221A82DEB2F42050A9CC357245D186D
                                            SHA-512:D2C15B34792474DA8BE3470147F888C184ECACF2E8A2E0A739ADC85FF4B0314771553EFE6EAD966C9C5D4C1F5E565266132D9F334D13AC7DF1501BAAD8FE2257
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......~.^h:.0;:.0;:.0;A.<;;.0;:.1;0.0;X.#;>.0;:.0;<.0;..2; .0;..6;;.0;<.;;5.0;.4;;.0;Rich:.0;................PE..L.....=...........!.....`...P......@i.......p....9`....................................................................g....~..<...............................h....................................................p..L............................text....Z.......`.................. ..`.rdata..'....p... ...p..............@..@.data...h...........................@....rsrc...............................@..@.reloc..:...........................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\plugins\is-M0I4H.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):45056
                                            Entropy (8bit):4.853195739293399
                                            Encrypted:false
                                            SSDEEP:768:ua+EuN+JpcTEMIBuk+vS+r/ktVEgr+9otjj:BuNSEhD6+r8t+9oF
                                            MD5:D5D93E823FA7258D34DFFA6D15AFA59F
                                            SHA1:E9FCD7ED97D659A09FD64DCCFF8DAB5749F1C7A9
                                            SHA-256:95CF864D738A9765B1295BA5CA1B653EBF3C6E325B5AF0785F1B46CE05D688F4
                                            SHA-512:657D5801B9A37F4D2234C6DB844EB4E1CA30EFB5956CCEDA0118C5D44D6B1E1EE49AC26B3B53E18DE0C0EE6579B19D872999B6E33B1D8DC147667948EA28C86B
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........".#.C.p.C.p.C.p._.p.C.p.C.p.C.p.\.p.C.p.C.p.C.pl_.p.C.p.`.p.C.p,E.p.C.p.`.p.C.p.c.p.C.pRich.C.p........................PE..L.....=...........!.....`...@......P`.......p....:`................................................................`~..g...t|..<............................... ....................................................p..\............................text....Q.......`.................. ..`.rdata.......p.......p..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1DN8R.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):86110
                                            Entropy (8bit):5.959546455793157
                                            Encrypted:false
                                            SSDEEP:1536:n0U/KLLKYqrTZ2g9Vlrpnu9CoU5Y386dmOhHnvzzeVe1:n0U/0LKYWr6CR5iHgOhHnrgm
                                            MD5:09DE48D387A3C0CD5B03195DE94784B9
                                            SHA1:BBFC1DE0DB0C33463345A34BE9CF8AC1EC6D81A9
                                            SHA-256:712618303BCB1932597C28C9F99AAB18E232B5F019C0748FFB697C08FEBD9307
                                            SHA-512:5B4C376238BF2711D4A9DAD127F9BBC39FCD820835E4B9AA2A8D2B9FDAEC6A0CF714C3744AFF7A311842C40DAED629869E5E65F3FA0A8462D5944DBDFBDCC5DB
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........MU...U...U.......W.......T...:...P...:...W...:...T...7...V...U...~.......T...S...G.......T...RichU...................PE..L....Ur@...........!.........P....................A`.........................P......................................P...........<....0.......................@..<....................................................................................text...@........................... ..`.rdata........... ..................@..@.data...8.... ....... ..............@....rsrc........0.......0..............@..@.reloc..f....@.......@..............@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-1KUPI.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):49249
                                            Entropy (8bit):5.258823116095141
                                            Encrypted:false
                                            SSDEEP:384:t0Tt0w1OmGwiYpQGviUCpa7YXF+XCPbzF/G4sTQ0PHxamprbPTz5ogjEr:t0ZlsUb7YX1B/PEHUmwr
                                            MD5:1C7985146A1ECA9FA0008C9E02790791
                                            SHA1:88E9F981CCB0778D8F7CF61B5FABEF23E3CE7C95
                                            SHA-256:5017F5D6A4902CECAA64FCF78F57A6939F6550DA3D1C0FBADE732D019DA68619
                                            SHA-512:17AF6BBA3125D6F3003EF9EACFC64B1DA86808AA975BB5CE007B01012325C175EB566A13C160F4DB42725DBE705F2E0B6959D9631764204323187F7A2CCE91F6
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........=bOZ\..Z\..Z\..!@..[\...@..[\..5C.._\..5C..X\..8C..Y\..Z\..x\...Z..[\..\...U\...|..[\..RichZ\..........................PE..L....Ur@...........!.....`...P......yb.......p....9`............................................................................<...................................pp...............................................p..l............................text...._.......`.................. ..`.rdata..=....p... ...p..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-4922F.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):45139
                                            Entropy (8bit):4.788372838984784
                                            Encrypted:false
                                            SSDEEP:384:oTFr8+Rbz7lJxYqmfbHWwfCjTndNlXVCr0PCzHCrbPTz5ogqcj:wh8oDl+H36TnlorECW
                                            MD5:FBFB901208E79DB5F33EB7F89F8F15D3
                                            SHA1:E671CDFEA50EE342049D74D2939F874CBA4AE2E6
                                            SHA-256:225B125DDB986E6ABB1F134E6B428B106FE16D102C65AA61BBD5FD95D67FA6A9
                                            SHA-512:99B5C0F9C464A2C464F9A5966DDB752D741D5C99F18C5122148AEF43B1D11F3AC2A1AE60A54AAD5C78320F86138C9581E22520F197741AF881F394CC4EDE76E6
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........8.W.VSW.VSW.VS,.ZSV.VS..XSV.VS8.\SR.VS8.RSU.VS5.EST.VSW.WSs.VS..PSV.VSQ.]SY.VS..RSV.VSRichW.VS........PE..L....Ur@...........!.....P...P.......B.......`....;`................................................................0r.......o..<....................................`...............................................`..t............................text....L.......P.................. ..`.rdata.......`... ...`..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................
                                            C:\Program Files\Common Files\FlashIntegro\ActiveX\x32\RMBin\tools\is-64E3N.tmp
                                            Process:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            File Type:Unknown
                                            Category:dropped
                                            Size (bytes):327767
                                            Entropy (8bit):7.692893011603594
                                            Encrypted:false
                                            SSDEEP:6144:D+cIfk6us3zzi+oiTAhBiD19rzaXTRu27U6evL8wUK7k2V3aqumtvTmzITX9y6AD:D+cIfkM3niXQAPcvaXTRZboLrjn1DxE5
                                            MD5:E9C106CD21AE3F195C9D7D6B959C0051
                                            SHA1:3488905B9420204322B5551FC234B86631CF40E3
                                            SHA-256:637DE17363E08DE7046AA314102856163259E88C054872F411BB0D7B8455BFD4
                                            SHA-512:0573AFD9492130FBD8B2538EBE1DCCC9C493EA1FFD9B1BA942431434DD377BD9F697BC6D42473957D7D7E97C8285860223C31B4E5A10CD5A8E2667F60C4B5F20
                                            Malicious:false
                                            Reputation:low
                                            Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........y.rP..!P..!P..!+..!R..!...!Q..!?..!U..!?..!R..!2..!S..!P..!w..!V;.!W..!...!Q..!V;.!_..!.8.!Q..!RichP..!................PE..L....Ur@...........!.........P......!.............1`............................................................................<....................................................................................................................text............................... ..`.rdata..(........ ..................@..@.data...$...........................@....rsrc...............................@..@.reloc..`...........................@..B................................................................................................................................................................................................................................................................................................................

                                            Static File Info

                                            No static file info

                                            Network Behavior

                                            No network behavior found

                                            Code Manipulations

                                            Statistics

                                            Behavior

                                            Click to jump to process

                                            System Behavior

                                            General

                                            Start time:10:19:59
                                            Start date:03/12/2020
                                            Path:C:\Windows\SysWOW64\cmd.exe
                                            Wow64 process (32bit):true
                                            Commandline:C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1' > cmdline.out 2>&1
                                            Imagebase:0xbd0000
                                            File size:232960 bytes
                                            MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            General

                                            Start time:10:20:00
                                            Start date:03/12/2020
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff6b2800000
                                            File size:625664 bytes
                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            General

                                            Start time:10:20:00
                                            Start date:03/12/2020
                                            Path:C:\Windows\SysWOW64\wget.exe
                                            Wow64 process (32bit):true
                                            Commandline:wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'http://www.videosoftdev.com/services/download.aspx?ProductID=1'
                                            Imagebase:0x400000
                                            File size:3895184 bytes
                                            MD5 hash:3DADB6E2ECE9C4B3E1E322E617658B60
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            General

                                            Start time:10:21:25
                                            Start date:03/12/2020
                                            Path:C:\Users\user\Desktop\download\video_editor_x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\Users\user\Desktop\download\video_editor_x64.exe'
                                            Imagebase:0x400000
                                            File size:89870912 bytes
                                            MD5 hash:10B5CDAB87CF1825DF1134F16DFF7062
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:Borland Delphi
                                            Antivirus matches:
                                            • Detection: 5%, Metadefender, Browse
                                            • Detection: 0%, ReversingLabs
                                            Reputation:low

                                            General

                                            Start time:10:21:26
                                            Start date:03/12/2020
                                            Path:C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp
                                            Wow64 process (32bit):true
                                            Commandline:'C:\Users\user\AppData\Local\Temp\is-M4I27.tmp\video_editor_x64.tmp' /SL5='$1F0056,89355248,121344,C:\Users\user\Desktop\download\video_editor_x64.exe'
                                            Imagebase:0x400000
                                            File size:1188528 bytes
                                            MD5 hash:B2EAFA8C7E4EAEB302AA4AB062B17EBA
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:Borland Delphi
                                            Antivirus matches:
                                            • Detection: 3%, Metadefender, Browse
                                            • Detection: 2%, ReversingLabs
                                            Reputation:low

                                            General

                                            Start time:10:22:38
                                            Start date:03/12/2020
                                            Path:C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' /install /passive /norestart
                                            Imagebase:0xc80000
                                            File size:15001520 bytes
                                            MD5 hash:1E7BD6790391B5B710C6372AB2042351
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            General

                                            Start time:10:22:39
                                            Start date:03/12/2020
                                            Path:C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\Windows\Temp\{B430B43B-6E75-4804-BCFD-37DBF80ECCF7}\.cr\vcredist_x64.exe' -burn.clean.room='C:\Users\user\AppData\Local\Temp\is-9NTLG.tmp\vcredist_x64.exe' -burn.filehandle.attached=580 -burn.filehandle.self=564 /install /passive /norestart
                                            Imagebase:0xf20000
                                            File size:647704 bytes
                                            MD5 hash:1D7599C4A31B82E70308C022E9494011
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Antivirus matches:
                                            • Detection: 2%, ReversingLabs
                                            Reputation:low

                                            General

                                            Start time:10:22:41
                                            Start date:03/12/2020
                                            Path:C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\Windows\Temp\{CEE95A1C-E22B-4560-8B03-72FA4E103FF8}\.be\VC_redist.x64.exe' -q -burn.elevated BurnPipe.{AEC565AB-0FED-47E7-88D9-B941D20CF512} {87809E35-81C0-47B4-86E7-066B690A99EC} 5088
                                            Imagebase:0x150000
                                            File size:647704 bytes
                                            MD5 hash:1D7599C4A31B82E70308C022E9494011
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Antivirus matches:
                                            • Detection: 0%, Metadefender, Browse
                                            • Detection: 0%, ReversingLabs
                                            Reputation:low

                                            General

                                            Start time:10:22:56
                                            Start date:03/12/2020
                                            Path:C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /burn.runonce
                                            Imagebase:0xa90000
                                            File size:647704 bytes
                                            MD5 hash:1D7599C4A31B82E70308C022E9494011
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Antivirus matches:
                                            • Detection: 0%, Metadefender, Browse
                                            • Detection: 0%, ReversingLabs
                                            Reputation:low

                                            General

                                            Start time:10:22:57
                                            Start date:03/12/2020
                                            Path:C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
                                            Imagebase:0xa90000
                                            File size:647704 bytes
                                            MD5 hash:1D7599C4A31B82E70308C022E9494011
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            General

                                            Start time:10:22:58
                                            Start date:03/12/2020
                                            Path:C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe
                                            Wow64 process (32bit):true
                                            Commandline:'C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.clean.room='C:\ProgramData\Package Cache\{40d3fee2-b257-46c2-bdc0-cb1088d97327}\VC_redist.x64.exe' -burn.filehandle.attached=600 -burn.filehandle.self=596 /passive /norestart /burn.log.append 'C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20201203102239.log' /install
                                            Imagebase:0xa90000
                                            File size:647704 bytes
                                            MD5 hash:1D7599C4A31B82E70308C022E9494011
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:low

                                            Disassembly

                                            Code Analysis

                                            Reset < >